This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC turns itself off [Solved]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I run ,

CyberPower Inc.

Windows 7 Home Premium,

service pack 1,

ADM FX - 4100 Quad Core Processor, 3.60Ghz

8.00GB Ram,

64-bit,

And for the last 3 days, it randomly turns itself off. When I turn it back on, I have the "start normally, run in safe mode. etc." option.

We cleaned it all out, I made sure connections were tight, I made sure all of the fans were coming on when turned on, I have been monitoring the temp which has been fine… Not sure if it may be a virus or hardware issue? ANy help would be great… If I turn it on and just let it sit, it will stay on for hours, but if I start doing things, then poof.

 

I was directed here and told to run aswMBR, and here is my log…

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-08-09 01:15:34
—————————–
01:15:34.033    OS Version: Windows x64 6.1.7601 Service Pack 1
01:15:34.033    Number of processors: 4 586 0x102
01:15:34.034    ComputerName: AMY-PC  UserName: Amy
01:15:35.669    Initialize success
01:15:35.683    VM: initialized successfully
01:15:35.686    VM: Amd CPU BiosDisabled
01:15:40.318    AVAST engine defs: 15080702
01:15:49.074    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000068
01:15:49.079    Disk 0 Vendor:   Size: 0MB BusType: 0
01:15:49.347    Disk 0 MBR read successfully
01:15:49.352    Disk 0 MBR scan
01:15:49.360    Disk 0 Windows 7 default MBR code
01:15:49.365    Disk 0 MBR hidden
01:15:49.403    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
01:15:49.445    Disk 0 default boot code
01:15:49.542    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       476838 MB offset 206848
01:15:49.681    Disk 0 scanning C:\Windows\system32\drivers
01:16:00.154    Service scanning
01:16:26.354    Modules scanning
01:16:26.354    Disk 0 trace - called modules:
01:16:26.374    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor.sys
01:16:26.384    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007a92790]
01:16:26.384    3 CLASSPNP.SYS[fffff8800186c43f] -> nt!IofCallDriver -> [0xfffffa80069aad20]
01:16:26.384    5 ACPI.sys[fffff88000ef87a1] -> nt!IofCallDriver -> \Device\00000068[0xfffffa8006b05310]
01:16:27.825    AVAST engine scan C:\Windows
01:16:40.096    AVAST engine scan C:\Windows\system32
01:18:58.735    AVAST engine scan C:\Windows\system32\drivers
01:19:09.037    AVAST engine scan C:\Users\Amy
01:20:19.037    Disk 0 MBR has been saved successfully to "C:\Users\Amy\Desktop\MBR.dat"
01:20:19.107    The log file has been saved successfully to "C:\Users\Amy\Desktop\aswMBR.txt"

 

This is my FRST scan file…

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:08-08-2015 01
Ran by [removed] (administrator) on AMY-PC (09-08-2015 01:30:49)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 9 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Juniper Networks, Inc.) C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(NDS Technologies) C:\Users\Amy\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Users\Amy\AppData\Local\DIRECTV Player\NDSPCShowServer.exe
(Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\McciCMService.exe
(iWin Inc.) C:\Program Files (x86)\Pogo Games\PGMTrusted.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
() C:\Users\Amy\Desktop\openhardwaremonitor-v0.7.1-beta\OpenHardwareMonitor\OpenHardwareMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_209.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_209.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12632168 2011-07-19] (Realtek Semiconductor)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM\…\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [309184 2012-03-28] (Citrix Systems, Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\Run: [PCShowServer] => C:\Users\Amy\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe [1765744 2013-11-17] (NDS Technologies)
AppInit_DLLs: C:\PROGRA~3\Wincert\WIN64C~1.DLL => C:\PROGRA~3\Wincert\WIN64C~1.DLL File not found
AppInit_DLLs:  C:\PROGRA~2\MOVIES~1\Datamngr\x64\mgrldr.dll => C:\PROGRA~2\MOVIES~1\Datamngr\x64\mgrldr.dll File not found
AppInit_DLLs-x32: c:\progra~3\wincert\win32c~1.dll => "c:\progra~3\wincert\win32c~1.dll" File not found
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-07] (AVAST Software)
CHR HKU\S-1-5-21-1666203005-3817340796-160210981-1002\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
HKU\S-1-5-21-1666203005-3817340796-160210981-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKU\S-1-5-21-1666203005-3817340796-160210981-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://sites.google.com/site/amyhere1/
SearchScopes: HKLM -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = http://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = http://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1666203005-3817340796-160210981-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-13] (Advanced Micro Devices)
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2014-09-19] (Siber Systems Inc.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-07] (AVAST Software)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2013-07-31] (Logitech, Inc.)
BHO-x32: &Yahoo! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll [2013-08-07] (Yahoo! Inc.)
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} ->  No File
BHO-x32: No Name -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} ->  No File
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2014-09-19] (Siber Systems Inc.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-27] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-07] (AVAST Software)
BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2013-07-31] (Logitech, Inc.)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-10-21] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-27] (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2014-09-19] (Siber Systems Inc.)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll [2013-08-07] (Yahoo! Inc.)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2014-09-19] (Siber Systems Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-10-21] (Microsoft Corporation.)
Toolbar: HKU\S-1-5-21-1666203005-3817340796-160210981-1002 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKU\S-1-5-21-1666203005-3817340796-160210981-1002 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2014-09-19] (Siber Systems Inc.)
DPF: HKLM-x32 {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://attvpn.arisevendor.net/dana-cached/sc/JuniperSetupClient.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation)
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{EB47C7B6-9FD3-4EFE-A29A-F7115438F68D}: [DhcpNameServer] 192.168.254.254

FireFox:
========
FF ProfilePath: C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\c9382cp1.default
FF DefaultSearchEngine.US: Google
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-27] (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1666203005-3817340796-160210981-1002: @nds.com/PlayerPlugin -> C:\Users\Amy\AppData\Local\DIRECTV Player\npPlayerPlugin.dll [2013-11-17] (DIRECTV)
FF Plugin HKU\S-1-5-21-1666203005-3817340796-160210981-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Amy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-10] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1666203005-3817340796-160210981-1002: NDS.com/PlayerPlugin -> C:\Users\Amy\AppData\Local\DIRECTV Player\npPlayerPlugin.dll [2013-11-17] (DIRECTV)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll [2012-03-28] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll [2012-03-28] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll [2012-03-28] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll [2012-03-28] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll [2012-03-28] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll [2012-03-28] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll [2012-03-28] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll [2012-03-28] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll [2012-03-28] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll [2012-03-19] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll [2012-03-28] (Citrix Systems, Inc.)
FF SearchPlugin: C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\c9382cp1.default\searchplugins\google-avast.xml [2015-01-28]
FF Extension: Noia Fox options - C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\c9382cp1.default\Extensions\[removed] [2012-07-10]
FF Extension: Scribblies Kids - C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\c9382cp1.default\Extensions\{33A8946C-B859-4f7d-8382-ADAB29623DEE}.xpi [2012-07-10]
FF Extension: mx3 - C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\c9382cp1.default\Extensions\{3d2ee42e-a6d9-4888-bd17-2148dc7928d7}.xpi [2012-07-10]
FF Extension: MicroFox - C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\c9382cp1.default\Extensions\{403304EE-066A-4a2a-8F41-F12028480A0A}.xpi [2012-07-10]
FF Extension: Nautipolis for Firefox - C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\c9382cp1.default\Extensions\{6C4BAFB6-2AC2-4405-A98D-546B55B3AE92}.xpi [2012-07-10]
FF Extension: YouTube High Definition - C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\c9382cp1.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2014-05-08]
FF Extension: Noia Fox - C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\c9382cp1.default\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi [2012-07-10]
FF Extension: Scribblies Brite - C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\c9382cp1.default\Extensions\{F587B2D4-7C09-4a23-AC4A-8D6E3CE8C7DA}.xpi [2012-07-10]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-02-18]
FF HKLM-x32\…\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-11-22]
FF HKLM-x32\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox
FF Extension: RoboForm Toolbar for Firefox - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2014-01-03]
FF HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox

Chrome:
=======
CHR Profile: C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Learn French - Très Bien) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeifanonhefcaphaeeknpklkfnjjmpec [2013-10-17]
CHR Extension: (geography puzzles) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahhobhjcbloinpmfpfamnpcedjeiaedk [2014-08-27]
CHR Extension: (Bookvoid) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbiiohnfgknkkoalnbonfdafmgbpckad [2014-08-27]
CHR Extension: (Global Map) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\biabadelbimllanaekjkipoflfdpihba [2014-09-12]
CHR Extension: (Duckie Deck - Games for Kids) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcldaifgljnnnikmmaoceclpcbfdaon [2014-08-27]
CHR Extension: (YouTube) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-02-25]
CHR Extension: (JunkFill) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\cajejbcjfkhgmfbapmhopccephhjedeb [2012-02-25]
CHR Extension: (Simple Autofill) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdjplknefldnfcncohonjbeeocljjmbm [2013-11-19]
CHR Extension: (Google Search) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-02-25]
CHR Extension: (Light) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dacdieigeclacgkdlmnojihknoblpafo [2014-08-27]
CHR Extension: (Magic Inputs Filler) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgchjemniofpmdkgnoejdkgomjldfgmh [2012-02-25]
CHR Extension: (Solitaire) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkelcbhdkpcdiiancfjhjcpdinbbfolp [2012-05-07]
CHR Extension: (Solitairey) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dofbnmhnoodmmlhflbcihicmbnhhinhp [2012-05-07]
CHR Extension: (Mahjongg) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegpopcingfghbompjfejakfeaolmbop [2012-05-07]
CHR Extension: (Solitaire Games) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eljmkmbmhmgmpmmbkagbobpmpocacdbo [2012-05-07]
CHR Extension: (Virtual Piano Black) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjagcpcbacoaogfljhglghpjhkmmfeeo [2012-05-07]
CHR Extension: (Coloring Pages) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\foniidelkdlapcpngdpcchdemnemdbnf [2014-08-27]
CHR Extension: (Photo Effects) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gafbpeehppejkfigihljgkjlhkidknjm [2014-08-27]
CHR Extension: (Ancient Odyssey Mahjong) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejnoiphkikhmpkfpilploabdnnpfpgm [2012-05-07]
CHR Extension: (Elmo and Zoe Count Hats) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfklepfhebppepfcnlkapahpjkckoeea [2014-08-27]
CHR Extension: (Planetarium) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp [2014-08-27]
CHR Extension: (Pictico — Coloring for Kids) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gndkeamlgkegbmmoheplcndpopglacgf [2014-08-27]
CHR Extension: (Reversi) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfnbmacmdncmcenonabhaknjieebpfgp [2012-05-07]
CHR Extension: (Watch Live Online TV) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibdhdjhjfcemacjmnemdfhhmbbelclde [2014-08-27]
CHR Extension: (Kindle Cloud Reader) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2014-08-27]
CHR Extension: (FRENCH MEMORY) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\idapckekcfdbejmjnjecgnphgecnkmek [2014-08-27]
CHR Extension: (World of Solitaire) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbnllnaaaohekjkcpfdllhhjijnidgn [2012-05-07]
CHR Extension: (USA Live TV ) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ignbeedgglooeoajinojhjbgpjndgobc [2014-08-27]
CHR Extension: (German Flashcards) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijecamokjmiajijbajfnlbkfknpplkdf [2014-08-27]
CHR Extension: (UNO ONLINE!) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jffcjnoimmgcilbfgfhjkldapkdkicii [2013-11-19]
CHR Extension: (Word War) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\kabpecppkafpeglblchgegjlajhdiidh [2013-11-21]
CHR Extension: (Lucas' Whiteboard) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaikeblfhigmfihlcbehjnemadbfhadg [2014-08-27]
CHR Extension: (Detroit Tigers Theme) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\kegciancnpbnmjnpoakoffjnjajdlmej [2014-08-29]
CHR Extension: (Sketchpad 3.5) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkghjbajgkcialbbimbifdcjilhcgoim [2014-08-27]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Dog licking screen clean) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcckfpphpmddlmffbhampmmbfgabaage [2014-08-27]
CHR Extension: (Pora Ora) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lolfbboglbaomhdfgnlmjfjnhfpcmcla [2014-08-27]
CHR Extension: (Lego Builder) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mapnbjhfjionggfhlkmhjbmbpgfdlolh [2014-08-27]
CHR Extension: (PBS Kids PLAY!) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkmpnidbgboeiebfgmoibgjhopampkj [2014-08-27]
CHR Extension: (Detroit Tigers) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\micnehbpodaaohhkbbpenachpbgaakjc [2014-08-29]
CHR Extension: (Mahjong) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mimcabmfjaeoldnchodmelflfjmgaojh [2012-05-07]
CHR Extension: (Google Drawings) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkaakpdehdafacodkgkpghoibnmamcme [2014-08-27]
CHR Extension: (WOW Connect 2) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkkicagmpjegkhkpdndmejpbpfhincfi [2014-09-12]
CHR Extension: (Dice) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkomhldhkbggnefgdjggpfaaljlfmahe [2014-09-12]
CHR Extension: (Learn French) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmbpackhnppgjmbkdomaciakggemkfme [2014-09-12]
CHR Extension: (99puzzles.com - The Best Jigsaw Puzzles) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mojepdcdhagkphhjdpeomllefjahglbl [2014-09-09]
CHR Extension: (My Home Plus) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\naiefbbjcibjigdgcllbaikfogbnaohn [2014-09-12]
CHR Extension: (Coloring Pages) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbldodhfmmfcfaooalepihkfkmjhnmei [2014-08-27]
CHR Extension: (Word Off) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndcpijpnakeeiadgldiclnehipkaohgn [2013-11-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-25]
CHR Extension: (Reversi) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhjkapjdlmmadkepnmlkpadnnnnoebm [2012-05-07]
CHR Extension: (Underwater Games - Into The Deep) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\oepplaobifgnddcccjpklgdfdbpencca [2014-08-27]
CHR Extension: (Stopwatch) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohbfkkmpnlpgbbfdflaiikoohbidaikj [2014-08-27]
CHR Extension: (French lessons - Frantastique) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ondpaahlldgcdnhgiflipkinlnldmanp [2014-09-12]
CHR Extension: (MegaStar Sliding) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfaogkfljpdfmodbmbogiiblppijleen [2014-08-27]
CHR Extension: (Gmail) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-02-25]
CHR Extension: (RoboForm Password Manager) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2014-03-24]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-03]
CHR HKLM-x32\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-03-24]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-08-16] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S4 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-07] (AVAST Software)
S4 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109008 2015-08-07] (AVAST Software)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [78088 2014-08-26] (Hewlett-Packard Company)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 McciCMService; C:\Program Files (x86)\Common Files\Motive\McciCMService.exe [319488 2011-07-05] (Alcatel-Lucent) [File not signed]
R2 McciCMService64; C:\Program Files\Common Files\Motive\McciCMService.exe [517632 2011-07-05] (Alcatel-Lucent) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
R2 PGMTrusted; C:\Program Files (x86)\Pogo Games\PGMTrusted.exe [520360 2013-03-25] (iWin Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-07] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28144 2015-08-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-07] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [454016 2015-08-07] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-07] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048856 2015-08-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-07] (AVAST Software)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 sscdserd; C:\Windows\System32\DRIVERS\sscdserd.sys [141384 2010-11-11] (MCCI Corporation)
U3 Winsock; no ImagePath
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
R3 WinRing0_1_2_0; \??\C:\Users\Amy\Desktop\openhardwaremonitor-v0.7.1-beta\OpenHardwareMonitor\OpenHardwareMonitor.sys [X]
U3 aswMBR; \??\C:\Users\Amy\AppData\Local\Temp\aswMBR.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-09 01:29 - 2015-08-09 01:30 - 00034582 _____ C:\Users\Amy\Desktop\FRST.txt
2015-08-09 01:29 - 2015-08-09 01:30 - 00000000 ____D C:\FRST
2015-08-09 01:29 - 2015-08-09 01:29 - 00012741 _____ C:\Users\Amy\Desktop\Addition.txt
2015-08-09 01:28 - 2015-08-09 01:28 - 02169856 _____ (Farbar) C:\Users\Amy\Desktop\FRST64.exe
2015-08-09 01:20 - 2015-08-09 01:20 - 00001934 _____ C:\Users\Amy\Desktop\aswMBR.txt
2015-08-09 01:20 - 2015-08-09 01:20 - 00000512 _____ C:\Users\Amy\Desktop\MBR.dat
2015-08-09 01:12 - 2015-08-09 01:12 - 05198336 _____ (AVAST Software) C:\Users\Amy\Desktop\aswMBR.exe
2015-08-09 01:05 - 2015-08-09 01:05 - 00000056 _____ C:\Windows\setupact.log
2015-08-09 01:05 - 2015-08-09 01:05 - 00000000 _____ C:\Windows\setuperr.log
2015-08-09 01:04 - 2015-08-09 01:04 - 00001018 _____ C:\Windows\PFRO.log
2015-08-08 22:04 - 2015-08-08 22:04 - 00023081 _____ C:\Users\Amy\Desktop\openhardwarereport3.txt
2015-08-08 21:41 - 2015-08-08 21:41 - 00002398 _____ C:\Users\Amy\Desktop\cc_20150808_214103.reg
2015-08-08 21:35 - 2015-08-08 21:35 - 00000472 _____ C:\Users\Amy\Desktop\cc_20150808_213502.reg
2015-08-08 21:34 - 2015-08-08 21:34 - 00023081 _____ C:\Users\Amy\Desktop\openhardwarereport2.txt
2015-08-08 20:57 - 2015-08-08 20:57 - 00023081 _____ C:\Users\Amy\Desktop\openhardwarereport1.txt
2015-08-08 20:48 - 2015-08-08 20:48 - 00000720 _____ C:\Users\Amy\Desktop\system info and post.txt
2015-08-08 20:45 - 2015-08-09 01:24 - 00000641 _____ C:\Users\Amy\Desktop\my system info.txt
2015-08-08 19:34 - 2015-08-08 19:34 - 00023081 _____ C:\Users\Amy\Desktop\openhardwarereport.txt
2015-08-08 19:31 - 2015-08-08 19:31 - 00000000 ____D C:\Windows\System32\Tasks\Open Hardware Monitor
2015-08-08 02:37 - 2015-08-08 02:37 - 00000000 ____D C:\Users\Amy\Desktop\openhardwaremonitor-v0.7.1-beta
2015-08-07 23:48 - 2015-08-07 23:48 - 00000507 _____ C:\Users\Amy\Desktop\Install FileOpenerPro.lnk
2015-08-07 23:46 - 2015-08-07 23:46 - 00900432 _____ (Mobile Agile System Installer) C:\Users\Amy\Desktop\Setup (1).exe
2015-08-07 22:13 - 2015-08-07 22:13 - 00023081 _____ C:\Users\Amy\Desktop\OpenHardwareMonitor.Report.txt
2015-08-07 22:10 - 2015-08-07 22:10 - 00000000 ____D C:\Users\Amy\Desktop\OpenHardwareMonitor
2015-08-07 22:09 - 2015-08-07 22:10 - 00511764 _____ C:\Users\Amy\Desktop\openhardwaremonitor-v0.7.1-beta.zip
2015-08-07 22:05 - 2015-08-07 22:06 - 01347888 _____ ( ) C:\Users\Amy\Desktop\hwmonitor-pro_1.23.exe
2015-08-07 15:46 - 2015-08-07 20:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-07 08:28 - 2015-08-07 08:38 - 00002035 _____ C:\Users\Public\Desktop\Avast Internet Security.lnk
2015-08-07 08:28 - 2015-08-07 08:28 - 00001942 _____ C:\Users\Public\Desktop\Avast SafeZone.lnk
2015-08-07 08:27 - 2015-08-07 08:27 - 00454016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2015-08-07 08:27 - 2015-08-07 08:27 - 00378880 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-08-07 08:27 - 2015-08-07 08:27 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-08-07 08:27 - 2015-08-07 08:27 - 00028144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2015-08-04 22:31 - 2015-08-04 22:42 - 00000000 ____D C:\Users\Amy\Desktop\pogo emotes_files
2015-08-04 22:12 - 2015-08-04 23:10 - 00000725 _____ C:\Users\Amy\Desktop\pino dump trump rules.txt
2015-08-03 09:37 - 2015-08-04 10:33 - 00003272 _____ C:\Users\Amy\Desktop\Jeffery games.txt
2015-08-02 08:52 - 2015-08-02 08:52 - 00000884 _____ C:\Users\Amy\Documents\cc_20150802_085215.reg
2015-07-30 02:44 - 2015-07-30 02:46 - 00018281 _____ C:\Users\Amy\Desktop\serj tankian  elect the dead.txt
2015-07-30 01:14 - 2015-08-06 00:53 - 00014231 _____ C:\Users\Amy\Desktop\FIVE FINGER DEATH PUNCH THE WRONG SIDE OF HEAVEN and the righteous side of hell, volume two.txt
2015-07-30 01:12 - 2015-07-30 01:12 - 00013834 _____ C:\Users\Amy\Desktop\FIVE FINGER DEATH PUNCH THE WRONG SIDE OF HEAVEN.txt
2015-07-24 08:23 - 2015-07-14 23:19 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-07-24 08:23 - 2015-07-14 23:19 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-07-24 08:23 - 2015-07-14 23:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-07-24 08:23 - 2015-07-14 23:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-07-24 08:23 - 2015-07-14 22:55 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-07-24 08:23 - 2015-07-14 22:55 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-07-24 08:23 - 2015-07-14 22:55 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-07-24 08:23 - 2015-07-14 22:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-07-24 08:23 - 2015-07-14 21:59 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-07-24 08:23 - 2015-07-14 21:52 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-07-24 00:12 - 2015-07-24 03:35 - 00000000 ____D C:\Users\Amy\Desktop\Phone photos 0715
2015-07-20 02:41 - 2015-07-20 02:48 - 00000357 _____ C:\Users\Amy\Desktop\Amys.txt
2015-07-18 02:06 - 2015-07-18 02:06 - 01748703 _____ C:\Users\Amy\Desktop\all_week_age_animated.kml
2015-07-18 01:40 - 2015-08-06 00:56 - 00022573 _____ C:\Users\Amy\Desktop\FIVE FINGER DEATH PUNCH.txt
2015-07-17 10:44 - 2015-07-17 10:44 - 00043068 _____ C:\Users\Amy\Documents\cc_20150717_104441.reg
2015-07-15 22:28 - 2015-07-04 14:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-15 22:28 - 2015-07-04 13:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-07-15 22:28 - 2015-07-01 16:56 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-07-15 22:28 - 2015-07-01 16:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-07-15 22:28 - 2015-07-01 16:49 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-07-15 22:28 - 2015-07-01 16:49 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-15 22:28 - 2015-07-01 16:49 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-15 22:28 - 2015-07-01 16:49 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-07-15 22:28 - 2015-07-01 16:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-15 22:28 - 2015-07-01 16:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-07-15 22:28 - 2015-07-01 16:49 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-07-15 22:28 - 2015-07-01 16:49 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-07-15 22:28 - 2015-07-01 16:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-07-15 22:28 - 2015-07-01 16:49 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-07-15 22:28 - 2015-07-01 16:49 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-07-15 22:28 - 2015-07-01 16:48 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-07-15 22:28 - 2015-07-01 16:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-07-15 22:28 - 2015-07-01 16:47 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-07-15 22:28 - 2015-07-01 16:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-07-15 22:28 - 2015-07-01 16:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-07-15 22:28 - 2015-07-01 16:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-07-15 22:28 - 2015-07-01 16:39 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-07-15 22:28 - 2015-07-01 16:30 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-07-15 22:28 - 2015-07-01 16:30 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-07-15 22:28 - 2015-07-01 16:30 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-07-15 22:28 - 2015-07-01 16:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-07-15 22:28 - 2015-07-01 16:30 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-07-15 22:28 - 2015-07-01 16:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-07-15 22:28 - 2015-07-01 16:30 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-07-15 22:28 - 2015-07-01 16:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-07-15 22:28 - 2015-07-01 16:30 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-07-15 22:28 - 2015-07-01 16:29 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-07-15 22:28 - 2015-07-01 16:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-07-15 22:28 - 2015-07-01 16:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-07-15 22:28 - 2015-07-01 16:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-07-15 22:28 - 2015-07-01 16:26 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-07-15 22:28 - 2015-07-01 16:24 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-07-15 22:28 - 2015-07-01 15:27 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-15 22:28 - 2015-07-01 15:26 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-15 22:28 - 2015-07-01 15:26 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-15 22:28 - 2015-06-17 13:47 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-15 22:28 - 2015-06-17 13:37 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-07-15 22:28 - 2015-06-11 13:57 - 06131200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-07-15 22:28 - 2015-06-11 13:57 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-07-15 22:28 - 2015-06-11 13:57 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-07-15 22:28 - 2015-06-11 13:56 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-07-15 22:28 - 2015-06-11 13:56 - 01057792 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-07-15 22:28 - 2015-06-11 13:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-07-15 22:28 - 2015-06-11 09:15 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-07-15 22:28 - 2015-06-09 14:03 - 03180544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-07-15 22:28 - 2015-06-09 14:03 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-07-15 22:28 - 2015-06-01 20:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-07-15 22:28 - 2015-06-01 19:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll
2015-07-15 22:27 - 2015-07-03 02:18 - 17887744 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-07-15 22:27 - 2015-07-03 02:01 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-07-15 22:27 - 2015-07-03 01:31 - 12386304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-07-15 22:27 - 2015-07-03 01:18 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-07-15 22:27 - 2015-06-25 04:57 - 03207168 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-07-15 22:27 - 2015-06-22 12:18 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-07-15 22:27 - 2015-06-22 12:17 - 10936320 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-07-15 22:27 - 2015-06-22 12:17 - 02343936 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-07-15 22:27 - 2015-06-22 12:12 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-07-15 22:27 - 2015-06-22 12:12 - 01387520 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-07-15 22:27 - 2015-06-22 12:11 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-07-15 22:27 - 2015-06-22 12:11 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-07-15 22:27 - 2015-06-22 12:11 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-07-15 22:27 - 2015-06-22 12:10 - 02158080 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-07-15 22:27 - 2015-06-22 12:10 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-07-15 22:27 - 2015-06-22 12:10 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-07-15 22:27 - 2015-06-22 12:10 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-07-15 22:27 - 2015-06-22 12:10 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-07-15 22:27 - 2015-06-22 12:10 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-07-15 22:27 - 2015-06-22 12:10 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-07-15 22:27 - 2015-06-22 12:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-07-15 22:27 - 2015-06-22 12:10 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-07-15 22:27 - 2015-06-22 12:10 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-07-15 22:27 - 2015-06-22 12:10 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-07-15 22:27 - 2015-06-22 12:09 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-07-15 22:27 - 2015-06-22 11:27 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-07-15 22:27 - 2015-06-22 11:27 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-07-15 22:27 - 2015-06-22 11:24 - 09750528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-07-15 22:27 - 2015-06-22 11:23 - 01139712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-07-15 22:27 - 2015-06-22 11:22 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-07-15 22:27 - 2015-06-22 11:22 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-07-15 22:27 - 2015-06-22 11:21 - 01804288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-07-15 22:27 - 2015-06-22 11:21 - 00718336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-07-15 22:27 - 2015-06-22 11:21 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-07-15 22:27 - 2015-06-22 11:21 - 00421888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-07-15 22:27 - 2015-06-22 11:21 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-07-15 22:27 - 2015-06-22 11:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-07-15 22:27 - 2015-06-22 11:21 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-07-15 22:27 - 2015-06-22 11:21 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-07-15 22:27 - 2015-06-22 11:20 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-07-15 22:27 - 2015-06-22 11:20 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-07-15 22:27 - 2015-06-22 11:20 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-07-15 22:27 - 2015-06-22 11:20 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-07-15 22:27 - 2015-06-22 11:20 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-07-15 22:27 - 2015-06-22 11:20 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2015-07-15 22:26 - 2015-06-15 17:50 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-07-15 22:26 - 2015-06-15 17:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-15 22:26 - 2015-06-15 17:45 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-07-15 22:26 - 2015-06-15 17:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-07-15 22:26 - 2015-06-15 17:45 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-07-15 22:26 - 2015-06-15 17:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-15 22:26 - 2015-06-15 17:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-07-15 22:26 - 2015-06-15 17:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-07-15 22:26 - 2015-06-15 17:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2015-07-15 22:26 - 2015-06-15 17:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-07-15 22:26 - 2015-06-15 17:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2015-07-15 22:26 - 2015-06-15 17:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2015-07-12 12:59 - 2015-07-12 12:59 - 00001837 _____ C:\Users\Public\Desktop\Defraggler.lnk
2015-07-10 23:22 - 2015-08-02 02:19 - 00002807 _____ C:\Users\Amy\Desktop\avenged sevenfold hail to the king.txt
2015-07-10 23:22 - 2015-07-10 23:36 - 00018439 _____ C:\Users\Amy\Desktop\Avenged sevenfold Nightmare.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-09 01:13 - 2009-07-14 00:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-09 01:13 - 2009-07-14 00:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-09 01:11 - 2009-07-14 01:13 - 00006514 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-09 01:08 - 2014-05-04 06:42 - 01484476 _____ C:\Windows\WindowsUpdate.log
2015-08-09 01:05 - 2012-02-25 17:43 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-09 01:05 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-09 00:39 - 2013-03-16 06:55 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-09 00:34 - 2012-02-25 17:43 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-08 21:39 - 2013-05-31 16:18 - 00000000 ____D C:\Users\Amy\Documents\Garmin
2015-08-08 21:39 - 2013-05-31 16:16 - 00000000 ____D C:\Users\Amy\AppData\Roaming\Garmin
2015-08-08 21:39 - 2013-05-31 16:16 - 00000000 ____D C:\Users\Amy\AppData\Local\Garmin
2015-08-08 21:39 - 2013-05-31 16:15 - 00000000 ____D C:\ProgramData\Garmin
2015-08-08 21:38 - 2009-07-14 01:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-08-08 15:44 - 2014-11-06 16:54 - 00019813 _____ C:\Windows\SysWOW64\debug.log
2015-08-08 02:37 - 2014-12-30 23:48 - 00492544 _____ C:\Users\Amy\Desktop\OpenHardwareMonitor.exe
2015-08-08 02:30 - 2012-02-16 14:48 - 00000000 __SHD C:\Recovery
2015-08-07 23:59 - 2014-05-22 15:24 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-07 23:48 - 2014-02-08 09:55 - 00000782 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-08-07 23:48 - 2012-09-23 09:58 - 00000000 ____D C:\Program Files\CCleaner
2015-08-07 22:00 - 2012-05-04 10:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-07 19:57 - 2012-06-30 01:08 - 00007637 _____ C:\Users\Amy\AppData\Local\Resmon.ResmonCfg
2015-08-07 08:28 - 2012-07-09 00:00 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-08-07 08:27 - 2014-05-01 19:38 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-08-07 08:27 - 2014-01-03 00:00 - 00150672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-08-07 08:27 - 2013-03-16 06:42 - 00274808 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-08-07 08:27 - 2013-03-16 06:42 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-08-07 08:27 - 2012-02-25 17:41 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-08-07 08:27 - 2012-02-18 10:26 - 01048856 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-08-07 08:27 - 2012-02-18 10:26 - 00447944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-08-07 08:27 - 2012-02-18 10:26 - 00090968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-08-06 22:54 - 2009-07-14 01:08 - 00032532 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-05 01:08 - 2015-06-17 02:10 - 00002795 _____ C:\Users\Amy\Desktop\avenged sevenfold lyrics.txt
2015-08-05 00:36 - 2012-02-25 17:46 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-04 22:41 - 2012-02-29 22:23 - 00000000 ____D C:\Users\Amy\Desktop\Photos
2015-08-02 09:56 - 2014-05-22 15:23 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-02 09:56 - 2012-04-07 12:58 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-08-02 09:56 - 2009-07-14 00:45 - 00000000 ____D C:\Windows\Setup
2015-08-02 08:54 - 2014-05-22 15:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-02 08:54 - 2013-02-08 08:20 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-08-02 03:36 - 2015-07-01 00:58 - 00019278 _____ C:\Users\Amy\Desktop\SYSTEM OF A DOWN - TOXICITY.txt
2015-08-02 03:24 - 2015-06-12 23:23 - 00013062 _____ C:\Users\Amy\Desktop\SYSTEM OF A DOWN SYSTEM OF A DOWN.txt
2015-07-26 03:37 - 2015-07-01 01:08 - 00015843 _____ C:\Users\Amy\Desktop\SYSTEM OF A DOWN - HYPNOTIZE.txt
2015-07-24 08:30 - 2009-07-14 00:45 - 00273920 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-22 23:00 - 2013-05-29 03:12 - 00263680 ___SH C:\Users\Amy\Thumbs.db
2015-07-22 23:00 - 2012-02-16 18:28 - 00000000 ___RD C:\Users\Amy\Desktop\AMY
2015-07-18 11:36 - 2012-02-18 20:59 - 00000000 ____D C:\Users\Amy\Desktop\World of Warcraft truwow Bloodcraft
2015-07-17 16:08 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\Vss
2015-07-16 12:03 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2015-07-15 22:38 - 2013-07-17 07:50 - 00000000 ____D C:\Windows\system32\MRT
2015-07-15 20:29 - 2012-02-25 17:43 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-15 20:29 - 2012-02-25 17:43 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-15 09:40 - 2013-03-16 06:55 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-15 09:40 - 2012-03-30 21:22 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-15 09:40 - 2012-02-16 18:16 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-15 00:44 - 2013-10-05 20:39 - 00000000 ____D C:\ProgramData\TEMP
2015-07-14 20:09 - 2013-04-09 14:59 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-07-14 20:08 - 2014-12-23 12:20 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-07-12 12:59 - 2013-03-06 11:35 - 00000000 ____D C:\Program Files\Defraggler

==================== Files in the root of some directories =======

2013-02-28 22:52 - 2013-03-01 23:01 - 0003312 _____ () C:\Users\Amy\AppData\Roaming\MultiScreen_log.log
2012-04-10 15:28 - 2013-12-04 22:02 - 0005632 _____ () C:\Users\Amy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-30 01:08 - 2015-08-07 19:57 - 0007637 _____ () C:\Users\Amy\AppData\Local\Resmon.ResmonCfg

Files to move or delete:
====================
C:\Users\Amy\ccsetup411.exe
C:\Users\Amy\ccsetup418.exe
C:\Users\Amy\chromeinstall-7u60.exe
C:\Users\Amy\dfsetup217.exe
C:\Users\Amy\dfsetup218.exe
C:\Users\Amy\HPPSdr.exe
C:\Users\Amy\jre-6u31-windows-x64.exe
C:\Users\Amy\jre-7u51-windows-i586.exe
C:\Users\Amy\setpoint6.61.15_smart (1).exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-08-02 00:18

==================== End of log ============================

:welcome:

 

Looks like you have a bit going on, I also need to see the Additions log from FRST, it should be on your desktop where you have FRST

Think I found it lol …

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:08-08-2015 01
Ran by [removed] (2015-08-09 01:29:55)
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1666203005-3817340796-160210981-500 - Administrator - Disabled)
Amy (S-1-5-21-1666203005-3817340796-160210981-1002 - Administrator - Enabled) => C:\Users\Amy
Guest (S-1-5-21-1666203005-3817340796-160210981-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1666203005-3817340796-160210981-1003 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Connect 9 Add-in (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\Adobe Connect 9 Add-in) (Version: 11,9,971,247 - Adobe Systems Incorporated)
Adobe Connect Add-in (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\Adobe Connect Add-in) (Version:  - )
Adobe Flash Player 18 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
AIM for Windows (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\AIM) (Version:  - AOL Inc.)
AMD Catalyst Install Manager (HKLM\…\{5E03A267-415E-5383-FA8F-3CE4145663B9}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avast Internet Security (HKLM-x32\…\avast) (Version: 10.3.2225 - AVAST Software)
Big Fish: Game Manager (HKLM-x32\…\BFGC) (Version: 3.2.0.6 - )
Bing Bar (HKLM-x32\…\{B4089055-D468-45A4-A6BA-5A138DD715FC}) (Version: 7.0.850.0 - Microsoft Corporation)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BuggedChecker Addon Updater (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\BuggedChecker Addon Updater) (Version:  - )
CCleaner (HKLM\…\CCleaner) (Version: 5.08 - Piriform)
Charter TV Player (HKLM-x32\…\{8c2440b0-0097-44bd-a912-c80e95e5b2b8}) (Version: 5.1 - Charter)
Citrix online plug-in - web (HKLM-x32\…\CitrixOnlinePluginPackWeb) (Version: 12.3.0.8 - Citrix Systems, Inc.)
Defraggler (HKLM\…\Defraggler) (Version: 2.19 - Piriform)
DIRECTV Player (HKLM-x32\…\{a1bb9be6-729f-4049-a36a-aad335c86c01}) (Version: 9.2 - DIRECTV)
Download Updater (AOL Inc.) (HKLM-x32\…\SoftwareUpdUtility) (Version:  - AOL Inc.) <==== ATTENTION
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 44.0.2403.130 - Google Inc.)
Google Earth Plug-in (HKLM-x32\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
HP Deskjet 1000 J110 series Basic Device Software (HKLM\…\{883B114D-BD3E-498F-9DAD-5E4A8E1C43BA}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 1000 J110 series Help (HKLM-x32\…\{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}) (Version: 140.0.65.65 - Hewlett Packard)
HP Support Solutions Framework (HKLM-x32\…\{348A1F5B-07B3-4436-9A47-FFE44EFE856E}) (Version: 11.51.0004 - Hewlett-Packard Company)
IncrediMail (x32 Version: 6.2.9.5181 - IncrediMail) Hidden
IncrediMail 2.0 (HKLM-x32\…\IncrediMail) (Version: 6.2.9.5181 - IncrediMail Ltd.)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\…\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 11 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218011FF}) (Version: 8.0.110 - Oracle Corporation)
Java 8 Update 45 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
JavaFX 2.1.1 (HKLM-x32\…\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Juniper Networks Host Checker (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\Neoteris_Host_Checker) (Version: 8.0.5.31739 - Juniper Networks)
Juniper Networks Network Connect 8.0 (HKLM-x32\…\Juniper Network Connect 8.0) (Version: 8.0.5.31739 - Juniper Networks)
Juniper Networks Setup Client (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\Juniper_Setup_Client) (Version: 8.0.5.47721 - Juniper Networks)
Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Logitech SetPoint 6.61 (HKLM\…\sp6) (Version: 6.61.15 - Logitech)
Lottso! Deluxe (remove only) (HKLM-x32\…\Lottso! Deluxe) (Version:  - )
Magic Vines™ (HKLM-x32\…\BFG-Magic Vines) (Version:  - )
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\…\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\…\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\…\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\…\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\…\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 39.0.3 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 39.0.3 (x86 en-US)) (Version: 39.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MultiScreen (HKLM-x32\…\{7E750925-00C9-4B23-A1E8-BBFC0955CFD8}) (Version: 3.0.13 - Samsung Electronics Ltd.)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
ON_OFF Charge B11.0110.1 (HKLM-x32\…\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE)
Photo Notifier and Animation Creator (HKLM-x32\…\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.)
Pogo Games (HKLM-x32\…\PogoDGC) (Version: 1.0 - ) <==== ATTENTION
Radialpoint Servicepoint Dashboard Extensions version 12.2.27.36396 (HKU\S-1-5-21-1666203005-3817340796-160210981-1002 Version: 12.2.27.36396 - ) Hidden
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6418 - Realtek Semiconductor Corp.)
RoboForm 7-9-9-1 (All Users) (HKLM-x32\…\AI RoboForm) (Version: 7-9-9-1 - Siber Systems)
SHG Installation (HKLM-x32\…\{C37A696D-30B7-42F1-8971-6149BAA5FE51}) (Version: 2.0.27 - SafeHarborGames)
ShortKeys Lite (HKLM-x32\…\ShortKeys Lite) (Version: 2.3.2.1 - Insight Software Solutions, Inc.)
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.5.1012 - SUPERAntiSpyware.com)
SystemCheck (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\457850000868e35c) (Version: 1.0.0.42 - SystemCheck)
The Poppit Show (HKLM-x32\…\The Poppit Show) (Version:  - Pogo.com)
Top Ten Solitaire (HKLM-x32\…\BFG-Top Ten Solitaire) (Version:  - )
Unity Web Player (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\UnityWebPlayer) (Version: 4.5.4f1 - Unity Technologies ApS)
WeatherBug (HKLM-x32\…\{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}) (Version: 7.0.0.10 - Earth Networks, Inc.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM-x32\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM-x32\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Yahoo! Messenger (HKLM-x32\…\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Yahoo! Toolbar (HKLM-x32\…\Yahoo! Companion) (Version:  - Yahoo! Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1666203005-3817340796-160210981-1002_Classes\CLSID\{4EA6BBD4-E775-4b7e-80FD-3651749850B0}\localserver32 -> C:\Users\Amy\AppData\Local\Charter\Charter TV Player\CaptureServer64.exe (Cisco)

==================== Restore Points =========================

02-08-2015 12:54:38 Scheduled Checkpoint
05-08-2015 11:34:31 Windows Update
07-08-2015 08:25:17 avast! antivirus system restore point
07-08-2015 08:28:26 Device Driver Package Install: Avast Network Service
07-08-2015 23:26:01 Restore Operation
08-08-2015 15:56:51 Windows Update
08-08-2015 21:38:54 Garmin Express

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2015-05-30 03:56 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 

Good Morning,

 

Thats not the entire additions log, the logs for all the tools and scanners we run will open in Notepad, open Notepad for Additions, and on the top left click on EDIT>SELECT ALL……EDIT>COPY, then comeback to this thread and paste it in

 

So far I do see some malware that we need to fix, waiting on the Additions log to see if there is more

That is the only additions log I could find…  This is the entire additions log that I have…

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:08-08-2015 01
Ran by [removed] (2015-08-09 01:29:55)
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1666203005-3817340796-160210981-500 - Administrator - Disabled)
Amy (S-1-5-21-1666203005-3817340796-160210981-1002 - Administrator - Enabled) => C:\Users\Amy
Guest (S-1-5-21-1666203005-3817340796-160210981-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1666203005-3817340796-160210981-1003 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Connect 9 Add-in (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\Adobe Connect 9 Add-in) (Version: 11,9,971,247 - Adobe Systems Incorporated)
Adobe Connect Add-in (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\Adobe Connect Add-in) (Version:  - )
Adobe Flash Player 18 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
AIM for Windows (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\AIM) (Version:  - AOL Inc.)
AMD Catalyst Install Manager (HKLM\…\{5E03A267-415E-5383-FA8F-3CE4145663B9}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avast Internet Security (HKLM-x32\…\avast) (Version: 10.3.2225 - AVAST Software)
Big Fish: Game Manager (HKLM-x32\…\BFGC) (Version: 3.2.0.6 - )
Bing Bar (HKLM-x32\…\{B4089055-D468-45A4-A6BA-5A138DD715FC}) (Version: 7.0.850.0 - Microsoft Corporation)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BuggedChecker Addon Updater (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\BuggedChecker Addon Updater) (Version:  - )
CCleaner (HKLM\…\CCleaner) (Version: 5.08 - Piriform)
Charter TV Player (HKLM-x32\…\{8c2440b0-0097-44bd-a912-c80e95e5b2b8}) (Version: 5.1 - Charter)
Citrix online plug-in - web (HKLM-x32\…\CitrixOnlinePluginPackWeb) (Version: 12.3.0.8 - Citrix Systems, Inc.)
Defraggler (HKLM\…\Defraggler) (Version: 2.19 - Piriform)
DIRECTV Player (HKLM-x32\…\{a1bb9be6-729f-4049-a36a-aad335c86c01}) (Version: 9.2 - DIRECTV)
Download Updater (AOL Inc.) (HKLM-x32\…\SoftwareUpdUtility) (Version:  - AOL Inc.) <==== ATTENTION
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 44.0.2403.130 - Google Inc.)
Google Earth Plug-in (HKLM-x32\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
HP Deskjet 1000 J110 series Basic Device Software (HKLM\…\{883B114D-BD3E-498F-9DAD-5E4A8E1C43BA}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 1000 J110 series Help (HKLM-x32\…\{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}) (Version: 140.0.65.65 - Hewlett Packard)
HP Support Solutions Framework (HKLM-x32\…\{348A1F5B-07B3-4436-9A47-FFE44EFE856E}) (Version: 11.51.0004 - Hewlett-Packard Company)
IncrediMail (x32 Version: 6.2.9.5181 - IncrediMail) Hidden
IncrediMail 2.0 (HKLM-x32\…\IncrediMail) (Version: 6.2.9.5181 - IncrediMail Ltd.)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\…\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 11 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218011FF}) (Version: 8.0.110 - Oracle Corporation)
Java 8 Update 45 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
JavaFX 2.1.1 (HKLM-x32\…\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Juniper Networks Host Checker (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\Neoteris_Host_Checker) (Version: 8.0.5.31739 - Juniper Networks)
Juniper Networks Network Connect 8.0 (HKLM-x32\…\Juniper Network Connect 8.0) (Version: 8.0.5.31739 - Juniper Networks)
Juniper Networks Setup Client (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\Juniper_Setup_Client) (Version: 8.0.5.47721 - Juniper Networks)
Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Logitech SetPoint 6.61 (HKLM\…\sp6) (Version: 6.61.15 - Logitech)
Lottso! Deluxe (remove only) (HKLM-x32\…\Lottso! Deluxe) (Version:  - )
Magic Vines™ (HKLM-x32\…\BFG-Magic Vines) (Version:  - )
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\…\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\…\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\…\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\…\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\…\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 39.0.3 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 39.0.3 (x86 en-US)) (Version: 39.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MultiScreen (HKLM-x32\…\{7E750925-00C9-4B23-A1E8-BBFC0955CFD8}) (Version: 3.0.13 - Samsung Electronics Ltd.)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
ON_OFF Charge B11.0110.1 (HKLM-x32\…\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE)
Photo Notifier and Animation Creator (HKLM-x32\…\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.)
Pogo Games (HKLM-x32\…\PogoDGC) (Version: 1.0 - ) <==== ATTENTION
Radialpoint Servicepoint Dashboard Extensions version 12.2.27.36396 (HKU\S-1-5-21-1666203005-3817340796-160210981-1002 Version: 12.2.27.36396 - ) Hidden
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6418 - Realtek Semiconductor Corp.)
RoboForm 7-9-9-1 (All Users) (HKLM-x32\…\AI RoboForm) (Version: 7-9-9-1 - Siber Systems)
SHG Installation (HKLM-x32\…\{C37A696D-30B7-42F1-8971-6149BAA5FE51}) (Version: 2.0.27 - SafeHarborGames)
ShortKeys Lite (HKLM-x32\…\ShortKeys Lite) (Version: 2.3.2.1 - Insight Software Solutions, Inc.)
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.5.1012 - SUPERAntiSpyware.com)
SystemCheck (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\457850000868e35c) (Version: 1.0.0.42 - SystemCheck)
The Poppit Show (HKLM-x32\…\The Poppit Show) (Version:  - Pogo.com)
Top Ten Solitaire (HKLM-x32\…\BFG-Top Ten Solitaire) (Version:  - )
Unity Web Player (HKU\S-1-5-21-1666203005-3817340796-160210981-1002\…\UnityWebPlayer) (Version: 4.5.4f1 - Unity Technologies ApS)
WeatherBug (HKLM-x32\…\{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}) (Version: 7.0.0.10 - Earth Networks, Inc.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM-x32\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM-x32\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Yahoo! Messenger (HKLM-x32\…\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Yahoo! Toolbar (HKLM-x32\…\Yahoo! Companion) (Version:  - Yahoo! Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1666203005-3817340796-160210981-1002_Classes\CLSID\{4EA6BBD4-E775-4b7e-80FD-3651749850B0}\localserver32 -> C:\Users\Amy\AppData\Local\Charter\Charter TV Player\CaptureServer64.exe (Cisco)

==================== Restore Points =========================

02-08-2015 12:54:38 Scheduled Checkpoint
05-08-2015 11:34:31 Windows Update
07-08-2015 08:25:17 avast! antivirus system restore point
07-08-2015 08:28:26 Device Driver Package Install: Avast Network Service
07-08-2015 23:26:01 Restore Operation
08-08-2015 15:56:51 Windows Update
08-08-2015 21:38:54 Garmin Express

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2015-05-30 03:56 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 

Good Morning,

 

There is a part of the Additions log that shows running tasks and its missing from your log , but I have seen this happen before. Go ahead and drag FRST64 and the Additions logs you have to the trash so we don't get them confused with future scans.

 

I am going to give you three tools to run to clean up your system, make sure there all run from the desktop.  The instructions for Malwarebytes you may want to print out and make sure its set the way I posted it

 

 

 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
[external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
===============================================================================
 
Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
 
 
[external image: MBAM_zpsr1ew7hep.png]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished and the log pops up…select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
 

I hope this is all that you requested, thanks..

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 


~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.6 (08.10.2015:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on Wed 08/12/2015 at 22:31:42.36
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER

\Software\Microsoft\Windows\CurrentVersion\Run\\rockettab



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER

\Software\Policies\Google



~~~ Files

Successfully deleted: [File] C:\Users\Amy\Appdata\Local

\google\chrome\user data\default\local storage

\hxxp_www.azlyrics.com_0.localstorage
Successfully deleted: [File] C:\Users\Amy\Appdata\Local

\google\chrome\user data\default\local storage

\hxxp_www.metrolyrics.com_0.localstorage
Successfully deleted: [File] C:\Windows

\SysWOW64\sho3311.tmp



~~~ Folders

Successfully deleted: [Folder] C:\Users\Amy\AppData

\Roaming\alawarentertainment



~~~ FireFox

Emptied folder: C:\Users\Amy\AppData\Roaming\mozilla

\firefox\profiles\c9382cp1.default\minidumps [917 files]



~~~ Chrome


[C:\Users\Amy\Appdata\Local\Google\Chrome\User Data

\Default\Preferences] - default search provider reset

[C:\Users\Amy\Appdata\Local\Google\Chrome\User Data

\Default\Preferences] - Extensions Deleted:

[C:\Users\Amy\Appdata\Local\Google\Chrome\User Data

\Default\Secure Preferences] - default search provider

reset

[C:\Users\Amy\Appdata\Local\Google\Chrome\User Data

\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~
Scan was completed on Wed 08/12/2015 at 22:36:44.54
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~




# AdwCleaner v4.208 - Logfile created 12/08/2015 at

22:39:12
# Updated 09/07/2015 by Xplode
# Database : 2015-08-12.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack

1 (x64)
# Username : Amy - AMY-PC
# Running from : C:\Users\Amy\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\Program Files (x86)\Mozilla Firefox

\browser\searchplugins\yahoo.xml

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

-\\ Internet Explorer v9.0.8112.16669


-\\ Mozilla Firefox v39.0.3 (x86 en-US)


-\\ Google Chrome v44.0.2403.155


*************************

AdwCleaner[R0].txt - [5675 bytes] - [12/08/2015 22:28:21]
AdwCleaner[R1].txt - [5934 bytes] - [12/08/2015 22:30:43]
AdwCleaner[R2].txt - [851 bytes] - [12/08/2015 22:39:12]
AdwCleaner[S0].txt - [6017 bytes] - [12/08/2015 22:32:17]

########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [968

bytes] ##########





Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 8/12/2015
Scan Time: 10:55 PM
Logfile: malware log.txt
Administrator: Yes

Version: 2.1.8.1057
Malware Database: v2015.08.12.05
Rootkit Database: v2015.08.06.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Amy

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 371336
Time Elapsed: 20 min, 7 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 2
PUP.Optional.DownloadAdmin, C:\Users\Amy\Setup (1).exe,

Quarantined, [5a9b28df0586d264e9eb408c43beeb15],
Trojan.Agent, C:\Users\Amy\Setup.exe, Quarantined,

[fafb03045932b2847379f4caf60dfe02],

Physical Sectors: 0
(No malicious items detected)


(end)
 

Good Morning

 

Just a few things removed , nothing that I feel would cause the issues that your having right now, sometimes a rootkit type of infection could be under foot that most scanners wont find, so I would like you to run rootkit scanner by Malwarebytes and lets see if it finds anything

 

Please download Malwarebytes Anti-Rootkit from Here
  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder… mbar-log.txt and system-log.txt
  • No logs were generated, after the scan it said Congratulations, no clean-up is required… Also, My PC has not turned itself off for 2 days, not sure why, perhaps whatever was wrong worked itself out? Thanks for the help and for any other advise you may have…

    Great, what I would do is post back in your original thread , its still open and let them know whats going on

     

    http://forums.whatthetech.com/index.php?showtopic=129902

     

     

     

    Double click on AdwCleaner.exe to run the tool again.
    • Click on the Uninstall button.
    • Click Yes when asked are you sure you want to uninstall.
    • Both AdwCleaner.exe, its folder and all logs will be removed.
    •  
       
      ==========================================================
       
       
      Please download DelFix and save the file to your Desktop.
       
      [external image: DelFix_zps139e2ea1.jpg]
       
      • Windows XP Double Click DelFix.exe to run the program. 
      • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
      • Checkmark " Remove Disinfection Tools"
      • Click the Run button
      •  
        This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
         
         
         
        ==========================================================
         
         
         
         
        How did I get infected in the first place ?  
         
        • WhattheTech
        • Grinler BleepingComputer 
        • GeeksTo Go
        • Dslreports
        •  
           
          Safe Surfn
          Ken
           
           
           
          http://users.telenet.be/bluepatchy/miekiemoes/Links.html#Online%20Scanners

          Ask AI

          AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

          Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI