This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Running Scripts and Freezing Up

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Scan
  • Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
  • Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

Additional scan result of Farbar Recovery Scan Tool (x86) Version:07-11-2015
Ran by [removed] (2015-11-09 20:45:30)
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
Microsoft Windows XP Home Edition Service Pack 3 (X86) (2012-09-11 22:15:23)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2052111302-861567501-725345543-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
Guest (S-1-5-21-2052111302-861567501-725345543-501 - Limited - Enabled)
HelpAssistant (S-1-5-21-2052111302-861567501-725345543-1000 - Limited - Disabled)
Lew (S-1-5-21-2052111302-861567501-725345543-1004 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Lew
SUPPORT_388945a0 (S-1-5-21-2052111302-861567501-725345543-1002 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: avast! Antivirus (Enabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 19 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Apple Application Support (HKLM\…\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AT&T; Troubleshoot & Resolve (HKLM\…\ATT-AT&T; Troubleshoot & Resolve) (Version: 8.5.0.48 - AT&T;)
Avast Free Antivirus (HKLM\…\avast) (Version: 10.4.2233 - AVAST Software)
Bing Bar (HKLM\…\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bing Maps 3D (HKLM\…\{2D87E961-577B-492B-AD54-1368680FB9A7}) (Version: 4.0.903.16005 - Microsoft Corporation)
Bing Rewards Client Installer (Version: 16.0.345.0 - Microsoft Corporation) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 3.23 - Piriform)
Centricity DICOM Viewer (HKLM\…\Centricity DICOM Viewer) (Version: 3.1.4 - GE Healthcare IT)
Chinese Traditional Fonts Support For Adobe Reader X (HKLM\…\{AC76BA86-7AD7-2448-0000-A00000000003}) (Version: 10.0.0 - Adobe Systems Incorporated)
Citrix Online Launcher (HKLM\…\{E5F6D26D-E180-4547-A865-565EAB61000C}) (Version: 1.0.362 - Citrix)
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
DIRECTV Player (HKLM\…\{43D1B973-3D12-42ba-9E6E-56A8FEFF5250}) (Version: 8.0 - DIRECTV)
D-Link DFE-530TX+ (HKLM\…\InstallShield_{2D6A5BD9-FE4B-49CD-8D96-2C4746302A82}) (Version:  - D-Link)
D-Link DFE-530TX+ (Version:  - D-Link) Hidden
D-Link PCI Fast Ethernet Adapter (HKLM\…\VN_VUIns_Rhine_D-Link) (Version:  - )
Enhanced Multimedia Keyboard Solution (HKLM\…\KBD) (Version:  - )
ESET Online Scanner v3 (HKLM\…\ESET Online Scanner) (Version:  - )
Google Chrome (HKLM\…\Google Chrome) (Version: 46.0.2490.80 - Google Inc.)
Google Earth Plug-in (HKLM\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.15 - Google Inc.) Hidden
HitmanPro 3.7 (HKLM\…\HitmanPro37) (Version: 3.7.10.251 - SurfRight B.V.)
HP Deskjet 3050 J610 series Basic Device Software (HKLM\…\{0564C76B-8E1F-4157-8654-B0F9F308BEE9}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 3050 J610 series Help (HKLM\…\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)
HP Update (HKLM\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Internet Explorer (Enable DEP) (HKLM\…\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version:  - )
iSEEK AnswerWorks English Runtime (HKLM\…\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: [removed] - Vantage Linguistics)
Java 8 Update 65 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
McAfee Virtual Technician (HKLM\…\McAfee Virtual Technician) (Version: 7.7.0.366 - McAfee, Inc.)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 41.0.2 (x86 en-US) (HKLM\…\Mozilla Firefox 41.0.2 (x86 en-US)) (Version: 41.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 41.0.2.5765 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 6.0 Parser (HKLM\…\{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}) (Version: 6.10.1129.0 - Microsoft Corporation)
Nikon Message Center 2 (HKLM\…\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
Nikon Movie Editor (HKLM\…\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.3.0 - Nikon)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version:  - )
Picture Control Utility (HKLM\…\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.4.2 - Nikon)
Quicken 2012 (HKLM\…\{0A1E0BDA-5E8F-436d-8BE5-7E97C5CB899D}) (Version: 21.1.7.18 - Intuit)
QuickTime 7 (HKLM\…\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version:  - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Roxio Creator DE (HKLM\…\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.1 - )
SketchUp 8 (HKLM\…\{8EB62C87-AAA6-4850-A5BC-64155884B973}) (Version: 3.0.16846 - Trimble Navigation Limited)
Spell Checker For OE 2.1 (HKLM\…\Spell Checker For OE 2.1) (Version:  - )
Spotify (HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\Spotify) (Version: 1.0.13.108.gcd94e7db - Spotify AB)
Spybot - Search & Destroy (HKLM\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.0.12 - Safer-Networking Ltd.)
TaxACT 2012 - 1040 Edition (HKLM\…\TaxACT 2012 - 1040 Edition) (Version:  - 2nd Story Software, Inc.)
TaxACT 2012 Georgia (HKLM\…\TaxACT 2012 Georgia) (Version:  - 2nd Story Software, Inc.)
TaxACT 2013 - 1040 Edition (HKLM\…\TaxACT 2013 - 1040 Edition) (Version:  - TaxACT, Inc.)
TaxACT 2013 Georgia (HKLM\…\TaxACT 2013 Georgia) (Version:  - TaxACT, Inc.)
TaxACT 2014 - 1040 Edition (HKLM\…\TaxACT 2014 - 1040 Edition) (Version: 1.00 - TaxACT, Inc.)
TaxACT 2014 Georgia (HKLM\…\TaxACT 2014 Georgia) (Version: 1.01 - TaxACT, Inc.)
Trend Micro RUBotted 2.0 Beta (HKLM\…\{54D4EAF5-4C80-4878-B4AC-5AE454A02E3C}_is1) (Version: 2.0.0.1034 - Trend Micro, Inc.)
ViewNX 2 (HKLM\…\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.3.0 - Nikon)
VIMGenSetup (HKLM\…\{70615FBA-A23A-489B-AA6C-858186D8D0BA}) (Version: 1.0.0 - trick77)
WD SES Driver Setup (Version: 1.0.0 - Western Digital) Hidden
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\KB892130) (Version:  - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows PowerShell(TM) 1.0 (HKLM\…\KB926139-v2) (Version: 2 - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
WOT for Internet Explorer (HKLM\…\{DCAEC601-735C-41AE-B84F-D792F09FB7D1}) (Version: 12.8.2.0 - WOT Services Oy)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2052111302-861567501-725345543-1004_Classes\CLSID\{0C03DEC4-B374-44DF-9B0D-38BD942080C4}\InprocServer32 -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\COPPXP_filter.ax ()
CustomCLSID: HKU\S-1-5-21-2052111302-861567501-725345543-1004_Classes\CLSID\{7a434a49-f21e-5011-8f99-aa7578492b9c}\InprocServer32 -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll (NDS)
 
==================== Restore Points =========================
 
12-08-2015 05:46:39 System Checkpoint
12-08-2015 07:44:28 Software Distribution Service 3.0
13-08-2015 07:53:04 System Checkpoint
14-08-2015 08:14:49 System Checkpoint
15-08-2015 09:13:54 System Checkpoint
16-08-2015 10:29:52 System Checkpoint
17-08-2015 10:37:35 System Checkpoint
18-08-2015 11:07:55 System Checkpoint
19-08-2015 12:07:29 System Checkpoint
20-08-2015 12:48:25 System Checkpoint
21-08-2015 13:36:56 System Checkpoint
22-08-2015 14:25:01 System Checkpoint
23-08-2015 15:25:01 System Checkpoint
24-08-2015 16:56:42 System Checkpoint
25-08-2015 17:40:20 System Checkpoint
26-08-2015 18:28:23 System Checkpoint
27-08-2015 19:19:51 System Checkpoint
28-08-2015 19:51:36 System Checkpoint
29-08-2015 20:26:46 System Checkpoint
30-08-2015 21:26:45 System Checkpoint
31-08-2015 14:06:47 Removed HP Deskjet 3050 J610 series Basic Device Software
31-08-2015 14:08:10 Removed HP Deskjet 3050 J610 series Basic Device Software
01-09-2015 09:47:19 avast! antivirus system restore point
01-09-2015 09:48:51 Installed Windows XP Wdf01009.
01-09-2015 10:01:32 Removed HP Update.
01-09-2015 10:01:41 Installed HP Update.
02-09-2015 11:48:34 Removed HP Deskjet 3050 J610 series Basic Device Software
02-09-2015 11:49:33 Removed HP Deskjet 3050 J610 series Help
02-09-2015 11:50:13 Removed HP Deskjet 3050 J610 series Product Improvement Study
03-09-2015 13:34:37 System Checkpoint
04-09-2015 14:33:42 System Checkpoint
05-09-2015 15:33:37 System Checkpoint
06-09-2015 15:58:05 System Checkpoint
07-09-2015 16:14:53 System Checkpoint
08-09-2015 17:14:57 System Checkpoint
09-09-2015 17:52:33 System Checkpoint
09-09-2015 18:41:24 Software Distribution Service 3.0
10-09-2015 19:23:36 System Checkpoint
11-09-2015 20:03:55 System Checkpoint
12-09-2015 21:00:05 System Checkpoint
13-09-2015 21:57:37 System Checkpoint
14-09-2015 22:29:13 System Checkpoint
15-09-2015 23:25:29 System Checkpoint
17-09-2015 00:05:39 System Checkpoint
17-09-2015 11:31:34 WinThruster Thu, Sep 17, 15  12:31
18-09-2015 11:34:01 System Checkpoint
19-09-2015 11:34:15 System Checkpoint
20-09-2015 11:39:14 System Checkpoint
21-09-2015 12:38:06 System Checkpoint
22-09-2015 14:10:44 System Checkpoint
23-09-2015 14:17:52 System Checkpoint
24-09-2015 07:37:33 avast! antivirus system restore point
24-09-2015 07:38:49 Installed Windows XP Wdf01009.
25-09-2015 08:37:27 System Checkpoint
26-09-2015 09:41:36 System Checkpoint
27-09-2015 10:21:22 System Checkpoint
28-09-2015 10:50:57 System Checkpoint
29-09-2015 12:31:14 System Checkpoint
30-09-2015 14:44:09 System Checkpoint
01-10-2015 14:59:58 System Checkpoint
02-10-2015 15:57:00 System Checkpoint
03-10-2015 14:00:56 Installed "ViewNX 2"
04-10-2015 16:58:08 System Checkpoint
05-10-2015 17:37:09 System Checkpoint
06-10-2015 17:43:39 System Checkpoint
07-10-2015 18:43:41 System Checkpoint
08-10-2015 18:50:07 System Checkpoint
09-10-2015 18:52:49 System Checkpoint
10-10-2015 19:28:25 System Checkpoint
11-10-2015 19:31:04 System Checkpoint
12-10-2015 19:47:29 System Checkpoint
13-10-2015 20:19:02 System Checkpoint
14-10-2015 19:43:52 Software Distribution Service 3.0
15-10-2015 19:53:43 System Checkpoint
16-10-2015 19:54:46 System Checkpoint
17-10-2015 20:08:07 System Checkpoint
18-10-2015 20:19:38 System Checkpoint
19-10-2015 21:11:14 System Checkpoint
20-10-2015 21:18:51 System Checkpoint
21-10-2015 21:58:30 System Checkpoint
22-10-2015 22:58:31 System Checkpoint
23-10-2015 23:16:33 System Checkpoint
24-10-2015 23:30:18 System Checkpoint
26-10-2015 00:28:27 System Checkpoint
27-10-2015 00:54:20 System Checkpoint
28-10-2015 01:54:22 System Checkpoint
29-10-2015 02:54:21 System Checkpoint
30-10-2015 03:26:28 System Checkpoint
31-10-2015 04:26:28 System Checkpoint
01-11-2015 04:30:22 System Checkpoint
02-11-2015 05:30:22 System Checkpoint
03-11-2015 06:12:27 System Checkpoint
04-11-2015 03:00:14 Software Distribution Service 3.0
05-11-2015 03:44:22 System Checkpoint
05-11-2015 18:22:49 Printer Driver GIRDAC Installed
06-11-2015 18:25:16 System Checkpoint
07-11-2015 19:25:16 System Checkpoint
08-11-2015 20:25:10 System Checkpoint
09-11-2015 12:47:39 Checkpoint by HitmanPro
09-11-2015 12:48:37 Checkpoint by HitmanPro
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2014-04-20 08:25 - 2014-03-05 18:24 - 00566098 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1  localhost
127.0.0.1  m.fr.a2dfp.net
127.0.0.1  ad.a8.net
127.0.0.1  asy.a8ww.net
127.0.0.1  abcstats.com
127.0.0.1  a.abv.bg
127.0.0.1  adserver.abv.bg
127.0.0.1  adv.abv.bg
127.0.0.1  bimg.abv.bg
127.0.0.1  ca.abv.bg
127.0.0.1  www2.a-counter.kiev.ua
127.0.0.1  track.acclaimnetwork.com
127.0.0.1  accuserveadsystem.com
127.0.0.1  www.accuserveadsystem.com
127.0.0.1  achmedia.com
127.0.0.1  csh.actiondesk.com
127.0.0.1  www.activemeter.com #[Tracking.Cookie]
127.0.0.1  ads.activepower.net
127.0.0.1  app.activetrail.com
127.0.0.1  stat.active24stats.nl #[Tracking.Cookie]
127.0.0.1  cms.ad2click.nl
127.0.0.1  ad2games.com
127.0.0.1  ads.ad2games.com
127.0.0.1  content.ad20.net
127.0.0.1  core.ad20.net
127.0.0.1  banner.ad.nu
127.0.0.1  cl21.v4.adaction.se
127.0.0.1  adadvisor.net
127.0.0.1  tag1.adaptiveads.com
127.0.0.1  www.adbanner.ro
 
There are 12420 more lines.
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job.bak => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\CandyUpdater.job.bak => C:\Documents and Settings\Lew\Local Settings\Application Data\ArcadeCandy\candyUpdater.exe
Task: C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job.bak => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\WINDOWS\Tasks\FixCleaner Scan.job.bak => C:\Program Files\FixCleaner\FixCleaner.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{90A41A15-AAF1-4707-8558-2318913D9F39}.job => C:\WINDOWS\system32\msfeedssync.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-03-19 09:43 - 2015-09-24 07:37 - 00103376 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-03-19 09:43 - 2015-09-24 07:37 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-11-09 09:17 - 2015-11-09 09:17 - 02990592 _____ () C:\Program Files\AVAST Software\Avast\defs\15110901\algo.dll
2015-11-09 16:51 - 2015-11-09 16:51 - 02990592 _____ () C:\Program Files\AVAST Software\Avast\defs\15110902\algo.dll
2012-11-24 14:32 - 2012-11-13 14:06 - 00108960 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2012-11-24 14:32 - 2012-11-13 14:06 - 00416160 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
2012-11-24 14:32 - 2012-11-13 14:06 - 00158624 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2012-11-24 14:32 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll
2012-11-24 14:32 - 2012-11-13 14:06 - 00528288 _____ () C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl
2014-01-07 06:40 - 2015-09-24 07:37 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
 
There are 7849 more sites.
 
IE trusted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\whatthetech.com -> hxxps://www.whatthetech.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\123simsen.com -> www.123simsen.com
 
There are 7848 more sites.
 
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\123simsen.com -> www.123simsen.com
 
There are 7849 more sites.
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2052111302-861567501-725345543-1004\Control Panel\Desktop\\Wallpaper -> 
HKU\S-1-5-21-2052111302-861567501-725345543-500\Control Panel\Desktop\\Wallpaper -> (None)
DNS Servers: 192.168.1.254
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: RTHDCPL => RTHDCPL.EXE
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Lew\Application Data\Spotify\spotify.exe] => Enabled:Spotify
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot-S&D; 2 Tray Icon
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\dpvsetup.exe] => Enabled:Microsoft DirectPlay Voice Test
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe] => Enabled:WebKit
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Lew\Local Settings\temp\2eat48h\CloudBackupSetup] => Enabled:CloudBackupSetup (in)
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\rundll32.exe] => Enabled:Run a DLL as an App
StandardProfile\AuthorizedApplications: [C:\Spotify.exe] => Enabled:Spotify
StandardProfile\AuthorizedApplications: [C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe] => :LocalSubNet:Enabled:HP Device Setup
StandardProfile\AuthorizedApplications: [C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe] => :LocalSubNet:Enabled:HP Network Communicator
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
DomainProfile\GloballyOpenPorts: [139:TCP] => Enabled:@xpsp2res.dll,-22004
DomainProfile\GloballyOpenPorts: [445:TCP] => Enabled:@xpsp2res.dll,-22005
DomainProfile\GloballyOpenPorts: [137:UDP] => Enabled:@xpsp2res.dll,-22001
DomainProfile\GloballyOpenPorts: [138:UDP] => Enabled:@xpsp2res.dll,-22002
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22007
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22008
StandardProfile\GloballyOpenPorts: [139:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22004
StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22005
StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22001
StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22002
 
==================== Faulty Device Manager Devices =============
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: LSI PCI-SV92PP Soft Modem
Description: LSI PCI-SV92PP Soft Modem
Class Guid: {4D36E96D-E325-11CE-BFC1-08002BE10318}
Manufacturer: LSI
Service: Modem
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: NVIDIA nForce Networking Controller
Description: NVIDIA nForce Networking Controller
Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318}
Manufacturer: NVIDIA
Service: NVENETFD
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/09/2015 12:18:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application mbam.exe, version 1.0.1.711, faulting module msvcr100.dll, version 10.0.40219.325, fault address 0x0008d6fd.
Processing media-specific event for [mbam.exe!ws!]
 
Error: (11/09/2015 11:22:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 41.0.2.5765, faulting module mozglue.dll, version 41.0.2.5765, fault address 0x0000ec91.
Processing media-specific event for [plugin-container.exe!ws!]
 
Error: (11/06/2015 08:12:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 41.0.2.5765, faulting module mozglue.dll, version 41.0.2.5765, fault address 0x0000ec91.
Processing media-specific event for [plugin-container.exe!ws!]
 
Error: (11/02/2015 08:21:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 41.0.2.5765, faulting module mozglue.dll, version 41.0.2.5765, fault address 0x0000ec91.
Processing media-specific event for [plugin-container.exe!ws!]
 
Error: (10/31/2015 09:20:10 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module wot.dll, version 12.8.2.0, fault address 0x00017fe0.
Processing media-specific event for [iexplore.exe!ws!]
 
Error: (10/25/2015 10:22:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (10/25/2015 10:22:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (10/25/2015 10:22:00 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (10/25/2015 10:06:45 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (10/24/2015 09:08:35 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module wot.dll, version 12.8.2.0, fault address 0x00017fe0.
Processing media-specific event for [iexplore.exe!ws!]
 
 
System errors:
=============
Error: (11/09/2015 12:51:00 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The HitmanPro 3.7 Crusader (Boot) service terminated with service-specific error 0 (0x0).
 
Error: (11/09/2015 12:50:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error: 
%%1053
 
Error: (11/09/2015 12:50:55 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D; 2 Security Center Service service to connect.
 
Error: (11/09/2015 12:50:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Trend Micro RUBotted Service service failed to start due to the following error: 
%%1053
 
Error: (11/09/2015 12:50:55 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the Trend Micro RUBotted Service service to connect.
 
Error: (11/09/2015 12:33:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error: 
%%1053
 
Error: (11/09/2015 12:33:56 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D; 2 Security Center Service service to connect.
 
Error: (11/09/2015 12:33:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Trend Micro RUBotted Service service failed to start due to the following error: 
%%1053
 
Error: (11/09/2015 12:33:56 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the Trend Micro RUBotted Service service to connect.
 
Error: (11/09/2015 12:24:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error: 
%%1053
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ 64 Processor 3800+
Percentage of memory in use: 59%
Total physical RAM: 958.48 MB
Available physical RAM: 388.58 MB
Total Virtual: 2310.54 MB
Available Virtual: 1744.32 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:465.75 GB) (Free:424.41 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: (Desktop Favorite) (CDROM) (Total:0.2 GB) (Free:0 GB) CDFS
Drive i: (My Passport) (Fixed) (Total:465.73 GB) (Free:352.99 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: 8F59DC31)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 465.7 GB) (Disk ID: 0004A183)
Partition 1: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-11-2015
Ran by [removed] (administrator) on LEW-0CCC0E88CE3 (09-11-2015 20:44:25)
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
[removed]
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Hewlett-Packard Company) C:\HP\KBD\kbd.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Alcatel-Lucent) C:\Program Files\ATT\8.5.0.48\ma\bin\pcTrayApp.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Spotify Ltd) C:\Documents and Settings\Lew\Application Data\Spotify\SpotifyWebHelper.exe
(Microsoft® Corporation) C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Outlook Express\msimn.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [KBD] => C:\HP\KBD\KBD.EXE [61440 2005-02-02] (Hewlett-Packard Company)
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-06] (AVAST Software)
HKLM\…\Run: [ATT_McciTrayApp] => C:\Program Files\ATT\8.5.0.48\ma\bin\pcTrayApp.exe [2044416 2015-01-22] (Alcatel-Lucent)
HKLM\…\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\…\Run: [TkBellExe] => C:\program files\real\realplayer\update\realsched.exe [295512 2013-09-07] (RealNetworks, Inc.)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKLM\…\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\Run: [Spotify Web Helper] => C:\Documents and Settings\Lew\Application Data\Spotify\SpotifyWebHelper.exe [2023480 2015-07-27] (Spotify Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-09-24] (AVAST Software)
Startup: C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK [2013-07-09]
ShortcutTarget: WKCALREM.LNK -> C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
BootExecute: autocheck autochk * bootdelete
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{2E5072BA-3DCD-43F1-A347-7B3E0450AF88}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: [S-1-5-21-2052111302-861567501-725345543-500] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2052111302-861567501-725345543-1004 -> {1FF59F01-1B18-4F35-8C03-65E1FEE35225} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei;=utf-8&ilc;=12&type;=531140&p;={searchTerms}
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-10-23] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-09-01] (AVAST Software)
BHO: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files\WOT\WOT.dll [2012-08-02] ()
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-23] (Oracle Corporation)
Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll [2012-08-02] ()
Toolbar: HKU\S-1-5-21-2052111302-861567501-725345543-1004 -> WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll [2012-08-02] ()
Toolbar: HKU\S-1-5-21-2052111302-861567501-725345543-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-06-08] (Microsoft Corporation)
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll [2012-08-02] ()
 
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Lew\Application Data\Mozilla\Firefox\Profiles\7an7alhq.default-1439150236187
FF DefaultSearchEngine: Yahoo!
FF DefaultSearchEngine.US: Yahoo!
FF SelectedSearchEngine: Yahoo!
FF Homepage: hxxps://search.yahoo.com/?type=531140&fr;=spigot-yhp-ff
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-17] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-23] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-23] (Oracle Corporation)
FF Plugin: @mcafee.com/MVT -> C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll [2015-08-18] (McAfee, Inc.)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files\Virtual Earth 3D\ [] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @Motive.com/NpMotive,version=1.1 -> C:\Program Files\ATT\8.5.0.48\ma\bin\npMotive.dll [2015-01-22] (Alcatel-Lucent)
FF Plugin: @Motive.com/npMotiveRequest,version=1.1 -> C:\Program Files\Common Files\Motive\npMotiveRequest.dll [2014-08-27] (Alcatel-Lucent)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll [2013-09-07] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll [2013-09-07] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2052111302-861567501-725345543-1004: @citrixonline.com/appdetectorplugin -> C:\Documents and Settings\Lew\Local Settings\Application Data\Citrix\Plugins\104\npappdetector.dll [2015-11-02] (Citrix Online)
FF Plugin HKU\S-1-5-21-2052111302-861567501-725345543-1004: @nds.com/PCShowPlugin -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPCShowPlugin.dll [No File]
FF Plugin HKU\S-1-5-21-2052111302-861567501-725345543-1004: @nds.com/PlayerPlugin -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll [2012-10-15] (NDS)
FF Plugin HKU\S-1-5-21-2052111302-861567501-725345543-1004: NDS.com/PlayerPlugin -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll [2012-10-15] (NDS)
FF Extension: Motive Extension - C:\Program Files\Mozilla Firefox\browser\extensions\[removed] [2015-09-24] [not signed]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-09-19] [not signed]
FF HKLM\…\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-07] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-09-24] [not signed]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (RealDownloader) - C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-08-20]
CHR Extension: (Motive Extension) - C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kofilaoejfjbjfopdnckahcidedndnln [2015-11-09]
CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-09]
CHR HKLM\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-19]
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\…\Chrome\Extension: [kofilaoejfjbjfopdnckahcidedndnln] - C:\Program Files\Common Files\Motive\extensions\MotiveRequest.crx [2015-09-24]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
S4 AT&T; Troubleshoot & Resolve; C:\Program Files\ATT\8.5.0.48\ma\bin\MAHostService.exe [321024 2015-01-22] (Alcatel-Lucent) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-24] (AVAST Software)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [106248 2015-11-09] (SurfRight B.V.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
S4 pcCMService; C:\Program Files\Common Files\Motive\pcCMService.exe [369152 2014-09-10] (Alcatel-Lucent) [File not signed]
S4 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S2 RUBotSrv; C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe [443416 2013-07-25] (Trend Micro Inc.)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
S3 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-09-24] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-09-24] (AVAST Software)
R1 AswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-09-24] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-09-24] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [794952 2015-11-06] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [435464 2015-11-06] (AVAST Software)
S3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [157888 2015-09-24] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-09-24] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-09-24] (AVAST Software)
R3 FETNDISB; C:\WINDOWS\System32\DRIVERS\dlkfet5b.sys [43008 2007-07-13] (D-Link                              )
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [114904 2015-11-09] (Malwarebytes Corporation)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [34176 2006-03-03] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13056 2006-03-03] (NVIDIA Corporation)
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-11-09 20:43 - 2015-11-09 20:44 - 00000000 ____D C:\FRST
2015-11-09 12:48 - 2015-11-09 12:48 - 00012956 _____ C:\WINDOWS\system32\.crusader
2015-11-09 12:43 - 2015-11-09 12:43 - 00001610 _____ C:\Documents and Settings\All Users\Desktop\HitmanPro.lnk
2015-11-09 12:43 - 2015-11-09 12:43 - 00000000 ____D C:\Program Files\HitmanPro
2015-11-09 12:43 - 2015-11-09 12:43 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\HitmanPro
2015-11-09 12:42 - 2015-11-09 12:49 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HitmanPro
2015-11-09 12:28 - 2015-11-09 12:39 - 00002352 _____ C:\WINDOWS\KB842773.log
2015-11-09 12:21 - 2015-11-09 12:22 - 00002669 _____ C:\AdwCleaner[S9].txt
2015-11-09 12:21 - 2015-11-09 12:21 - 00002551 _____ C:\AdwCleaner[R15].txt
2015-11-09 12:20 - 2015-11-09 12:20 - 00002490 _____ C:\AdwCleaner[R14].txt
2015-11-06 08:48 - 2015-11-06 08:48 - 00000680 _____ C:\Documents and Settings\Lew\My Documents\cc_20151106_084808.reg
2015-11-05 11:11 - 2015-11-05 11:11 - 00001082 _____ C:\Documents and Settings\Lew\My Documents\cc_20151105_111147.reg
2015-11-02 22:45 - 2015-11-02 22:45 - 00000000 ____D C:\Program Files\McAfee
2015-11-02 22:45 - 2015-11-02 22:45 - 00000000 ____D C:\Documents and Settings\Lew\Application Data\McAfee
2015-11-02 22:45 - 2015-11-02 22:45 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
2015-11-02 21:14 - 2015-11-02 21:14 - 00004526 _____ C:\Documents and Settings\Lew\My Documents\cc_20151102_211453.reg
2015-11-02 21:01 - 2015-11-02 21:01 - 00000000 ____D C:\Documents and Settings\Lew\Local Settings\Application Data\Citrix
2015-10-29 20:20 - 2015-10-29 20:20 - 00002487 _____ C:\AdwCleaner[S8].txt
2015-10-29 20:20 - 2015-10-29 20:20 - 00002369 _____ C:\AdwCleaner[R13].txt
2015-10-23 08:27 - 2015-10-23 08:27 - 00002816 _____ C:\AdwCleaner[S7].txt
2015-10-23 08:26 - 2015-10-23 08:26 - 00002690 _____ C:\AdwCleaner[R12].txt
2015-10-23 08:10 - 2015-10-23 08:10 - 00000000 ____D C:\Program Files\Common Files\Java
2015-10-18 09:21 - 2015-10-18 09:21 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Trend Micro
2015-10-16 08:49 - 2015-10-16 08:52 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-10-15 11:40 - 2015-10-15 11:45 - 11534454 _____ C:\Documents and Settings\Lew\My Documents\Boat Lift.bmp
2015-10-13 20:27 - 2015-10-17 02:27 - 03996360 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-11-09 20:45 - 2014-03-26 21:48 - 00000000 ____D C:\Documents and Settings\Lew\Local Settings\temp
2015-11-09 20:38 - 2013-09-13 07:15 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-11-09 20:31 - 2015-09-19 10:17 - 00000282 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
2015-11-09 20:31 - 2015-09-19 10:17 - 00000274 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
2015-11-09 20:31 - 2014-03-23 11:07 - 00000218 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-11-09 20:31 - 2013-07-10 09:57 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-09 20:31 - 2012-09-12 13:58 - 00000274 _____ C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
2015-11-09 20:31 - 2012-09-11 19:49 - 00043531 _____ C:\WINDOWS\system32\nvapps.xml
2015-11-09 20:31 - 2006-02-28 07:00 - 00012598 _____ C:\WINDOWS\system32\wpa.dbl
2015-11-09 20:27 - 2012-09-12 13:50 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-09 19:57 - 2013-07-10 09:57 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-09 19:10 - 2012-09-11 17:18 - 00000178 ___SH C:\Documents and Settings\Lew\ntuser.ini
2015-11-09 16:27 - 2015-07-29 19:38 - 00032534 _____ C:\WINDOWS\SchedLgU.Txt
2015-11-09 13:09 - 2014-05-01 10:43 - 01410380 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-09 12:50 - 2012-09-11 17:18 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-09 12:50 - 2012-09-11 10:34 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-11-09 12:50 - 2012-09-11 10:34 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-11-09 12:49 - 2012-11-24 14:32 - 00524288 _____ C:\WINDOWS\system32\config\SpybotSD.evt
2015-11-09 11:31 - 2014-06-25 13:18 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-09 10:55 - 2014-01-08 08:41 - 00000418 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{90A41A15-AAF1-4707-8558-2318913D9F39}.job
2015-11-09 10:41 - 2012-11-24 14:32 - 00000446 _____ C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
2015-11-09 10:41 - 2012-09-11 17:18 - 00000000 ____D C:\Documents and Settings\Lew
2015-11-08 15:00 - 2014-03-23 11:07 - 00000212 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2015-11-07 13:49 - 2012-09-12 13:58 - 00000282 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
2015-11-06 15:06 - 2012-09-14 16:42 - 00015114 _____ C:\Documents and Settings\Lew\Application Data\wklnhst.dat
2015-11-06 14:47 - 2013-07-10 09:57 - 00794952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2015-11-06 14:47 - 2013-07-10 09:57 - 00435464 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2015-11-05 18:22 - 2012-09-11 17:18 - 00000000 __SHD C:\Documents and Settings\LocalService
2015-11-05 18:22 - 2012-09-11 17:16 - 00000000 __SHD C:\Documents and Settings\NetworkService
2015-11-05 11:15 - 2014-11-19 13:34 - 00000675 _____ C:\Documents and Settings\Lew\Desktop\Grocery List.txt
2015-11-04 00:30 - 2012-11-24 14:32 - 00000616 _____ C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2015-11-03 09:31 - 2012-09-11 17:13 - 00023392 _____ C:\WINDOWS\system32\nscompat.tlb
2015-11-03 09:31 - 2012-09-11 17:13 - 00016832 _____ C:\WINDOWS\system32\amcompat.tlb
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\WindowsShell.Manifest
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\system32\wuaucpl.cpl.manifest
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\system32\sapi.cpl.manifest
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\system32\nwc.cpl.manifest
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\system32\ncpa.cpl.manifest
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\system32\cdplayer.exe.manifest
2015-11-02 22:45 - 2012-09-12 13:15 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\McAfee
2015-11-02 20:37 - 2015-06-13 14:30 - 00000000 ____D C:\AdwCleaner
2015-11-02 19:40 - 2012-09-12 11:19 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2603381$
2015-11-02 08:26 - 2012-09-11 10:32 - 00603070 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-02 07:44 - 2012-09-24 10:40 - 00000235 _____ C:\Documents and Settings\Lew\Desktop\The Brunswick News - Home Page.url
2015-10-31 08:50 - 2014-08-27 06:53 - 00000000 ____D C:\Documents and Settings\Lew\Desktop\1938 Ford Woody   Mecum Auctions_files
2015-10-30 08:22 - 2014-02-15 09:54 - 00000352 _____ C:\Documents and Settings\Lew\Desktop\7-Day Forecast for Hampton Point.url
2015-10-28 10:30 - 2013-12-08 12:20 - 00000272 _____ C:\Documents and Settings\Lew\Desktop\Lost Atlanta The Way We Were.url
2015-10-27 17:31 - 2012-11-16 16:07 - 00000241 _____ C:\Documents and Settings\Lew\Desktop\craigslist Brunswick, GA.url
2015-10-26 13:57 - 2012-09-11 10:30 - 00000360 ___SH C:\boot.ini
2015-10-25 09:07 - 2013-09-04 16:08 - 00000000 ____D C:\Documents and Settings\Lew\My Documents\Capital One Statements
2015-10-25 09:02 - 2013-07-25 10:02 - 00000000 ____D C:\Documents and Settings\Lew\My Documents\GA Power Bills
2015-10-25 08:57 - 2013-07-04 08:52 - 00000000 ____D C:\Documents and Settings\Lew\My Documents\JWSC Statements
2015-10-23 08:39 - 2013-01-25 12:27 - 00001621 _____ C:\Documents and Settings\Lew\Desktop\Central Modern High-Spec En-suite in London.url
2015-10-23 08:36 - 2012-12-06 09:35 - 00000773 _____ C:\Documents and Settings\Lew\Desktop\Travel News You Can Use.url
2015-10-23 08:20 - 2015-03-03 19:18 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-10-23 08:20 - 2014-08-08 14:41 - 00000000 ____D C:\Program Files\Java
2015-10-23 08:09 - 2015-09-04 17:07 - 00000000 ____D C:\Documents and Settings\Lew\.oracle_jre_usage
2015-10-23 08:09 - 2015-03-03 19:18 - 00146432 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2015-10-23 08:09 - 2015-03-03 19:18 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2015-10-19 08:39 - 2013-12-27 17:04 - 00000253 _____ C:\Documents and Settings\Lew\Desktop\Bible Study Tools Online - Verses, Commentaries, Concordances, Verses, Parallel Versions.url
2015-10-18 14:08 - 2014-02-21 13:45 - 00000752 _____ C:\Documents and Settings\Lew\Desktop\Invisible Mask - Clear Bra Paint Protection,.url
2015-10-18 14:04 - 2015-03-17 18:13 - 00000724 _____ C:\Documents and Settings\Lew\Desktop\Mozilla Firefox.lnk
2015-10-18 10:34 - 2014-08-25 18:43 - 00000000 ____D C:\Documents and Settings\Lew\Local Settings\Application Data\Adobe
2015-10-18 10:34 - 2012-09-12 13:50 - 00780488 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-10-18 10:34 - 2012-09-12 13:50 - 00142536 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-10-18 09:32 - 2012-09-12 13:08 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB970430$
2015-10-18 08:55 - 2015-08-28 08:29 - 00000000 ____D C:\Program Files\ATT
2015-10-17 11:16 - 2015-03-17 18:13 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-10-17 09:18 - 2015-01-06 17:21 - 00000000 ____D C:\Documents and Settings\Lew\Desktop\Carol
2015-10-14 19:53 - 2013-08-08 02:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-10-14 19:44 - 2012-09-12 11:21 - 141105520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
 
==================== Files in the root of some directories =======
 
2015-10-03 14:06 - 2015-10-03 14:06 - 0000268 ___RH () C:\Documents and Settings\Lew\Application Data\Hybrid Basic
2015-10-03 14:19 - 2015-10-03 14:19 - 0000268 ___RH () C:\Documents and Settings\Lew\Application Data\Hybrid Chords
2015-10-03 14:06 - 2015-10-03 14:06 - 0000268 ___RH () C:\Documents and Settings\Lew\Application Data\Hybrid Morph
2014-03-25 10:11 - 2014-03-25 10:11 - 0000041 _____ () C:\Documents and Settings\Lew\Application Data\WB.CFG
2012-09-14 16:42 - 2015-11-06 15:06 - 0015114 _____ () C:\Documents and Settings\Lew\Application Data\wklnhst.dat
2012-09-20 15:50 - 2015-01-06 21:17 - 0133120 _____ () C:\Documents and Settings\Lew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== End of FRST.txt ============================
Running from C:\Documents and Settings\[removed]\My Documents\Downloads

It's best we move Farbar's to desktop.

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
Task: C:\WINDOWS\Tasks\CandyUpdater.job.bak => C:\Documents and Settings\Lew\Local Settings\Application Data\ArcadeCandy\candyUpdater.exe
URLSearchHook: [S-1-5-21-2052111302-861567501-725345543-500] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2052111302-861567501-725345543-1004 -> {1FF59F01-1B18-4F35-8C03-65E1FEE35225} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=531140&p={searchTerms}
Toolbar: HKU\S-1-5-21-2052111302-861567501-725345543-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF Homepage: hxxps://search.yahoo.com/?type=531140&fr=spigot-yhp-ff
FF Plugin HKU\S-1-5-21-2052111302-861567501-725345543-1004: @nds.com/PCShowPlugin -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPCShowPlugin.dll [No File]
EmptyTemp:
Hosts:
End


Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


~~~~~~~~~~~~~~`

All tools that I have you download should be placed on the desktop unless otherwise stated. If you are familiar with how to save files to the desktop then you can skip this step.

Since you are continuing with this step then I assume you are unfamiliar with saving files to your desktop. As a result it's easiest if you configure your browser(s) to download any tools to the desktop by default. Please use the appropriate instructions below depending on the browser you are using.
[external image: Chrome.JPG]Google Chrome - Click the "Customize and control Google Chrome" button in the upper right-corner of the browser.[external image: Settings.JPG] Choose Settings. at the bottom of the screen click the
"Show advanced settings…" link. Scroll down to find the Downloads section and click the Change… button. Select your desktop and click OK.
[external image: Firefox.JPG]Mozilla Firefox - Click the "Open Menu" button in the upper right-corner of the browser. [external image: Settings.JPG] Choose Options. In the downloads section, click the Browse button, click on the Desktop folder
and the click the "Select Folder" button. Click OK to get out of the Options menu.
[external image: IE.jpg]Internet Explorer - Click the Tools menu in the upper right-corner of the browser. [external image: Tools.JPG] Select View downloads. Select the Options link in the lower left of the window. Click Browse and
select the Desktop and then choose the Select Folder button. Click OK to get out of the download options screen and then click Close to get out of the View Downloads screen.
NOTE: IE8 Does not support changing download locations in this manner. You will need to download the tool(s) to the default folder, usually Downloads, then copy them to the desktop.






[external image: bullseye_zpse9eaf36e.gif]Malwarebytes Anti-Rootkit
  • Download Malwarebytes Anti-Rootkit
  • Once the file has been downloaded, right click on the downloaded file and select the Extract all menu option.
  • Follow the instructions to extract the ZIP file to a folder called mbar-versionnumber on your desktop.
  • Once the ZIP file has been extracted, open the folder and when that folder opens, double-click on the mbar folder.
  • Double-click on the mbar.exe file to launch Malwarebytes Anti-Rootkit.
  • After you double-click on the mbar.exe file, you may receive a User Account Control (UAC) message if you are sure you wish to allow the program to run. Please allow to start Malwarebytes Anti-Rootkit correctly.
  • Malwarebytes Anti-Rootkit will now install necessary drivers that are required for the program to operate correctly.
  • If you receive a DDA driver message like could not load DDA driver, click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer and will start automatically.
[external image: MBAMAnti-Rootkit1_zps4613be8c.png]
  • Please click by the introduction screen on the Next button to continue.
[external image: MBAMAnti-Rootkit2update_zpsf85fca28.png]
  • Next you will see the Update Database screen.
  • Click on the Update button so Malwarebytes Anti-Rootkit can download the latest definition updates.
[external image: MBAMAnti-Rootkitupdatecomplete_zpscf9f4c]
  • When the update has finished, click on the Next button.
[external image: MBAMAnti-Rootkitscan_zps9b346fe7.png]
  • Next you can select some basic scanning options. Make sure the Drivers, Sectors, and System scan targets are selected before you click on the Scan button.
  • Malwarebytes Anti-Rootkit will now start scanning your computer for rootkits. This scan can take some time, so please be patient.
[external image: MBAMAnti-Rootkitscan-results_zps9f0fdf8e]
  • When the scan with Malwarebytes Anti-Rootkit is finished, the program will display a screen with the results from the scan.
  • Make sure everything is selected and that the option to create a restore point is checked.
  • Next click on the Cleanup button. Malwarebytes Anti-Rootkit will then prompt you to reboot your computer.
  • Click on Yes button to restart your computer.
  • There will now be two log files created in the mbar folder called system-log.txt and one that starts with mbar-log.
  • The mbar-log file will always start with mbar-log, but the rest will be named using a timestamp indicating the time it was run.
    • For example, mbar-log-2012-11-12 (19-13-32).txt corresponds to mbar-log-year-month-day (hour-minute-second).txt.
  • The system-log.txt contains information about each time you have run MBAR and contains diagnostic information from the program.
  • ~~~~~~~~~~~~~~~~~~`

    [external image: thisisujrt.gif]
    Please download Junkware Removal Tool
    or from here http://downloads.malwarebytes.org/file/jrt
    to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    ~~~~~~~~~~~~
    please post
    Fixlog.txt
    MBAR log
    JRT.txt
Fix result of Farbar Recovery Scan Tool (x86) Version:07-11-2015
Ran by [removed] (2015-11-10 10:00:42) Run:1
Running from C:\Documents and Settings\[removed]\Desktop
[removed]
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
Task: C:\WINDOWS\Tasks\CandyUpdater.job.bak => C:\Documents and Settings\Lew\Local Settings\Application Data\ArcadeCandy\candyUpdater.exe
URLSearchHook: [S-1-5-21-2052111302-861567501-725345543-500] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2052111302-861567501-725345543-1004 -> {1FF59F01-1B18-4F35-8C03-65E1FEE35225} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=531140&p={searchTerms}
Toolbar: HKU\S-1-5-21-2052111302-861567501-725345543-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF Homepage: hxxps://search.yahoo.com/?type=531140&fr=spigot-yhp-ff
FF Plugin HKU\S-1-5-21-2052111302-861567501-725345543-1004: @nds.com/PCShowPlugin -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPCShowPlugin.dll [No File]
EmptyTemp:
Hosts:
End
 
 
 
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
C:\WINDOWS\Tasks\CandyUpdater.job.bak => moved successfully
Could not restore Default URLSearchHook.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
"HKU\S-1-5-21-2052111302-861567501-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1FF59F01-1B18-4F35-8C03-65E1FEE35225}" => key removed successfully.
HKCR\CLSID\{1FF59F01-1B18-4F35-8C03-65E1FEE35225} => key not found. 
HKU\S-1-5-21-2052111302-861567501-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. 
Firefox "homepage" removed successfully.
"HKU\S-1-5-21-2052111302-861567501-725345543-1004\Software\MozillaPlugins\@nds.com/PCShowPlugin" => key removed successfully.
C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPCShowPlugin.dll => not found.
Hosts restored successfully.
EmptyTemp: => 1.3 GB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 10:04:29 ====
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
 
Database version:
  main:    v2015.11.10.05
  rootkit: v2015.11.04.02
 
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Lew :: LEW-0CCC0E88CE3 [administrator]
 
11/10/2015 10:28:33 AM
mbar-log-2015-11-10 (10-28-33).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 340430
Time elapsed: 17 minute(s), 25 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)

I had two of the files set in the posting window and was to place the third file in place and my computer rebooted running the Junk File program….Let me know if you got the files you needed.

 

Lew

No it did not reboot while running JRT…..I had "What the Tech" forum in my task bar, with the other txt and log files ready to be posted up…..Didn't know JRT would reboot after it scanned…..I can run again……Doubt it will find anything……..I am using Chrome as my web browser now….seems to be doing pretty good……Firefox seems to have been giving me problems…….Also I am running Avast virus program….I really don't like it….It is always running checks on every web page I visit….Takes for ever sometime. .

 

AT&T Uverse customers offers Mcafee Suite for free to their customers….However It will not load on my desktop….Just another Problem I have to deal with. 

 
Here is the JRT log file after running again……
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Microsoft Windows XP x86
Ran by [removed] on Tue 11/10/2015 at 14:04:49.67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Informational
 
C:\WINDOWS\system32\tasklist.exe doesn't exist [Process check skipped . Windows XP Home Edition?]
 
 
 
~~~ Folders
 
 
 
~~~ Chrome
 
 
[C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 11/10/2015 at 14:08:14.07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Doubt it will find anything……..I am using Chrome as my web browser now….seems to be doing pretty good……Firefox seems to have been giving me problems…….Also I am running Avast virus program….I really don't like it….It is always running checks on every web page I visit….Takes for ever sometime. .

 

AT&T Uverse customers offers Mcafee Suite for free to their customers….However It will not load on my desktop….Just another Problem I have to deal with.

Glad to hear Chrome is working good.
 
Let's see if you can update Firefox
Open Firefox,  look to the top right corner at [external image: Settings.JPG]
Click on that and at the far bottom is a small blue question mark,  click on that
Next click on About Firefox,  this should tell us if it's up to date.
 
Now,  as for antivirus,  it's possible you'll have problems finding one that still supports XP.
Let me give you a list to check through.
  • [external image: 8fj6i2U.png] avast! Free Anti-Virus (free)
  • [external image: UbJpW95.png] Microsoft Security Essentials (free)
  • [external image: GzlsbnV.png] ESET NOD32 Anti-Virus (paid)
  • [external image: YARWD1t.png] Kaspersky Anti-Virus (paid)
  • [external image: 7D2ig3K.png] Emsisoft Internet Security (paid)
Each paid-for Anti-Virus comes with a free trial if you wish to try the software before purchasing.
 
Let's see if we run an online scan if it can pick something up we're not seeing.

What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.



Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

[external image: GzlsbnV.png]ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.
  • Please download ESET Online Scan and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the programme.
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Place a checkmark next to Enable detection of potentially unwanted applications.
  • Click Advanced settings. Place a checkmark next to:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Ensure Remove found threats is unchecked.
  • Click Start.
  • Wait for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points.
  • Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
  • Push the Back button.
  • Place a checkmark next to [external image: xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png] and click [external image: SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png].
  • Re-enable your anti-virus software.
  • Copy the contents of the log and paste in your next reply.
Here is the Eset Scan.  After I hit the back button as you instructed….Not sure what I am supposed to do….It just says finish….I have not closed out Eset at this point….It's in my task bar……
 
 
C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP576\A0087446.exe Win32/Systweak.O potentially unwanted application
C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP576\A0087449.exe a variant of Win32/Systweak potentially unwanted application
C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP594\A0095398.exe a variant of Win32/Systweak.A potentially unwanted application
C:\System Volume Information\_restore{39BD494D-4C19-4CC2-9C7A-2A460FA1F53D}\RP623\A0098847.exe a variant of Win32/Systweak potentially unwanted application

 

.I have not closed out Eset at this point….It's in my task bar……

It's fine,  you can close it out.

 

What it found rest in old restore points.

And you can actually leave those alone but,  do not use those restore points to restore your computer to or the infection would become active again.

 

OR

We can create a good restore point from here.

 

 

update Firefox

 

Were you able to check Firefox for updates?

 

Please also tell me what the computer is doing now.

Firefox version is 41.1.02 however my Laptop shows Firefox version is 42.0.  Why not dump the restore files Eset found and create a new restore point?  PC seems to be doing much better now….However I am using Chrome as my browser….Not Firefox……Let's update Firefox.  Not sure how to do that…… 

Let's see if you can update Firefox
Open Firefox, look to the top right corner at [external image: Settings.JPG]
Click on that and at the far bottom is a small blue question mark, click on that
Next click on About Firefox, this should tell us if it's up to date.

~~~

For restore points

click on the Start button, right-click Computer, and then clicking Properties.
In the left pane, click System protection. Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
Under Protection Settings, click Configure.
Under Disk Space Usage, click Delete.
Click Continue, and then click OK.


http://windows.microsoft.com/en-us/windows7/create-a-restore-point
To create a new restore point

Open System by clicking the Start button , right-clicking Computer, and then clicking Properties.
In the left pane, click System protection. …
Click the System Protection tab, and then click Create.
In the System Protection dialog box, type a description, and then click Create.
 

~~~~~~~~~

 

 

PC seems to be doing much better now.

Good deal

Ready to remove tools and quarantine folders?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI