This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google redirect plus more? [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First of all, thanks in advance for any and all help. I have not been able to create any new folders for a little while now, just recently started noticing problems clicking on links in chrome, most videos will not load, and noticed the home page was changed to this "https://search.yahoo.com/?type=444990&fr;=spigot-yhp-gc" instead of the new tab page. The aswMBR scan results: aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software Run date: 2015-11-09 20:09:58 —————————– 20:09:58.283 OS Version: Windows x64 6.1.7601 Service Pack 1 20:09:58.283 Number of processors: 8 586 0x2A07 20:09:58.283 ComputerName: DJHAROLD UserName: Owner 20:10:06.332 Initialize success 20:10:06.504 VM: initialized successfully 20:10:06.520 VM: Intel CPU supported 20:10:14.815 VM: supported disk I/O iaStor.sys 20:16:46.884 AVAST engine defs: 15110902 20:18:59.435 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 20:18:59.441 Disk 0 Vendor: Hitachi_ JE4O Size: 715404MB BusType: 3 20:18:59.569 VM: Disk 0 MBR read successfully 20:18:59.576 Disk 0 MBR scan 20:18:59.587 Disk 0 unknown MBR code 20:18:59.595 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 20:18:59.604 Disk 0 default boot code 20:18:59.628 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 277504 MB offset 206848 20:18:59.641 Disk 0 Partition - 00 0F Extended LBA 415904 MB offset 568535040 20:18:59.693 Disk 0 Partition 3 00 27 Hidden NTFS WinRE NTFS 21894 MB offset 1420306432 20:18:59.755 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 415903 MB offset 568537088 20:18:59.899 Disk 0 scanning C:\Windows\system32\drivers 20:19:20.159 Service scanning 20:20:15.763 Modules scanning 20:20:15.763 Disk 0 trace - called modules: 20:20:15.794 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 20:20:15.794 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007e47790] 20:20:15.810 3 CLASSPNP.SYS[fffff88001bcd43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80062cb050] 20:20:17.604 AVAST engine scan C:\Windows 20:20:25.154 AVAST engine scan C:\Windows\system32 20:28:51.409 AVAST engine scan C:\Windows\system32\drivers 20:29:16.634 AVAST engine scan C:\Users\Owner 20:48:58.049 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat" 20:48:58.052 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt" 21:11:29.071 AVAST engine scan C:\ProgramData 21:25:14.701 Disk 0 statistics 4594174/0/27 @ 0.87 MB/s 21:25:14.721 Scan finished successfully 11:22:30.447 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat" 11:22:30.457 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt" ========================================================================================== The FRST scan results: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015 Ran by [removed] (administrator) on DJHAROLD (09-11-2015 20:21:01) Running from C:\Users\[removed]\Downloads [removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe () C:\Program Files\pcreg\pcreg.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe () C:\Users\Owner\AppData\Roaming\ShieldSoft\UI\bin\shieldsoftService.exe (Intel(R) Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ShieldSoft) C:\Users\Owner\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft.exe () C:\Users\Owner\AppData\Roaming\ShieldSoft\UI\bin\shieldui.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe () C:\Users\Owner\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft64.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avpui.exe (Intel Corporation) C:\Windows\System32\igfxext.exe () C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe (Seagate LLC) C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe () C:\Windows\Samsung\PanelMgr\caller64.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\SamsungFastStart\SmartRestarter.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe (AVAST Software) C:\Users\Owner\Downloads\aswMBR.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11660904 2010-11-30] (Realtek Semiconductor) HKLM\…\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-11-01] (Intel(R) Corporation) HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2817872 2012-04-25] (ELAN Microelectronics Corp.) HKLM\…\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.) HKLM\…\Run: [pcreg] => C:\Program Files\pcreg\service.exe [89816 2014-04-25] () HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-08-13] (Apple Inc.) HKLM-x32\…\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-01] (CyberLink) HKLM-x32\…\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2010-08-25] (cyberlink) HKLM-x32\…\Run: [Samsung PanelMgr] => C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] () HKLM-x32\…\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-09] (Microsoft Corporation) HKLM-x32\…\Run: [MaxMenuMgr] => C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [185640 2009-05-01] (Seagate LLC) HKLM-x32\…\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-09-23] (Apple Inc.) HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.) HKLM-x32\…\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.) HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\…\Run: [] => [X] HKLM-x32\…\Run: [ShopAtHomeWatcher] => C:\Users\Owner\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe HKLM-x32\…\Run: [ShopAtHomeUpdater] => C:\Users\Owner\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeUpdater.exe HKLM-x32\…\Run: [pcreg] => C:\Program Files\pcreg\service.exe [89816 2014-04-25] () HKLM-x32\…\Run: [fst_us_63] => [X] HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.) Winlogon\Notify\DfLogon: LogonDll.dll [X] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKLM\…\Policies\Explorer: [NoDrives] 524288 HKLM\…\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Run: [BackupAgent] => C:\Program Files (x86)\Strongvault Online Backup\BackupAgent.exe HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Run: [NVIDIA nTune] => "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" clear HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Run: [pcreg] => C:\Program Files\pcreg\service.exe [89816 2014-04-25] () HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Run: [iLivid] => "C:\Users\Owner\AppData\Local\iLivid\iLivid.exe" -autorun HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\MountPoints2: {3e04a122-3e0b-11e0-8fec-806e6f6e6963} - E:\Autorun.exe HKU\S-1-5-21-2250843709-3518569377-988331573-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Corporation) HKU\S-1-5-18\…\Policies\Explorer: [HideSCAHealth] 1 AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2012-06-20] ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk [2014-02-04] ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-02-06] ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-02-06] ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{5C6A50C2-DA0F-433D-A99D-E6EA9BB7587B}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{673CB153-F46F-45C4-9695-9F8CC0C87D90}: [DhcpNameServer] [removed] [removed] Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a;=cmi_14_20_ie&cd;=2XzuyEtN2Y1L1Qzu0EzztCtCtAtBtByCzytBzz0F0BzzyB0CtN0D0Tzu0SzzyCzytN1L2XzutBtFtBtDtFtCtAtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0F0AtC0C0FyEzztG0B0E0AyEtG0D0EtDtBtGtD0F0BzztGtD0D0A0Dzz0DzzyC0C0BtBzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0AyDyBtB0CtAtCtG0DtDtC0AtGtC0AyDtBtG0A0F0EzytGyC0C0D0B0BtByD0F0FyCzzyB2Q&cr;=1045947792&ir;= HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com HKU\S-1-5-21-2250843709-3518569377-988331573-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/ HKU\S-1-5-21-2250843709-3518569377-988331573-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.yahoo.com/?type=444990&fr;=spigot-nt-gc SearchScopes: HKLM-x32 -> DefaultScope {7102907D-3ADD-49A3-809A-E7D6000A2745} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=SMSTDF&pc;=MASM&src;=IE-SearchBox SearchScopes: HKU\.DEFAULT -> {47AE1BA9-0BD1-44F4-88AE-45F8F7B605EF} URL = hxxp://www.basicserve.com/?prt=BASICSERVE111&sp;=&keywords;={searchTerms} SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-2250843709-3518569377-988331573-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_gc&ei;=utf-8&ilc;=12&type;=444990&p;={searchTerms} SearchScopes: HKU\S-1-5-21-2250843709-3518569377-988331573-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_gc&ei;=utf-8&ilc;=12&type;=444990&p;={searchTerms} BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-09-29] (Microsoft Corporation) BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\dca-bho.dll [2015-08-21] (Compete, Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-10-28] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-28] (Microsoft Corporation) BHO-x32: &Yahoo;! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28] (Yahoo! Inc.) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.) BHO-x32: No Name -> {2EECD738-5844-4a99-B4B6-146BF802613B} -> No File BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14] (CANON INC.) BHO-x32: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-26] (Microsoft Corporation) BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-14] (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation) BHO-x32: W2PBrowser Class -> {AA609D72-8482-4076-8991-8CDAE5B93BCB} -> C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll [2010-09-16] () BHO-x32: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO-x32: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-bho.dll [2015-08-21] (Compete, Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-10-28] (Microsoft Corporation) BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation) BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-14] (Oracle Corporation) BHO-x32: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28] (Yahoo! Inc) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.) Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation) Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28] (Yahoo! Inc.) Toolbar: HKLM-x32 - No Name - {98889811-442D-49dd-99D7-DC866BE87DBC} - No File Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14] (CANON INC.) Toolbar: HKU\S-1-5-21-2250843709-3518569377-988331573-1002 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default FF DefaultSearchEngine: Yahoo! FF DefaultSearchEngine.US: Yahoo! FF SelectedSearchEngine: Yahoo! FF Homepage: hxxps://search.yahoo.com/?type=444990&fr;=spigot-nt-gc FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-10-18] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-18] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-07-30] () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.) FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-14] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-14] (Oracle Corporation) FF Plugin-x32: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] () FF Plugin-x32: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] () FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-20] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-26] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2250843709-3518569377-988331573-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Owner\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS) FF user.js: detected! => C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default\user.js [2015-11-09] FF SearchPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default\searchplugins\shield Yahoo!.xml [2015-11-09] FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-02-06] [not signed] FF HKLM-x32\…\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-02-06] [not signed] FF HKLM-x32\…\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-02-06] [not signed] FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-06-20] [not signed] FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] [not signed] FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] [not signed] FF HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Firefox\Extensions: [ConsumerInput@Compete] - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi FF Extension: Consumer Input - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi [2015-06-25] [not signed] Chrome: ======= CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-06] CHR Extension: (MapsGalaxy) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajbijfenhocdombdaghijgbodhiipopm [2015-01-29] CHR Extension: (Google Docs) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-06] CHR Extension: (Google Drive) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22] CHR Extension: (YouTube) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26] CHR Extension: (Adblock Plus) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-09-26] CHR Extension: (Google Search) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28] CHR Extension: (Kaspersky Protection) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-02-23] CHR Extension: (Google Sheets) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-06] CHR Extension: (Google Docs Offline) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-01] CHR Extension: (Do Not Disturb!) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilnddakjdkpofoablibghfikpeknhbia [2015-02-17] CHR Extension: (PicBadges) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjkknncnlepghplinfpikcijdbmidbg [2014-10-28] [UpdateUrl: hxxp://static.picbadges.com/plugin/chrome-updates.xml] <==== ATTENTION CHR Extension: (Chrome Web Store Payments) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-27] CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2015-11-05] CHR Extension: (Gmail) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30] CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22] CHR HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22] CHR HKLM-x32\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM-x32\…\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\Owner\AppData\Local\Wajam\Chrome\wajam.crx [2012-06-14] CHR HKLM-x32\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.) R2 AVP15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avp.exe [194000 2015-06-23] (Kaspersky Lab ZAO) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2780856 2015-10-07] (Microsoft Corporation) S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [246256 2010-08-24] (CyberLink) S2 consumerinput_update; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [106296 2014-05-18] (ConsumerInput) S3 consumerinput_updatem; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [106296 2014-05-18] (ConsumerInput) U2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [408576 2010-08-31] (Red Bend Ltd.) [File not signed] R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed] R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] () S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-11-01] () R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed] S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2057736 2015-09-07] (Electronic Arts) R2 pcregservice; C:\Program Files\pcreg\pcreg.exe [249024 2014-04-25] () R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed] R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed] R2 ShieldSoft; C:\Users\Owner\AppData\Roaming\ShieldSoft\UI\bin\ShieldsoftService.exe [83456 2015-11-02] () [File not signed] R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [911872 2010-08-31] (Intel(R) Corporation) [File not signed] S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [247016 2015-06-23] (Kaspersky Lab UK Ltd) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-23] (Kaspersky Lab ZAO) R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [64368 2015-06-23] (Kaspersky Lab ZAO) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [159960 2015-06-23] (Kaspersky Lab ZAO) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [225976 2015-07-01] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [831672 2015-10-06] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [39280 2015-06-23] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [40304 2015-06-23] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [39280 2015-06-23] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [24944 2015-06-23] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [65208 2015-06-23] (Kaspersky Lab ZAO) R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [85360 2015-06-23] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [190648 2015-10-06] (Kaspersky Lab ZAO) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [52320 2013-03-14] (hxxp://libusb-win32.sourceforge.net) S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2011-02-21] (Windows (R) 2003 DDK 3790 provider) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed] S3 ALSysIO; \??\C:\Users\Owner\AppData\Local\Temp\ALSysIO64.sys [X] S3 WinRing0_1_2_0; \??\C:\Users\Owner\AppData\Local\Temp\tmpA3EC.tmp [X] U3 aswMBR; \??\C:\Users\Owner\AppData\Local\Temp\aswMBR.sys [X] U3 aswVmm; \??\C:\Users\Owner\AppData\Local\Temp\aswVmm.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-11-09 20:21 - 2015-11-09 20:23 - 00033868 _____ C:\Users\Owner\Downloads\FRST.txt 2015-11-09 20:16 - 2015-11-09 20:21 - 00000000 ____D C:\FRST 2015-11-09 20:16 - 2015-11-09 20:19 - 00001447 _____ C:\Users\Owner\Desktop\FRST64 - Shortcut.lnk 2015-11-09 20:16 - 2015-11-09 20:16 - 00001447 _____ C:\Users\Owner\Desktop\aswMBR - Shortcut.lnk 2015-11-09 20:16 - 2015-11-09 20:16 - 00001420 _____ C:\Users\Owner\Desktop\dds - Shortcut.lnk 2015-11-09 20:13 - 2015-11-09 20:13 - 02198528 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe 2015-11-09 20:10 - 2015-11-09 20:10 - 00027362 _____ C:\Users\Owner\Desktop\dds.txt 2015-11-09 20:10 - 2015-11-09 20:10 - 00006604 _____ C:\Users\Owner\Desktop\attach.txt 2015-11-09 20:08 - 2015-11-09 20:08 - 05198336 _____ (AVAST Software) C:\Users\Owner\Downloads\aswMBR.exe 2015-11-09 20:05 - 2015-11-09 20:05 - 00688992 ____R (Swearware) C:\Users\Owner\Downloads\dds.scr 2015-11-09 19:48 - 2015-11-09 19:48 - 00000000 ____D C:\Users\Owner\AppData\Local\Macromedia 2015-11-09 19:38 - 2015-11-09 19:53 - 00000000 ____D C:\Users\Owner\AppData\Local\Mozilla 2015-11-09 19:37 - 2015-11-09 19:37 - 00001166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-11-09 19:37 - 2015-11-09 19:37 - 00001154 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-11-09 19:37 - 2015-11-09 19:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-11-09 19:35 - 2015-11-09 19:35 - 00243656 _____ C:\Users\Owner\Downloads\Firefox Setup Stub 42.0.exe 2015-11-06 19:24 - 2015-11-06 19:24 - 00000000 ___HD C:\OneDriveTemp 2015-11-05 17:03 - 2015-11-05 17:03 - 02077392 _____ (Microsoft Corporation) C:\Users\Owner\Downloads\IE11-Windows6.1 (2).exe 2015-11-05 16:59 - 2015-11-05 16:59 - 02077392 _____ (Microsoft Corporation) C:\Users\Owner\Downloads\IE11-Windows6.1 (1).exe 2015-11-03 22:22 - 2015-11-03 22:22 - 00000000 ____D C:\Users\Owner\Desktop\2015 FALL FAMILY PICS 2015-11-02 14:48 - 2015-11-02 14:48 - 00000000 ____D C:\Users\Owner\AppData\Roaming\ShieldSoft 2015-10-28 16:27 - 2015-10-28 16:27 - 01089320 _____ (Unity Technologies ApS) C:\Users\Owner\Downloads\UnityWebPlayer.exe 2015-10-25 19:28 - 2015-10-25 19:29 - 00000000 ____D C:\Users\Owner\Desktop\10-20-15 2015-10-11 16:11 - 2015-10-11 16:11 - 00000000 ____D C:\Windows\System32\Tasks\Apple ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-11-09 20:23 - 2014-05-18 08:24 - 00000458 _____ C:\Windows\Tasks\CIMT_S-1-5-21-2250843709-3518569377-988331573-1002.job 2015-11-09 20:23 - 2011-02-06 02:30 - 00000050 _____ C:\Windows\system32\SupplicantTest.log 2015-11-09 20:17 - 2009-07-13 22:45 - 00022976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-11-09 20:17 - 2009-07-13 22:45 - 00022976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-11-09 19:59 - 2011-09-21 21:56 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-11-09 19:54 - 2011-02-06 19:20 - 02060482 _____ C:\Windows\WindowsUpdate.log 2015-11-09 19:50 - 2009-07-13 23:13 - 00006458 _____ C:\Windows\system32\PerfStringBackup.INI 2015-11-09 19:46 - 2013-09-04 19:54 - 00000000 ___RD C:\Users\Owner\SkyDrive 2015-11-09 19:44 - 2014-05-18 08:23 - 00000964 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job 2015-11-09 19:44 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-11-09 19:44 - 2009-07-13 22:51 - 00129121 _____ C:\Windows\setupact.log 2015-11-09 19:38 - 2012-08-17 09:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-11-09 19:38 - 2012-05-01 18:06 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-11-09 19:28 - 2014-05-18 08:23 - 00000968 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job 2015-11-05 17:05 - 2013-11-28 11:20 - 00012018 _____ C:\Windows\IE11_main.log 2015-11-04 21:08 - 2013-02-13 20:42 - 00000000 ____D C:\ProgramData\CanonIJPLM 2015-11-03 22:59 - 2011-09-18 22:14 - 00000000 ____D C:\Users\Owner\AppData\Local\CrashDumps 2015-11-02 23:29 - 2014-08-10 13:06 - 00002164 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk 2015-11-02 15:56 - 2014-05-18 08:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks 2015-11-02 15:55 - 2014-05-18 08:19 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Real 2015-11-02 15:55 - 2014-05-18 08:19 - 00000000 ____D C:\Program Files (x86)\Real 2015-11-02 15:54 - 2014-09-02 17:46 - 00000000 ____D C:\ProgramData\Package Cache 2015-11-02 15:54 - 2014-05-18 08:18 - 00000000 ____D C:\ProgramData\Real 2015-11-02 14:59 - 2012-11-07 01:08 - 00000000 ____D C:\Users\Owner\AppData\Local\Unity 2015-11-02 14:59 - 2011-02-06 03:41 - 01003064 _____ C:\Windows\PFRO.log 2015-11-02 14:48 - 2014-05-18 08:37 - 00000000 ____D C:\temp 2015-11-01 22:38 - 2015-01-01 16:32 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-10-28 11:04 - 2013-09-04 19:24 - 00000000 ____D C:\Program Files\Microsoft Office 15 2015-10-20 23:02 - 2014-11-25 19:02 - 00000000 ____D C:\Users\Owner\Desktop\EmmaKatelynn 2015-10-20 21:14 - 2014-01-01 19:03 - 00461824 ___SH C:\Users\Owner\Desktop\Thumbs.db 2015-10-20 20:53 - 2015-09-29 18:27 - 00000000 ____D C:\Users\Owner\Desktop\Camera 2015-10-18 14:38 - 2012-05-01 18:06 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-10-18 14:38 - 2011-09-25 18:57 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-10-15 10:15 - 2013-03-07 21:10 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk ==================== Files in the root of some directories ======= 2013-07-15 20:29 - 2013-07-15 20:28 - 2409984 _____ () C:\Program Files\PX5 Advanced Sound Editor.msi 2014-05-18 08:25 - 2014-05-18 08:37 - 0001190 _____ () C:\Users\Owner\AppData\Roaming\aps.scan.quick.results 2014-05-18 08:25 - 2014-05-18 08:37 - 0000000 _____ () C:\Users\Owner\AppData\Roaming\aps.scan.results 2014-05-18 08:25 - 2014-05-18 08:37 - 0000318 _____ () C:\Users\Owner\AppData\Roaming\aps.uninstall.scan.results 2013-08-17 13:06 - 2013-08-18 10:10 - 0000496 _____ () C:\Users\Owner\AppData\Roaming\UserMetrics.osl 2012-08-09 00:23 - 2012-08-09 00:23 - 0022440 _____ () C:\Users\Owner\AppData\Local\190833628_Setup.crx 2012-08-09 14:09 - 2012-08-09 14:09 - 0022440 _____ () C:\Users\Owner\AppData\Local\240382890_Setup.crx 2012-08-22 17:35 - 2012-08-22 17:35 - 0022440 _____ () C:\Users\Owner\AppData\Local\8976367_Setup.crx 2012-08-17 09:47 - 2012-08-17 09:46 - 0022440 _____ () C:\Users\Owner\AppData\Local\91735345_Setup.crx 2014-06-16 18:45 - 2014-09-02 16:56 - 0000003 _____ () C:\Users\Owner\AppData\Local\proxy.log 2013-10-23 12:25 - 2013-10-23 12:25 - 0000017 _____ () C:\Users\Owner\AppData\Local\resmon.resmoncfg 2013-07-24 14:25 - 2013-07-24 14:25 - 0000000 _____ () C:\ProgramData\2c233b353d3d352c_c 2012-06-20 10:31 - 2012-06-20 12:43 - 0001248 _____ () C:\ProgramData\hpzinstall.log 2011-02-06 02:46 - 2011-02-06 02:46 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2011-02-06 02:42 - 2011-02-06 02:43 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2011-02-06 02:39 - 2011-02-06 02:42 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log 2011-02-06 02:43 - 2011-02-06 02:44 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log 2011-02-06 02:44 - 2011-02-06 02:45 - 0000108 _____ () C:\ProgramData\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}.log Some files in TEMP: ==================== C:\Users\Owner\AppData\Local\Temp\APNSetup.exe C:\Users\Owner\AppData\Local\Temp\autorun.dll C:\Users\Owner\AppData\Local\Temp\C071.exe C:\Users\Owner\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe C:\Users\Owner\AppData\Local\Temp\jre-8u40-windows-au.exe C:\Users\Owner\AppData\Local\Temp\lowproc.exe C:\Users\Owner\AppData\Local\Temp\stubhelper.dll ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-11-04 18:54 ==================== End of FRST.txt ============================ The FRST Addition: Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-11-2015 Ran by [removed] (2015-11-09 20:24:04) Running from C:\Users\[removed]\Downloads Windows 7 Home Premium Service Pack 1 (X64) (2011-03-14 16:24:18) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2250843709-3518569377-988331573-500 - Administrator - Disabled) Guest (S-1-5-21-2250843709-3518569377-988331573-501 - Administrator - Disabled) HomeGroupUser$ (S-1-5-21-2250843709-3518569377-988331573-1010 - Administrator - Enabled) Owner (S-1-5-21-2250843709-3518569377-988331573-1002 - Administrator - Enabled) => C:\Users\Owner UpdatusUser (S-1-5-21-2250843709-3518569377-988331573-1000 - Administrator - Enabled) => C:\Users\UpdatusUser ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden Adobe Flash Player 19 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 19.0.0.226 - Adobe Systems Incorporated) Adobe Flash Player 19 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated) Adobe Reader XI (11.0.13) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\…\{A50679D9-6CBD-4FCD-BACB-62EF3894F6F3}) (Version: 4.0.3 - Apple Inc.) Apple Application Support (64-bit) (HKLM\…\{1F72FDD5-A069-45B4-928F-D0F16492DC69}) (Version: 4.0.3 - Apple Inc.) Apple Mobile Device Support (HKLM\…\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.) Best Buy pc app (HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\48e4cff94f039634) (Version: 3.2.523.2 - Best Buy) Best Buy pc app (Version: 3.0.0.0 - Best Buy) Hidden Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Canon MG6300 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6300_series) (Version: 1.00 - Canon Inc.) CDDRV_Installer (Version: 4.60 - Logitech) Hidden Core Temp 1.0 RC6 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.0 - Alcpu) CPUID HWMonitor 1.24 (HKLM\…\CPUID HWMonitor_is1) (Version: - ) ETDWare PS/2-X64 10.7.14.12_WHQL (HKLM\…\Elantech) (Version: 10.7.14.12 - ELAN Microelectronic Corp.) Google Chrome (HKLM-x32\…\Google Chrome) (Version: 46.0.2490.80 - Google Inc.) Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP) HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP) HP Photosmart Essential 3.5 (HKLM\…\HP Photosmart Essential) (Version: 3.5 - HP) HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B (HKLM\…\{B61ED343-0B14-4241-999C-490CB1A20DA4}) (Version: 13.0 - HP) HP Smart Web Printing 4.51 (HKLM\…\HP Smart Web Printing) (Version: 4.51 - HP) HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) iCloud (HKLM\…\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.) Intel WiMAX Tutorial (HKLM\…\{4F26C164-9373-4974-8F43-E0F2176AF937}) (Version: 1.5.3.1 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\…\{AF162E20-417F-4946-A06D-65734984957F}) (Version: 14.00.0000 - Intel Corporation) Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel® PROSet/Wireless WiMAX Software (HKLM\…\{6548B189-BEA4-4041-80E0-AEB60548E046}) (Version: 2.03.2000 - Intel Corporation) iTunes (HKLM\…\{BFEAB774-C7DC-4032-B05A-DA5F7CB7B365}) (Version: 12.2.2.25 - Apple Inc.) Java 8 Update 40 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation) Kaspersky Anti-Virus (HKLM-x32\…\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: 15.0.2.396 - Kaspersky Lab) Kaspersky Anti-Virus (x32 Version: 15.0.2.396 - Kaspersky Lab) Hidden KhalInstallWrapper (Version: 2.00.0000 - Logitech) Hidden Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Click-to-Run 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Home and Student 2013 - en-us (HKLM\…\HomeStudentRetail - en-us) (Version: 15.0.4763.1003 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\OneDriveSetup.exe) (Version: 17.3.6201.1019 - Microsoft Corporation) Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 42.0 - Mozilla) Network64 (Version: 130.0.572.000 - Hewlett-Packard) Hidden Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: - ) NVIDIA Graphics Driver 306.97 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.97 - NVIDIA Corporation) NVIDIA Update 1.10.8 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation) OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4763.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4763.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4763.1003 - Microsoft Corporation) Hidden Origin (HKLM-x32\…\Origin) (Version: 9.4.11.2806 - Electronic Arts, Inc.) QuickTime 7 (HKLM-x32\…\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.) Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 13.0 - HP) SRS Premium Sound Control Panel (HKLM\…\{2998191E-A35E-47E2-BE38-7702C731D722}) (Version: 1.10.1000 - SRS Labs, Inc.) The Sims 4 (HKLM-x32\…\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.10.63.1020 - Electronic Arts Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2250843709-3518569377-988331573-1002_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64\FileCoAuthLib64.dll () CustomCLSID: HKU\S-1-5-21-2250843709-3518569377-988331573-1002_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation) ==================== Restore Points ========================= Check "winmgmt" service or repair WMI. ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 20:34 - 2009-06-10 15:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0046A7F1-5A67-469F-8664-42D0BD94E0EE} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe [2010-12-06] (Samsung Electronics Co., Ltd.) Task: {0E05618D-BF9A-480A-A5EA-0072F638B605} - \AdobeFlashPlayerUpdate 2 -> No File <==== ATTENTION Task: {155B6058-33CF-4455-8E6F-CC8C5CDEB3A3} - System32\Tasks\ConsumerInputUpdateTaskMachineUA => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2014-05-18] (ConsumerInput) <==== ATTENTION Task: {1E028465-D86C-4272-B388-FADEE618F146} - System32\Tasks\SRS Premium Sound => C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel_64.exe [2010-11-29] (SRS Labs, Inc.) Task: {2098ACC1-6CED-4921-B19E-A184417D06AF} - System32\Tasks\CIMT_S-1-5-21-2250843709-3518569377-988331573-1002 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-09-30] () <==== ATTENTION Task: {22384C39-B566-4FE1-9147-AE11BF8DD4D5} - System32\Tasks\{18C38DDF-3BDF-4C62-BACE-7D3DA7EDE41D} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DQOZFEG\vcredist_x64.exe" -d C:\Users\Owner\Desktop Task: {2CBDF1B5-365B-48AB-A3BD-4B6366012227} - System32\Tasks\{E0CD76EE-6E6B-4596-9AE4-45737717B7B2} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CU73BYAL\vcredist_x64.exe" -d C:\Users\Owner\Desktop Task: {3877F6F4-F36C-4E01-819D-772020F61EC1} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager2.exe [2010-12-13] (Samsung Electronics) Task: {3955F5D1-4455-4BA5-AF2D-0A767F5D7334} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-05053A95\EPM.exe Task: {401BA4B4-05AA-4B90-9E35-8EEC4ECD03C2} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-05-18] (AnyProtect by CMI) <==== ATTENTION Task: {42FF7575-C657-4178-B1C2-79428FAEBF6F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-07] (Microsoft Corporation) Task: {46B98050-E0D8-422F-B629-1DABAEE5C2A4} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-05-18] (AnyProtect by CMI) <==== ATTENTION Task: {4999CA73-E324-4419-BE48-BBCDE372B03E} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-11-17] (SEC) Task: {4BC58754-30B3-408D-A207-56DAE0BD54A4} - \AdobeFlashPlayerUpdate -> No File <==== ATTENTION Task: {4F496F78-F213-454C-8149-2739CE92A225} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2010-12-17] (Samsung Electronics Co., Ltd.) Task: {5B5F66DA-21B8-4450-B94A-CD19A9F6DD89} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated) Task: {5F26AD1F-470F-49C3-9D93-42323A344401} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-18] (Adobe Systems Incorporated) Task: {628C1FC5-8C34-4FF2-8F23-78116C8C0A16} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2010-08-26] (Samsung Electronics) Task: {713B10A1-DA57-4B90-ADDD-C1D647803659} - System32\Tasks\{515B7F2C-272D-43AB-A0E4-B5EC616782ED} => C:\Program Files (x86)\Origin Games\The Sims 4\__Installer\vc\vc2013\redist\vcredist_x86.exe [2015-04-04] (Microsoft Corporation) Task: {740B76A5-7150-4CC0-BA39-0DE308E58366} - System32\Tasks\{0961E788-4B83-4584-A69D-50DD7DE2A3E7} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2RHW11Q9\Win7Vista_64_152258.exe" -d C:\Users\Owner\Desktop Task: {77E1A039-129B-4A5E-A771-D644FF32F195} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe [2010-08-04] (Samsung Electronics Co., Ltd.) Task: {79E86527-8DC3-40B0-9FD0-9383DEDB91E5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe Task: {8F468533-3918-4722-85AE-BC53CF2B673F} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2010-11-10] (CyberLink) Task: {8F742CE9-B10A-4997-B6E1-3B0B9C8F6D2B} - System32\Tasks\{415A2F84-4790-4836-A7B2-208D73A0D38B} => C:\Program Files (x86)\Origin Games\The Sims 4\__Installer\vc\vc2013\redist\vcredist_x86.exe [2015-04-04] (Microsoft Corporation) Task: {AF908F3F-9D9B-4D3D-86BC-4E407EB4BF66} - System32\Tasks\{2A36888D-F4D9-4614-B3FA-0A4EA26E9EBF} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5DQOZFEG\vcredist_x64.exe" -d C:\Users\Owner\Desktop Task: {B4BAB576-094F-41D1-83E1-024B423DDE1E} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-05-18] (AnyProtect by CMI) <==== ATTENTION Task: {B79C9B8A-3F5C-439C-8850-9CF041176703} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-12-17] (Samsung Electronics. Co. Ltd.) Task: {D275EF63-FD75-4F09-A470-903CE535A52B} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-19] (SAMSUNG Electronics co., LTD.) Task: {E64EB62F-5DCB-48D5-8A4E-291ED1EA4AA6} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2011-09-04] (SAMSUNG Electronics) Task: {E7BC6D23-3EA2-48B5-8651-E7F7FB2C59C7} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-07] (Microsoft Corporation) Task: {E9CD05D3-7FE2-41A3-AE51-14E352AECF36} - System32\Tasks\ConsumerInputUpdateTaskMachineCore => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2014-05-18] (ConsumerInput) <==== ATTENTION Task: {F1D62B7D-9792-433E-8CA5-3E819EDE38E1} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe [2010-11-28] (Samsung Electronics Co., Ltd.) Task: {F7B646EA-6E49-46E9-ADDA-BFD21B16017D} - System32\Tasks\pcreg => C:\Program Files\pcreg\service.exe [2014-04-25] () <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\CIMT_S-1-5-21-2250843709-3518569377-988331573-1002.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cff2ed3b0fad6c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cfffcec7be10da.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d04267ba3ebe8c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d091b5cd8843e6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0c0d6d20f25cc.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e4f077fffb5f.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0f2156d3e6b5f.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2010-11-01 21:58 - 2010-11-01 21:58 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2011-02-06 02:47 - 2008-06-04 17:53 - 00027648 _____ () C:\Windows\System32\spd__l.dll 2013-10-14 17:26 - 2012-10-02 13:51 - 00086888 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-11-02 14:48 - 2015-11-02 04:25 - 00854528 ____N () C:\Users\Owner\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft64.dll 2015-10-28 11:03 - 2015-09-01 10:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2015-02-13 04:20 - 2015-02-13 04:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-09-23 15:47 - 2015-09-23 15:47 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-03-19 10:44 - 2015-10-07 18:28 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2013-02-13 20:55 - 2012-03-28 06:49 - 00140456 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE 2014-04-25 02:13 - 2014-04-25 02:13 - 00249024 _____ () C:\Program Files\pcreg\pcreg.exe 2011-02-06 02:42 - 2009-12-01 01:21 - 00244904 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2015-11-02 14:48 - 2015-11-02 04:24 - 00083456 ____N () C:\Users\Owner\AppData\Roaming\ShieldSoft\UI\bin\ShieldsoftService.exe 2011-02-06 02:48 - 2010-04-20 17:44 - 00719872 _____ () C:\Windows\system32\SnMinDrv.dll 2010-11-01 21:58 - 2010-11-01 21:58 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2011-02-06 19:50 - 2010-11-28 22:34 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2015-11-02 14:48 - 2015-09-01 12:45 - 00423424 ____N () C:\Users\Owner\AppData\Roaming\ShieldSoft\UI\bin\shieldui.exe 2015-11-02 14:48 - 2015-11-02 04:24 - 00081408 ____N () C:\Users\Owner\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft64.exe 2011-02-06 02:48 - 2010-06-07 21:15 - 00618496 _____ () C:\Windows\Samsung\PanelMgr\SSMMgr.exe 2015-09-30 03:06 - 2015-09-30 03:06 - 01265696 _____ () C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe 2011-02-06 02:48 - 2009-03-02 19:18 - 00306688 _____ () C:\Windows\Samsung\PanelMgr\caller64.exe 2014-12-23 16:54 - 2014-12-23 16:54 - 01272616 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\kpcengine.2.3.dll 2015-11-02 14:48 - 2015-11-02 04:24 - 00488448 ____N () C:\Users\Owner\AppData\Roaming\ShieldSoft\UI\bin\shieldsoft.dll 2011-02-06 02:35 - 2006-08-11 21:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll 2011-02-06 02:53 - 2010-07-05 04:42 - 00203776 _____ () C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll 2009-11-01 23:20 - 2009-11-01 23:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-01 23:23 - 2009-11-01 23:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2011-02-06 02:58 - 2010-05-07 08:22 - 01636864 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll 2015-02-20 17:29 - 2015-02-20 17:29 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll 2014-12-23 16:54 - 2014-12-23 16:54 - 00502056 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed]\npcontentblocker.dll 2014-12-23 16:54 - 2014-12-23 16:54 - 00608040 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed]\npvkplugin.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2250843709-3518569377-988331573-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 0) (EnableLUA: 0) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Launch Jawbone Updater.lnk => C:\Windows\pss\Launch Jawbone Updater.lnk.Startup MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart MSCONFIG\startupreg: IntelWirelessWiMAX => "C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe" /tasktray /nosplash MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" MSCONFIG\startupreg: SMessaging => "C:\Users\Owner\AppData\Local\Strongvault Online Backup\SMessaging.exe" MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{E57D3DDB-8A74-462A-A1E8-6101903A0C3C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{00093ABB-D9DD-4319-865E-AA7147B47B28}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{C39971B2-80B9-4894-80BC-4F8A73750299}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{31D5916B-BC14-4E4E-B0BD-47AEBD15C316}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe FirewallRules: [{54B5CC0D-1D4B-4247-AB70-049E26E85DB4}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe FirewallRules: [{59DC6C15-FBC6-4D1A-90DB-CA016E1FE9F8}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe FirewallRules: [{F641BF1A-B100-4F70-97B7-736D80DF58BC}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe FirewallRules: [{2212951D-E033-41AA-809E-2F8948528632}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel Wireless Display\WiDiApp.exe FirewallRules: [{6A13BD39-204C-44A9-B530-D78B9BBFB08E}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR8.EXE FirewallRules: [{8AB36EE9-1797-41BE-9E11-881DCECD188D}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD9.EXE FirewallRules: [{0FEAE839-B159-40B8-8C1E-648817EEF420}] => (Allow) C:\Windows\System32\SUPDSvc.exe FirewallRules: [{9DC6F1C9-46E5-4EAF-A121-ED742829B70A}] => (Allow) C:\Windows\System32\SUPDSvc.exe FirewallRules: [{6CE7EF25-E62E-4790-9C9E-213C05704281}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\USDAgent.exe FirewallRules: [{5B188DC3-745D-441A-879C-47E61880B9C9}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\USDAgent.exe FirewallRules: [{28ADA12E-F362-417A-B224-828979982098}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\ICCUpdater.exe FirewallRules: [{7C7A7C44-95AA-4CE5-B5CE-6DF564C658A2}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\ICCUpdater.exe FirewallRules: [{71B07848-864A-446A-8187-4B6E48DB1F2E}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{5F981935-3556-403B-AB34-39059EDD4446}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{105DC6AB-3BA5-4681-8510-9CDA22CE32F1}] => (Allow) LPort=2869 FirewallRules: [{D667C785-BB79-4AFE-B098-EE27FB0874AC}] => (Allow) LPort=1900 FirewallRules: [{26CF7D92-1FEA-4023-BD8C-36665F73BF2B}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{940CB5AC-BD9F-4119-868D-16C55D526FE0}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe FirewallRules: [TCP Query User{A940A6DB-CD33-4DAD-B6CF-5BCA5864C0FC}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe FirewallRules: [UDP Query User{DC4B20AD-DBF3-4DAC-B4B5-F6B30781073A}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe FirewallRules: [{F60A9753-6454-4CCD-B537-081885220E2A}] => (Block) C:\program files (x86)\electronic arts\eadm\core.exe FirewallRules: [{93B9049D-FDBB-403F-ACEA-EC7B9D239268}] => (Block) C:\program files (x86)\electronic arts\eadm\core.exe FirewallRules: [TCP Query User{A040EC43-2109-4542-99BD-D4472DD5E76E}C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2011 11.0.1.400\english\setup.exe] => (Allow) C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2011 11.0.1.400\english\setup.exe FirewallRules: [UDP Query User{8A5D9070-32BB-41CE-B39E-ED9737C34288}C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2011 11.0.1.400\english\setup.exe] => (Allow) C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2011 11.0.1.400\english\setup.exe FirewallRules: [{C5741AB8-59BB-4123-BD60-E5339B418CF4}] => (Allow) C:\Program Files (x86)\LimeWire\LimeWire.exe FirewallRules: [{706EC39B-7EAA-4B90-9F54-C8622239109C}] => (Allow) C:\Program Files (x86)\LimeWire\LimeWire.exe FirewallRules: [{B0219291-8C07-45F7-86BF-B7F10196EB31}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{D124AAD0-FCF6-4F6B-A2C2-55407B83B1E9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{1F962205-030C-46A1-9C5A-FA1B4A6AA1B9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe FirewallRules: [{88A223DA-C33C-4778-AD5D-CCDDFC8B68A8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe FirewallRules: [{B87E245D-7470-4918-913A-CBCB436C945F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{E4E0751E-1570-4003-BE6B-A7F70BCA121F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{D93680B4-AB04-4E4F-8380-AECBFA5F8CC8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe FirewallRules: [{311D3DCF-27E1-4F7A-965C-2FEC0D2C87F6}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{82D09A6C-D958-4EEB-95B5-0560A3634190}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe FirewallRules: [{8B1A153B-C889-47A8-8BFE-4B45D855A434}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{A7F4F4E0-3000-466C-8ED4-6E39E6AB1A26}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe FirewallRules: [{CFE4045E-B7BF-48A5-ADAD-AD32378B7452}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{05DC365F-507C-4AEB-907E-97A498FDB960}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe FirewallRules: [{3EE137B2-6F9C-4118-97D5-CB57D7266E2C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe FirewallRules: [{53A69F37-9CFD-4DC2-846A-6D6FB720AD55}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe FirewallRules: [{784439B4-F173-4911-8394-DE83517E3A2C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe FirewallRules: [{FF354922-0E6D-4CA1-BD86-365C631432D7}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe FirewallRules: [{59A31A2A-B0AC-4EF6-963E-642EAE3EFC6A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe FirewallRules: [{996583B2-5F05-414C-A943-3D545480D323}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{AAFB3790-CF5B-4DC9-9C25-9F54C972FA95}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{E74980C5-3EA5-43B9-99C1-450D5EE619AB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{F414FC67-D788-44CC-A631-2D68FA5588DA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{C7D71876-B891-489D-AFE6-168AAB7DC550}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{14A46EC4-65BC-4A6D-80F4-62AFBB36B0F7}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe FirewallRules: [{648B9514-F1F9-481E-9ACA-FBF8595798CA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7CB9E140-6408-4045-A675-EA8689ACBC39}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E9FE2670-BFCA-4F0D-8E0D-B860444F9D04}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{8285799F-42E6-4D52-AD3B-71FB4B298B03}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{963F7FB5-D4FD-4AC3-8992-ACBBE20E0CF6}] => (Allow) C:\Program Files (x86)\Jawbone\JawboneUpdater.exe FirewallRules: [{990EC569-5E53-454C-A14E-4D73D27EB200}] => (Allow) C:\Program Files (x86)\Jawbone\JawboneUpdater.exe FirewallRules: [TCP Query User{A3E60798-AB19-4FCE-9EE9-EAAEAE7E4E5F}C:\program files (x86)\jawbone\jawboneupdater.exe] => (Allow) C:\program files (x86)\jawbone\jawboneupdater.exe FirewallRules: [UDP Query User{7A37244A-68D1-447D-9556-AC5319FC909C}C:\program files (x86)\jawbone\jawboneupdater.exe] => (Allow) C:\program files (x86)\jawbone\jawboneupdater.exe FirewallRules: [{D6329886-00CE-4886-A2EF-ACC359D26D5A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{16C7909A-6DF7-4772-9423-A46EE63A009D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{821EC2AC-7A04-41B4-92B7-F01DAE1A8CC2}] => (Allow) C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{988FB558-B56F-4CE6-9A67-5B3F04B5F064}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{A61DDF12-3250-4263-9375-67B9E7080AC3}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{52BD859B-2D82-4D5B-AC8D-E187D1163F17}] => (Allow) C:\Windows\SysWOW64\ARFC\wrtc.exe FirewallRules: [{E4756446-ADA3-4A70-9F0D-89F79C723832}] => (Allow) C:\Windows\SysWOW64\ARFC\wrtc.exe FirewallRules: [{0CCF73E6-1323-4804-86F7-3E7482CAE893}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{0DCD8DD6-5AF0-4A2F-A6BE-876D4547C650}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{D4BE6F59-31EE-4BA8-9448-7564C0F9A18C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{1FDF6AAA-64ED-45A9-8C57-98F8E541778B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{4F083666-8F83-496F-9CD9-720D59297B59}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sanctum2\Binaries\Win32\SanctumGame-Win32-Shipping.exe FirewallRules: [{96A397AA-BCC5-42D1-83A5-8CFE9719C0F1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sanctum2\Binaries\Win32\SanctumGame-Win32-Shipping.exe FirewallRules: [{8F681844-5585-421F-8C4E-0F648F3A0533}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Sniper Challenge\HMSC.exe FirewallRules: [{095EDB9F-3F3B-41F0-BE62-934292E60F71}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Sniper Challenge\HMSC.exe FirewallRules: [{8C69EF38-B1BE-4526-9CA0-4B84A4E8F70E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Blood Money\HitmanBloodMoney.exe FirewallRules: [{82507706-D6FD-44AC-90F5-01ECCE7839BF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Blood Money\HitmanBloodMoney.exe FirewallRules: [{3C929E29-3DD6-44F4-8441-B623DB7C9216}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Blood Money\configure.exe FirewallRules: [{5FA607A6-1B18-4A75-87A0-F4F3115E305D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Blood Money\configure.exe FirewallRules: [{3405F809-457E-49FF-BCDA-4A6B44184732}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman 2 Silent Assassin\hitman2.exe FirewallRules: [{EBFF5E99-32FF-41F2-8A3F-7E47569D00A0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman 2 Silent Assassin\hitman2.exe FirewallRules: [{3DA046BB-E096-4298-B4DA-8CD46CE6AC62}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman 2 Silent Assassin\config.exe FirewallRules: [{8BBA7CAB-DBD3-42D1-8A7D-AC024B135765}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman 2 Silent Assassin\config.exe FirewallRules: [{1AC5B8EC-43B4-4FAC-B452-A94202E9BAFB}] => (Allow) C:\Users\Owner\AppData\Local\Temp\Phx4317\speedmax.exe FirewallRules: [{D544C5DA-3EDD-4EFA-B866-CA346112BF3D}] => (Allow) C:\Users\Owner\AppData\Local\Temp\speedmax_24437.exe FirewallRules: [{85F30162-37AC-4367-A64A-D4A111374D51}] => (Allow) C:\Users\Owner\AppData\Local\Temp\updater_155528.exe FirewallRules: [{3F662C77-188B-4BF3-AEB9-EE9854671FEE}] => (Allow) c:\program files\pcreg\pcreg.exe FirewallRules: [{2D69807E-839A-48F4-9EAB-0DF783949552}] => (Allow) c:\program files\pcreg\pcreg.exe FirewallRules: [{D64214DE-1D67-4E66-AFE9-1398CF1EF0D2}] => (Allow) c:\program files\pcreg\service.exe FirewallRules: [{D6BABC84-5DB1-403A-8FF7-E5A1D1E75177}] => (Allow) c:\program files\pcreg\service.exe FirewallRules: [{29E3D91C-A28A-454E-9892-C3E4DA899A62}] => (Allow) C:\Users\Owner\AppData\Local\Temp\file_to_run55364.exe FirewallRules: [{76363144-694E-4304-9441-2D59925A2954}] => (Allow) C:\Users\Owner\AppData\Local\Temp\file_to_run55364.exe FirewallRules: [{9910A60C-7ECF-4C56-9352-B0872F9F3513}] => (Allow) C:\Windows\TEMP\file_to_run551761.exe FirewallRules: [{47D0F168-AF90-4823-A654-60361E327192}] => (Allow) C:\Windows\TEMP\file_to_run551761.exe FirewallRules: [{E36C6D03-6261-4091-9BD2-4514F637CC93}] => (Allow) C:\Program Files (x86)\Bench\Proxy\proc.exe FirewallRules: [{0140C642-BD22-4F2A-934C-158274173A1E}] => (Allow) C:\Program Files (x86)\Bench\Proxy\pwdg.exe FirewallRules: [{D4A79BC5-E23C-4EDD-A9AC-A59036DDD834}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{B07BAC76-6F14-405D-AAA0-237E50A61601}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{35E15747-E2D2-4FA6-A262-46522B965A15}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{76779C48-8538-4688-8D67-C593951C8A78}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{3324F527-1910-4D90-AAC1-9CD046E92F8B}] => (Allow) C:\Windows\TEMP\file_to_run551348.exe FirewallRules: [{301B5329-297E-40FE-B6D9-BFC75E7D9A60}] => (Allow) C:\Windows\TEMP\file_to_run551348.exe FirewallRules: [{8BEA0F76-0DA5-4C14-AA7F-DA06B0EFF66C}] => (Allow) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avpui.exe FirewallRules: [{E1EC8BF5-ED19-4C86-8727-DAAF5B2B1752}] => (Allow) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avpui.exe FirewallRules: [{123D605D-8F9F-4FB4-B706-511096BED354}] => (Allow) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avpui.exe FirewallRules: [{21CC3F09-C165-46A2-8E94-ABC206D1301E}] => (Allow) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avpui.exe FirewallRules: [{DD5291E1-0EDA-44C5-B3F3-8228FCABAC9C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{B8350886-F876-48B7-86C1-7AE9FA30DE3A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft Teredo Tunneling Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (11/09/2015 07:54:52 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Information only. The action cannot be completed. Try the action again. If the problem continues, contact Microsoft Product Support. Error: (11/09/2015 07:50:41 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (11/09/2015 07:50:41 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (11/09/2015 07:47:25 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Information only. (Stream product id=0x0066): Streaming Failed Error: (11/09/2015 07:46:54 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Information only. Too many failures while downloading ranges: 2 Error: (11/09/2015 07:44:52 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Information only. The action cannot be completed. Try the action again. If the problem continues, contact Microsoft Product Support. Error: (11/09/2015 07:44:52 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Information only. Product registration is corrupted for {90140011-0066-0409-0000-0000000FF1CE} Error: (11/09/2015 07:44:52 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Information only. Uninstall key is not found for product {90140011-0066-0409-0000-0000000FF1CE} Error: (11/09/2015 07:44:52 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Information only. Product registration is corrupted for {90140011-0066-0409-0000-0000000FF1CE} Error: (11/09/2015 07:44:52 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Information only. Uninstall key is not found for product {90140011-0066-0409-0000-0000000FF1CE} System errors: ============= Error: (11/09/2015 07:48:19 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The NVIDIA Update Service Daemon service failed to start due to the following error: %%1069 Error: (11/09/2015 07:48:19 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: %%1330 To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). Error: (11/09/2015 07:46:34 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147467259 Error: (11/09/2015 07:46:34 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Function Discovery Resource Publication service terminated with the following error: %%-2147467259 Error: (11/09/2015 07:46:12 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Intel® PROSet/Wireless WiMAX Red Bend Device Management Service service hung on starting. Error: (11/09/2015 07:45:20 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC) Error: (11/09/2015 07:45:14 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (11/09/2015 07:44:15 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Function Discovery Resource Publication service terminated with the following error: %%-2147467259 Error: (11/09/2015 07:42:21 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (11/09/2015 07:24:27 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147467259 CodeIntegrity: =================================== Date: 2015-10-06 21:29:41.157 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-10-06 21:29:41.157 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-10-06 21:29:41.110 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-10-06 21:29:41.110 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-06-23 16:49:23.766 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-06-23 16:49:23.748 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-06-23 16:49:23.673 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-06-23 16:49:23.667 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-20 18:07:55.897 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-20 18:07:55.895 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-2630QM CPU @ 2.00GHz Percentage of memory in use: 63% Total physical RAM: 6056.29 MB Available physical RAM: 2198.79 MB Total Virtual: 12110.76 MB Available Virtual: 6901.51 MB ==================== Drives ================================ Drive c: (Harolds) (Fixed) (Total:271 GB) (Free:51.04 GB) NTFS Drive d: () (Fixed) (Total:406.16 GB) (Free:406.03 GB) NTFS Drive e: (Sims4EP01) (CDROM) (Total:1.6 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 698.6 GB) (Disk ID: 7E0593CD) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=271 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=406.2 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=21.4 GB) - (Type=27) ==================== End of Addition.txt ============================

Hello FootballplayaDJ and welcome to WTT.

My name is Satchfan and I would be glad to help you with your computer problem.

 

Your log was not easy to read because you had "Word Wrap" on in Notepad - please make sure that it is UNchecked, (more about this below)

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.


  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Farbar Recovery Scan Tool

Please run FRST again and post the new log.

Logs to include with next post:

AdwCleaner log
JRT.txt
New Frst.txt


Thanks

Satchfan

 

Satchfan,
The "wordwrap" setting was not checked, anything else I should check before I copy and paste the next logs?

Thanks, Dustin

Thanks Satchfan,

 

(This message looks right in the preview so hopefully it won't reformat when I post)

 

# AdwCleaner v5.019 - Logfile created 11/11/2015 at 08:39:39
# Updated 08/11/2015 by Xplode
# Database : 2015-11-09.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Owner - DJHAROLD
# Running from : C:\Users\Owner\Downloads\adwcleaner_5.019.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : consumerinput_update
[-] Service Deleted : consumerinput_updatem
[-] Service Deleted : pcregservice
[-] Service Deleted : ShieldSoft

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files\CouponDownloader
[-] Folder Deleted : C:\Program Files\pcreg
[-] Folder Deleted : C:\Program Files (x86)\AnyProtectEx
[-] Folder Deleted : C:\Program Files (x86)\Bench
[-] Folder Deleted : C:\Program Files (x86)\Conduit
[-] Folder Deleted : C:\Program Files (x86)\coupon downloader
[-] Folder Deleted : C:\Program Files (x86)\PC Speed Maximizer
[-] Folder Deleted : C:\Program Files (x86)\predm
[-] Folder Deleted : C:\Program Files (x86)\Consumer Input
[-] Folder Deleted : C:\Program Files (x86)\Yahoo!\Companion
[-] Folder Deleted : C:\ProgramData\apn
[-] Folder Deleted : C:\ProgramData\Ask
[-] Folder Deleted : C:\ProgramData\Babylon
[-] Folder Deleted : C:\ProgramData\Browser Manager
[-] Folder Deleted : C:\ProgramData\Conduit
[-] Folder Deleted : C:\ProgramData\DSearchLink
[-] Folder Deleted : C:\ProgramData\Yahoo! Companion
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Conduit
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Wajam
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Consumer Input
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajbijfenhocdombdaghijgbodhiipopm
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Temp\apn
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\BabylonToolbar
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\HPAppData
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\PriceGong
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\ShopAtHome
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\Babylon
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\file scout
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\ShopAtHome
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\ShieldSoft
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\Yahoo!\Companion
[-] Folder Deleted : C:\Users\Owner\Documents\ShopToWin
[#] Folder Deleted : C:\Windows\SysNative\Tasks\pcreg

***** [ Files ] *****

[-] File Deleted : C:\END
[-] File Deleted : C:\user.js
[-] File Deleted : C:\user.js
[-] File Deleted : C:\Program Files (x86)\Mozilla Firefox\user.js
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pbjikboenpfhbbejgkoklgkhjpfogcam_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pbjikboenpfhbbejgkoklgkhjpfogcam_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ajbijfenhocdombdaghijgbodhiipopm_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ajbijfenhocdombdaghijgbodhiipopm_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_mapsgalaxy.dl.mywebsearch.com_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_mapsgalaxy.dl.mywebsearch.com_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\LocalLow\SkwConfig.bin
[-] File Deleted : C:\Users\Owner\AppData\Roaming\aps.scan.quick.results
[-] File Deleted : C:\Users\Owner\AppData\Roaming\aps.scan.results
[-] File Deleted : C:\Users\Owner\AppData\Roaming\aps.uninstall.scan.results
[-] File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default\user.js
[-] File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default\user.js
[-] File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
[-] File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
[-] File Deleted : C:\Windows\SysNative\drivers\netfilter64.sys

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : APSnotifierPP1
[-] Task Deleted : APSnotifierPP2
[-] Task Deleted : APSnotifierPP3
[-] Task Deleted : ConsumerInputUpdateTaskMachineCore
[-] Task Deleted : ConsumerInputUpdateTaskMachineUA
[-] Task Deleted : pcreg

***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
[-] Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [iLivid]
[-] Key Deleted : HKLM\SOFTWARE\Classes\*\shell\filescout
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor
[-] Key Deleted : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\dcabho.Dca
[-] Key Deleted : HKLM\SOFTWARE\Classes\dcabho.Dca.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [pcreg]
[-] Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [pcreg]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ShopAtHomeWatcher]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ShopAtHomeUpdater]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [fst_us_63]
[-] Key Deleted : HKCU\Software\5a53d7d1e634eb12
[-] Key Deleted : HKLM\SOFTWARE\5a53d7d1e634eb12
[-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3291327
[-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3316070
[-] Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [ConsumerInput@Compete]
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{40A61B9E-B111-46EE-A1F2-C1100192BA48}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{76481128-CCDC-4073-8F65-B06F23B138FC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E2C1A522-B8E1-45D1-B316-F5625004A28C}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKCU\Software\AnyProtect
[-] Key Deleted : HKCU\Software\APN PIP
[-] Key Deleted : HKCU\Software\BABSOLUTION
[-] Key Deleted : HKCU\Software\BrowserMngr
[-] Key Deleted : HKCU\Software\Compete
[-] Key Deleted : HKCU\Software\coupon downloader
[-] Key Deleted : HKCU\Software\DataMngr
[+] Key Deleted : HKCU\Software\DataMngr_Toolbar
[-] Key Deleted : HKCU\Software\ilivid
[-] Key Deleted : HKCU\Software\IM
[-] Key Deleted : HKCU\Software\ImInstaller
[-] Key Deleted : HKCU\Software\InstallCore
[-] Key Deleted : HKCU\Software\iVIDI Plugin
[-] Key Deleted : HKCU\Software\pc speed maximizer
[-] Key Deleted : HKCU\Software\powerpack
[-] Key Deleted : HKCU\Software\SweetIM
[-] Key Deleted : HKCU\Software\Tutorials
[-] Key Deleted : HKCU\Software\TutoTag
[-] Key Deleted : HKCU\Software\iVIDI.org
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Compete
[-] Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
[-] Key Deleted : HKCU\Software\AppDataLow\Software\CouponDownloader
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Freecause
[-] Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\AdvertisingSupport
[-] Key Deleted : HKLM\SOFTWARE\Babylon
[-] Key Deleted : HKLM\SOFTWARE\BrowserMngr
[-] Key Deleted : HKLM\SOFTWARE\CompeteInc
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\DataMngr
[-] Key Deleted : HKLM\SOFTWARE\FreeSoftToday
[-] Key Deleted : HKLM\SOFTWARE\InstallIQ
[-] Key Deleted : HKLM\SOFTWARE\SweetIM
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Consumer Input Installer
[-] Key Deleted : [x64] HKLM\SOFTWARE\CouponDownloader
[-] Key Deleted : [x64] HKLM\SOFTWARE\LevelQualityWatcher
[-] Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork
[-] Key Deleted : HKU\.DEFAULT\Software\BrowserMngr
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\coupon downloader
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\CouponDownloader
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{47AE1BA9-0BD1-44F4-88AE-45F8F7B605EF}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}

***** [ Web browsers ] *****

[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxps://search.yahoo.com/?type=444990&fr=spigot-nt-gc");
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : aaaaaiabcopkplhgaedhbloeejhhankf
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ajbijfenhocdombdaghijgbodhiipopm
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : jpmbfleldcgkldadpdinhjjopdfpjfjp
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : pbjikboenpfhbbejgkoklgkhjpfogcam

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [15703 bytes] ##########
 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on Wed 11/11/2015 at  8:51:23.84
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks

Successfully deleted: [Task] C:\Windows\system32\tasks\CIMT_S-1-5-21-2250843709-3518569377-988331573-1002
Successfully deleted: [Task] C:\Windows\system32\tasks\EasySpeedUpManager
Successfully deleted: [Task] C:\Windows\Tasks\CIMT_S-1-5-21-2250843709-3518569377-988331573-1002.job



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer



~~~ Files

Successfully deleted: [File] C:\Users\Owner\Appdata\Local\proxy.log
Successfully deleted: [File] C:\Windows\SysWOW64\sho293F.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho2945.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho2B92.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho3D2A.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho513A.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho8761.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho87E.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoA377.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoB3AC.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoB45D.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoBDB5.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoBFDA.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoC171.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoD86A.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoDAB5.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoE30C.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoF7C8.tmp



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Owner\Appdata\Local\{3322171E-8314-4C3D-944C-D43367347B3F}
Successfully deleted: [Empty Folder] C:\Users\Owner\Appdata\Local\{61EBAB25-96EA-45A1-BCB9-8AB45A83BC63}
Successfully deleted: [Empty Folder] C:\Users\Owner\Appdata\Local\{9F478891-DEE9-4AB9-8E5F-BD548970449C}
Successfully deleted: [Empty Folder] C:\Users\Owner\Appdata\Local\{C2741235-F38B-4EC4-9A03-5DE82ECE7138}
Successfully deleted: [Empty Folder] C:\Users\Owner\Appdata\Local\{F0F1928C-0926-4DD4-8B38-ECE4975886BA}
Successfully deleted: [Folder] C:\ai_recyclebin
Successfully deleted: [Folder] C:\Program Files (x86)\consumer input
Successfully deleted: [Folder] C:\Program Files (x86)\Shop to Win 36
Successfully deleted: [Folder] C:\Program Files (x86)\strongvault online backup
Successfully deleted: [Folder] C:\Program Files\004
Successfully deleted: [Folder] C:\ProgramData\best buy pc app
Successfully deleted: [Folder] C:\ProgramData\strongvault online backup
Successfully deleted: [Folder] C:\Users\Owner\Appdata\Local\best buy pc app
Successfully deleted: [Folder] C:\Users\Owner\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\Users\Owner\Appdata\Local\strongvault online backup
Successfully deleted: [Folder] C:\Users\Owner\AppData\Roaming\compete
Successfully deleted: [Folder] C:\Windows\SysWOW64\ai_recyclebin



~~~ Chrome


[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
pbjikboenpfhbbejgkoklgkhjpfogcam

[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 11/11/2015 at  8:58:00.50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by [removed] (administrator) on DJHAROLD (11-11-2015 10:57:31)
Running from C:\Users\[removed]\Downloads
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avp.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avpui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11660904 2010-11-30] (Realtek Semiconductor)
HKLM\…\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-11-01] (Intel(R) Corporation)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2817872 2012-04-25] (ELAN Microelectronics Corp.)
HKLM\…\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.)
HKLM\…\Run: [pcreg] => C:\Program Files\pcreg\service.exe
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-08-13] (Apple Inc.)
HKLM-x32\…\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-01] (CyberLink)
HKLM-x32\…\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2010-08-25] (cyberlink)
HKLM-x32\…\Run: [Samsung PanelMgr] => C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] ()
HKLM-x32\…\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-09] (Microsoft Corporation)
HKLM-x32\…\Run: [MaxMenuMgr] => C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [185640 2009-05-01] (Seagate LLC)
HKLM-x32\…\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-09-23] (Apple Inc.)
HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.)
HKLM-x32\…\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
Winlogon\Notify\DfLogon: LogonDll.dll [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKLM\…\Policies\Explorer: [NoDrives] 524288
HKLM\…\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Run: [BackupAgent] => C:\Program Files (x86)\Strongvault Online Backup\BackupAgent.exe
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Run: [NVIDIA nTune] => "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\MountPoints2: {3e04a122-3e0b-11e0-8fec-806e6f6e6963} - E:\Autorun.exe
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\…\Policies\Explorer: [HideSCAHealth] 1
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2012-06-20]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk [2014-02-04]
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-02-06]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-02-06]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{5C6A50C2-DA0F-433D-A99D-E6EA9BB7587B}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{673CB153-F46F-45C4-9695-9F8CC0C87D90}: [DhcpNameServer] [removed] [removed]

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/
SearchScopes: HKLM-x32 -> DefaultScope {7102907D-3ADD-49A3-809A-E7D6000A2745} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2250843709-3518569377-988331573-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-09-29] (Microsoft Corporation)
BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-10-28] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-28] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14] (CANON INC.)
BHO-x32: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-26] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-14] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation)
BHO-x32: W2PBrowser Class -> {AA609D72-8482-4076-8991-8CDAE5B93BCB} -> C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll [2010-09-16] ()
BHO-x32: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-10-28] (Microsoft Corporation)
BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-14] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14] (CANON INC.)
Toolbar: HKU\S-1-5-21-2250843709-3518569377-988331573-1002 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default
FF DefaultSearchEngine:  Yahoo!
FF DefaultSearchEngine.US:  Yahoo!
FF SelectedSearchEngine:  Yahoo!
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-10] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-07-30] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-14] (Oracle Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-20] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-26] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2250843709-3518569377-988331573-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Owner\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default\searchplugins\shield Yahoo!.xml [2015-11-09]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-02-06] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-02-06] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-02-06] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-06-20] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed]
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] [not signed]
FF HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-06]
CHR Extension: (Google Docs) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-06]
CHR Extension: (Google Drive) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Adblock Plus) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-09-26]
CHR Extension: (Google Search) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Kaspersky Protection) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-02-23]
CHR Extension: (Google Sheets) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-06]
CHR Extension: (Google Docs Offline) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-01]
CHR Extension: (Do Not Disturb!) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilnddakjdkpofoablibghfikpeknhbia [2015-02-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-27]
CHR Extension: (Gmail) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30]
CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKLM-x32\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 AVP15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avp.exe [194000 2015-06-23] (Kaspersky Lab ZAO)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2780856 2015-10-07] (Microsoft Corporation)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [246256 2010-08-24] (CyberLink)
U2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [408576 2010-08-31] (Red Bend Ltd.) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-11-01] ()
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2057736 2015-09-07] (Electronic Arts)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [911872 2010-08-31] (Intel(R) Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [247016 2015-06-23] (Kaspersky Lab UK Ltd)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-23] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [64368 2015-06-23] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [159960 2015-06-23] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [225976 2015-07-01] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [831672 2015-10-06] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [39280 2015-06-23] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [40304 2015-06-23] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [39280 2015-06-23] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [24944 2015-06-23] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [65208 2015-06-23] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [85360 2015-06-23] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [190648 2015-10-06] (Kaspersky Lab ZAO)
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [52320 2013-03-14] (hxxp://libusb-win32.sourceforge.net)
S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2011-02-21] (Windows (R) 2003 DDK 3790 provider)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 ALSysIO; \??\C:\Users\Owner\AppData\Local\Temp\ALSysIO64.sys [X]
S3 WinRing0_1_2_0; \??\C:\Users\Owner\AppData\Local\Temp\tmpA3EC.tmp [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-11 08:58 - 2015-11-11 08:58 - 00003981 _____ C:\Users\Owner\Desktop\JRT.txt
2015-11-11 08:50 - 2015-11-11 08:50 - 01801288 _____ (Malwarebytes) C:\Users\Owner\Downloads\JRT.exe
2015-11-11 08:35 - 2015-11-11 08:39 - 00000000 ____D C:\AdwCleaner
2015-11-11 08:34 - 2015-11-11 08:34 - 01712128 _____ C:\Users\Owner\Downloads\adwcleaner_5.019.exe
2015-11-10 21:39 - 2015-11-10 21:39 - 05286088 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-11-10 11:22 - 2015-11-10 11:22 - 00002527 _____ C:\Users\Owner\Desktop\aswMBR.txt
2015-11-10 11:22 - 2015-11-10 11:22 - 00000512 _____ C:\Users\Owner\Desktop\MBR.dat
2015-11-09 20:24 - 2015-11-09 20:25 - 00046268 _____ C:\Users\Owner\Downloads\Addition.txt
2015-11-09 20:21 - 2015-11-11 10:57 - 00025231 _____ C:\Users\Owner\Downloads\FRST.txt
2015-11-09 20:16 - 2015-11-11 10:57 - 00000000 ____D C:\FRST
2015-11-09 20:16 - 2015-11-09 20:19 - 00001447 _____ C:\Users\Owner\Desktop\FRST64 - Shortcut.lnk
2015-11-09 20:16 - 2015-11-09 20:16 - 00001447 _____ C:\Users\Owner\Desktop\aswMBR - Shortcut.lnk
2015-11-09 20:16 - 2015-11-09 20:16 - 00001420 _____ C:\Users\Owner\Desktop\dds - Shortcut.lnk
2015-11-09 20:13 - 2015-11-09 20:13 - 02198528 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
2015-11-09 20:10 - 2015-11-09 20:10 - 00027362 _____ C:\Users\Owner\Desktop\dds.txt
2015-11-09 20:10 - 2015-11-09 20:10 - 00006604 _____ C:\Users\Owner\Desktop\attach.txt
2015-11-09 20:08 - 2015-11-09 20:08 - 05198336 _____ (AVAST Software) C:\Users\Owner\Downloads\aswMBR.exe
2015-11-09 20:05 - 2015-11-09 20:05 - 00688992 ____R (Swearware) C:\Users\Owner\Downloads\dds.scr
2015-11-09 19:48 - 2015-11-09 19:48 - 00000000 ____D C:\Users\Owner\AppData\Local\Macromedia
2015-11-09 19:38 - 2015-11-09 19:53 - 00000000 ____D C:\Users\Owner\AppData\Local\Mozilla
2015-11-09 19:37 - 2015-11-09 19:37 - 00001166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-11-09 19:37 - 2015-11-09 19:37 - 00001154 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-11-09 19:37 - 2015-11-09 19:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-09 19:35 - 2015-11-09 19:35 - 00243656 _____ C:\Users\Owner\Downloads\Firefox Setup Stub 42.0.exe
2015-11-06 19:24 - 2015-11-06 19:24 - 00000000 ___HD C:\OneDriveTemp
2015-11-05 17:03 - 2015-11-05 17:03 - 02077392 _____ (Microsoft Corporation) C:\Users\Owner\Downloads\IE11-Windows6.1 (2).exe
2015-11-05 16:59 - 2015-11-05 16:59 - 02077392 _____ (Microsoft Corporation) C:\Users\Owner\Downloads\IE11-Windows6.1 (1).exe
2015-11-03 22:22 - 2015-11-03 22:22 - 00000000 ____D C:\Users\Owner\Desktop\2015 FALL FAMILY PICS
2015-10-28 16:27 - 2015-10-28 16:27 - 01089320 _____ (Unity Technologies ApS) C:\Users\Owner\Downloads\UnityWebPlayer.exe
2015-10-25 19:28 - 2015-10-25 19:29 - 00000000 ____D C:\Users\Owner\Desktop\10-20-15

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-11 10:59 - 2011-02-06 02:30 - 00000050 _____ C:\Windows\system32\SupplicantTest.log
2015-11-11 10:54 - 2011-09-21 21:56 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-11-11 10:38 - 2012-05-01 18:06 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-11 09:58 - 2011-02-06 19:20 - 01136077 _____ C:\Windows\WindowsUpdate.log
2015-11-11 09:29 - 2009-07-13 22:45 - 00022976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-11 09:29 - 2009-07-13 22:45 - 00022976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-11 08:53 - 2013-11-28 11:20 - 00013206 _____ C:\Windows\IE11_main.log
2015-11-11 08:52 - 2013-09-04 19:54 - 00000000 ___RD C:\Users\Owner\SkyDrive
2015-11-11 08:50 - 2009-07-13 23:13 - 00006458 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-11 08:43 - 2011-02-06 03:41 - 01003622 _____ C:\Windows\PFRO.log
2015-11-11 08:43 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-11 08:43 - 2009-07-13 22:51 - 00129233 _____ C:\Windows\setupact.log
2015-11-11 08:40 - 2012-08-17 09:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-11 08:40 - 2012-06-20 12:15 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Yahoo!
2015-11-11 08:39 - 2012-06-20 12:14 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2015-11-10 21:41 - 2012-05-01 18:06 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-10 21:41 - 2011-09-25 18:57 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-04 21:08 - 2013-02-13 20:42 - 00000000 ____D C:\ProgramData\CanonIJPLM
2015-11-03 22:59 - 2011-09-18 22:14 - 00000000 ____D C:\Users\Owner\AppData\Local\CrashDumps
2015-11-02 23:29 - 2014-08-10 13:06 - 00002164 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-11-02 15:56 - 2014-05-18 08:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
2015-11-02 15:55 - 2014-05-18 08:19 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Real
2015-11-02 15:55 - 2014-05-18 08:19 - 00000000 ____D C:\Program Files (x86)\Real
2015-11-02 15:54 - 2014-09-02 17:46 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-02 15:54 - 2014-05-18 08:18 - 00000000 ____D C:\ProgramData\Real
2015-11-02 14:59 - 2012-11-07 01:08 - 00000000 ____D C:\Users\Owner\AppData\Local\Unity
2015-11-02 14:48 - 2014-05-18 08:37 - 00000000 ____D C:\temp
2015-11-01 22:38 - 2015-01-01 16:32 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-10-28 11:04 - 2013-09-04 19:24 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-10-20 23:02 - 2014-11-25 19:02 - 00000000 ____D C:\Users\Owner\Desktop\EmmaKatelynn
2015-10-20 21:14 - 2014-01-01 19:03 - 00461824 ___SH C:\Users\Owner\Desktop\Thumbs.db
2015-10-20 20:53 - 2015-09-29 18:27 - 00000000 ____D C:\Users\Owner\Desktop\Camera
2015-10-15 10:15 - 2013-03-07 21:10 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk

==================== Files in the root of some directories =======

2013-07-15 20:29 - 2013-07-15 20:28 - 2409984 _____ () C:\Program Files\PX5 Advanced Sound Editor.msi
2013-08-17 13:06 - 2013-08-18 10:10 - 0000496 _____ () C:\Users\Owner\AppData\Roaming\UserMetrics.osl
2012-08-09 00:23 - 2012-08-09 00:23 - 0022440 _____ () C:\Users\Owner\AppData\Local\190833628_Setup.crx
2012-08-09 14:09 - 2012-08-09 14:09 - 0022440 _____ () C:\Users\Owner\AppData\Local\240382890_Setup.crx
2012-08-22 17:35 - 2012-08-22 17:35 - 0022440 _____ () C:\Users\Owner\AppData\Local\8976367_Setup.crx
2012-08-17 09:47 - 2012-08-17 09:46 - 0022440 _____ () C:\Users\Owner\AppData\Local\91735345_Setup.crx
2013-10-23 12:25 - 2013-10-23 12:25 - 0000017 _____ () C:\Users\Owner\AppData\Local\resmon.resmoncfg
2013-07-24 14:25 - 2013-07-24 14:25 - 0000000 _____ () C:\ProgramData\2c233b353d3d352c_c
2012-06-20 10:31 - 2012-06-20 12:43 - 0001248 _____ () C:\ProgramData\hpzinstall.log
2011-02-06 02:46 - 2011-02-06 02:46 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2011-02-06 02:42 - 2011-02-06 02:43 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2011-02-06 02:39 - 2011-02-06 02:42 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
2011-02-06 02:43 - 2011-02-06 02:44 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2011-02-06 02:44 - 2011-02-06 02:45 - 0000108 _____ () C:\ProgramData\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}.log

Some files in TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\APNSetup.exe
C:\Users\Owner\AppData\Local\Temp\autorun.dll
C:\Users\Owner\AppData\Local\Temp\C071.exe
C:\Users\Owner\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\lowproc.exe
C:\Users\Owner\AppData\Local\Temp\sqlite3.dll
C:\Users\Owner\AppData\Local\Temp\stubhelper.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-11-10 00:33

==================== End of FRST.txt ============================

 

They were fine thanks.

 

Hopefully things have already improved somewhat but we still have work to do.

 

I have to pop out for a while but will check the new FRST log and post the next set of instructions later.

 

Meanwhile, you need to move Farbar Recovery Scan Tool to your desktop otherwise any "fix" I ask you to run will not work.

  • go to your Downloads folder and locate Farbar Recovery Scan Tool
  • right click and select Cut
  • go to an empty spot on your desktop, right click and select Paste

Farbar Recovery Scan Tool should now be on your desktop.

 

Satchfan

YESSSS! already seeing drastic improvement! All programs you have had me install are moved to the desktop. No worries, I understand you have your own life to enjoy or work away lol.

 

Thanks again,

Dustin

As I said in the previous post, please make sure you have moved FRST to your desktop before following these instructions.


Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

HKLM\…\Run: [pcreg] => C:\Program Files\pcreg\service.exe
HKLM-x32\…\Run: [] => [X]
Winlogon\Notify\DfLogon: LogonDll.dll [X]
HKLM\…\Policies\Explorer: [NoDrives] 524288
SearchScopes: HKLM-x32 -> DefaultScope {7102907D-3ADD-49A3-809A-E7D6000A2745} URL =
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
CHR HKLM\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKLM-x32\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
S3 ALSysIO; \??\C:\Users\Owner\AppData\Local\Temp\ALSysIO64.sys [X]
S3 WinRing0_1_2_0; \??\C:\Users\Owner\AppData\Local\Temp\tmpA3EC.tmp [X]
CMD: ipconfig /flushdns
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

================================================

Download Malwarebytes-Anti-Malware

Click here.

  • double-click mbam-setup.exe and follow the prompts to install the program – (Note: Vista & Windows 7 users, please right-click and select “Run as Administrator”)
  • select the “Scan” tab at the top
  • there are three scan types; choose Threat Scan, then click on Scan
  • when the scan is complete, if no malicious items are found you can close the program
  • if malicious items are found be sure that everything is checked and click Quarantine
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.

NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Logs to include with the next post:

Fixlog.txt
Mbam.txt


Can you tell me what outstanding problems you have.

Satchfan

 

Satchfan,

 

I can't create new folders

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by [removed] (2015-11-11 17:30:57) Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************

HKLM\…\Run: [pcreg] => C:\Program Files\pcreg\service.exe
HKLM-x32\…\Run: [] => [X]
Winlogon\Notify\DfLogon: LogonDll.dll [X]
HKLM\…\Policies\Explorer: [NoDrives] 524288
SearchScopes: HKLM-x32 -> DefaultScope {7102907D-3ADD-49A3-809A-E7D6000A2745} URL =
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
CHR HKLM\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKLM-x32\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
S3 ALSysIO; \??\C:\Users\Owner\AppData\Local\Temp\ALSysIO64.sys [X]
S3 WinRing0_1_2_0; \??\C:\Users\Owner\AppData\Local\Temp\tmpA3EC.tmp [X]
CMD: ipconfig /flushdns
EmptyTemp:
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\pcreg => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DfLogon" => key removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDrives => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758} => value removed successfully
"HKLM\SOFTWARE\Google\Chrome\Extensions\mgjkknncnlepghplinfpikcijdbmidbg" => key removed successfully
C:\Users\Owner\AppData\Local\8976367_Setup.crx => moved successfully
"HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\Google\Chrome\Extensions\mgjkknncnlepghplinfpikcijdbmidbg" => key removed successfully
"C:\Users\Owner\AppData\Local\8976367_Setup.crx" => not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mgjkknncnlepghplinfpikcijdbmidbg" => key removed successfully
"C:\Users\Owner\AppData\Local\8976367_Setup.crx" => not found.
ALSysIO => service removed successfully
WinRing0_1_2_0 => service removed successfully

=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

EmptyTemp: => 12 GB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 17:32:31 ====

 

##########################################################################################################

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 11/11/2015
Scan Time: 5:42 PM
Logfile: MBAM.txt
Administrator: Yes

Version: 2.2.0.1024
Malware Database: v2015.11.11.08
Rootkit Database: v2015.11.04.02
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Owner

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 436491
Time Elapsed: 40 min, 46 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 143
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\APPID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassSvc, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\APPID\{D5FA0C65-08BE-4F86-B30F-2E285694863A}, Quarantined, [7c4803797c0fac8ac16742f5c73bb848],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D5FA0C65-08BE-4F86-B30F-2E285694863A}, Quarantined, [7c4803797c0fac8ac16742f5c73bb848],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{D5FA0C65-08BE-4F86-B30F-2E285694863A}, Quarantined, [7c4803797c0fac8ac16742f5c73bb848],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\APPID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3COMClassService, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3COMClassService.1.0, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3COMClassService, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3COMClassService.1.0, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3COMClassService, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3COMClassService.1.0, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0C6D49F4-6E41-4632-BE86-F210D5D894BA}, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback.1.0, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebMachineFallback, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback.1.0, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebMachineFallback.1.0, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{0C6D49F4-6E41-4632-BE86-F210D5D894BA}, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0DC6DC6C-048E-4B03-8F2D-7D6B90571172}, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreMachineClass.1, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreMachineClass, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreMachineClass, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoreMachineClass, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreMachineClass.1, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoreMachineClass.1, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{0DC6DC6C-048E-4B03-8F2D-7D6B90571172}, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1AB0B6A3-9BC5-419B-B86D-40FA2998A131}, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreClass.1, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreClass, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreClass, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoreClass, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreClass.1, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoreClass.1, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{1AB0B6A3-9BC5-419B-B86D-40FA2998A131}, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3A40DF53-EB22-49FE-9246-8084403424E7}, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine.1.0, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CredentialDialogMachine, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine.1.0, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CredentialDialogMachine.1.0, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3A40DF53-EB22-49FE-9246-8084403424E7}, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3DBBAB3C-4077-4EC4-BF2C-E89C7784846A}, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebSvc.1.0, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebSvc, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebSvc, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebSvc, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebSvc.1.0, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebSvc.1.0, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3DBBAB3C-4077-4EC4-BF2C-E89C7784846A}, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5CF02202-6278-47EE-9947-C2D0A057EABD}, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.ProcessLauncher.1.0, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.ProcessLauncher, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.ProcessLauncher, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.ProcessLauncher, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.ProcessLauncher.1.0, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.ProcessLauncher.1.0, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{5CF02202-6278-47EE-9947-C2D0A057EABD}, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{65BF611F-85CD-4E7F-966C-853573462C14}, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{65BF611F-85CD-4E7F-966C-853573462C14}, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\DcaHost.DcaHost.1, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\DcaHost.DcaHost, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DcaHost.DcaHost, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\DcaHost.DcaHost, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DcaHost.DcaHost.1, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\DcaHost.DcaHost.1, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{87A125E5-B663-496F-954E-488A82FAC012}, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoCreateAsync.1.0, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoCreateAsync, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoCreateAsync, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoCreateAsync, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoCreateAsync.1.0, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoCreateAsync.1.0, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{87A125E5-B663-496F-954E-488A82FAC012}, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8AF9C44C-E497-4776-A7EF-F6455F982825}, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachine, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{8AF9C44C-E497-4776-A7EF-F6455F982825}, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D4F484EE-BF68-4B61-AB83-C1E0EF88D876}, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachine.1.0, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachine, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachine, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebMachine, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachine.1.0, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebMachine.1.0, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D4F484EE-BF68-4B61-AB83-C1E0EF88D876}, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine.1.0, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInput.OneClickProcessLauncherMachine, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine.1.0, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInput.OneClickProcessLauncherMachine.1.0, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\INTERFACE\{C015D269-0F4E-4B52-A91F-721F6DAC9437}, Quarantined, [9f253f3d6d1e3402ec3193a406fc10f0],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}, Quarantined, [d9eb5c204e3d59dd95889c9b857d19e7],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C015D269-0F4E-4B52-A91F-721F6DAC9437}, Quarantined, [d9eb5c204e3d59dd95889c9b857d19e7],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C015D269-0F4E-4B52-A91F-721F6DAC9437}, Quarantined, [d9eb5c204e3d59dd95889c9b857d19e7],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}, Quarantined, [d7ede696e5a61e1853cafc3bea18b34d],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}, Quarantined, [5a6a6a12cbc075c11a03013608fa32ce],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\APPID\ConsumerInputUpdate.exe, Quarantined, [7450d5a7c9c223130952c79ea0634bb5],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\APPID\dca-host.exe, Quarantined, [269e06766c1f41f5a907693c4eb5ce32],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\ConsumerInputUpdate.exe, Quarantined, [566eb5c7bfcc78be2b308ed7739036ca],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\dca-host.exe, Quarantined, [5b69ec90fd8e2a0ce8c8e9bc4fb40cf4],
PUP.Optional.BrowserGuardian, HKLM\SOFTWARE\WOW6432NODE\Browser Guardian, Quarantined, [695bcab2b2d904328d3cf56b2cd7d32d],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\ConsumerInput, Quarantined, [7b4978046c1f46f0cb91214409fa956b],
PUP.Optional.SavingsExplorer, HKLM\SOFTWARE\WOW6432NODE\Savings Explorer, Quarantined, [457f3a42a5e60b2b3c6be3a89a697789],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\ConsumerInputUpdate.exe, Quarantined, [17ad8cf0ed9e092d9cbf86dfd42f7090],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\dca-host.exe, Quarantined, [3a8a7a02c4c7e650268a683de61d29d7],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\com.compete.cinm, Quarantined, [913378043c4f38fe1d964f541be808f8],
PUP.Optional.Ividi, HKU\S-1-5-21-2250843709-3518569377-988331573-1000\SOFTWARE\iVIDI Plugin, Quarantined, [7c48aece4d3e4ee837e07503de25f010],
PUP.Optional.Ividi, HKU\S-1-5-21-2250843709-3518569377-988331573-1000\SOFTWARE\iVIDI.org, Quarantined, [42823547503b4beb7c9ccfa9da29e51b],
PUP.Optional.ConsumerInput, HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\ConsumerInput, Quarantined, [ebd95a22eba058dedb7e96cfd42f3bc5],

Registry Values: 8
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}|AppPath, C:\Program Files (x86)\Consumer Input\InternetExplorer, Quarantined, [a3213b41dbb0d75fcbe90f9422e144bc]
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\Mysearchdial\1.8.29.0\, Quarantined, [6b5975077a11f73f0ec9067b6b98f40c]
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}|AppPath, C:\Program Files (x86)\Consumer Input\InternetExplorer, Quarantined, [c7fd6418c1ca8da9f0c4c3e0bc47e818]
PUP.Optional.Perion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{988FB558-B56F-4CE6-9A67-5B3F04B5F064}, v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Windows\System32\dmwu.exe|Name=dmwu|, Quarantined, [c9fb4933e6a5ff37b810fbdae122b64a]
PUP.Optional.Perion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{A61DDF12-3250-4263-9375-67B9E7080AC3}, v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Windows\System32\dmwu.exe|Name=dmwu|, Quarantined, [457f7606028952e4e1e7785dd42fb749]
PUP.Optional.Perion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{52BD859B-2D82-4D5B-AC8D-E187D1163F17}, v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Windows\SysWOW64\ARFC\wrtc.exe|Name=wrtc|, Quarantined, [17ad572538537fb748670fc7bd46bd43]
PUP.Optional.Perion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{E4756446-ADA3-4A70-9F0D-89F79C723832}, v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Windows\SysWOW64\ARFC\wrtc.exe|Name=wrtc|, Quarantined, [e3e1a4d86427c175f3bc1eb8de257987]
PUM.Optional.LowRiskFileTypes, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ASSOCIATIONS|LowRiskFileTypes, .zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.log;, Quarantined, [b014512b2a61c47200bf6d6038cb867a]

Registry Data: 0
(No malicious items detected)

Folders: 1
PUP.Optional.Ividi, C:\Program Files (x86)\iVIDI.org plugin, Quarantined, [556f87f59eed0a2c976c29417f8307f9],

Files: 5
PUP.Optional.Ividi, C:\Program Files (x86)\iVIDI.org plugin\IEhelperActiveX.dll, Quarantined, [2f953c402b60063029843df003fdee12],
PUP.Optional.Conduit, C:\temp\embededstub_new2.exe, Quarantined, [f2d288f41e6d76c02571240836ca8d73],
PUP.Optional.ExcitingApps, C:\temp\guardian.exe, Quarantined, [70547dffc2c952e47e580a1db8498e72],
PUP.Optional.CouponDownloader, C:\temp\t_ff.exe, Quarantined, [5272d9a34d3eb284f8aa7daf38c86b95],
PUP.Optional.RocketFuel, C:\Users\Owner\Downloads\Xvid_RocketFuelInstaller.exe, Quarantined, [41835c20a5e644f2831d130f1de7f30d],

Physical Sectors: 0
(No malicious items detected)


(end)

How are you trying to create a new folder, ie are you using right-click or by using the "File > New Folder" menu in Windows Explorer?

Can you tell me how your computer is running now.

Satchfan

I have tried both ways, the option for creating a folder is just not there.

The computer seems to be running quite well, I have been able to do several things it was giving me problems with before

Dustin

Let’s try using a command prompt to try and create a new folder.

To do this, follow the steps below:

  • click on Start, then in the search box type CMD
  • right-click, on cmd and from the menu that appears, click on Run as administrator
  • type the following in the command prompt:

mkdir folderName (replace “folderName” with the folder name of your choice)

Check if the folder has been created on the C drive
 

There is a registry fix we could try but first I’d like you to check your system files:

  • click on Start, All Programs. Accessories, then right click on Command Prompt and click on Run as administrator
  • type in sfc /scannow in the command window and press Enter - note the space between the c and the /
  • if any files require replacing SFC will replace them. You may be asked to insert your Windows 7 Disk for this process to continue. This can be done with a borrowed Windows 7 disk if you don't have one.
  • be patient because the scan may take some time.
  • allow the scan to run and when completed, reboot the system.

 

Let me know the result.

 

Satchfan
 

I ran the sfc scan and it says "Windows Resource Protection found corrupt files but was unable to fix some of them". It also gave me a log, but it is quite long so I will only post if you would want to see it.

 

Dustin

We need to see what can't be fixed:

  • click on Start, All Programs. Accessories, then right click on Command Prompt and click on Run as administrator
  • type in the following command, (or better still. copy and paste), then press Enter
    findstr /c:"[SR]" %windir%\logs\cbs\cbs.log >%userprofile%\Desktop\sfcdetails.txt
    
  • close the cmd prompt by typing Exit and then pressing the return key
  • click on the sfcdetails.txt file that has just been placed on your desktop and copy/paste the findings in your next reply.

Thanks

Satchfan

 

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI