This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer is slow and won't open up pages [Solved]

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I want to install Windows 10 when I can,but something is wrong here. I have Firefox and run yahoo. But I can't even open other websites. i got a message saying I had malware and I was supposed to call a number. I have run several of my security programs and nothing is wrong. I couldn't even get the topic up that talked about a slow computer. I have no idea where to start here. I downloaded a new firefox because the other wouldn't even open. What do I do next?
I want to install Windows 10 when I can,but something is wrong here. I have Firefox and run yahoo. But I can't even open other websites. i got a message saying I had malware and I was supposed to call a number. I have run several of my security programs and nothing is wrong. I couldn't even get the topic up that talked about a slow computer. I have no idea where to start here. I downloaded a new firefox because the other wouldn't even open. What do I do next?

Hello PattiChati and welcome back to the WTT forum.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.


  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop

  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects – everything that is reported is not necessarily bad

If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

AdwCleaner log
RKreport.txt
Frst.txt
Addition.txt


Thanks

Satchfan

 

Regarding the PM you have sent me, if you have problems, try following the instructions in Safe Mode with Networking.

# AdwCleaner v2.306 - Logfile created 09/21/2015 at 14:10:22

# Updated 19/07/2013 by Xplode

# Operating system : Windows 8.1  (64 bits)

# User : Patti - NYKAMP-PC

# Boot Mode : Normal

# Running from : C:\Users\Patti\Downloads\AdwCleaner.exe

# Option [Delete]

 

 

***** [Services] *****

 

 

***** [Files / Folders] *****

 

 

***** [Registry] *****

 

 

***** [Internet Browsers] *****

 

-\\ Internet Explorer v11.0.9600.17840

 

[OK] Registry is clean.

 

-\\ Mozilla Firefox v40.0.3 (x86 en-US)

 

File : C:\Users\Patti\AppData\Roaming\Mozilla\Firefox\Profiles\l9qemj8f.default\prefs.js

 

Deleted : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\"[…]

 

-\\ Google Chrome v45.0.2454.93

 

File : C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default\Preferences

 

[OK] File is clean.

 

-\\ Chromium v46.0.2480.0

 

File : C:\Users\Patti\AppData\Local\Chromium\User Data\Default\Preferences

 

[OK] File is clean.

 

*************************

 

AdwCleaner[R1].txt - [1705 octets] - [21/09/2015 14:05:22]

AdwCleaner[R2].txt - [1765 octets] - [21/09/2015 14:05:50]

AdwCleaner[R3].txt - [1266 octets] - [21/09/2015 14:09:21]

AdwCleaner[S2].txt - [1199 octets] - [21/09/2015 14:10:22]

 

########## EOF - C:\AdwCleaner[S2].txt - [1259 octets] ##########

RogueKiller V10.10.6.0 [Sep 21 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com
 
Operating System : Windows 8.1 (6.3.9600) 64 bits version
Started in : Normal mode
User : Patti [Administrator]
Started from : C:\Users\Patti\Desktop\RogueKiller.exe
Mode : Scan – Date : 09/21/2015 14:36:43
 
¤¤¤ Processes : 0 ¤¤¤
 
¤¤¤ Registry : 8 ¤¤¤
[VT.Generic.36F] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> Found
[VT.Generic.36F] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> Found
[VT.Generic.36F] (X64) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> Found
[VT.Generic.36F] (X86) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> Found
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://toshiba13.msn.com -> Found
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://toshiba13.msn.com -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://toshiba13.msn.com -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://toshiba13.msn.com -> Found
 
¤¤¤ Tasks : 3 ¤¤¤
[Suspicious.Path|VT.DealPly] %WINDIR%\Tasks\UpdateTask.job – C:\Users\Patti\AppData\Local\{8469B~1\UNINST~1.EXE (/Check) -> Found
[Suspicious.Path] \Unimioanrruo – "C:\ProgramData\Unimioanrruo\1.0.5.1\mnuanvou.exe" ("/e=L3A9MTk1NTAxXi91PTY0YTk4ZDBkMzIzZjRiZTBiMmJiY2ZhMTFiOWEwMjJhXi9kPWNoZWFwY291cG9uYWxlcnQuY29tXi9uPUNPVVBeL2E9Q291cG9uQWxlcnReL3Q=") -> Found
[Suspicious.Path|VT.DealPly] \UpdateTask – C:\Users\Patti\AppData\Local\{8469B~1\UNINST~1.EXE (/Check) -> Found
 
¤¤¤ Files : 0 ¤¤¤
 
¤¤¤ Hosts File : 0 ¤¤¤
 
¤¤¤ Antirootkit : 0 (Driver: Not loaded [0x20]) ¤¤¤
 
¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] l9qemj8f.default : user_pref("browser.startup.homepage", "http://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_prgasst_15_39¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0CyE0EtAyCzyyEyDtBtCyD0D0D0CyEtN0D0Tzu0StCtAyDzytN1L2XzutAtFtCtDtFtCtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StByCtAtDtCzyzzyCtG0FyE0FtDtGyE0BtAtBtG0B0F0C0FtGyDtBtB0BzzzztD0EyB0BzzyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FtAyE0EyByDyD0AtG0AtD0FyEtGyEtCtC0DtGzyyB0D0EtG0A0AyCtD0CtCyE0B0AtBtAtB2QtN0A0LzuyE%26cr%3D1596817938%26a%3Dwny_prgasst_15_39%26os%3DWindows8.1"); -> Found
 
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABD075 +++++
— User —
[MBR] a84dd93b5b19931ceaddbccc47850486
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [SYSTEM] Basic data partition | Offset (sectors): 2048 | Size: 450 MB
1 - Basic data partition | Offset (sectors): 923648 | Size: 260 MB
2 - Basic data partition | Offset (sectors): 1456128 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 1718272 | Size: 702965 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1441390592 | Size: 350 MB
5 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1442107392 | Size: 11250 MB
User = LL1 … OK
User = LL2 … OK
 
+++++ PhysicalDrive1: HP Photosmart 6520 USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )
 
Ran by [removed] (2015-09-21 14:53:26)
Running from C:\Users\[removed]\Desktop
Windows 8.1 (X64) (2013-12-13 23:25:29)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1679494073-3026066304-2182815410-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-1679494073-3026066304-2182815410-501 - Administrator - Disabled)
HomeGroupUser$ (S-1-5-21-1679494073-3026066304-2182815410-1089 - Limited - Enabled)
Patti (S-1-5-21-1679494073-3026066304-2182815410-1001 - Administrator - Enabled) => C:\Users\Patti
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.6 - Atheros Communications Inc.)
Auslogics Duplicate File Finder (HKLM-x32\…\{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1) (Version: 3.4.2.0 - Auslogics Labs Pty Ltd)
CCleaner (HKLM\…\CCleaner) (Version: 4.19 - Piriform)
Chromium (HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\Chromium) (Version: 46.0.2480.0 - Chromium)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Duplicate File Finder (HKLM-x32\…\{1041487C-12E6-47FE-B83A-E9891782C8FE}}_is1) (Version: 6.1.0.0 - Ashisoft)
GIMP 2.6.10 (HKLM-x32\…\WinGimp-2.0_is1) (Version: 2.6.10 - The GIMP Team)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 45.0.2454.93 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\…\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Hallmark Card Studio 2013 (HKLM-x32\…\{A6E08FBC-FC99-4CEE-B645-83A42107BE89}) (Version: 14.0.0.28 - Creative Home)
Hallmark Card Studio 2013 Bonus Pack (HKLM-x32\…\{2339C775-C7EA-4103-9A82-E12EB67FA2A3}) (Version: 1.0.0.1 - Creative Home)
HP Photosmart 6520 series Basic Device Software (HKLM\…\{1151BCF8-3246-4E34-9C17-22E66318C41C}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3345 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) WiDi (HKLM\…\{EDBA2433-0910-4C72-8C5B-8FEDAE3EF18E}) (Version: 3.5.34.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{8e41467d-297e-496d-8b0f-e771b6c87c06}) (Version: 16.11.0 - Intel Corporation)
Java 7 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F03217065FF}) (Version: 7.0.650 - Oracle)
Macrium Reflect Free Edition (HKLM\…\MacriumReflect) (Version: 5.2 - Paramount Software (UK) Ltd.)
Macrium Reflect Free Edition (Version: 5.2.6474 - Paramount Software (UK) Ltd.) Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microfast PC (HKLM-x32\…\Microfast PC 1.0.14) (Version: 1.0.14 - Microfast PC)
Microfast PC (x32 Version: 1.0.14 - Microfast PC) Hidden
Microsoft Baseline Security Analyzer 2.3 (HKLM\…\{D8D25854-D7F0-45C5-8702-D650A5A23E21}) (Version: 2.3.2208 - Microsoft Corporation)
Microsoft Office (HKLM-x32\…\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Mozilla Firefox 40.0.3 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 40.0.3 (x86 en-US)) (Version: 40.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla)
NETGEAR Genie (HKLM-x32\…\NETGEAR Genie) (Version: 2.3.1.13 - NETGEAR Inc.)
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6794 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Samsung Kies3 (HKLM-x32\…\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14083.9 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.14083.9 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
Search Provided by Yahoo (HKLM-x32\…\Wincy) (Version:  - Wincy)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
ShieldSoft (HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\ShieldSoft) (Version: 1.0 - ShieldSoft)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SpywareBlaster 5.0 (HKLM-x32\…\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)
SUABnR (HKLM-x32\…\InstallShield_{2485354C-6B65-4978-BB91-CCE61442377B}) (Version: 1.1.0.13103_1 - Samsung Electronics Co., Ltd.)
SUABnR (x32 Version: 1.1.0.13103_1 - Samsung Electronics Co., Ltd.) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.8.21 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.29947 - TeamViewer)
TOSHIBA Application Installer (HKLM-x32\…\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.4 - TOSHIBA)
Toshiba Book Place (HKLM-x32\…\{24B45620-22B6-4E4A-B836-FF30A0B0404E}) (Version: 3.1.9534 - K-NFB Reading Technology, Inc.)
TOSHIBA Desktop Assist (HKLM\…\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.02.01.6407 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\…\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.2.0.6404 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\…\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.00.6625.6402 - Toshiba Corporation)
TOSHIBA HDD Accelerator (HKLM\…\{DB4D9937-0B14-4EF1-BF9A-BB7E3B9DCB04}) (Version: 1.1.0001 - Toshiba Corporation)
TOSHIBA HDD Protection (HKLM\…\{94A90C69-71C1-470A-88F5-AA47ECC96B40}) (Version: 2.5.0002.64002 - Toshiba Corporation)
TOSHIBA Password Utility (HKLM-x32\…\{B1786E63-2127-42C9-95A3-146E5F727BF1}) (Version: v1.0.0.9 - TOSHIBA Corporation)
TOSHIBA PC Health Monitor (HKLM\…\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.9.09.6400 - Toshiba Corporation)
TOSHIBA Quality Application (HKLM-x32\…\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.8 - TOSHIBA)
TOSHIBA Recovery Media Creator (HKLM-x32\…\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.2.0.54043005 - Toshiba Corporation)
TOSHIBA Resolution+ Plug-in for Windows Media Player (HKLM-x32\…\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}) (Version: 1.2.8.0 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\…\{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}) (Version: 2.6.8 - Toshiba Corporation)
TOSHIBA System Driver (HKLM-x32\…\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0032 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\…\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.00.0002.32002 - Toshiba Corporation)
TOSHIBA User's Guide (HKLM-x32\…\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
TOSHIBA VIDEO PLAYER (HKLM\…\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.3.27.102  - Toshiba Corporation)
TOSHIBARegistration (HKLM-x32\…\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.1.6 - TOSHIBA)
Verizon Wireless Software Upgrade Assistant - Samsung(ar) (HKLM-x32\…\{A3070098-A41D-42D9-B6D3-2EF15285E719}) (Version: 2.14.0605 - Samsung Electronics Co., Ltd.)
Verizon Wireless Software Utility Application for Android - Samsung (HKLM-x32\…\{B5300E76-AA13-4542-8E0E-776A280FE47E}) (Version: 2.14.0503 - Samsung Electronics Co., Ltd.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
05-09-2015 14:09:03 Scheduled Checkpoint
09-09-2015 03:37:46 Windows Update
16-09-2015 06:24:10 Scheduled Checkpoint
19-09-2015 14:30:09 Chrome Cleanup Tool
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 09:25 - 2013-08-22 09:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0C004A94-BE6C-42A7-8829-7DC8A5914C88} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {1322A334-23B8-4025-B844-79E5B7373637} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\SymErr.exe
Task: {24FF6BD8-140A-4A03-ACB5-A45AA83574CE} - System32\Tasks\UpdateTask => C:\Users\Patti\AppData\Local\{8469B~1\UNINST~1.EXE [2015-09-16] ()
Task: {6C7E3192-0929-4723-9D7C-F60721D64F4C} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-07-31] (TOSHIBA Corporation)
Task: {6F2AE581-BBB6-4CE0-AAA1-813917B1391B} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-11] (Adobe Systems Incorporated)
Task: {782654FD-470E-4CA7-9167-1CF8B389CCCF} - System32\Tasks\Microfast_LogOn => C:\Program Files (x86)\Microfast PC\MicrofastPC.exe [2015-08-19] ()
Task: {7C815E78-14E6-4319-A63E-89BDDFC5FD5A} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\SymErr.exe
Task: {81BB484E-4339-4FBB-B68E-44CFE92F501C} - System32\Tasks\Microfast_Protect => C:\Program Files (x86)\Microfast PC\chconf.exe [2015-08-19] (Microsoft)
Task: {979026BC-23F4-4FA6-9421-3F3D7EF5B92E} - System32\Tasks\HP AR Program Upload - 7635039faa2847ceb8b980b869b48daee0ddc6a36cfb4ac79db1bdb464ef6e0f => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-10-17] (TODO: )
Task: {9A5C215A-3337-4F37-B83D-763085D523BA} - \Optimizer Pro Schedule -> No File <==== ATTENTION
Task: {9AB7EFC1-61B5-4B0E-AC7F-FFE1481DA3A2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {AC55050F-89CA-422D-B9C4-D567D3AA93CA} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-08-28] (Synaptics Incorporated)
Task: {B3F91BD3-65D2-4705-95D6-8936ACF6A86A} - System32\Tasks\pcreg => C:\Program Files\pcmax\service.exe [2014-05-29] () <==== ATTENTION
Task: {B8F976AF-A6E2-45D6-9044-4F9B576955DF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {BC9AE2BC-D19D-421C-B21E-C3A1849558D8} - System32\Tasks\HP AR Program Upload - bf1cf2500a5345929d13fd404a9b27d88489c6c3333248cfba01ff6f21f63d49 => C:\Program Files\HP\HP Photosmart 6520 series\bin\HPRewards.exe [2012-10-17] (TODO: )
Task: {DD0C1FC2-90F8-4319-BA71-1A55EAF2CE54} - System32\Tasks\Microfast_Daily => C:\Program Files (x86)\Microfast PC\MicrofastPC.exe [2015-08-19] ()
Task: {E12E4098-B1EF-4011-A581-0B2E12F6BA37} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {E71AE23B-4D7C-4A65-889D-E0F83F506D42} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-10-29] (Piriform Ltd)
Task: {F05ABC77-4238-43A5-A901-C5C7BA5908B0} - System32\Tasks\Unimioanrruo => C:\ProgramData\Unimioanrruo\1.0.5.1\mnuanvou.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microfast_Protect.job => C:\Program Files (x86)\Microfast PC\chconf.exe
Task: C:\WINDOWS\Tasks\UpdateTask.job => C:\Users\Patti\AppData\Local\{8469B~1\UNINST~1.EXE
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:23 - 2010-10-20 16:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-09-11 20:39 - 2015-09-02 15:31 - 00825344 ____N () C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft64.dll
2015-09-11 20:39 - 2015-09-02 15:28 - 00083456 ____N () C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\ShieldsoftService.exe
2015-09-11 20:39 - 2015-09-01 14:45 - 00423424 ____N () C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldui.exe
2015-09-11 20:39 - 2015-09-02 15:31 - 00081408 ____N () C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft64.exe
2013-03-24 23:35 - 2012-06-25 13:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-09-11 20:39 - 2015-09-02 15:29 - 00472576 ____N () C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:45 - 2010-10-20 16:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
AlternateDataStreams: C:\Users\Patti\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\Patti\SkyDrive (2).old:ms-properties
AlternateDataStreams: C:\Users\Patti\SkyDrive (3).old:ms-properties
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\100sexlinks.com -> 100sexlinks.com
 
There are 6052 more restricted sites.
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Patti\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 0) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\…\StartupApproved\StartupFolder: => "Event Planner Reminder.lnk"
HKLM\…\StartupApproved\Run: => "TecoResident"
HKLM\…\StartupApproved\Run: => "TSleepSrv"
HKLM\…\StartupApproved\Run: => "SRS Premium Sound 3D"
HKLM\…\StartupApproved\Run: => "TCrdMain"
HKLM\…\StartupApproved\Run: => "ThpSrv"
HKLM\…\StartupApproved\Run: => "TODDMain"
HKLM\…\StartupApproved\Run: => "TosWaitSrv"
HKLM\…\StartupApproved\Run32: => "HP Software Update"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\…\StartupApproved\Run32: => "BCSSync"
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\StartupApproved\StartupFolder: => "OneNote 2010 Screen Clipper and Launcher.lnk"
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\StartupApproved\Run: => "NETGEARGenie"
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\StartupApproved\Run: => "HP Photosmart 6520 series (NET)"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{9FFE2667-5136-4317-B0EC-2C6722F77EB3}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{02211E39-61A5-4178-9275-9517C6BC7B34}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{446CAFC8-EC16-452D-AAC2-3936E313AEF3}] => (Allow) LPort=1900
FirewallRules: [{20FA5F22-8B6C-452A-BBD0-FC725A27FDFF}] => (Allow) LPort=2869
FirewallRules: [{0BF184D3-F71F-4356-B609-76D3C72C47EB}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [TCP Query User{1006214B-9A9C-41CE-A26C-CC103DEA4BC0}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{FB36FC0C-7FA3-409A-98F6-765AF63D9279}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [{327A27A7-E181-46CF-A288-2B61ED86218C}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS55A5\HPDiagnosticCoreUI.exe
FirewallRules: [{ECB2B2AC-B85F-4141-9847-62C2A81A80C2}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS55A5\HPDiagnosticCoreUI.exe
FirewallRules: [{239E6EAD-9912-4C10-9948-79149E6E0BE2}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3AA6\HPDiagnosticCoreUI.exe
FirewallRules: [{D790FC45-EB95-4411-80E9-35DAD32363A0}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3AA6\HPDiagnosticCoreUI.exe
FirewallRules: [{02825BE2-0AD8-4996-99C5-8D620AD779D4}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS51A1\HPDiagnosticCoreUI.exe
FirewallRules: [{4F1DB23F-66D8-4C2C-A930-02C28177224D}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS51A1\HPDiagnosticCoreUI.exe
FirewallRules: [{E3B706F5-490F-4E9D-BB42-C49B908C194E}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0E79\HPDiagnosticCoreUI.exe
FirewallRules: [{C6060188-A7F3-453F-8794-4949AEE237B0}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0E79\HPDiagnosticCoreUI.exe
FirewallRules: [{CD657239-4B1D-4856-8198-DF0FE68F65A7}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS6367\HPDiagnosticCoreUI.exe
FirewallRules: [{001C58D6-C527-4B7B-9BB4-ED35F572DB9C}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS6367\HPDiagnosticCoreUI.exe
FirewallRules: [{61D25BF1-C1B9-41DD-B5A0-B163E21D5255}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS4D48\HPDiagnosticCoreUI.exe
FirewallRules: [{240839EE-E376-4421-B79E-0048E0827A56}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS4D48\HPDiagnosticCoreUI.exe
FirewallRules: [{09052382-D613-40D2-BAD3-0A933AACB434}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS606D\hppiw.exe
FirewallRules: [{D6514A71-15C7-4129-8645-99A3958DD4F2}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS606D\hppiw.exe
FirewallRules: [{7BE6601A-D077-470A-AEBD-55E9CAC97730}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\DeviceSetup.exe
FirewallRules: [{D68E4DD4-4F9C-42ED-9CE0-B4FFCBF45907}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{A1CA6C84-93FF-4AAF-B674-33AE08051CC2}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{B6E9BD0B-7E1C-4F93-B4F1-D81F5EEB7B53}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS741C\HPDiagnosticCoreUI.exe
FirewallRules: [{12821D79-548F-4FDC-81A9-AA4F2E3D5F41}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS741C\HPDiagnosticCoreUI.exe
FirewallRules: [{AFBC6597-504C-4559-B562-189C3713AB08}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS251A\HPDiagnosticCoreUI.exe
FirewallRules: [{31B7196C-7D82-4CFB-BD8F-AFF68DA0316A}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS251A\HPDiagnosticCoreUI.exe
FirewallRules: [{4989B835-BBCA-48D2-A026-C9A9E4B0248C}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3406\HPDiagnosticCoreUI.exe
FirewallRules: [{C3B3F610-EEE2-429E-A6CC-30D48259DC68}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3406\HPDiagnosticCoreUI.exe
FirewallRules: [{2DA94F4D-F2A3-456D-B292-C1772D01207B}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS4800\HPDiagnosticCoreUI.exe
FirewallRules: [{D50FA04B-F6A8-4697-A5D0-40535B627D98}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS4800\HPDiagnosticCoreUI.exe
FirewallRules: [{C04183A0-4CD9-47D1-84F4-D7298B60CA0A}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS483E\HPDiagnosticCoreUI.exe
FirewallRules: [{85BECF09-DA39-4737-8CDC-9967F8C21512}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS483E\HPDiagnosticCoreUI.exe
FirewallRules: [{278182CD-4DC9-4F38-AFD7-76CC9C5F9CDE}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS5009\HPDiagnosticCoreUI.exe
FirewallRules: [{82BEB5DE-47E1-4359-8FB9-93CB65E3BD4F}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS5009\HPDiagnosticCoreUI.exe
FirewallRules: [{ABA33D4F-C44D-4B37-9D34-BFBDB00F8630}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS6A79\HPDiagnosticCoreUI.exe
FirewallRules: [{9DF081B0-5A8D-4078-BAEA-793AF2AEF2EB}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS6A79\HPDiagnosticCoreUI.exe
FirewallRules: [TCP Query User{0A5F966C-CC94-41E6-B407-C8058FBA67FF}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{46BB4DA2-0113-40BE-9A48-A2D61E697BDB}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [{A75B6F88-F1BB-4241-B1D2-C6FE8DB30008}] => (Allow) C:\Users\Patti\AppData\Local\Temp\n5270\speedmaxZS_1605-d640b376.exe
FirewallRules: [{B5805387-0A36-440D-B96C-A7956A4249EE}] => (Allow) C:\Users\Patti\AppData\Local\Temp\speedmax_15374.exe
FirewallRules: [{61C113E4-7600-4E84-9CC4-6A30627A09B3}] => (Allow) C:\Users\Patti\AppData\Local\Temp\updater_146472.exe
FirewallRules: [{C46E3AD1-F150-4BB9-95E3-A71A0A6FE6D9}] => (Allow) c:\program files\pcmax\pcmax.exe
FirewallRules: [{4367A904-9BDC-48D9-9D20-103901850AC9}] => (Allow) c:\program files\pcmax\pcmax.exe
FirewallRules: [{39A79686-72DB-4805-8177-C7DB4412A822}] => (Allow) c:\program files\pcmax\service.exe
FirewallRules: [{22D48403-E286-4BC9-9102-9A2681FE24CD}] => (Allow) c:\program files\pcmax\service.exe
FirewallRules: [{4AD53368-7FB6-4C5A-9B07-A62705493699}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55720.exe
FirewallRules: [{175B321D-9740-4C06-9030-B9BB308C29F1}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55720.exe
FirewallRules: [{CCF0EA46-F48D-44DA-B799-FDA04BD1AE5D}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55428.exe
FirewallRules: [{3C36CF10-2FDE-41BC-933D-FEEC6F1CDB5B}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55428.exe
FirewallRules: [{39EB686F-2A0A-4707-AF9A-2462D657B1AC}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{D2436DEF-46A2-41E4-83A1-DC7B56D79795}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{F52DFA7A-AC01-4F13-A7D5-3C748888975C}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{4B9F8327-2C72-4FB7-8B53-D8CC9922A3B2}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{D9BB7A29-4000-4226-AD3B-CF0A5424C7DB}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{4992FC9D-747B-4BAC-972A-1945D53B25E1}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS15F8\HPDiagnosticCoreUI.exe
FirewallRules: [{24D78248-EA3F-4972-82F4-AD6894E73E82}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS15F8\HPDiagnosticCoreUI.exe
FirewallRules: [{06D14F67-F1B3-4499-A172-69A865D06F43}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS002D\HPDiagnosticCoreUI.exe
FirewallRules: [{CC50A56F-70BB-4722-913E-C981747091EE}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS002D\HPDiagnosticCoreUI.exe
FirewallRules: [{6070F7D3-9311-4AC5-96C3-957BD25F17F5}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS007E\HPDiagnosticCoreUI.exe
FirewallRules: [{4FBC4404-766B-4663-B1CF-F6DBCDB8D1D9}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS007E\HPDiagnosticCoreUI.exe
FirewallRules: [{A591AEC1-2B7B-4129-B095-482AB20B4006}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS015C\HPDiagnosticCoreUI.exe
FirewallRules: [{7840A9CE-1E5B-46DA-8AEF-ACC87E48CD1B}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS015C\HPDiagnosticCoreUI.exe
FirewallRules: [{ADA7F9D2-29A5-490F-A782-DD22A48A8015}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS28A0\HPDiagnosticCoreUI.exe
FirewallRules: [{63ADD7C2-A412-4B67-B99F-EF13B14CCE0A}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS28A0\HPDiagnosticCoreUI.exe
FirewallRules: [{B3C8CAEB-DFFC-4561-8607-8EEA3FF29960}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS5C45\HPDiagnosticCoreUI.exe
FirewallRules: [{153BDD50-E308-4694-BEFF-5FAFA018D7F7}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS5C45\HPDiagnosticCoreUI.exe
FirewallRules: [{AB08D670-0837-4299-BAB5-D85BF8C1F7E2}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS48A5\HPDiagnosticCoreUI.exe
FirewallRules: [{ED030D6E-C4B0-4BF8-9B77-ED943BC428F5}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS48A5\HPDiagnosticCoreUI.exe
FirewallRules: [{D92B3D85-DF50-41C2-B14C-9F2551B095BD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C6499CDE-A177-4805-96D5-F458B6483848}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{E93ABC9A-4963-4988-ACD6-9AF657774A17}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{1EC0FF29-84DE-4156-9C70-5032A1B7B411}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{46E16B45-1F73-4B55-9BA5-288C91A6E012}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3124\HPDiagnosticCoreUI.exe
FirewallRules: [{D20391A3-AC99-4193-82CA-AEAAF0CFFFFC}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS3124\HPDiagnosticCoreUI.exe
FirewallRules: [{67031B83-DE4D-427C-8DE9-ECE061BC2935}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS315B\HPDiagnosticCoreUI.exe
FirewallRules: [{1A89905F-9900-48FB-B4BC-C4C0AF1EFF06}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS315B\HPDiagnosticCoreUI.exe
FirewallRules: [{8AC5F686-CA29-468D-AF46-CCB11B334BF3}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS32A2\HPDiagnosticCoreUI.exe
FirewallRules: [{4D50AF72-4BAB-4C72-9DA1-53E707F22780}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS32A2\HPDiagnosticCoreUI.exe
FirewallRules: [{4DC6CDEF-A81B-48A3-97FC-ADCFD8FA0450}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS218B\HPDiagnosticCoreUI.exe
FirewallRules: [{425A582C-6C31-450C-9776-E5B3E3F82457}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS218B\HPDiagnosticCoreUI.exe
FirewallRules: [{18648448-F9BE-495D-8899-C5A132E211A6}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0B81\HPDiagnosticCoreUI.exe
FirewallRules: [{06FF5FF3-5683-43C9-B9CB-D242CFDEED20}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0B81\HPDiagnosticCoreUI.exe
FirewallRules: [{3A59A446-AEA5-461A-8F95-B426A90A6486}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0BC9\HPDiagnosticCoreUI.exe
FirewallRules: [{C0AD9B1B-97AF-439E-9FFA-FEF7EB155D92}] => (Allow) C:\Users\Patti\AppData\Local\Temp\7zS0BC9\HPDiagnosticCoreUI.exe
FirewallRules: [{730815A7-6CAA-42B6-B18A-CC74B7D146F2}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55715.exe
FirewallRules: [{6C47E9E8-AF3A-494E-A8DE-D95305484568}] => (Allow) C:\Users\Patti\AppData\Local\Temp\file_to_run55715.exe
FirewallRules: [{23D41958-B4C5-426C-8948-2E78CCAFFE04}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{5D1FC8B4-E58A-4154-ADE5-BBFF438965A1}] => (Allow) C:\Users\Patti\AppData\Local\Chromium\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
Name: TOSHIBA x64 ACPI-Compliant Value Added Logical and General Purpose Device
Description: TOSHIBA x64 ACPI-Compliant Value Added Logical and General Purpose Device
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: TOSHIBA
Service: TVALZ
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/21/2015 02:51:01 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.
 
Error: (09/21/2015 01:50:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_DeviceAssociationService, version: 6.3.9600.17415, time stamp: 0x54504177
Faulting module name: ntdll.dll, version: 6.3.9600.17936, time stamp: 0x55a68e0c
Exception code: 0xc0000374
Fault offset: 0x00000000000f1280
Faulting process id: 0x1cc
Faulting application start time: 0xsvchost.exe_DeviceAssociationService0
Faulting application path: svchost.exe_DeviceAssociationService1
Faulting module path: svchost.exe_DeviceAssociationService2
Report Id: svchost.exe_DeviceAssociationService3
Faulting package full name: svchost.exe_DeviceAssociationService4
Faulting package-relative application ID: svchost.exe_DeviceAssociationService5
 
Error: (09/21/2015 01:43:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: setup.exe_unknown, version: 0.0.0.0, time stamp: 0x2a425e19
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54504ade
Exception code: 0x000006ba
Fault offset: 0x00014598
Faulting process id: 0x1b1c
Faulting application start time: 0xsetup.exe_unknown0
Faulting application path: setup.exe_unknown1
Faulting module path: setup.exe_unknown2
Report Id: setup.exe_unknown3
Faulting package full name: setup.exe_unknown4
Faulting package-relative application ID: setup.exe_unknown5
 
Error: (09/19/2015 02:03:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wwahost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: ea4
 
Start Time: 01d0f304cd6cc51c
 
Termination Time: 4294967295
 
Application Path: C:\WINDOWS\syswow64\wwahost.exe
 
Report Id: c2af9fae-5ef8-11e5-bed7-008cfa434a00
 
Faulting package full name: Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c
 
Faulting package-relative application ID: App
 
Error: (09/19/2015 02:03:22 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LiveComm.exe version 17.5.9600.20911 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 8e0
 
Start Time: 01d0f304c1e98d27
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: b57a5249-5ef8-11e5-bed7-008cfa434a00
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (09/19/2015 02:01:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chVrTxzlCKe.exe, version: 1.0.0.0, time stamp: 0x55fa4b62
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54504ade
Exception code: 0xc06d007e
Fault offset: 0x00014598
Faulting process id: 0x1144
Faulting application start time: 0xchVrTxzlCKe.exe0
Faulting application path: chVrTxzlCKe.exe1
Faulting module path: chVrTxzlCKe.exe2
Report Id: chVrTxzlCKe.exe3
Faulting package full name: chVrTxzlCKe.exe4
Faulting package-relative application ID: chVrTxzlCKe.exe5
 
Error: (09/19/2015 02:01:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SUKAbQ.exe, version: 1.0.0.0, time stamp: 0x55fa4b73
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54505737
Exception code: 0xc06d007e
Fault offset: 0x0000000000008b9c
Faulting process id: 0x13ec
Faulting application start time: 0xSUKAbQ.exe0
Faulting application path: SUKAbQ.exe1
Faulting module path: SUKAbQ.exe2
Report Id: SUKAbQ.exe3
Faulting package full name: SUKAbQ.exe4
Faulting package-relative application ID: SUKAbQ.exe5
 
Error: (09/16/2015 09:35:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 45.0.2454.93, time stamp: 0x55f350f6
Faulting module name: chrome.exe, version: 45.0.2454.93, time stamp: 0x55f350f6
Exception code: 0xc0000409
Fault offset: 0x0004c8c1
Faulting process id: 0x1ec
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Faulting package full name: chrome.exe4
Faulting package-relative application ID: chrome.exe5
 
Error: (09/16/2015 01:27:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: setup.exe_unknown, version: 0.0.0.0, time stamp: 0x2a425e19
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54504ade
Exception code: 0x000006ba
Fault offset: 0x00014598
Faulting process id: 0xa54
Faulting application start time: 0xsetup.exe_unknown0
Faulting application path: setup.exe_unknown1
Faulting module path: setup.exe_unknown2
Report Id: setup.exe_unknown3
Faulting package full name: setup.exe_unknown4
Faulting package-relative application ID: setup.exe_unknown5
 
Error: (09/16/2015 01:26:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: setup.exe_unknown, version: 0.0.0.0, time stamp: 0x2a425e19
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54504ade
Exception code: 0x000006ba
Fault offset: 0x00014598
Faulting process id: 0x1a20
Faulting application start time: 0xsetup.exe_unknown0
Faulting application path: setup.exe_unknown1
Faulting module path: setup.exe_unknown2
Report Id: setup.exe_unknown3
Faulting package full name: setup.exe_unknown4
Faulting package-relative application ID: setup.exe_unknown5
 
 
System errors:
=============
Error: (09/21/2015 02:20:59 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The pcmaxservice Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (09/21/2015 02:20:16 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Windows\System32\drivers\TrueSight.sys
 
Error: (09/21/2015 02:10:56 PM) (Source: DCOM) (EventID: 10010) (User: NYKAMP-PC)
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}
 
Error: (09/21/2015 01:57:13 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The HP Network Devices Support service hung on starting.
 
Error: (09/21/2015 01:51:46 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Device Association Service service, but this action failed with the following error: 
%%1056
 
Error: (09/21/2015 01:51:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (09/21/2015 01:51:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Intel(R) Management and Security Application Local Management Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (09/21/2015 01:51:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
 
Error: (09/21/2015 01:51:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (09/21/2015 01:51:15 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
%%1056
 
 
CodeIntegrity:
===================================
  Date: 2015-09-21 13:14:43.531
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-19 20:46:32.310
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-19 14:45:12.496
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 14:17:38.234
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 06:14:54.772
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-12 18:52:31.937
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-12 16:36:20.412
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-12 15:30:15.323
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-08-24 15:08:54.455
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-08-15 14:02:22.643
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz
Percentage of memory in use: 27%
Total physical RAM: 8076.22 MB
Available physical RAM: 5866.38 MB
Total Virtual: 17292.22 MB
Available Virtual: 15325.61 MB
 
==================== Drives ================================
 
Drive c: (TI10658600C) (Fixed) (Total:686.49 GB) (Free:612.17 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

I hope this is what you wanted.  I had a hard time getting the websites to open and the downloads to take place.  Between my 3 browsers I managed.Thanks.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by [removed] (administrator) on NYKAMP-PC (21-09-2015 15:13:44)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NETGEAR) C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Reflect\ReflectService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Windows\System32\Locator.exe
() C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldsoftService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Toshiba Corporation) C:\Program Files\Toshiba\Teco\TecoService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\HDD Accelerator\THAccelSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(ShieldSoft) C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft.exe
() C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldui.exe
() C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft64.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13261456 2012-12-10] (Realtek Semiconductor)
HKLM\…\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2609064 2012-08-30] ()
HKLM\…\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [178016 2013-08-21] (TOSHIBA Corporation)
HKLM\…\Run: [TSleepSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSleepSrv.exe [1548952 2012-08-04] (TOSHIBA Corporation)
HKLM\…\Run: [TODDMain] => C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe [213136 2012-08-04] ()
HKLM\…\Run: [ThpSrv] => C:\windows\system32\thpsrv /logon
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\…\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [354144 2013-08-13] (TOSHIBA Corporation)
HKLM\…\Run: [pcreg] => C:\Program Files\pcmax\service.exe [79088 2014-05-29] ()
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\…\Run: [pcreg] => C:\Program Files\pcmax\service.exe [79088 2014-05-29] ()
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
HKLM-x32\…\Run: [AddressBookReminderApp] => C:\Program Files (x86)\Creative Home\Hallmark Card Studio 2013\ReminderApp.exe
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\…\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\Run: [NETGEARGenie] => C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe [602880 2013-11-14] (NETGEAR Inc.)
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\Run: [HP Photosmart 6520 series (NET)] => C:\Program Files\HP\HP Photosmart 6520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\Run: [RunIt] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe [377000 2015-09-19] (Mozilla Corporation)
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\Run: [pcreg] => C:\Program Files\pcmax\service.exe [79088 2014-05-29] ()
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-29] (Piriform Ltd)
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\…\Run: [ShieldSoft] => C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\shieldui.exe [423424 2015-09-01] ()
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Event Planner Reminder.lnk [2014-09-17]
ShortcutTarget: Event Planner Reminder.lnk -> C:\Program Files (x86)\Creative Home\Hallmark Card Studio 2013\Planner\PLNRnote.exe (Creative Home)
Startup: C:\Users\Patti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Photosmart 6520 series (Network).lnk [2014-01-05]
ShortcutTarget: Monitor Ink Alerts - HP Photosmart 6520 series (Network).lnk -> C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Patti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2014-01-09]
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Patti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verizon Wireless Software Utility Application for Android – Samsung.lnk [2014-08-10]
ShortcutTarget: Verizon Wireless Software Utility Application for Android – Samsung.lnk -> C:\Users\Patti\AppData\Roaming\VERIZON\UA_ar\UA.exe (SAMSUNG Electornics Co., Ltd.)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3AD4F85E-4C1E-4782-B8D4-FC4A4E3B8791}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://toshiba13.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKU\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_prgasst_15_39¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0CyE0EtAyCzyyEyDtBtCyD0D0D0CyEtN0D0Tzu0StCtAyDzytN1L2XzutAtFtCtDtFtCtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StByCtAtDtCzyzzyCtG0FyE0FtDtGyE0BtAtBtG0B0F0C0FtGyDtBtB0BzzzztD0EyB0BzzyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FtAyE0EyByDyD0AtG0AtD0FyEtGyEtCtC0DtGzyyB0D0EtG0A0AyCtD0CtCyE0B0AtBtAtB2QtN0A0LzuyE%26cr%3D1596817938%26a%3Dwny_prgasst_15_39%26os%3DWindows 8.1&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = 
SearchScopes: HKU\S-1-5-21-1679494073-3026066304-2182815410-1001 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = 
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-18] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: No Name -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} ->  No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-18] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\Patti\AppData\Roaming\Mozilla\Firefox\Profiles\l9qemj8f.default
FF DefaultSearchEngine: Rocket Tab
FF DefaultSearchEngine.US: Search Provided by Yahoo
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Rocket Tab
FF Homepage: hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_prgasst_15_39¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0CyE0EtAyCzyyEyDtBtCyD0D0D0CyEtN0D0Tzu0StCtAyDzytN1L2XzutAtFtCtDtFtCtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StByCtAtDtCzyzzyCtG0FyE0FtDtGyE0BtAtBtG0B0F0C0FtGyDtBtB0BzzzztD0EyB0BzzyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FtAyE0EyByDyD0AtG0AtD0FyEtGyEtCtC0DtGzyyB0D0EtG0A0AyCtD0CtCyE0B0AtBtAtB2QtN0A0LzuyE%26cr%3D1596817938%26a%3Dwny_prgasst_15_39%26os%3DWindows 8.1
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-11] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-11] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-03] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-28] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Patti\AppData\Roaming\Mozilla\Firefox\Profiles\l9qemj8f.default\searchplugins\search-provided-by-yahoo.xml [2015-09-21]
FF SearchPlugin: C:\Users\Patti\AppData\Roaming\Mozilla\Firefox\Profiles\l9qemj8f.default\searchplugins\shieldRocket Tab.xml [2015-09-17]
FF Extension: MyWordTool - C:\Users\Patti\AppData\Roaming\Mozilla\Firefox\Profiles\l9qemj8f.default\Extensions\[removed] [2014-01-13]
FF Extension: Garmin Communicator - C:\Users\Patti\AppData\Roaming\Mozilla\Firefox\Profiles\l9qemj8f.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2015-06-01]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-09-19]
StartMenuInternet: FIREFOX.EXE - firefox.exe
 
Chrome: 
=======
CHR HomePage: Default -> hxxps://us-mg5.mail.yahoo.com/neo/launch?.rand=4mthfotmot96e#mail
CHR StartupUrls: Default -> "hxxps://us-mg5.mail.yahoo.com/neo/launch?.rand=4q7d89othmpbp","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_omxmedia_15_38¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzuzy0CyE0EtAyCzyyEyDtBtCyD0D0D0CyEtN0D0Tzu0StCtAyDyEtN1L2XzutAtFtCtBtFyDtFtAtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2Szy0B0DyBtC0FzyyBtGtDyEtD0AtGyEtB0C0AtG0AtDyBzztGyCtByC0CyDzytD0DtB0E0AyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FtAyE0EyByDyD0AtG0AtD0FyEtGyEtCtC0DtGzyyB0D0EtG0A0AyCtD0CtCyE0B0AtBtAtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDtCyC%26cr%3D1654742972%26a%3Dwncy_omxmedia_15_38%26os%3DWindows%2B8.1","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_prgasst_15_39¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0CyE0EtAyCzyyEyDtBtCyD0D0D0CyEtN0D0Tzu0StCtAyDzytN1L2XzutAtFtCtDtFtCtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StByCtAtDtCzyzzyCtG0FyE0FtDtGyE0BtAtBtG0B0F0C0FtGyDtBtB0BzzzztD0EyB0BzzyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FtAyE0EyByDyD0AtG0AtD0FyEtGyEtCtC0DtGzyyB0D0EtG0A0AyCtD0CtCyE0B0AtBtAtB2QtN0A0LzuyE%26cr%3D1596817938%26a%3Dwny_prgasst_15_39%26os%3DWindows 8.1"
CHR DefaultSearchURL: Default -> hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_prgasst_15_39¶m1=1¶m2=f%3D4%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0CyE0EtAyCzyyEyDtBtCyD0D0D0CyEtN0D0Tzu0StCtAyDzytN1L2XzutAtFtCtDtFtCtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StByCtAtDtCzyzzyCtG0FyE0FtDtGyE0BtAtBtG0B0F0C0FtGyDtBtB0BzzzztD0EyB0BzzyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FtAyE0EyByDyD0AtG0AtD0FyEtGyEtCtC0DtGzyyB0D0EtG0A0AyCtD0CtCyE0B0AtBtAtB2QtN0A0LzuyE%26cr%3D1596817938%26a%3Dwny_prgasst_15_39%26os%3DWindows 8.1&p={searchTerms}
CHR DefaultSearchKeyword: Default -> search provided by yahoo.com
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR Profile: C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Yahoo Web) - C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default\Extensions\acjpdakpjonkfmggcmanlhdakfkhloii [2014-07-15]
CHR Extension: (Google Docs) - C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-05]
CHR Extension: (Google Drive) - C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-05]
CHR Extension: (YouTube) - C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-05]
CHR Extension: (Google Search) - C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-05]
CHR Extension: (Google Docs Offline) - C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-05]
CHR Extension: (Gmail) - C:\Users\Patti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-05]
StartMenuInternet: Google Chrome - chrome.exe
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 HPSLPSVC; C:\Users\Patti\AppData\Local\Temp\7zS606D\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-08] ()
R2 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [232192 2013-11-14] (NETGEAR)
S2 pcmaxservice; C:\Program Files\pcmax\pcmax.exe [241344 2014-05-29] ()
R2 ReflectService.exe; C:\Program Files\Macrium\Reflect\ReflectService.exe [1141232 2014-05-29] (Paramount Software UK Ltd)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-08-31] (Realtek Semiconductor)
R2 ShieldSoft; C:\Users\Patti\AppData\Roaming\ShieldSoft\UI\bin\ShieldsoftService.exe [83456 2015-09-02] () [File not signed]
R2 THAccelSvc; C:\Program Files\TOSHIBA\HDD Accelerator\THAccelSvc.exe [214488 2012-08-10] (TOSHIBA CORPORATION)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864 2014-01-08] (Intel® Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 cleanhlp; C:\EEK\Run\cleanhlp64.sys [57024 2013-10-13] (Emsisoft GmbH)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3349984 2014-04-17] (Intel Corporation)
R2 NPF; C:\WINDOWS\system32\drivers\npf.sys [35344 2013-12-13] (CACE Technologies, Inc.)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-03] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-28] (Synaptics Incorporated)
R0 THAccel; C:\Windows\System32\DRIVERS\THAccel.sys [131520 2012-08-10] (TOSHIBA CORPORATION)
S3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [32624 2013-08-19] (Windows (R) Win 7 DDK provider)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-09-21] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-21 15:07 - 2015-09-21 15:07 - 00000162 ____H C:\Users\Patti\Desktop\~$dition.txt
2015-09-21 14:53 - 2015-09-21 15:09 - 00049779 _____ C:\Users\Patti\Desktop\Addition.txt
2015-09-21 14:52 - 2015-09-21 15:13 - 00023056 _____ C:\Users\Patti\Desktop\FRST.txt
2015-09-21 14:52 - 2015-09-21 15:13 - 00000000 ____D C:\FRST
2015-09-21 14:52 - 2015-09-21 14:52 - 02191360 _____ (Farbar) C:\Users\Patti\Desktop\FRST64.exe
2015-09-21 14:50 - 2015-09-21 14:50 - 02191360 _____ (Farbar) C:\Users\Patti\Downloads\FRST64.exe
2015-09-21 14:20 - 2015-09-21 14:20 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-09-21 14:20 - 2015-09-21 14:20 - 00000000 ____D C:\ProgramData\RogueKiller
2015-09-21 14:19 - 2015-09-21 14:19 - 18801736 _____ C:\Users\Patti\Desktop\RogueKiller.exe
2015-09-21 14:10 - 2015-09-21 14:10 - 00001328 _____ C:\AdwCleaner[S2].txt
2015-09-21 14:09 - 2015-09-21 14:09 - 00001266 _____ C:\AdwCleaner[R3].txt
2015-09-21 14:05 - 2015-09-21 14:05 - 00001765 _____ C:\AdwCleaner[R2].txt
2015-09-21 14:05 - 2015-09-21 14:05 - 00001705 _____ C:\AdwCleaner[R1].txt
2015-09-21 14:01 - 2015-09-21 14:01 - 00000000 _____ C:\WINDOWS\SysWOW64\${FILE_SN_DLL}
2015-09-21 13:48 - 2015-09-21 13:51 - 00000000 ____D C:\AdwCleaner
2015-09-21 13:48 - 2015-09-21 13:48 - 00000000 __SHD C:\ProgramData\360Quarant
2015-09-21 13:48 - 2015-09-21 13:48 - 00000000 __SHD C:\$360Section
2015-09-21 13:47 - 2015-09-21 13:47 - 00000000 ____D C:\Program Files (x86)\WinYahoo
2015-09-21 13:44 - 2015-09-21 15:12 - 00000294 _____ C:\WINDOWS\Tasks\Microfast_Protect.job
2015-09-21 13:44 - 2015-09-21 14:14 - 00003482 _____ C:\WINDOWS\System32\Tasks\Microfast_LogOn
2015-09-21 13:44 - 2015-09-21 13:45 - 00000000 ____D C:\Users\Patti\AppData\Roaming\MicrofastPC
2015-09-21 13:44 - 2015-09-21 13:44 - 00003104 _____ C:\WINDOWS\System32\Tasks\Microfast_Protect
2015-09-21 13:44 - 2015-09-21 13:44 - 00001003 _____ C:\Users\Public\Desktop\Microfast PC.lnk
2015-09-21 13:44 - 2015-09-21 13:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microfast PC
2015-09-21 13:44 - 2015-09-21 13:44 - 00000000 ____D C:\Program Files (x86)\Microfast PC
2015-09-21 13:43 - 2015-09-21 14:14 - 00003922 _____ C:\WINDOWS\System32\Tasks\Microfast_Daily
2015-09-21 13:43 - 2015-09-21 13:47 - 00000000 ____D C:\Users\Patti\AppData\Local\rali
2015-09-21 13:43 - 2015-09-21 13:43 - 01354223 _____ C:\Users\Patti\Downloads\adwcleaner_3.216.exe
2015-09-21 13:43 - 2015-09-21 13:43 - 00000000 ____D C:\Program Files (x86)\360
2015-09-21 13:29 - 2015-09-21 13:39 - 00000000 ____D C:\WINDOWS\pss
2015-09-19 17:50 - 2015-09-19 17:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-09-19 14:01 - 2015-09-19 14:01 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-09-19 13:58 - 2015-09-21 14:11 - 00000693 _____ C:\WINDOWS\setupact.log
2015-09-19 13:58 - 2015-09-19 13:58 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-09-19 13:57 - 2015-09-21 14:11 - 00022322 _____ C:\WINDOWS\PFRO.log
2015-09-17 18:05 - 2015-09-19 18:04 - 00003450 _____ C:\WINDOWS\System32\Tasks\Unimioanrruo
2015-09-16 15:22 - 2015-09-21 13:47 - 00001174 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-09-16 15:20 - 2015-09-16 15:20 - 00242752 _____ C:\Users\Patti\Downloads\Firefox Setup Stub 40.0.3.exe
2015-09-16 15:20 - 2015-09-16 15:20 - 00242752 _____ C:\Users\Patti\Downloads\Firefox Setup Stub 40.0.3 (1).exe
2015-09-16 14:27 - 2015-09-19 14:27 - 00000104 _____ C:\Users\Patti\AppData\Roaming\WB.CFG
2015-09-16 14:09 - 2015-09-19 14:04 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-09-16 14:09 - 2015-09-16 14:09 - 00002050 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-09-16 14:09 - 2015-09-16 14:09 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-09-16 14:08 - 2015-09-16 14:08 - 75858112 _____ (Adobe Systems Incorporated) C:\Users\Patti\Downloads\AdbeRdr11010_en_US (1).exe
2015-09-16 14:07 - 2015-09-16 14:08 - 75858112 _____ (Adobe Systems Incorporated) C:\Users\Patti\Downloads\AdbeRdr11010_en_US.exe
2015-09-16 13:27 - 2015-09-21 14:27 - 00000290 _____ C:\WINDOWS\Tasks\UpdateTask.job
2015-09-16 13:27 - 2015-09-16 13:27 - 00002628 _____ C:\WINDOWS\System32\Tasks\UpdateTask
2015-09-16 13:27 - 2015-09-16 13:27 - 00000000 ____D C:\Users\Patti\AppData\Local\Chromium
2015-09-16 13:26 - 2015-09-16 14:27 - 00000000 ____D C:\Users\Patti\AppData\Local\{8469B235-A0C1-DE8D-CD59-FB65E93107FD}
2015-09-16 13:26 - 2015-09-16 13:27 - 00000000 ____D C:\Users\Patti\AppData\Local\mina
2015-09-16 13:26 - 2015-09-16 13:26 - 01057488 _____ (Adobe) C:\Users\Patti\Downloads\Adobe Reader.exe
2015-09-16 13:26 - 2015-09-16 13:26 - 00000000 ____D C:\Users\Patti\AppData\Local\Setup84585859
2015-09-16 13:25 - 2015-09-16 13:25 - 00869144 _____ (Generic ) C:\Users\Patti\Downloads\Adobe Reader Setup.exe
2015-09-15 22:21 - 2015-09-15 22:21 - 00000000 ____D C:\Users\Patti\Desktop\Documents\samsung
2015-09-13 22:29 - 2015-09-13 22:29 - 19733696 _____ (Microsoft Corporation) C:\Users\Patti\Downloads\MediaCreationToolx64.exe
2015-09-13 22:29 - 2015-09-13 22:29 - 00000000 ___HD C:\$Windows.~WS
2015-09-13 09:10 - 2015-09-13 11:55 - 00026288 _____ C:\Users\Patti\Desktop\GWXWebWindows.exe
2015-09-12 20:49 - 2015-09-12 20:51 - 00000000 ____D C:\Users\Patti\Desktop\Priority Medicare
2015-09-12 19:11 - 2015-09-21 14:26 - 01802152 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-12 16:10 - 2015-09-12 16:10 - 00222727 _____ C:\Users\Patti\Desktop\Documents\Bookmarks91215.html
2015-09-11 20:39 - 2015-09-11 20:39 - 00000000 ____D C:\Users\Patti\AppData\Roaming\ShieldSoft
2015-09-08 17:54 - 2015-08-26 22:48 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-09-08 17:54 - 2015-08-26 14:00 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-09-08 17:54 - 2015-08-26 14:00 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-09-08 17:54 - 2015-08-26 14:00 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-09-08 17:54 - 2015-08-26 14:00 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-09-08 17:54 - 2015-08-26 10:46 - 03705344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-09-08 17:54 - 2015-08-26 10:29 - 02240512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-09-08 17:54 - 2015-08-26 10:27 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-09-08 17:54 - 2015-08-26 10:27 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-09-08 17:54 - 2015-08-26 10:26 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-09-08 17:54 - 2015-08-26 10:26 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-09-08 17:54 - 2015-08-26 10:26 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-09-08 17:53 - 2015-09-02 22:18 - 02531400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-09-08 17:53 - 2015-09-02 22:17 - 01903848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-09-08 17:53 - 2015-09-02 14:48 - 02345472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-09-08 17:53 - 2015-09-02 13:09 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-09-08 17:53 - 2015-08-22 14:19 - 25188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-09-08 17:53 - 2015-08-22 13:35 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-08 17:53 - 2015-08-22 13:34 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-08 17:53 - 2015-08-22 13:22 - 19856384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-09-08 17:53 - 2015-08-22 13:21 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-08 17:53 - 2015-08-22 13:20 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-09-08 17:53 - 2015-08-22 12:55 - 00504832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-08 17:53 - 2015-08-22 12:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-08 17:53 - 2015-08-22 12:45 - 00665600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-08 17:53 - 2015-08-22 12:41 - 14451712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-08 17:53 - 2015-08-22 12:41 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-09-08 17:53 - 2015-08-22 12:41 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-09-08 17:53 - 2015-08-22 12:39 - 02126336 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-09-08 17:53 - 2015-08-22 12:28 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-09-08 17:53 - 2015-08-22 12:26 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-09-08 17:53 - 2015-08-22 12:22 - 12857344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-08 17:53 - 2015-08-22 12:18 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-09-08 17:53 - 2015-08-22 12:14 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-09-08 17:53 - 2015-08-22 12:00 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-09-08 17:53 - 2015-08-22 11:56 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-09-08 17:53 - 2015-07-30 13:18 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkEd.dll
2015-09-08 17:53 - 2015-07-30 12:22 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkEd.dll
2015-09-08 17:53 - 2015-07-22 10:34 - 02775552 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-08 17:53 - 2015-07-22 10:33 - 01728000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-08 17:53 - 2015-07-22 10:25 - 02461184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-08 17:53 - 2015-07-22 10:25 - 01546752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-08 17:53 - 2015-07-22 10:19 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-09-08 17:53 - 2015-07-22 09:52 - 01633792 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-09-08 17:53 - 2015-07-18 14:31 - 00194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-08 17:53 - 2015-07-18 14:29 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-08 17:53 - 2015-07-18 14:29 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-08 17:53 - 2015-07-18 14:27 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-08 17:53 - 2015-07-17 10:15 - 00951296 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-09-08 17:53 - 2015-07-17 10:10 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-09-08 17:53 - 2015-07-03 17:51 - 01380056 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-09-08 17:53 - 2015-07-03 10:00 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-09-08 17:53 - 2015-06-27 07:47 - 00118616 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2015-09-08 17:53 - 2015-06-19 13:07 - 02819072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2015-09-08 17:52 - 2015-09-01 22:56 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-09-08 17:52 - 2015-09-01 22:55 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-08 17:52 - 2015-09-01 22:50 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-08 17:52 - 2015-09-01 22:17 - 00301568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-08 17:52 - 2015-09-01 22:13 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-08 17:52 - 2015-08-22 12:50 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-09-08 17:52 - 2015-08-22 12:44 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-09-08 17:52 - 2015-08-22 12:41 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-09-08 17:52 - 2015-08-22 12:23 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-09-08 17:52 - 2015-08-22 12:20 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-09-08 17:52 - 2015-08-22 12:18 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-09-08 17:52 - 2015-08-22 12:18 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-09-08 17:52 - 2015-08-22 12:01 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-09-08 17:52 - 2015-08-22 11:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-09-08 17:52 - 2015-08-03 17:15 - 00074928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2015-09-08 17:52 - 2015-08-03 17:15 - 00065600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2015-09-08 17:52 - 2015-08-01 10:22 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2015-09-08 17:52 - 2015-07-31 23:47 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schtasks.exe
2015-09-08 17:52 - 2015-07-31 23:45 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe
2015-09-08 17:52 - 2015-07-31 23:38 - 01265152 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-08 17:52 - 2015-07-31 23:37 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskeng.exe
2015-09-08 17:52 - 2015-07-31 23:37 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskeng.exe
2015-09-08 17:52 - 2015-07-13 23:27 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzsync.exe
2015-09-08 17:52 - 2015-07-13 15:10 - 00411455 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-09-08 17:52 - 2015-07-09 12:14 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-21 15:00 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-21 14:51 - 2013-05-27 22:17 - 00297472 ___SH C:\Users\Patti\Downloads\Thumbs.db
2015-09-21 14:49 - 2013-12-13 19:29 - 00000000 __RDO C:\Users\Patti\SkyDrive
2015-09-21 14:32 - 2013-12-12 20:31 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1679494073-3026066304-2182815410-1001
2015-09-21 14:30 - 2013-12-14 00:32 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-21 14:21 - 2014-07-02 00:40 - 00000926 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-21 14:11 - 2014-07-02 00:40 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-21 14:11 - 2013-08-22 10:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-21 13:50 - 2013-12-13 19:04 - 00000000 ____D C:\Users\Patti
2015-09-21 13:47 - 2014-07-02 00:41 - 00002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-21 13:29 - 2013-08-22 09:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-09-21 13:05 - 2013-12-14 00:29 - 00003930 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B2B7A784-E280-41B3-B0ED-41F57FC93B6E}
2015-09-20 23:39 - 2013-05-11 12:17 - 03935232 ___SH C:\Users\Patti\Desktop\Thumbs.db
2015-09-19 20:08 - 2014-02-16 21:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-19 20:08 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\Camera
2015-09-19 19:48 - 2013-08-12 21:55 - 00496640 _____ C:\Users\Patti\Desktop\PATTI'S MONTHLY EXPENSES.xls
2015-09-19 19:41 - 2014-07-04 13:19 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-19 14:26 - 2014-01-05 11:42 - 00000000 ____D C:\Users\Patti\AppData\Local\Google
2015-09-17 18:00 - 2013-12-12 20:39 - 00001186 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-09-16 14:09 - 2012-12-03 02:26 - 00000000 ____D C:\ProgramData\Adobe
2015-09-16 13:20 - 2013-08-17 17:11 - 00000000 ____D C:\Users\Patti\Desktop\Documents\Recipes
2015-09-15 10:16 - 2014-07-02 00:40 - 00003898 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-15 10:16 - 2014-07-02 00:40 - 00003662 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-12 20:38 - 2013-11-14 03:28 - 00869476 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-12 19:13 - 2013-08-14 21:56 - 00000000 ____D C:\Users\Patti\Desktop\Documents\Reflect
2015-09-12 19:03 - 2015-07-15 14:42 - 00000000 ____D C:\WINDOWS\Minidump
2015-09-12 18:34 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\schemas
2015-09-12 15:45 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\rescache
2015-09-12 15:17 - 2013-08-22 10:44 - 00560168 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-12 15:12 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-09-12 06:30 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-11 20:39 - 2014-06-01 11:31 - 00000000 ____D C:\temp
2015-09-09 03:46 - 2013-12-14 17:58 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-09 03:46 - 2012-07-26 03:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-09 03:45 - 2013-11-14 03:17 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-09 03:42 - 2013-12-12 21:55 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-26 18:37 - 2013-12-12 21:55 - 134753440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
 
==================== Files in the root of some directories =======
 
2015-09-16 14:27 - 2015-09-19 14:27 - 0000104 _____ () C:\Users\Patti\AppData\Roaming\WB.CFG
2014-07-04 17:09 - 2014-07-04 17:09 - 0591320 _____ (ClickMeIn Limited) C:\Users\Patti\AppData\Local\nss6104.tmp
2013-12-14 18:38 - 2013-12-14 18:38 - 0000057 _____ () C:\ProgramData\Ament.ini
 
Some files in TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\CreateToastShortcut.exe
C:\Users\Administrator\AppData\Local\Temp\CreateToastShortcutDll.dll
C:\Users\Administrator\AppData\Local\Temp\StartMenu.exe
C:\Users\Administrator\AppData\Local\Temp\TosNoRestart.exe
C:\Users\Patti\AppData\Local\Temp\1f0fb7c2d13cc0c07ff2ca40747bc03e_360tray.exe
C:\Users\Patti\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Patti\AppData\Local\Temp\Quarantine.exe
C:\Users\Patti\AppData\Local\Temp\setup.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-19 14:41
 
==================== End of FRST.txt ============================

Thanks for the logs which showed some issue so let’s start with clearing up some first and then see wgere we are.


Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

  • close all programs
  • double-click RogueKiller.exe - Windows 7: right-click the program and select Run as Administrator'
  • after it has completed it's prescan, click on Scan
  • click on the click on the “Registry” tab
  • make sure the following entries there are checked:


    [VT.Generic.36F] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> Found
    [VT.Generic.36F] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> Found
    [VT.Generic.36F] (X64) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> Found
    [VT.Generic.36F] (X86) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> Found
    [PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page :
    http://toshiba13.msn.com -> Found
    [PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
    http://toshiba13.msn.com -> Found
    [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
    http://toshiba13.msn.com -> Found
    [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
    http://toshiba13.msn.com -> Found

     

  • click on the click on the “Tasks” tab and place a checkmark next to these:


    [Suspicious.Path|VT.DealPly] %WINDIR%\Tasks\UpdateTask.job – C:\Users\Patti\AppData\Local\{8469B~1\UNINST~1.EXE (/Check) -> Found
    [Suspicious.Path] \Unimioanrruo – "C:\ProgramData\Unimioanrruo\1.0.5.1\mnuanvou.exe" ("/e=L3A9MTk1NTAxXi91PTY0YTk4ZDBkMzIzZjRiZTBiMmJiY2ZhMTFiOWEwMjJhXi9kPWNoZWFwY291cG9uYWxlcnQuY29tXi9uPUNPVVBeL2E9Q291cG9uQWxlcnReL3Q=") -> Found
    [Suspicious.Path|VT.DealPly] \UpdateTask – C:\Users\Patti\AppData\Local\{8469B~1\UNINST~1.EXE (/Check) -> Found

     

  • then press the Delete button and post the log it produces.

===================================================

Download zoek.exe to your Desktop:

Important: Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.
 

  • on Windows Vista, 7/8, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:

    createsrpoint;
    autoclean;
    emptyalltemp;
    emptyflash;
    emptyiecache;
    emptyffcache;
    ipconfig /flushdns;b
    
  • close any open programs.click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

Logs to include with next post:

RogueKiller fix log
zoek-results.log


Thanks

Satchfan

 

RogueKiller V10.10.6.0 [Sep 21 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com
 
Operating System : Windows 8.1 (6.3.9600) 64 bits version
Started in : Normal mode
User : Patti [Administrator]
Started from : C:\Users\Patti\Desktop\RogueKiller.exe
Mode : Delete – Date : 09/22/2015 14:30:05
 
¤¤¤ Processes : 0 ¤¤¤
 
¤¤¤ Registry : 8 ¤¤¤
[VT.Generic.36F] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> ERROR [0]
[VT.Generic.36F] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> ERROR [0]
[VT.Generic.36F] (X64) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> ERROR [0]
[VT.Generic.36F] (X86) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Windows\CurrentVersion\Run | pcreg : C:\Program Files\pcmax\service.exe [7] -> ERROR [2]
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Replaced (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> Replaced (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> Replaced (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1679494073-3026066304-2182815410-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> Replaced (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
 
¤¤¤ Tasks : 3 ¤¤¤
[Suspicious.Path|VT.DealPly] %WINDIR%\Tasks\UpdateTask.job – C:\Users\Patti\AppData\Local\{8469B~1\UNINST~1.EXE (/Check) -> ERROR [0]
[Suspicious.Path] \Unimioanrruo – "C:\ProgramData\Unimioanrruo\1.0.5.1\mnuanvou.exe" ("/e=L3A9MTk1NTAxXi91PTY0YTk4ZDBkMzIzZjRiZTBiMmJiY2ZhMTFiOWEwMjJhXi9kPWNoZWFwY291cG9uYWxlcnQuY29tXi9uPUNPVVBeL2E9Q291cG9uQWxlcnReL3Q=") -> Not selected
[Suspicious.Path|VT.DealPly] \UpdateTask – C:\Users\Patti\AppData\Local\{8469B~1\UNINST~1.EXE (/Check) -> ERROR [0]
 
¤¤¤ Files : 0 ¤¤¤
 
¤¤¤ Hosts File : 0 ¤¤¤
 
¤¤¤ Antirootkit : 0 (Driver: Not loaded [0x20]) ¤¤¤
 
¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] l9qemj8f.default : user_pref("browser.startup.homepage", "http://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_prgasst_15_39¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0CyE0EtAyCzyyEyDtBtCyD0D0D0CyEtN0D0Tzu0StCtAyDzytN1L2XzutAtFtCtDtFtCtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StByCtAtDtCzyzzyCtG0FyE0FtDtGyE0BtAtBtG0B0F0C0FtGyDtBtB0BzzzztD0EyB0BzzyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FtAyE0EyByDyD0AtG0AtD0FyEtGyEtCtC0DtGzyyB0D0EtG0A0AyCtD0CtCyE0B0AtBtAtB2QtN0A0LzuyE%26cr%3D1596817938%26a%3Dwny_prgasst_15_39%26os%3DWindows8.1"); -> Not selected
 
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABD075 +++++
— User —
[MBR] a84dd93b5b19931ceaddbccc47850486
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [SYSTEM] Basic data partition | Offset (sectors): 2048 | Size: 450 MB
1 - Basic data partition | Offset (sectors): 923648 | Size: 260 MB
2 - Basic data partition | Offset (sectors): 1456128 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 1718272 | Size: 702965 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1441390592 | Size: 350 MB
5 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1442107392 | Size: 11250 MB
User = LL1 … OK
User = LL2 … OK
 
+++++ PhysicalDrive1: HP Photosmart 6520 USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

I cannot download zoek, truied three websites.  Sure did get a bunch of junk though, black boxes all over the screen.  Just uninstalled the programs it installed.  So now what should I do?  Thanks.

The sites I downloaded it from put on a bunch of other stuff.  do you have a safe site I can download it from?  I was careful not to check yes to anything but it downloaded it anyway.  Is malwarebytes an antivirus or is Microsoft defender?
Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI