This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

fbstatic-a.akamaihd.net [Closed]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help me get rid of   fbstatic-a.akamaihd.net.

 

I can't access Facebook and I fear it is causing other computer issues very soon. Researched online, but it is out of my scope to fix.

 

When Tom Coyote first began I was fortunate to receive help with a major problem. I'm thankful someone is still here willing to help regular computer users that can be trusted.

Hello Nala and welcome back to the WTT forum.

 

fbstatic-a.akamaihd.net is trustworthy and used by Facebook, (and other large websites), to speed up downloads.

 

Your problem could be Facebook-related or you may need to clear your browser cache and reset your browser settings.

 

Please let me know if that has helped and if you still have a problem we'll run some scans and have a look at other possibilities.

 

Satchfan

I cleared the browser cache. Did not reset the browser settings because of password etc. loss until I know I must do this.

 

After I posted my first board message, I used the tools provided by WTT to obtain the logs for your review. This instantly eliminated the fbstatic-a.akamaihd.net visible scrolling bar from the bottom left corner of the Facebook log in page. I was able to log into Facebook with no further issue and my system has been running much faster since.

 

Here are log results. I am so thankful to have your help with this issue. Please help me rid my system from anything you deem threatening.

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version:02-08-2015 01
Ran by [removed] (2015-08-05 00:01:36)
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1766275910-2450894708-632072239-500 - Administrator - Disabled)
Guest (S-1-5-21-1766275910-2450894708-632072239-501 - Limited - Disabled)
Janelle (S-1-5-21-1766275910-2450894708-632072239-1000 - Administrator - Enabled) => C:\Users\Janelle
Mary (S-1-5-21-1766275910-2450894708-632072239-1002 - Administrator - Enabled) => C:\Users\Mary
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Activation Assistant for the 2007 Microsoft Office suites (HKLM\…\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
ActiveCheck component for HP Active Support Library (Version: 3.0.0.2 - Hewlett-Packard) Hidden
Adobe Flash Player 18 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader 8 (HKLM\…\{AC76BA86-7AD7-1033-7B44-A80000000002}) (Version: 8.0.0 - Adobe Systems Incorporated)
AppCore (Version: 1 - Symantec Corporation) Hidden
AV (Version: 1 - Symantec Corporation) Hidden
ccCommon (Version: 106.2.0.21 - Symantec) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.01 - Piriform)
Cisco Connect (HKLM\…\Cisco Connect) (Version: 1.2.10104.2 - Cisco Consumer Products LLC)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
ESU for Microsoft Vista (HKLM\…\{88A548E6-4B09-43E7-AD55-3C7D1B37706D}) (Version: 2.0.2.1 - Hewlett-Packard)
Google Chrome (HKLM\…\Google Chrome) (Version: 44.0.2403.130 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\…\CNXT_MODEM_HDA_HSF) (Version:  - )
HP Active Support Library (HKLM\…\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}) (Version: 3.1.9.1 - Hewlett-Packard)
HP Customer Experience Enhancements (HKLM\…\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.1.0.2278 - Hewlett-Packard)
HP Easy Setup - Frontend (HKLM\…\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.1.0.2279 - Hewlett-Packard)
HP Help and Support (HKLM\…\{9061CEF2-51F5-42C9-8A70-9ED351C6597A}) (Version: 1.1.0 - Hewlett-Packard)
HP Pavilion Webcam Driver for Vista v061.001.00005 (HKLM\…\{5CA81D12-9EC2-4082-972B-43ECA63F41F2}) (Version: 061.001.00005 - Chicony)
HP Photosmart Essential 2.0 (HKLM\…\HP Photosmart Essential) (Version: 2.0 - HP)
HP Quick Launch Buttons 6.20 B1 (HKLM\…\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.20 B1 - Hewlett-Packard)
HP QuickPlay 3.2 (HKLM\…\{45D707E9-F3C4-11D9-A373-0050BAE317E1}) (Version:  - )
HP Total Care Advisor (HKLM\…\{F6B29003-A078-4491-AFBE-62EFB6CFFE19}) (Version: 1.1.19 - Hewlett-Packard)
HP Update (HKLM\…\{612F4E20-3661-4D44-AD79-823F1B613FB3}) (Version: 5.002.008.001 - Hewlett-Packard)
HP User Guides 0041 (HKLM\…\{AF0B98A9-F7E2-4FF5-88C7-7960EB91752B}) (Version: 1.03.0002 - Hewlett-Packard)
HP Wireless Assistant (HKLM\…\{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}) (Version: 3.00 H3 - Hewlett-Packard)
HPAsset component for HP Active Support Library (Version: 3.0.2.2 - Hewlett-Packard) Hidden
HPNetworkAssistant (HKLM\…\{228C6B46-64E2-404E-898A-EF0830603EF4}) (Version: 1.1.70 - Hewlett-Packard.)
Internet Explorer (Enable DEP) (HKLM\…\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version:  - )
IrfanView (remove only) (HKLM\…\IrfanView) (Version:  - )
Java 8 Update 31 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Java(TM) SE Runtime Environment 6 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0160000}) (Version: 1.6.0.0 - Sun Microsystems, Inc.)
LightScribe  1.4.136.1 (Version: 1.4.136.1 - http://www.lightscribe.com)Hidden
LiveUpdate 3.2 (Symantec Corporation) (HKLM\…\LiveUpdate) (Version: 3.2.0.41 - Symantec Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Fix it Center (HKLM\…\{B7588D45-AFDC-4C93-9E2E-A100F3554B64}) (Version: 1.0.0100 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
Move Media Player (HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Move Media Player) (Version:  - Move Networks)
MSCU for Microsoft Vista (HKLM\…\{3FFB3B34-D639-4384-9AE9-DDE58430D86F}) (Version: 1.0.1.1 - Hewlett-Packard)
MSRedist (Version: 1.0.0.0 - Symantec Corporation) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM\…\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM\…\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
muvee autoProducer 6.0 (HKLM\…\{0BFC200F-C45D-4271-AF34-4CA969225DEB}) (Version: 6.00.050 - muvee Technologies)
My HP Games (HKLM\…\WildTangent hplaptop Master Uninstall) (Version: HPLAP0503 - WildTangent)
Norton AntiVirus (Version: 14.2.0.29 - Symantec Corporation) Hidden
Norton Confidential Browser Component (Version: 1.5.0.29 - Symantec Corporation) Hidden
Norton Confidential Web Protection Component (Version: 1.5.0.29 - Symantec Corporation) Hidden
Norton Internet Security (Symantec Corporation) (HKLM\…\SymSetup.{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}) (Version: 10.2.0.30 - Symantec Corporation)
Norton Internet Security (Version: 10.1.0 - Symantec Corp.) Hidden
Norton Internet Security (Version: 10.2.0.30 - Symantec Corporation) Hidden
Norton Protection Center (Version: 2007.2.0.22 - Symantec Corporation) Hidden
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.4 - NVIDIA Corporation)
PMB (HKLM\…\{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}) (Version: 5.5.00.11260 - Sony Corporation)
PSSWCORE (Version: 2.00.5000 - Hewlett-Packard) Hidden
QuickTime 7 (HKLM\…\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Rhapsody (HKLM\…\Rhapsody) (Version:  - )
Rhapsody Player Engine (HKLM\…\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}) (Version: 1.0.604 - RealNetworks)
Roxio Creator Audio (HKLM\…\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.4.0 - Roxio)
Roxio Creator Basic v9 (HKLM\…\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.4.0 - Roxio)
Roxio Creator Copy (HKLM\…\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio)
Roxio Creator Data (HKLM\…\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio)
Roxio Creator EasyArchive (HKLM\…\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio)
Roxio Creator Tools (HKLM\…\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio)
Roxio Express Labeler 3 (HKLM\…\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 3.2.1 - Roxio)
Roxio MyDVD Basic v9 (HKLM\…\{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}) (Version: 9.0.551 - Roxio)
SPBBC 32bit (Version: 3.2.0.21 - Symantec Corporation) Hidden
Symantec Real Time Storage Protection Component (Version: 10.1.4.2 - Symantec Corporation) Hidden
SymNet (Version: 7.2.0.15 - Symantec Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 11.0.7.0 - Synaptics)
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{e3e02f12-2adb-478c-8742-5f0819f9f0f4}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{e473a65c-8087-49a3-affd-c5bc4a10669b}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{f4c28532-b9d0-4950-a2df-e83f9929242b}\InprocServer32 -> C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll (MindSpark)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{fc345d4c-b8f4-4674-bff7-3c37d2e535ee}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{fd6484ed-ebe3-4c3d-938a-8238003b41b7}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
 
==================== Restore Points =========================
 
11-07-2015 11:54:01 Scheduled Checkpoint
12-07-2015 16:17:46 Windows Update
15-07-2015 18:26:33 Scheduled Checkpoint
15-07-2015 18:56:37 Windows Update
17-07-2015 09:47:57 Scheduled Checkpoint
18-07-2015 19:57:33 Windows Update
23-07-2015 19:19:33 Windows Update
28-07-2015 19:12:02 Windows Update
31-07-2015 23:01:09 Windows Update
31-07-2015 23:32:16 Restore Operation
01-08-2015 10:28:49 Restore Operation
01-08-2015 12:40:01 Windows Update
04-08-2015 18:59:22 AA11
04-08-2015 20:10:52 Restore Operation
04-08-2015 20:33:03 Restore Operation
04-08-2015 21:23:12 Restore Operation
04-08-2015 23:05:07 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 03:23 - 2006-09-18 14:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0D584032-436C-4E12-90F9-BC136FA4EE56} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd)
Task: {1F014C22-11EA-4585-9D8F-C4363BB38751} - System32\Tasks\PC Unleashed => C:\Program Files\PC Unleashed Online\PC Unleashed\pcu.exe [2012-07-19] (PC Unleashed Online, Inc.)
Task: {3062B010-09B0-4171-9967-935DF58F28BA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-04] (Adobe Systems Incorporated)
Task: {608DCA47-66AA-45F7-B64A-47E8B04B3DBB} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\OSUpgrade => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunHandleOSUpgrade
Task: {610C123E-E75B-4FFB-A9EB-14B2E4251660} - System32\Tasks\{44E094D7-1DC5-4FCC-A3DC-A2E4FF5F4D76} => C:\Program Files\Skype\Phone\Skype.exe
Task: {6ABC175F-3949-40B0-B045-58BD6ACEE499} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-27] (Google Inc.)
Task: {6C7BCA72-D959-4C1C-9D2F-9CB4935D55D5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-27] (Google Inc.)
Task: {A388C444-1D6E-4259-AE16-83E1E1C54246} - System32\Tasks\{C6E2C9FA-2FB6-4B9A-9086-ABE7FF602C1F} => pcalua.exe -a C:\PROGRA~1\Zynga\UNWISE.EXE -c   /U C:\PROGRA~1\Zynga\INSTALL.LOG
Task: {AAA9C09D-8453-41C7-BA18-93DBFCF28B09} - System32\Tasks\HPCeeScheduleForJanelle => C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-03-23] (Hewlett-Packard)
Task: {C5C00E62-28DE-4166-B95D-11151B0A6BA7} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\ConfigExec => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunCollectConfigurationInfo
Task: {C81D473C-C0C4-4127-8516-1365D7FCF574} - System32\Tasks\HP Health Check => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09] (Hewlett-Packard)
Task: {D395CBD8-97A9-43F0-BC9E-B61BF670F395} - System32\Tasks\{DEC880E0-57F8-492C-A84D-6F4DD5CD60AE} => pcalua.exe -a C:\Windows\system32\javacpl.cpl -c Java
Task: {F9C398E4-49F1-4C82-98C5-324659342CFB} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForJanelle.job => C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe
Task: C:\Windows\Tasks\PC Unleashed.job => C:\Program Files\PC Unleashed Online\PC Unleashed\pcu.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2007-05-31 02:21 - 2007-03-28 17:45 - 00270431 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
2007-05-31 02:21 - 2007-03-28 17:45 - 00233573 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00032768 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00114783 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00339968 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll
2007-05-31 02:20 - 2007-03-28 17:44 - 00061440 _____ () C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll
2007-05-16 11:43 - 2007-05-16 11:43 - 00677432 ____R () C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\Web\Wallpaper\img34.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{964F56F1-41AD-446F-B77E-82B071B28749}] => (Allow) C:\Program Files\HP\QuickPlay\QP.exe
FirewallRules: [{95E87BAB-D6F1-493C-AF4A-24B8CD4E995B}] => (Allow) C:\Program Files\HP\QuickPlay\QPService.exe
FirewallRules: [{748AB940-A937-49CF-B0BE-DDE3197C8C3F}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{B33D8B4B-4DF8-4E93-9CF8-80A110094D07}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{C6FFCC69-5FEF-42B6-8093-109073549692}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{51134F5C-05F7-485C-A9F7-8C3A7AF53B8B}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{825DD0AB-F15C-4AE4-879F-02D0098A5DBA}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{2F81CA3D-A256-4BCF-8C72-A9B4ECE9CD72}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [TCP Query User{81F7F573-2E0E-4F6E-9AF2-4D32BC5E6737}C:\program files\hp games\wheel of fortune\wheel of fortune.exe] => (Block) C:\program files\hp games\wheel of fortune\wheel of fortune.exe
FirewallRules: [UDP Query User{0FF5FE79-1718-4D5F-843D-934158FDF2B9}C:\program files\hp games\wheel of fortune\wheel of fortune.exe] => (Block) C:\program files\hp games\wheel of fortune\wheel of fortune.exe
FirewallRules: [{6970BDF2-9C56-4A2C-AF78-474954847B5C}] => (Allow) LPort=80
FirewallRules: [{A0F5CD9E-13EC-4D38-B369-0A5C2513BB22}] => (Allow) LPort=80
FirewallRules: [{4677590A-FFC7-4A3C-B305-9EC8888C3FCE}] => (Allow) LPort=80
FirewallRules: [{5DD5967B-6554-4E2D-8D6E-AEB6A5693BE0}] => (Allow) C:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exe
FirewallRules: [{82381A18-4994-4A86-9AC4-0D553E263286}] => (Allow) C:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exe
FirewallRules: [{0440192A-FA1C-429F-8FC8-8C216DA976F0}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{6A6FEB30-CF72-4331-BF5A-93AED3262624}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
 
System errors:
=============
Error: (08/04/2015 10:17:31 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: KtmRm for Distributed Transaction Coordinator
 
Error: (08/04/2015 10:14:25 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000ShellHWDetection
 
Error: (08/04/2015 10:11:00 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: CyberLink Task Scheduler (CTS)CyberLink Background Capture Service (CBCS)%%1070
 
Error: (08/04/2015 10:10:59 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: CyberLink Background Capture Service (CBCS)
 
Error: (08/04/2015 10:09:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: MyFunCardsService%%3
 
Error: (08/04/2015 10:09:05 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:08:04 PM on 8/4/2015 was unexpected.
 
Error: (08/04/2015 10:08:54 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: The default transaction resource manager on volume D: encountered a non-retryable error and could not start.  The data contains the error code.
 
Error: (08/04/2015 09:39:12 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: KtmRm for Distributed Transaction Coordinator
 
Error: (08/04/2015 09:31:13 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: CyberLink Task Scheduler (CTS)CyberLink Background Capture Service (CBCS)%%1070
 
Error: (08/04/2015 09:31:13 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: CyberLink Background Capture Service (CBCS)
 
 
Microsoft Office:
=========================
 
CodeIntegrity:
===================================
  Date: 2014-01-01 19:46:34.373
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:46:33.921
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:46:33.546
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:46:33.125
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:45:55.890
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:45:55.311
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:45:54.857
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:45:54.406
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-12-03 17:49:39.111
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-12-03 17:49:38.730
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: AMD Turion™ 64 X2 Mobile Technology TL-60
Percentage of memory in use: 56%
Total physical RAM: 1981.87 MB
Available physical RAM: 860.04 MB
Total Virtual: 4214.26 MB
Available Virtual: 2784.87 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:140.85 GB) (Free:47.61 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (HP_RECOVERY) (Fixed) (Total:8.2 GB) (Free:0 GB) NTFS ==>[system with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 149.1 GB) (Disk ID: C6450749)
Partition 1: (Active) - (Size=140.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=8.2 GB) - (Type=07 NTFS)
 
==================== End of log ============================
 
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version:02-08-2015 01
Ran by [removed] (2015-08-05 00:01:36)
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1766275910-2450894708-632072239-500 - Administrator - Disabled)
Guest (S-1-5-21-1766275910-2450894708-632072239-501 - Limited - Disabled)
Janelle (S-1-5-21-1766275910-2450894708-632072239-1000 - Administrator - Enabled) => C:\Users\Janelle
Mary (S-1-5-21-1766275910-2450894708-632072239-1002 - Administrator - Enabled) => C:\Users\Mary
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Activation Assistant for the 2007 Microsoft Office suites (HKLM\…\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
ActiveCheck component for HP Active Support Library (Version: 3.0.0.2 - Hewlett-Packard) Hidden
Adobe Flash Player 18 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader 8 (HKLM\…\{AC76BA86-7AD7-1033-7B44-A80000000002}) (Version: 8.0.0 - Adobe Systems Incorporated)
AppCore (Version: 1 - Symantec Corporation) Hidden
AV (Version: 1 - Symantec Corporation) Hidden
ccCommon (Version: 106.2.0.21 - Symantec) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.01 - Piriform)
Cisco Connect (HKLM\…\Cisco Connect) (Version: 1.2.10104.2 - Cisco Consumer Products LLC)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
ESU for Microsoft Vista (HKLM\…\{88A548E6-4B09-43E7-AD55-3C7D1B37706D}) (Version: 2.0.2.1 - Hewlett-Packard)
Google Chrome (HKLM\…\Google Chrome) (Version: 44.0.2403.130 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\…\CNXT_MODEM_HDA_HSF) (Version:  - )
HP Active Support Library (HKLM\…\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}) (Version: 3.1.9.1 - Hewlett-Packard)
HP Customer Experience Enhancements (HKLM\…\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.1.0.2278 - Hewlett-Packard)
HP Easy Setup - Frontend (HKLM\…\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.1.0.2279 - Hewlett-Packard)
HP Help and Support (HKLM\…\{9061CEF2-51F5-42C9-8A70-9ED351C6597A}) (Version: 1.1.0 - Hewlett-Packard)
HP Pavilion Webcam Driver for Vista v061.001.00005 (HKLM\…\{5CA81D12-9EC2-4082-972B-43ECA63F41F2}) (Version: 061.001.00005 - Chicony)
HP Photosmart Essential 2.0 (HKLM\…\HP Photosmart Essential) (Version: 2.0 - HP)
HP Quick Launch Buttons 6.20 B1 (HKLM\…\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.20 B1 - Hewlett-Packard)
HP QuickPlay 3.2 (HKLM\…\{45D707E9-F3C4-11D9-A373-0050BAE317E1}) (Version:  - )
HP Total Care Advisor (HKLM\…\{F6B29003-A078-4491-AFBE-62EFB6CFFE19}) (Version: 1.1.19 - Hewlett-Packard)
HP Update (HKLM\…\{612F4E20-3661-4D44-AD79-823F1B613FB3}) (Version: 5.002.008.001 - Hewlett-Packard)
HP User Guides 0041 (HKLM\…\{AF0B98A9-F7E2-4FF5-88C7-7960EB91752B}) (Version: 1.03.0002 - Hewlett-Packard)
HP Wireless Assistant (HKLM\…\{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}) (Version: 3.00 H3 - Hewlett-Packard)
HPAsset component for HP Active Support Library (Version: 3.0.2.2 - Hewlett-Packard) Hidden
HPNetworkAssistant (HKLM\…\{228C6B46-64E2-404E-898A-EF0830603EF4}) (Version: 1.1.70 - Hewlett-Packard.)
Internet Explorer (Enable DEP) (HKLM\…\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version:  - )
IrfanView (remove only) (HKLM\…\IrfanView) (Version:  - )
Java 8 Update 31 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Java(TM) SE Runtime Environment 6 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0160000}) (Version: 1.6.0.0 - Sun Microsystems, Inc.)
LightScribe  1.4.136.1 (Version: 1.4.136.1 - http://www.lightscribe.com)Hidden
LiveUpdate 3.2 (Symantec Corporation) (HKLM\…\LiveUpdate) (Version: 3.2.0.41 - Symantec Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Fix it Center (HKLM\…\{B7588D45-AFDC-4C93-9E2E-A100F3554B64}) (Version: 1.0.0100 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
Move Media Player (HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Move Media Player) (Version:  - Move Networks)
MSCU for Microsoft Vista (HKLM\…\{3FFB3B34-D639-4384-9AE9-DDE58430D86F}) (Version: 1.0.1.1 - Hewlett-Packard)
MSRedist (Version: 1.0.0.0 - Symantec Corporation) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM\…\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM\…\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
muvee autoProducer 6.0 (HKLM\…\{0BFC200F-C45D-4271-AF34-4CA969225DEB}) (Version: 6.00.050 - muvee Technologies)
My HP Games (HKLM\…\WildTangent hplaptop Master Uninstall) (Version: HPLAP0503 - WildTangent)
Norton AntiVirus (Version: 14.2.0.29 - Symantec Corporation) Hidden
Norton Confidential Browser Component (Version: 1.5.0.29 - Symantec Corporation) Hidden
Norton Confidential Web Protection Component (Version: 1.5.0.29 - Symantec Corporation) Hidden
Norton Internet Security (Symantec Corporation) (HKLM\…\SymSetup.{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}) (Version: 10.2.0.30 - Symantec Corporation)
Norton Internet Security (Version: 10.1.0 - Symantec Corp.) Hidden
Norton Internet Security (Version: 10.2.0.30 - Symantec Corporation) Hidden
Norton Protection Center (Version: 2007.2.0.22 - Symantec Corporation) Hidden
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.4 - NVIDIA Corporation)
PMB (HKLM\…\{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}) (Version: 5.5.00.11260 - Sony Corporation)
PSSWCORE (Version: 2.00.5000 - Hewlett-Packard) Hidden
QuickTime 7 (HKLM\…\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Rhapsody (HKLM\…\Rhapsody) (Version:  - )
Rhapsody Player Engine (HKLM\…\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}) (Version: 1.0.604 - RealNetworks)
Roxio Creator Audio (HKLM\…\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.4.0 - Roxio)
Roxio Creator Basic v9 (HKLM\…\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.4.0 - Roxio)
Roxio Creator Copy (HKLM\…\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio)
Roxio Creator Data (HKLM\…\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio)
Roxio Creator EasyArchive (HKLM\…\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio)
Roxio Creator Tools (HKLM\…\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio)
Roxio Express Labeler 3 (HKLM\…\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 3.2.1 - Roxio)
Roxio MyDVD Basic v9 (HKLM\…\{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}) (Version: 9.0.551 - Roxio)
SPBBC 32bit (Version: 3.2.0.21 - Symantec Corporation) Hidden
Symantec Real Time Storage Protection Component (Version: 10.1.4.2 - Symantec Corporation) Hidden
SymNet (Version: 7.2.0.15 - Symantec Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 11.0.7.0 - Synaptics)
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{e3e02f12-2adb-478c-8742-5f0819f9f0f4}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{e473a65c-8087-49a3-affd-c5bc4a10669b}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{f4c28532-b9d0-4950-a2df-e83f9929242b}\InprocServer32 -> C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll (MindSpark)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{fc345d4c-b8f4-4674-bff7-3c37d2e535ee}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{fd6484ed-ebe3-4c3d-938a-8238003b41b7}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
 
==================== Restore Points =========================
 
11-07-2015 11:54:01 Scheduled Checkpoint
12-07-2015 16:17:46 Windows Update
15-07-2015 18:26:33 Scheduled Checkpoint
15-07-2015 18:56:37 Windows Update
17-07-2015 09:47:57 Scheduled Checkpoint
18-07-2015 19:57:33 Windows Update
23-07-2015 19:19:33 Windows Update
28-07-2015 19:12:02 Windows Update
31-07-2015 23:01:09 Windows Update
31-07-2015 23:32:16 Restore Operation
01-08-2015 10:28:49 Restore Operation
01-08-2015 12:40:01 Windows Update
04-08-2015 18:59:22 AA11
04-08-2015 20:10:52 Restore Operation
04-08-2015 20:33:03 Restore Operation
04-08-2015 21:23:12 Restore Operation
04-08-2015 23:05:07 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 03:23 - 2006-09-18 14:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0D584032-436C-4E12-90F9-BC136FA4EE56} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd)
Task: {1F014C22-11EA-4585-9D8F-C4363BB38751} - System32\Tasks\PC Unleashed => C:\Program Files\PC Unleashed Online\PC Unleashed\pcu.exe [2012-07-19] (PC Unleashed Online, Inc.)
Task: {3062B010-09B0-4171-9967-935DF58F28BA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-04] (Adobe Systems Incorporated)
Task: {608DCA47-66AA-45F7-B64A-47E8B04B3DBB} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\OSUpgrade => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunHandleOSUpgrade
Task: {610C123E-E75B-4FFB-A9EB-14B2E4251660} - System32\Tasks\{44E094D7-1DC5-4FCC-A3DC-A2E4FF5F4D76} => C:\Program Files\Skype\Phone\Skype.exe
Task: {6ABC175F-3949-40B0-B045-58BD6ACEE499} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-27] (Google Inc.)
Task: {6C7BCA72-D959-4C1C-9D2F-9CB4935D55D5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-27] (Google Inc.)
Task: {A388C444-1D6E-4259-AE16-83E1E1C54246} - System32\Tasks\{C6E2C9FA-2FB6-4B9A-9086-ABE7FF602C1F} => pcalua.exe -a C:\PROGRA~1\Zynga\UNWISE.EXE -c   /U C:\PROGRA~1\Zynga\INSTALL.LOG
Task: {AAA9C09D-8453-41C7-BA18-93DBFCF28B09} - System32\Tasks\HPCeeScheduleForJanelle => C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-03-23] (Hewlett-Packard)
Task: {C5C00E62-28DE-4166-B95D-11151B0A6BA7} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\ConfigExec => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunCollectConfigurationInfo
Task: {C81D473C-C0C4-4127-8516-1365D7FCF574} - System32\Tasks\HP Health Check => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09] (Hewlett-Packard)
Task: {D395CBD8-97A9-43F0-BC9E-B61BF670F395} - System32\Tasks\{DEC880E0-57F8-492C-A84D-6F4DD5CD60AE} => pcalua.exe -a C:\Windows\system32\javacpl.cpl -c Java
Task: {F9C398E4-49F1-4C82-98C5-324659342CFB} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForJanelle.job => C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe
Task: C:\Windows\Tasks\PC Unleashed.job => C:\Program Files\PC Unleashed Online\PC Unleashed\pcu.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2007-05-31 02:21 - 2007-03-28 17:45 - 00270431 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
2007-05-31 02:21 - 2007-03-28 17:45 - 00233573 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00032768 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00114783 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00339968 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll
2007-05-31 02:20 - 2007-03-28 17:44 - 00061440 _____ () C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll
2007-05-16 11:43 - 2007-05-16 11:43 - 00677432 ____R () C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\Web\Wallpaper\img34.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{964F56F1-41AD-446F-B77E-82B071B28749}] => (Allow) C:\Program Files\HP\QuickPlay\QP.exe
FirewallRules: [{95E87BAB-D6F1-493C-AF4A-24B8CD4E995B}] => (Allow) C:\Program Files\HP\QuickPlay\QPService.exe
FirewallRules: [{748AB940-A937-49CF-B0BE-DDE3197C8C3F}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{B33D8B4B-4DF8-4E93-9CF8-80A110094D07}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{C6FFCC69-5FEF-42B6-8093-109073549692}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{51134F5C-05F7-485C-A9F7-8C3A7AF53B8B}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{825DD0AB-F15C-4AE4-879F-02D0098A5DBA}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{2F81CA3D-A256-4BCF-8C72-A9B4ECE9CD72}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [TCP Query User{81F7F573-2E0E-4F6E-9AF2-4D32BC5E6737}C:\program files\hp games\wheel of fortune\wheel of fortune.exe] => (Block) C:\program files\hp games\wheel of fortune\wheel of fortune.exe
FirewallRules: [UDP Query User{0FF5FE79-1718-4D5F-843D-934158FDF2B9}C:\program files\hp games\wheel of fortune\wheel of fortune.exe] => (Block) C:\program files\hp games\wheel of fortune\wheel of fortune.exe
FirewallRules: [{6970BDF2-9C56-4A2C-AF78-474954847B5C}] => (Allow) LPort=80
FirewallRules: [{A0F5CD9E-13EC-4D38-B369-0A5C2513BB22}] => (Allow) LPort=80
FirewallRules: [{4677590A-FFC7-4A3C-B305-9EC8888C3FCE}] => (Allow) LPort=80
FirewallRules: [{5DD5967B-6554-4E2D-8D6E-AEB6A5693BE0}] => (Allow) C:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exe
FirewallRules: [{82381A18-4994-4A86-9AC4-0D553E263286}] => (Allow) C:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exe
FirewallRules: [{0440192A-FA1C-429F-8FC8-8C216DA976F0}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{6A6FEB30-CF72-4331-BF5A-93AED3262624}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
 
System errors:
=============
Error: (08/04/2015 10:17:31 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: KtmRm for Distributed Transaction Coordinator
 
Error: (08/04/2015 10:14:25 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000ShellHWDetection
 
Error: (08/04/2015 10:11:00 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: CyberLink Task Scheduler (CTS)CyberLink Background Capture Service (CBCS)%%1070
 
Error: (08/04/2015 10:10:59 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: CyberLink Background Capture Service (CBCS)
 
Error: (08/04/2015 10:09:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: MyFunCardsService%%3
 
Error: (08/04/2015 10:09:05 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:08:04 PM on 8/4/2015 was unexpected.
 
Error: (08/04/2015 10:08:54 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: The default transaction resource manager on volume D: encountered a non-retryable error and could not start.  The data contains the error code.
 
Error: (08/04/2015 09:39:12 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: KtmRm for Distributed Transaction Coordinator
 
Error: (08/04/2015 09:31:13 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: CyberLink Task Scheduler (CTS)CyberLink Background Capture Service (CBCS)%%1070
 
Error: (08/04/2015 09:31:13 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: CyberLink Background Capture Service (CBCS)
 
 
Microsoft Office:
=========================
 
CodeIntegrity:
===================================
  Date: 2014-01-01 19:46:34.373
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:46:33.921
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:46:33.546
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:46:33.125
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:45:55.890
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:45:55.311
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:45:54.857
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-01 19:45:54.406
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-12-03 17:49:39.111
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-12-03 17:49:38.730
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: AMD Turion™ 64 X2 Mobile Technology TL-60
Percentage of memory in use: 56%
Total physical RAM: 1981.87 MB
Available physical RAM: 860.04 MB
Total Virtual: 4214.26 MB
Available Virtual: 2784.87 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:140.85 GB) (Free:47.61 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (HP_RECOVERY) (Fixed) (Total:8.2 GB) (Free:0 GB) NTFS ==>[system with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 149.1 GB) (Disk ID: C6450749)
Partition 1: (Active) - (Size=140.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=8.2 GB) - (Type=07 NTFS)
 
==================== End of log ============================
 
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-08-2015 01
Ran by [removed] (administrator) on JANELLE-PC (05-08-2015 00:00:45)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
(Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
(Symantec Corporation) C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
() C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
(CyberLink Corp.) C:\Program Files\Hp\QuickPlay\QPService.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehmsas.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1045800 2008-03-28] (Synaptics, Inc.)
HKLM\…\Run: [QPService] => C:\Program Files\HP\QuickPlay\QPService.exe [176128 2007-03-28] (CyberLink Corp.)
HKLM\…\Run: [QlbCtrl] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [159744 2007-02-13] ( Hewlett-Packard Development Company, L.P.)
HKLM\…\Run: [HP Health Check Scheduler] => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)
HKLM\…\Run: [PMBVolumeWatcher] => C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [hpWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [480560 2007-10-03] (Hewlett-Packard Development Company, L.P.)
HKLM\…\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-02-18] (Hewlett-Packard)
HKLM\…\Run: [Search Protection] => C:\ProgramData\Search Protection\SearchProtection.exe
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
HKU\S-1-5-18\…\RunOnce: [adaware] => reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f
HKU\S-1-5-18\…\RunOnce: [adaware_XP] => reg.exe delete "HKCU\Software\adaware" /f
AppInit_DLLs: C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL => C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL File not found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2007-05-31]
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk [2007-05-31]
ShortcutTarget: Adobe Reader Synchronizer.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = 
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
URLSearchHook: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 - (No Name) - {f4c28532-b9d0-4950-a2df-e83f9929242b} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll (MindSpark)
SearchScopes: HKLM -> {A9A5A44B-65D6-4CE2-BD35-55F5467AAD17} URL = http://www.ask.com/web?q={searchTerms}&l;=dis&o;=ushpl
SearchScopes: HKLM -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT2438727
SearchScopes: HKLM -> {E22D2942-636A-4FAB-AE76-63F24DDBECC1} URL = http://search.live.com/results.aspx?q={searchTerms}&entrypoint;={referrer:source?}&FORM;=HVNUS7
SearchScopes: HKLM -> {F3F92588-AF51-4B46-9EA9-CCD5DE246D63} URL = http://search.yahoo.com/search?p={searchTerms}&ei;={inputEncoding}&fr;=hp-pvnb
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.bing.com/search?FORM=U146DF&PC;=U146&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.bing.com/search?FORM=U146DF&PC;=U146&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {A9A5A44B-65D6-4CE2-BD35-55F5467AAD17} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {d48efd2d-1c0c-4d68-bbc3-2f219c756723} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {E22D2942-636A-4FAB-AE76-63F24DDBECC1} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {E8D2F204-299B-4266-97E4-0126F66E3FD3} URL = http://securedsearch2.lavasoft.com/results.php?pr=vmn&id;=adawaretb&v;=3_8&idate;=2014-04-24&hsimp;=yhs-lavasoft&ent;=ch&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {F3F92588-AF51-4B46-9EA9-CCD5DE246D63} URL = 
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22] (Adobe Systems Incorporated)
BHO: No Name -> {1E8A6170-7264-4D0F-BEAE-D42A53123C75} -> c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-12] (Symantec Corporation)
BHO: No Name -> {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} ->  No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-22] (Oracle Corporation)
BHO: Search Assistant BHO -> {c4b22c87-45ef-4f43-89f2-40db2078864e} -> C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll [2012-10-19] (MindSpark)
BHO: No Name -> {da71fd14-5f7b-46ae-b8b1-44074a38f331} ->  No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-22] (Oracle Corporation)
Toolbar: HKLM - Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll [2007-01-12] (Symantec Corporation)
Toolbar: HKLM - MyFunCards - {210f1b36-3b7f-41a4-b5da-3eb87f5a56c2} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mbar.dll [2012-10-19] (MindSpark)
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} -  No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} -  No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} -  No File
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1
Tcpip\..\Interfaces\{28F058A5-ABB1-48F7-A91F-A3143EF6CC6C}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{9BBF898D-8D4D-4C50-87CB-98891C247373}: [DhcpNameServer] [removed] [removed] 192.168.1.1
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-22] (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @MyFunCards_5m.com/Plugin -> C:\Program Files\MyFunCards_5m\bar\1.bin\NP5mStub.dll [2012-10-19] (MindSpark)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-27] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-27] (Google Inc.)
FF Plugin HKU\S-1-5-21-1766275910-2450894708-632072239-1000: @movenetworks.com/Quantum Media Player -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll [2010-04-23] (Move Networks)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-04-11]
FF HKLM\…\Firefox\Extensions: [5mffxtbr@MyFunCards_5m.com] - C:\Program Files\MyFunCards_5m\bar\1.bin
FF Extension: No Name - C:\Program Files\MyFunCards_5m\bar\1.bin [2012-10-19]
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Janelle\AppData\Roaming\Move Networks
FF Extension: Move Media Player - C:\Users\Janelle\AppData\Roaming\Move Networks [2010-04-23]
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [{07433EEA-AEA0-461F-AB9F-35D67476BA7E}] - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E}
FF Extension: XULRunner - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E} [2011-03-12]
 
Chrome: 
=======
CHR Profile: C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-22]
CHR Extension: (Google Drive) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-22]
CHR Extension: (YouTube) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-22]
CHR Extension: (Google Search) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-22]
CHR Extension: (MSN Homepage) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkcgfbgohboipdhliafmacjnhjbhmim [2015-02-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-22]
CHR Extension: (Gmail) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-22]
CHR HKU\S-1-5-21-1766275910-2450894708-632072239-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - https://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [554616 2007-01-05] (Symantec Corporation)
R2 ccEvtMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
R2 ccSetMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
R2 CLCapSvc; C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe [270431 2007-03-28] () [File not signed]
S2 CLSched; C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe [118877 2007-03-28] () [File not signed]
R2 CLTNetCnService; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
S3 Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [110592 2007-01-09] (Hewlett-Packard Development Company, L.P.) [File not signed]
S3 comHost; c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [49248 2007-01-13] (Symantec Corporation)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [File not signed]
R2 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [135168 2006-05-02] (Hewlett-Packard Development Company, L.P.) [File not signed]
S3 IDriverT; C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S3 ISPwdSvc; c:\Program Files\Norton Internet Security\isPwdSvc.exe [80504 2007-01-14] (Symantec Corporation)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2006-12-14] (Hewlett-Packard Company) [File not signed]
S3 LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE [2918008 2007-01-05] (Symantec Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
S3 RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [880640 2007-02-12] (Sonic Solutions) [File not signed]
S3 Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [1174664 2007-05-31] (Symantec Corporation)
R2 SymAppCore; c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe [47712 2007-01-05] (Symantec Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S2 MyFunCards_5mService; C:\PROGRA~1\MYFUNC~2\bar\1.bin\5mbarsvc.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 eabfiltr; C:\Windows\System32\DRIVERS\eabfiltr.sys [8192 2006-11-30] (Hewlett-Packard Development Company, L.P.)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [387384 2007-01-10] (Symantec Corporation)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-10-06] (GFI Software)
S3 IDSvix86; C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20070108.003\IDSvix86.sys [212280 2006-12-28] (Symantec Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R3 NAVENG; C:\ProgramData\Symantec\Definitions\VirusDefs\20070110.052\NAVENG.SYS [80408 2007-01-10] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Symantec\Definitions\VirusDefs\20070110.052\NAVEX15.SYS [833048 2007-01-10] (Symantec Corporation)
R1 SBRE; C:\Windows\system32\drivers\SBREDrv.sys [101720 2011-06-30] (Sunbelt Software)
S3 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [417592 2007-01-03] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [247608 2007-01-12] (Symantec Corporation)
S3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [276792 2007-01-12] (Symantec Corporation)
R1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [25400 2007-01-12] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [115000 2007-05-31] (Symantec Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U5 SYMTDI; C:\Windows\System32\Drivers\SYMTDI.sys [191544 2007-01-09] (Symantec Corporation)
U3 aswMBR; \??\C:\Users\Janelle\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Janelle\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-05 00:00 - 2015-08-05 00:01 - 00021538 _____ C:\Users\Janelle\Downloads\FRST.txt
2015-08-04 23:59 - 2015-08-05 00:00 - 00000000 ____D C:\FRST
2015-08-04 23:57 - 2015-08-04 23:58 - 01673728 _____ (Farbar) C:\Users\Janelle\Downloads\FRST.exe
2015-08-04 23:53 - 2015-08-04 23:53 - 00004149 _____ C:\Users\Janelle\Documents\Documents\Documents\aswMBR.txt
2015-08-04 23:53 - 2015-08-04 23:53 - 00000512 _____ C:\Users\Janelle\Documents\Documents\Documents\MBR.dat
2015-08-04 23:06 - 2015-08-04 23:07 - 05198336 _____ (AVAST Software) C:\Users\Janelle\Downloads\aswMBR.exe
2015-08-04 20:24 - 2015-08-04 21:29 - 00000000 ____D C:\Program Files\GUM81CC.tmp
2015-08-04 20:09 - 2015-08-04 20:10 - 05831179 _____ (Piriform Ltd) C:\Users\Janelle\Downloads\9AA6.tmp
2015-07-31 17:27 - 2015-08-01 10:36 - 00000000 ____D C:\Program Files\Skype
2015-07-31 17:27 - 2015-07-31 17:27 - 00000000 ____D C:\Users\Janelle\AppData\Local\Skype
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-04 23:51 - 2013-09-06 17:08 - 01992870 _____ C:\Windows\WindowsUpdate.log
2015-08-04 23:46 - 2006-11-02 05:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-04 23:46 - 2006-11-02 05:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-04 23:14 - 2014-10-01 21:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-04 23:10 - 2015-05-27 17:57 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-04 22:33 - 2014-10-01 21:35 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-08-04 22:33 - 2014-10-01 21:35 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-08-04 22:10 - 2010-04-13 20:25 - 00047962 _____ C:\ProgramData\nvModes.001
2015-08-04 22:09 - 2015-05-27 17:57 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-04 22:09 - 2006-11-02 06:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-04 21:51 - 2015-05-27 18:00 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-04 21:29 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\system32\Msdtc
2015-08-04 21:28 - 2013-05-10 23:29 - 00000000 ____D C:\Users\Mary
2015-08-04 21:28 - 2010-03-24 21:33 - 00000000 ____D C:\Users\Janelle
2015-08-04 21:28 - 2006-11-02 03:22 - 51380224 _____ C:\Windows\system32\config\software_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 40632320 _____ C:\Windows\system32\config\components_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 25427968 _____ C:\Windows\system32\config\system_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00524288 _____ C:\Windows\system32\config\default_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2015-08-04 21:27 - 2015-05-27 18:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-04 21:27 - 2010-03-24 21:42 - 00000000 ____D C:\Users\Janelle\AppData\Local\QuickPlay
2015-08-04 21:27 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\system32\spool
2015-08-04 21:27 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\registration
2015-08-04 21:23 - 2011-03-24 14:04 - 00000000 ____D C:\Users\Janelle\AppData\Roaming\HpUpdate
2015-08-04 20:09 - 2010-06-16 22:20 - 00000000 ____D C:\Users\Janelle\AppData\Roaming\Skype
2015-08-04 19:08 - 2010-04-13 20:25 - 00047962 _____ C:\ProgramData\nvModes.dat
2015-08-01 10:36 - 2010-06-16 22:19 - 00000000 ____D C:\ProgramData\Skype
2015-07-31 18:23 - 2010-09-26 20:58 - 00000052 _____ C:\Windows\system32\DOErrors.log
 
==================== Files in the root of some directories =======
 
2013-05-27 15:35 - 2013-05-18 19:03 - 0186768 _____ () C:\Program Files\20res.dll
2013-05-27 15:35 - 2013-05-18 19:03 - 0708168 _____ (MindSpark) C:\Program Files\20Uninstall YourLocalLotto Toolbar.dll
2011-10-10 09:48 - 2011-10-10 09:48 - 0000272 _____ () C:\Users\Janelle\AppData\Roaming\.backup.dm
2012-09-21 17:01 - 2012-09-23 14:29 - 0000048 _____ () C:\Users\Janelle\AppData\Roaming\0F478F.dat
2014-02-02 17:41 - 2014-02-02 17:41 - 0002086 _____ () C:\Users\Janelle\AppData\Roaming\data.sec
2012-09-21 17:01 - 2012-09-21 17:01 - 0000028 _____ () C:\Users\Janelle\AppData\Roaming\Filesop.txt.block
2010-03-24 23:01 - 2010-04-13 19:51 - 0013119 _____ () C:\Users\Janelle\AppData\Roaming\nvModes.001
2010-03-24 23:01 - 2010-04-13 15:55 - 0013119 _____ () C:\Users\Janelle\AppData\Roaming\nvModes.dat
2012-09-21 18:14 - 2012-09-21 18:14 - 0000030 _____ () C:\Users\Janelle\AppData\Roaming\ok.txt.block
2012-09-23 14:38 - 2012-09-23 14:38 - 0000041 _____ () C:\Users\Janelle\AppData\Roaming\smss.exe.tmp
2012-09-21 18:14 - 2012-09-21 18:14 - 0002176 _____ () C:\Users\Janelle\AppData\Roaming\WARNING.txt
2012-03-02 11:18 - 2015-03-06 21:24 - 0000384 _____ () C:\Users\Janelle\AppData\Roaming\wklnhst.dat
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\AtStart.txt
2012-09-21 17:01 - 2012-09-23 15:24 - 0006529 _____ () C:\Users\Janelle\AppData\Local\chromeupdate.crx
2010-06-03 17:04 - 2015-03-05 23:04 - 0007620 _____ () C:\Users\Janelle\AppData\Local\d3d9caps.dat
2010-04-08 16:58 - 2015-06-26 18:10 - 0004608 _____ () C:\Users\Janelle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\DSwitch.txt
2011-03-12 05:10 - 2011-05-10 01:08 - 0001034 _____ () C:\Users\Janelle\AppData\Local\Mdebukijaduxoxu.dat
2011-03-12 05:10 - 2011-05-10 01:08 - 0000000 _____ () C:\Users\Janelle\AppData\Local\Mwuda.bin
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\QSwitch.txt
2012-09-22 14:32 - 2012-09-22 14:32 - 0000000 _____ () C:\ProgramData\50pWN8.dat
2012-09-22 14:31 - 2012-09-22 14:31 - 0000001 _____ () C:\ProgramData\5U0eRTH0.exe.b
2012-09-22 14:31 - 2012-09-22 14:31 - 0000001 _____ () C:\ProgramData\5U0eRTH0.exe_.b
2010-06-16 22:22 - 2010-06-16 22:22 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2007-05-31 02:34 - 2012-06-23 14:09 - 0000675 _____ () C:\ProgramData\hpzinstall.log
2010-04-13 20:25 - 2015-08-04 22:10 - 0047962 _____ () C:\ProgramData\nvModes.001
2010-04-13 20:25 - 2015-08-04 19:08 - 0047962 _____ () C:\ProgramData\nvModes.dat
 
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1766275910-2450894708-632072239-1000\$ef8a5bbf5833eadd22ca66c158232ebe
 
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$ef8a5bbf5833eadd22ca66c158232ebe
 
ZeroAccess:
C:\Users\Janelle\AppData\Local\{ef8a5bbf-5833-eadd-22ca-66c158232ebe}
ZeroAccess:
C:\Users\Janelle\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files\Google\Desktop\Install
 
Some files in TEMP:
====================
C:\Users\Mary\AppData\Local\Temp\symlcsv1.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
 
 
LastRegBack: 2015-08-04 22:37
 
==================== End of log ============================
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-08-2015 01
Ran by [removed] (administrator) on JANELLE-PC (05-08-2015 00:00:45)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
(Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
(Symantec Corporation) C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
() C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
(CyberLink Corp.) C:\Program Files\Hp\QuickPlay\QPService.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehmsas.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1045800 2008-03-28] (Synaptics, Inc.)
HKLM\…\Run: [QPService] => C:\Program Files\HP\QuickPlay\QPService.exe [176128 2007-03-28] (CyberLink Corp.)
HKLM\…\Run: [QlbCtrl] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [159744 2007-02-13] ( Hewlett-Packard Development Company, L.P.)
HKLM\…\Run: [HP Health Check Scheduler] => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)
HKLM\…\Run: [PMBVolumeWatcher] => C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [hpWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [480560 2007-10-03] (Hewlett-Packard Development Company, L.P.)
HKLM\…\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-02-18] (Hewlett-Packard)
HKLM\…\Run: [Search Protection] => C:\ProgramData\Search Protection\SearchProtection.exe
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
HKU\S-1-5-18\…\RunOnce: [adaware] => reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f
HKU\S-1-5-18\…\RunOnce: [adaware_XP] => reg.exe delete "HKCU\Software\adaware" /f
AppInit_DLLs: C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL => C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL File not found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2007-05-31]
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk [2007-05-31]
ShortcutTarget: Adobe Reader Synchronizer.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = 
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
URLSearchHook: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 - (No Name) - {f4c28532-b9d0-4950-a2df-e83f9929242b} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll (MindSpark)
SearchScopes: HKLM -> {A9A5A44B-65D6-4CE2-BD35-55F5467AAD17} URL = http://www.ask.com/web?q={searchTerms}&l;=dis&o;=ushpl
SearchScopes: HKLM -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT2438727
SearchScopes: HKLM -> {E22D2942-636A-4FAB-AE76-63F24DDBECC1} URL = http://search.live.com/results.aspx?q={searchTerms}&entrypoint;={referrer:source?}&FORM;=HVNUS7
SearchScopes: HKLM -> {F3F92588-AF51-4B46-9EA9-CCD5DE246D63} URL = http://search.yahoo.com/search?p={searchTerms}&ei;={inputEncoding}&fr;=hp-pvnb
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.bing.com/search?FORM=U146DF&PC;=U146&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.bing.com/search?FORM=U146DF&PC;=U146&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {A9A5A44B-65D6-4CE2-BD35-55F5467AAD17} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {d48efd2d-1c0c-4d68-bbc3-2f219c756723} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {E22D2942-636A-4FAB-AE76-63F24DDBECC1} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {E8D2F204-299B-4266-97E4-0126F66E3FD3} URL = http://securedsearch2.lavasoft.com/results.php?pr=vmn&id;=adawaretb&v;=3_8&idate;=2014-04-24&hsimp;=yhs-lavasoft&ent;=ch&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {F3F92588-AF51-4B46-9EA9-CCD5DE246D63} URL = 
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22] (Adobe Systems Incorporated)
BHO: No Name -> {1E8A6170-7264-4D0F-BEAE-D42A53123C75} -> c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-12] (Symantec Corporation)
BHO: No Name -> {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} ->  No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-22] (Oracle Corporation)
BHO: Search Assistant BHO -> {c4b22c87-45ef-4f43-89f2-40db2078864e} -> C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll [2012-10-19] (MindSpark)
BHO: No Name -> {da71fd14-5f7b-46ae-b8b1-44074a38f331} ->  No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-22] (Oracle Corporation)
Toolbar: HKLM - Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll [2007-01-12] (Symantec Corporation)
Toolbar: HKLM - MyFunCards - {210f1b36-3b7f-41a4-b5da-3eb87f5a56c2} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mbar.dll [2012-10-19] (MindSpark)
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} -  No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} -  No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} -  No File
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1
Tcpip\..\Interfaces\{28F058A5-ABB1-48F7-A91F-A3143EF6CC6C}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{9BBF898D-8D4D-4C50-87CB-98891C247373}: [DhcpNameServer] [removed] [removed] 192.168.1.1
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-22] (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @MyFunCards_5m.com/Plugin -> C:\Program Files\MyFunCards_5m\bar\1.bin\NP5mStub.dll [2012-10-19] (MindSpark)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-27] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-27] (Google Inc.)
FF Plugin HKU\S-1-5-21-1766275910-2450894708-632072239-1000: @movenetworks.com/Quantum Media Player -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll [2010-04-23] (Move Networks)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-04-11]
FF HKLM\…\Firefox\Extensions: [5mffxtbr@MyFunCards_5m.com] - C:\Program Files\MyFunCards_5m\bar\1.bin
FF Extension: No Name - C:\Program Files\MyFunCards_5m\bar\1.bin [2012-10-19]
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Janelle\AppData\Roaming\Move Networks
FF Extension: Move Media Player - C:\Users\Janelle\AppData\Roaming\Move Networks [2010-04-23]
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [{07433EEA-AEA0-461F-AB9F-35D67476BA7E}] - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E}
FF Extension: XULRunner - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E} [2011-03-12]
 
Chrome: 
=======
CHR Profile: C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-22]
CHR Extension: (Google Drive) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-22]
CHR Extension: (YouTube) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-22]
CHR Extension: (Google Search) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-22]
CHR Extension: (MSN Homepage) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkcgfbgohboipdhliafmacjnhjbhmim [2015-02-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-22]
CHR Extension: (Gmail) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-22]
CHR HKU\S-1-5-21-1766275910-2450894708-632072239-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - https://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [554616 2007-01-05] (Symantec Corporation)
R2 ccEvtMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
R2 ccSetMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
R2 CLCapSvc; C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe [270431 2007-03-28] () [File not signed]
S2 CLSched; C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe [118877 2007-03-28] () [File not signed]
R2 CLTNetCnService; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
S3 Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [110592 2007-01-09] (Hewlett-Packard Development Company, L.P.) [File not signed]
S3 comHost; c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [49248 2007-01-13] (Symantec Corporation)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [File not signed]
R2 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [135168 2006-05-02] (Hewlett-Packard Development Company, L.P.) [File not signed]
S3 IDriverT; C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S3 ISPwdSvc; c:\Program Files\Norton Internet Security\isPwdSvc.exe [80504 2007-01-14] (Symantec Corporation)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2006-12-14] (Hewlett-Packard Company) [File not signed]
S3 LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE [2918008 2007-01-05] (Symantec Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
S3 RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [880640 2007-02-12] (Sonic Solutions) [File not signed]
S3 Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [1174664 2007-05-31] (Symantec Corporation)
R2 SymAppCore; c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe [47712 2007-01-05] (Symantec Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S2 MyFunCards_5mService; C:\PROGRA~1\MYFUNC~2\bar\1.bin\5mbarsvc.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 eabfiltr; C:\Windows\System32\DRIVERS\eabfiltr.sys [8192 2006-11-30] (Hewlett-Packard Development Company, L.P.)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [387384 2007-01-10] (Symantec Corporation)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-10-06] (GFI Software)
S3 IDSvix86; C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20070108.003\IDSvix86.sys [212280 2006-12-28] (Symantec Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R3 NAVENG; C:\ProgramData\Symantec\Definitions\VirusDefs\20070110.052\NAVENG.SYS [80408 2007-01-10] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Symantec\Definitions\VirusDefs\20070110.052\NAVEX15.SYS [833048 2007-01-10] (Symantec Corporation)
R1 SBRE; C:\Windows\system32\drivers\SBREDrv.sys [101720 2011-06-30] (Sunbelt Software)
S3 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [417592 2007-01-03] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [247608 2007-01-12] (Symantec Corporation)
S3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [276792 2007-01-12] (Symantec Corporation)
R1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [25400 2007-01-12] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [115000 2007-05-31] (Symantec Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U5 SYMTDI; C:\Windows\System32\Drivers\SYMTDI.sys [191544 2007-01-09] (Symantec Corporation)
U3 aswMBR; \??\C:\Users\Janelle\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Janelle\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-05 00:00 - 2015-08-05 00:01 - 00021538 _____ C:\Users\Janelle\Downloads\FRST.txt
2015-08-04 23:59 - 2015-08-05 00:00 - 00000000 ____D C:\FRST
2015-08-04 23:57 - 2015-08-04 23:58 - 01673728 _____ (Farbar) C:\Users\Janelle\Downloads\FRST.exe
2015-08-04 23:53 - 2015-08-04 23:53 - 00004149 _____ C:\Users\Janelle\Documents\Documents\Documents\aswMBR.txt
2015-08-04 23:53 - 2015-08-04 23:53 - 00000512 _____ C:\Users\Janelle\Documents\Documents\Documents\MBR.dat
2015-08-04 23:06 - 2015-08-04 23:07 - 05198336 _____ (AVAST Software) C:\Users\Janelle\Downloads\aswMBR.exe
2015-08-04 20:24 - 2015-08-04 21:29 - 00000000 ____D C:\Program Files\GUM81CC.tmp
2015-08-04 20:09 - 2015-08-04 20:10 - 05831179 _____ (Piriform Ltd) C:\Users\Janelle\Downloads\9AA6.tmp
2015-07-31 17:27 - 2015-08-01 10:36 - 00000000 ____D C:\Program Files\Skype
2015-07-31 17:27 - 2015-07-31 17:27 - 00000000 ____D C:\Users\Janelle\AppData\Local\Skype
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-04 23:51 - 2013-09-06 17:08 - 01992870 _____ C:\Windows\WindowsUpdate.log
2015-08-04 23:46 - 2006-11-02 05:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-04 23:46 - 2006-11-02 05:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-04 23:14 - 2014-10-01 21:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-04 23:10 - 2015-05-27 17:57 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-04 22:33 - 2014-10-01 21:35 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-08-04 22:33 - 2014-10-01 21:35 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-08-04 22:10 - 2010-04-13 20:25 - 00047962 _____ C:\ProgramData\nvModes.001
2015-08-04 22:09 - 2015-05-27 17:57 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-04 22:09 - 2006-11-02 06:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-04 21:51 - 2015-05-27 18:00 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-04 21:29 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\system32\Msdtc
2015-08-04 21:28 - 2013-05-10 23:29 - 00000000 ____D C:\Users\Mary
2015-08-04 21:28 - 2010-03-24 21:33 - 00000000 ____D C:\Users\Janelle
2015-08-04 21:28 - 2006-11-02 03:22 - 51380224 _____ C:\Windows\system32\config\software_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 40632320 _____ C:\Windows\system32\config\components_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 25427968 _____ C:\Windows\system32\config\system_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00524288 _____ C:\Windows\system32\config\default_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2015-08-04 21:27 - 2015-05-27 18:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-04 21:27 - 2010-03-24 21:42 - 00000000 ____D C:\Users\Janelle\AppData\Local\QuickPlay
2015-08-04 21:27 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\system32\spool
2015-08-04 21:27 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\registration
2015-08-04 21:23 - 2011-03-24 14:04 - 00000000 ____D C:\Users\Janelle\AppData\Roaming\HpUpdate
2015-08-04 20:09 - 2010-06-16 22:20 - 00000000 ____D C:\Users\Janelle\AppData\Roaming\Skype
2015-08-04 19:08 - 2010-04-13 20:25 - 00047962 _____ C:\ProgramData\nvModes.dat
2015-08-01 10:36 - 2010-06-16 22:19 - 00000000 ____D C:\ProgramData\Skype
2015-07-31 18:23 - 2010-09-26 20:58 - 00000052 _____ C:\Windows\system32\DOErrors.log
 
==================== Files in the root of some directories =======
 
2013-05-27 15:35 - 2013-05-18 19:03 - 0186768 _____ () C:\Program Files\20res.dll
2013-05-27 15:35 - 2013-05-18 19:03 - 0708168 _____ (MindSpark) C:\Program Files\20Uninstall YourLocalLotto Toolbar.dll
2011-10-10 09:48 - 2011-10-10 09:48 - 0000272 _____ () C:\Users\Janelle\AppData\Roaming\.backup.dm
2012-09-21 17:01 - 2012-09-23 14:29 - 0000048 _____ () C:\Users\Janelle\AppData\Roaming\0F478F.dat
2014-02-02 17:41 - 2014-02-02 17:41 - 0002086 _____ () C:\Users\Janelle\AppData\Roaming\data.sec
2012-09-21 17:01 - 2012-09-21 17:01 - 0000028 _____ () C:\Users\Janelle\AppData\Roaming\Filesop.txt.block
2010-03-24 23:01 - 2010-04-13 19:51 - 0013119 _____ () C:\Users\Janelle\AppData\Roaming\nvModes.001
2010-03-24 23:01 - 2010-04-13 15:55 - 0013119 _____ () C:\Users\Janelle\AppData\Roaming\nvModes.dat
2012-09-21 18:14 - 2012-09-21 18:14 - 0000030 _____ () C:\Users\Janelle\AppData\Roaming\ok.txt.block
2012-09-23 14:38 - 2012-09-23 14:38 - 0000041 _____ () C:\Users\Janelle\AppData\Roaming\smss.exe.tmp
2012-09-21 18:14 - 2012-09-21 18:14 - 0002176 _____ () C:\Users\Janelle\AppData\Roaming\WARNING.txt
2012-03-02 11:18 - 2015-03-06 21:24 - 0000384 _____ () C:\Users\Janelle\AppData\Roaming\wklnhst.dat
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\AtStart.txt
2012-09-21 17:01 - 2012-09-23 15:24 - 0006529 _____ () C:\Users\Janelle\AppData\Local\chromeupdate.crx
2010-06-03 17:04 - 2015-03-05 23:04 - 0007620 _____ () C:\Users\Janelle\AppData\Local\d3d9caps.dat
2010-04-08 16:58 - 2015-06-26 18:10 - 0004608 _____ () C:\Users\Janelle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\DSwitch.txt
2011-03-12 05:10 - 2011-05-10 01:08 - 0001034 _____ () C:\Users\Janelle\AppData\Local\Mdebukijaduxoxu.dat
2011-03-12 05:10 - 2011-05-10 01:08 - 0000000 _____ () C:\Users\Janelle\AppData\Local\Mwuda.bin
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\QSwitch.txt
2012-09-22 14:32 - 2012-09-22 14:32 - 0000000 _____ () C:\ProgramData\50pWN8.dat
2012-09-22 14:31 - 2012-09-22 14:31 - 0000001 _____ () C:\ProgramData\5U0eRTH0.exe.b
2012-09-22 14:31 - 2012-09-22 14:31 - 0000001 _____ () C:\ProgramData\5U0eRTH0.exe_.b
2010-06-16 22:22 - 2010-06-16 22:22 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2007-05-31 02:34 - 2012-06-23 14:09 - 0000675 _____ () C:\ProgramData\hpzinstall.log
2010-04-13 20:25 - 2015-08-04 22:10 - 0047962 _____ () C:\ProgramData\nvModes.001
2010-04-13 20:25 - 2015-08-04 19:08 - 0047962 _____ () C:\ProgramData\nvModes.dat
 
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1766275910-2450894708-632072239-1000\$ef8a5bbf5833eadd22ca66c158232ebe
 
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$ef8a5bbf5833eadd22ca66c158232ebe
 
ZeroAccess:
C:\Users\Janelle\AppData\Local\{ef8a5bbf-5833-eadd-22ca-66c158232ebe}
ZeroAccess:
C:\Users\Janelle\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files\Google\Desktop\Install
 
Some files in TEMP:
====================
C:\Users\Mary\AppData\Local\Temp\symlcsv1.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
 
 
LastRegBack: 2015-08-04 22:37
 
==================== End of log ============================

Hello again Nala.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.


  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

================================================

Run Security Check

Download Security Check by screen317 from here or here.

  • save it to your Desktop
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE: If you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED!, try rebooting the system and then run SecurityCheck again.

When you’ve done the above, please run FRST again and send the new log

Logs to include with next post:

AdwCleaner log
JRT.txt
Checkup.txt
Frst.txt


Thanks

Satchfan

 

Thank you, Satchfan, for you guidance and help. Below are the needed scan logs.
 
 
AdwCleaner log
# AdwCleaner v4.208 - Logfile created 08/08/2015 at 14:32:53
# Updated 09/07/2015 by Xplode
# Database : 2015-08-01.1 [Server]
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (x86)
# Username : Janelle - JANELLE-PC
# Running from : C:\Users\Janelle\Downloads\adwcleaner_4.208.exe
# Option : Cleaning
 
***** [ Services ] *****
 
[#] Service Deleted : MyFunCards_5mService
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\FunWebProducts
Folder Deleted : C:\Program Files\MyFunCards_5m
Folder Deleted : C:\Program Files\UtilityChest_49EI
Folder Deleted : C:\Windows\system32\config\systemprofile\AppData\Roaming\Systweak
Folder Deleted : C:\Users\Janelle\AppData\Local\Conduit
Folder Deleted : C:\Users\Janelle\AppData\Local\iac
Folder Deleted : C:\Users\Janelle\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Janelle\AppData\LocalLow\iac
Folder Deleted : C:\Users\Janelle\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Janelle\AppData\LocalLow\MyFunCards_5m
Folder Deleted : C:\Users\Janelle\AppData\LocalLow\UtilityChest_49EI
Folder Deleted : C:\Users\Janelle\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\Janelle\AppData\Roaming\rightbackup
Folder Deleted : C:\Users\Janelle\AppData\Roaming\SecureSearch
Folder Deleted : C:\Users\Janelle\AppData\Roaming\Systweak
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
File Deleted : C:\Program Files\20res.dll
File Deleted : C:\Windows\system32\roboot.exe
File Deleted : C:\Windows\system32\drivers\SPPD.sys
File Deleted : C:\Users\Janelle\AppData\Roaming\WARNING.txt
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Search Protection]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@MyFunCards_5m.com/Plugin
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.DynamicBarButton
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.DynamicBarButton.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.FeedManager
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.FeedManager.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.HTMLMenu
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.HTMLMenu.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.HTMLPanel
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.HTMLPanel.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.MultipleButton
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.MultipleButton.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.PseudoTransparentPlugin
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.PseudoTransparentPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.Radio
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.Radio.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.RadioSettings
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.RadioSettings.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.ScriptButton
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.ScriptButton.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.SettingsPlugin
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.SettingsPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.SkinLauncher
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.SkinLauncher.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.SkinLauncherSettings
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.SkinLauncherSettings.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.ThirdPartyInstaller
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.ThirdPartyInstaller.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.UrlAlertButton
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.UrlAlertButton.1
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.XMLSessionPlugin
Key Deleted : HKLM\SOFTWARE\Classes\MyFunCards_5m.XMLSessionPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2438727
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3196716
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{268CA04C-106C-4636-B707-95E8CD5859E0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8C428C4B-C9E2-4B74-B791-88C3FEE48F36}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2FF49ED5-A3EF-410B-918E-97DECEB5996D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2FF49ED5-A3EF-410B-918E-97DECEB5996D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A9A5A44B-65D6-4CE2-BD35-55F5467AAD17}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d48efd2d-1c0c-4d68-bbc3-2f219c756723}
Key Deleted : HKCU\Software\distromatic
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Freecause
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\MyFunCards_5m
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\InstallIQ
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\MyFunCards_5m
Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork
Key Deleted : HKU\.DEFAULT\Software\systweak
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{25780A42-8553-4a2e-AA54-F413C5D8DA19}_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyFunCards_5mbar Uninstall
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v9.0.8112.16545
 
 
-\\ Google Chrome v44.0.2403.130
 
[C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] : 
 
*************************
 
AdwCleaner[R0].txt - [34205 bytes] - [08/08/2015 14:30:02]
AdwCleaner[S0].txt - [7957 bytes] - [08/08/2015 14:32:53]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8016  bytes] ##########
 
JRT.txt
 
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.5 (08.05.2015:1)
OS: Windows Vista (TM) Home Premium x86
Ran by [removed] on Sat 08/08/2015 at 14:44:58.85
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1}
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{210f1b36-3b7f-41a4-b5da-3eb87f5a56c2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{c4b22c87-45ef-4f43-89f2-40db2078864e}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{da71fd14-5f7b-46ae-b8b1-44074a38f331}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A9A5A44B-65D6-4CE2-BD35-55F5467AAD17}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E8D2F204-299B-4266-97E4-0126F66E3FD3}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{E22D2942-636A-4FAB-AE76-63F24DDBECC1}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c4b22c87-45ef-4f43-89f2-40db2078864e}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{da71fd14-5f7b-46ae-b8b1-44074a38f331}
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\ProgramData\50pWN8.dat
 
 
 
~~~ Folders
 
Successfully deleted: [Empty Folder] C:\Users\Janelle\Appdata\Local\{3B7D8ED1-8284-4760-B08C-D5FD6AC6315E}
Successfully deleted: [Empty Folder] C:\Users\Janelle\Appdata\Local\{E2635555-A231-4F45-B41E-5A841EDD4473}
Successfully deleted: [Empty Folder] C:\Users\Janelle\Appdata\Local\{ef8a5bbf-5833-eadd-22ca-66c158232ebe}
Successfully deleted: [Empty Folder] C:\Users\Janelle\Appdata\Local\{FC514C4F-5A4F-4F77-95F8-F28610262BEB}
Successfully deleted: [Folder] C:\ProgramData\google
 
 
 
~~~ Chrome
 
 
[C:\Users\Janelle\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Janelle\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\Janelle\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Janelle\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 08/08/2015 at 14:52:20.61
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Checkup.txt
Results of screen317's Security Check version 1.006  
 Windows Vista Service Pack 2 x86 (UAC is enabled)  
 Internet Explorer 9  
 Internet Explorer 8  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
Microsoft Security Essentials   
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:````````` 
 CCleaner     
 Java 8 Update 31  
 Java(TM) SE Runtime Environment 6 
 Java version 32-bit out of Date! 
 Adobe Reader 8 Adobe Reader out of Date! 
 Google Chrome (43.0.2357.130) 
 Google Chrome (44.0.2403.130) 
````````Process Check: objlist.exe by Laurent````````  
 Norton ccSvcHst.exe 
 Microsoft Security Essentials MSMpEng.exe 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 0 % 
````````````````````End of Log`````````````````````` 
 
Frst.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:08-08-2015 01
Ran by [removed] (administrator) on JANELLE-PC (08-08-2015 15:45:10)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1045800 2008-03-28] (Synaptics, Inc.)
HKLM\…\Run: [QPService] => C:\Program Files\HP\QuickPlay\QPService.exe [176128 2007-03-28] (CyberLink Corp.)
HKLM\…\Run: [QlbCtrl] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [159744 2007-02-13] ( Hewlett-Packard Development Company, L.P.)
HKLM\…\Run: [HP Health Check Scheduler] => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)
HKLM\…\Run: [PMBVolumeWatcher] => C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [hpWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [480560 2007-10-03] (Hewlett-Packard Development Company, L.P.)
HKLM\…\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-02-18] (Hewlett-Packard)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
HKU\S-1-5-18\…\RunOnce: [adaware] => reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f
HKU\S-1-5-18\…\RunOnce: [adaware_XP] => reg.exe delete "HKCU\Software\adaware" /f
AppInit_DLLs: C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL => C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL File not found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2007-05-31]
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk [2007-05-31]
ShortcutTarget: Adobe Reader Synchronizer.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = 
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
URLSearchHook: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 - (No Name) - {f4c28532-b9d0-4950-a2df-e83f9929242b} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll No File
SearchScopes: HKLM -> {F3F92588-AF51-4B46-9EA9-CCD5DE246D63} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvnb
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.bing.com/search?FORM=U146DF&PC=U146&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {d48efd2d-1c0c-4d68-bbc3-2f219c756723} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {E22D2942-636A-4FAB-AE76-63F24DDBECC1} URL = 
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {F3F92588-AF51-4B46-9EA9-CCD5DE246D63} URL = 
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22] (Adobe Systems Incorporated)
BHO: No Name -> {1E8A6170-7264-4D0F-BEAE-D42A53123C75} -> c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-12] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-22] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-22] (Oracle Corporation)
Toolbar: HKLM - Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll [2007-01-12] (Symantec Corporation)
Toolbar: HKLM - No Name - {210f1b36-3b7f-41a4-b5da-3eb87f5a56c2} -  No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} -  No File
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1
Tcpip\..\Interfaces\{28F058A5-ABB1-48F7-A91F-A3143EF6CC6C}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{9BBF898D-8D4D-4C50-87CB-98891C247373}: [DhcpNameServer] [removed] [removed] 192.168.1.1
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-22] (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [No File]
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [No File]
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-05] (Google Inc.)
FF Plugin HKU\S-1-5-21-1766275910-2450894708-632072239-1000: @movenetworks.com/Quantum Media Player -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll [2010-04-23] (Move Networks)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-04-11]
FF HKLM\…\Firefox\Extensions: [5mffxtbr@MyFunCards_5m.com] - C:\Program Files\MyFunCards_5m\bar\1.bin
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Janelle\AppData\Roaming\Move Networks
FF Extension: Move Media Player - C:\Users\Janelle\AppData\Roaming\Move Networks [2010-04-23]
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [{07433EEA-AEA0-461F-AB9F-35D67476BA7E}] - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E}
FF Extension: XULRunner - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E} [2011-03-12]
 
Chrome: 
=======
CHR Profile: C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-22]
CHR Extension: (Google Drive) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-22]
CHR Extension: (YouTube) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-22]
CHR Extension: (Google Search) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-22]
CHR Extension: (MSN Homepage) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkcgfbgohboipdhliafmacjnhjbhmim [2015-02-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-22]
CHR Extension: (Gmail) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-22]
CHR HKU\S-1-5-21-1766275910-2450894708-632072239-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - https://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [554616 2007-01-05] (Symantec Corporation)
R2 ccEvtMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
R2 ccSetMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
S2 CLCapSvc; C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe [270431 2007-03-28] () [File not signed]
S2 CLSched; C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe [118877 2007-03-28] () [File not signed]
S2 CLTNetCnService; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
S3 Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [110592 2007-01-09] (Hewlett-Packard Development Company, L.P.) [File not signed]
S3 comHost; c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [49248 2007-01-13] (Symantec Corporation)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [File not signed]
S2 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [135168 2006-05-02] (Hewlett-Packard Development Company, L.P.) [File not signed]
S3 IDriverT; C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S3 ISPwdSvc; c:\Program Files\Norton Internet Security\isPwdSvc.exe [80504 2007-01-14] (Symantec Corporation)
S2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2006-12-14] (Hewlett-Packard Company) [File not signed]
S3 LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE [2918008 2007-01-05] (Symantec Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
S3 RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [880640 2007-02-12] (Sonic Solutions) [File not signed]
S3 Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [1174664 2007-05-31] (Symantec Corporation)
R2 SymAppCore; c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe [47712 2007-01-05] (Symantec Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 eabfiltr; C:\Windows\System32\DRIVERS\eabfiltr.sys [8192 2006-11-30] (Hewlett-Packard Development Company, L.P.)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [387384 2007-01-10] (Symantec Corporation)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-10-06] (GFI Software)
S3 IDSvix86; C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20070108.003\IDSvix86.sys [212280 2006-12-28] (Symantec Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R3 NAVENG; C:\ProgramData\Symantec\Definitions\VirusDefs\20070110.052\NAVENG.SYS [80408 2007-01-10] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Symantec\Definitions\VirusDefs\20070110.052\NAVEX15.SYS [833048 2007-01-10] (Symantec Corporation)
R1 SBRE; C:\Windows\system32\drivers\SBREDrv.sys [101720 2011-06-30] (Sunbelt Software)
S3 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [417592 2007-01-03] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [247608 2007-01-12] (Symantec Corporation)
S3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [276792 2007-01-12] (Symantec Corporation)
R1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [25400 2007-01-12] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [115000 2007-05-31] (Symantec Corporation)
U3 Winsock; no ImagePath
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U5 SYMTDI; C:\Windows\System32\Drivers\SYMTDI.sys [191544 2007-01-09] (Symantec Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-08 15:45 - 2015-08-08 15:45 - 00000000 ____D C:\Users\Janelle\Downloads\FRST-OlderVersion
2015-08-08 15:15 - 2015-08-08 15:16 - 00852684 _____ C:\Users\Janelle\Downloads\SecurityCheck (1).exe
2015-08-08 15:15 - 2015-08-08 15:15 - 00852684 _____ C:\Users\Janelle\Downloads\SecurityCheck.exe
2015-08-08 14:52 - 2015-08-08 14:52 - 00003107 _____ C:\Users\Janelle\Desktop\JRT.txt
2015-08-08 14:43 - 2015-08-08 14:43 - 01797896 _____ (Malwarebytes Corporation) C:\Users\Janelle\Downloads\1EF0.tmp
2015-08-08 14:42 - 2015-08-08 14:43 - 01797896 _____ (Malwarebytes Corporation) C:\Users\Janelle\Downloads\JRT.exe
2015-08-08 14:29 - 2015-08-08 15:43 - 00000000 ____D C:\AdwCleaner
2015-08-08 14:28 - 2015-08-08 14:28 - 02248704 _____ C:\Users\Janelle\Downloads\adwcleaner_4.208 (1).exe
2015-08-08 14:27 - 2015-08-08 14:27 - 02248704 _____ C:\Users\Janelle\Downloads\adwcleaner_4.208.exe
2015-08-05 00:06 - 2015-08-05 00:06 - 00029723 _____ C:\Users\Janelle\Downloads\FRST 8-4-15.txt
2015-08-05 00:06 - 2015-08-05 00:06 - 00029675 _____ C:\Users\Janelle\Downloads\Addition - FRST Farbar Recovery 8-4-15.txt
2015-08-05 00:01 - 2015-08-05 00:03 - 00029675 _____ C:\Users\Janelle\Downloads\Addition.txt
2015-08-05 00:00 - 2015-08-08 15:45 - 00016819 _____ C:\Users\Janelle\Downloads\FRST.txt
2015-08-04 23:59 - 2015-08-08 15:45 - 00000000 ____D C:\FRST
2015-08-04 23:57 - 2015-08-08 15:45 - 01673216 _____ (Farbar) C:\Users\Janelle\Downloads\FRST.exe
2015-08-04 23:53 - 2015-08-04 23:53 - 00004149 _____ C:\Users\Janelle\Documents\Documents\Documents\aswMBR.txt
2015-08-04 23:53 - 2015-08-04 23:53 - 00000512 _____ C:\Users\Janelle\Documents\Documents\Documents\MBR.dat
2015-08-04 23:06 - 2015-08-04 23:07 - 05198336 _____ (AVAST Software) C:\Users\Janelle\Downloads\aswMBR.exe
2015-08-04 20:24 - 2015-08-04 21:29 - 00000000 ____D C:\Program Files\GUM81CC.tmp
2015-08-04 20:09 - 2015-08-04 20:10 - 05831179 _____ (Piriform Ltd) C:\Users\Janelle\Downloads\9AA6.tmp
2015-07-31 17:27 - 2015-08-01 10:36 - 00000000 ____D C:\Program Files\Skype
2015-07-31 17:27 - 2015-07-31 17:27 - 00000000 ____D C:\Users\Janelle\AppData\Local\Skype
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-08 15:23 - 2013-09-06 17:08 - 01176642 _____ C:\Windows\WindowsUpdate.log
2015-08-08 15:14 - 2014-10-01 21:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-08 14:51 - 2006-11-02 05:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-08 14:51 - 2006-11-02 05:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-08 14:50 - 2015-05-27 17:57 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-08 14:36 - 2015-05-27 17:57 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-08 14:36 - 2010-04-13 20:25 - 00047962 _____ C:\ProgramData\nvModes.001
2015-08-08 14:35 - 2015-06-26 18:21 - 00000330 _____ C:\Windows\Tasks\HPCeeScheduleForJanelle.job
2015-08-08 14:35 - 2006-11-02 06:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-08 14:34 - 2006-11-02 06:01 - 00032528 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-07 21:32 - 2010-09-26 20:58 - 00000052 _____ C:\Windows\system32\DOErrors.log
2015-08-06 20:55 - 2010-04-13 20:25 - 00047962 _____ C:\ProgramData\nvModes.dat
2015-08-05 18:44 - 2012-08-01 03:18 - 00000414 _____ C:\Windows\Tasks\PC Unleashed.job
2015-08-04 22:33 - 2014-10-01 21:35 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-08-04 22:33 - 2014-10-01 21:35 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-08-04 21:51 - 2015-05-27 18:00 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-04 21:29 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\system32\Msdtc
2015-08-04 21:28 - 2013-05-10 23:29 - 00000000 ____D C:\Users\Mary
2015-08-04 21:28 - 2010-03-24 21:33 - 00000000 ____D C:\Users\Janelle
2015-08-04 21:28 - 2006-11-02 03:22 - 51380224 _____ C:\Windows\system32\config\software_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 40632320 _____ C:\Windows\system32\config\components_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 25427968 _____ C:\Windows\system32\config\system_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00524288 _____ C:\Windows\system32\config\default_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2015-08-04 21:27 - 2015-05-27 18:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-04 21:27 - 2010-03-24 21:42 - 00000000 ____D C:\Users\Janelle\AppData\Local\QuickPlay
2015-08-04 21:27 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\system32\spool
2015-08-04 21:27 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\registration
2015-08-04 21:23 - 2011-03-24 14:04 - 00000000 ____D C:\Users\Janelle\AppData\Roaming\HpUpdate
2015-08-04 20:09 - 2010-06-16 22:20 - 00000000 ____D C:\Users\Janelle\AppData\Roaming\Skype
2015-08-01 10:36 - 2010-06-16 22:19 - 00000000 ____D C:\ProgramData\Skype
 
==================== Files in the root of some directories =======
 
2013-05-27 15:35 - 2013-05-18 19:03 - 0708168 _____ (MindSpark) C:\Program Files\20Uninstall YourLocalLotto Toolbar.dll
2011-10-10 09:48 - 2011-10-10 09:48 - 0000272 _____ () C:\Users\Janelle\AppData\Roaming\.backup.dm
2012-09-21 17:01 - 2012-09-23 14:29 - 0000048 _____ () C:\Users\Janelle\AppData\Roaming\0F478F.dat
2014-02-02 17:41 - 2014-02-02 17:41 - 0002086 _____ () C:\Users\Janelle\AppData\Roaming\data.sec
2012-09-21 17:01 - 2012-09-21 17:01 - 0000028 _____ () C:\Users\Janelle\AppData\Roaming\Filesop.txt.block
2010-03-24 23:01 - 2010-04-13 19:51 - 0013119 _____ () C:\Users\Janelle\AppData\Roaming\nvModes.001
2010-03-24 23:01 - 2010-04-13 15:55 - 0013119 _____ () C:\Users\Janelle\AppData\Roaming\nvModes.dat
2012-09-21 18:14 - 2012-09-21 18:14 - 0000030 _____ () C:\Users\Janelle\AppData\Roaming\ok.txt.block
2012-09-23 14:38 - 2012-09-23 14:38 - 0000041 _____ () C:\Users\Janelle\AppData\Roaming\smss.exe.tmp
2012-03-02 11:18 - 2015-03-06 21:24 - 0000384 _____ () C:\Users\Janelle\AppData\Roaming\wklnhst.dat
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\AtStart.txt
2010-06-03 17:04 - 2015-03-05 23:04 - 0007620 _____ () C:\Users\Janelle\AppData\Local\d3d9caps.dat
2010-04-08 16:58 - 2015-06-26 18:10 - 0004608 _____ () C:\Users\Janelle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\DSwitch.txt
2011-03-12 05:10 - 2011-05-10 01:08 - 0001034 _____ () C:\Users\Janelle\AppData\Local\Mdebukijaduxoxu.dat
2011-03-12 05:10 - 2011-05-10 01:08 - 0000000 _____ () C:\Users\Janelle\AppData\Local\Mwuda.bin
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\QSwitch.txt
2012-09-22 14:31 - 2012-09-22 14:31 - 0000001 _____ () C:\ProgramData\5U0eRTH0.exe.b
2012-09-22 14:31 - 2012-09-22 14:31 - 0000001 _____ () C:\ProgramData\5U0eRTH0.exe_.b
2010-06-16 22:22 - 2010-06-16 22:22 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2007-05-31 02:34 - 2012-06-23 14:09 - 0000675 _____ () C:\ProgramData\hpzinstall.log
2010-04-13 20:25 - 2015-08-08 14:36 - 0047962 _____ () C:\ProgramData\nvModes.001
2010-04-13 20:25 - 2015-08-06 20:55 - 0047962 _____ () C:\ProgramData\nvModes.dat
 
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1766275910-2450894708-632072239-1000\$ef8a5bbf5833eadd22ca66c158232ebe
 
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$ef8a5bbf5833eadd22ca66c158232ebe
 
ZeroAccess:
C:\Users\Janelle\AppData\Local\{ef8a5bbf-5833-eadd-22ca-66c158232ebe}
ZeroAccess:
C:\Users\Janelle\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files\Google\Desktop\Install
 
Some files in TEMP:
====================
C:\Users\Janelle\AppData\Local\Temp\Quarantine.exe
C:\Users\Janelle\AppData\Local\Temp\sqlite3.dll
C:\Users\Mary\AppData\Local\Temp\symlcsv1.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
 
 
LastRegBack: 2015-08-08 14:43
 
==================== End of log ============================

That cleaned up a lot but unfortunately one or more of the identified infections is known to use a backdoor trojan known as ZeroAccess, a particularly nasty rootkit infection.

This allows hackers to remotely control your computer, steal critical system information and download and execute files without your knowledge.

I would advice you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the infection has been identified and because of its backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS.

Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

 

These infections can possibly be cleaned, but it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting both system partitions and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, If you decide to go through with the cleanup, please proceed with the following steps:

================================================

Run Farbar Recovery Scan Tool

Farbar Recovery Scan Tool is in your Downloads folder. It’s a good idea to move it to your desktop otherwise future fixes may not work.

  • go to your Downloads folder and locate Farbar Recovery Scan Tool
  • right click and select Cut
  • go to an empty spot on your desktop, right click and select Paste

Farbar Recovery Scan Tool should now be on your desktop.


Open notepad (Start >All Programs > Accessories > Notepad). Please copy the entire contents of the code box below and paste it into Notepad.

URLSearchHook: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 - (No Name) - {f4c28532-b9d0-4950-a2df-e83f9929242b} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll No File
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.bing.com/…rc=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {d48efd2d-1c0c-4d68-bbc3-2f219c756723} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {E22D2942-636A-4FAB-AE76-63F24DDBECC1} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {F3F92588-AF51-4B46-9EA9-CCD5DE246D63} URL =
Toolbar: HKLM - No Name - {210f1b36-3b7f-41a4-b5da-3eb87f5a56c2} -  No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} -  No File
FF HKLM\…\Firefox\Extensions: [5mffxtbr@MyFunCards_5m.com] - C:\Program Files\MyFunCards_5m\bar\1.bin
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [{07433EEA-AEA0-461F-AB9F-35D67476BA7E}] - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E}
FF Extension: XULRunner - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E} [2011-03-12]
U3 Winsock; no ImagePath
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
2015-08-04 20:09 - 2015-08-04 20:10 - 05831179 _____ (Piriform Ltd) C:\Users\Janelle\Downloads\9AA6.tmp
2015-07-31 17:27 - 2015-07-31 17:27 - 00000000 ____D C:\Users\Janelle\AppData\Local\Skype
2011-03-12 05:10 - 2011-05-10 01:08 - 0001034 _____ () C:\Users\Janelle\AppData\Local\Mdebukijaduxoxu.dat
2011-03-12 05:10 - 2011-05-10 01:08 - 0000000 _____ () C:\Users\Janelle\AppData\Local\Mwuda.bin
DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E}
C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E} [2011-03-12]
C:\Users\Janelle\Downloads\9AA6.tmp
C:\Users\Janelle\AppData\Local\Skype
C:\Users\Janelle\AppData\Local\{ef8a5bbf-5833-eadd-22ca-66c158232ebe}
C:\Users\Janelle\AppData\Local\Google\Desktop\Install
C:\Program Files\Google\Desktop\Install
C:\Program Files\MyFunCards
C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E}
C:\Program Files\Lavasoft\Ad-Aware
EmptyTemp:

NOTE: this script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

================================================

Please run these in the order requested.

Run TDSSKiller

Please download TDSSKiller.zip

  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan
    • only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.
    • then click Continue > Reboot now
  • copy and paste the log in your next reply.
    • A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)

======================================================

Download and run ComboFix

Download Combofix from either of the links below, and save it to your desktop.  

Link 1
Link 2

**Note:  It MUST be saved directly to your desktop. Choose save as and then make sure you choose Desktop

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.

  • when finished, it will produce a report for you.  
  • please post the C:\ComboFix.txt in your next post.

Please also remember to include (Fixlog.txt) and the TDSSKiller log

Thanks

Satchfan

 

Satchfan, I'm in trouble now and making contact from another computer system. I cannot access the internet after performing the first scan.

I read all your information and also that of the links you provided, and decided to proceed with your instructions of cleanup since what I use my computer for is considered of low security concern. It seemed worth the try to clean up before reformat and reinstall.

As you suggested, I moved FSRT to the desktop from downloads and then copied the code box into Notepad, but when I tried to use the desktop icon it did not work, so I created a file in downloads and placed it back there along with the fix code. I linked there and it worked. When it rebooted itself and I logged into my system to proceed to the next step, I was unable to link to the internet by either Google Chrome or Internet Explorer. I troubleshooted my connection problem and rebooted modem, router box, and went to COMPUTER to check on links etc. When that failed, I resolved to try a System Reboot back to the last change so I could access Internet and contact you. The System Reboot failed.

Now my computer internet access results in a message that has a picture of a dinosaur above it: THIS WEBPAGE IS NOT AVAILABLE. DNS_PROBE_FINISHED_NO_INTERNET. This is the message that first appeared right after the fix and the machine rebooted itself.

Let's see if we can restore it easily but if this doesn't work don't worry as there are other solutions available to solve this problem.

Run Zoek

Download zoek.exe to your Desktop:

Important : Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.

  • on Windows Vista, 7, and 8, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

Let me know how that goes.

I am travelling today so my reply may be a bit more delayed.

Thanks

Satchfan

 

I am reading your email from my workplace computer. My question is whether I will be able to download zoek.exe without the ability to access the internet on my infected home computer?

Hi Nala

 

As you cannot access the internet with your PC, you will need to download Zoek and save it to a USB flash drive or other removable media. copy it to the desktop of the infected computer and then follow the previous instructions to run Zoek.

Please let me know if you need more explanation, (had a long day today and the instructions may be my problem, not yours). :weee:

Satchpad, I did as instructed and the scan just completed with a reboot. Attempted Internet and first seemed it was successful because it linked to Google title page with the search bar and beneath it "Welcome to Google" and "Chrome Web Store" links which did not happen before the scan, but when I tried to search sites or use my personal bookmark links, still appearing across the top of the page, the result is the dinosaur and verbiage of previous. The same with trying to link to the other two pages. Should I reinstate the antivirus by checking the Real-time protection? Or should I leave this as is until we are done trying to restore internet access?

Uninstall/Reinstall Google Chrome

It seems Chrome is the immediate problem so let’s try to re-install it.

First save all your bookmarks/favourites.

  • open Chrome, click on the 3 bars in the top right hand corner, select Bookmarks and then Bookmarks Manager
  • click on Organise and then select Export Bookmarks to HTML file, then choose Desktop to save it
  • again, click on the three bars in the top right hand corner and select Settings
  • in the list of Settings under “Sign in” click on Disconnect your Google Account
  • in the text of the next window click on “Google Dashboard” then, at the “Chrome sync” screen, click on Stop and Clear at the bottom
  • a box will open and ask for confirmation, click on OK (wait for this to complete before doing the next step)
  • when confirmation appears close that page and then click on Disconnect account
  • shut Google Chrome, click on Start > Control Panel > Programs and Features (or Add/Remove Programs in XP) and uninstall Google Chrome. Select Everything for removal if asked.

Reboot the system and then reinstall Google Chrome from here

Repeat the process to reinstate your bookmarks by going to Bookmarks > Bookmarks Manager > Organise and select Import Bookmarks.

Satchfan
 

 

I don't use Chrome but have just installed it to see what I have under "Settings" and I don't have it either. Had to sign in to get that to appear so please sign in using your Google Chrome username and password: when you've done that, Disconnect your Google Account will appear and you can continue with the other instructions.

Not having internet access on my computer, there was no way for me to sign in and perform the steps to delete and reinstall on my system via the link you provided. I had to access my account and delete it from another computer. I then went to my computer programs page and uninstalled Google Chrome. What occurs now in trying to access the internet is the inability to do so via my Internet Explorer.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI