Google redirect plus more? [Solved]
11 min read
Hello FootballplayaDJ and welcome to WTT.
My name is Satchfan and I would be glad to help you with your computer problem.
Your log was not easy to read because you had "Word Wrap" on in Notepad - please make sure that it is UNchecked, (more about this below)
Please read the following guidelines which will help to make cleaning your machine easier:
- please follow all instructions in the order posted
- please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
- all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
- if you don't understand something, please don't hesitate to ask for clarification before proceeding
- the fixes are specific to your problem and should only be used for this issue on this machine.
- please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
===================================================
Note: Please run these in the order given in the instructions.
===================================================
Download and run AdwCleaner
Download AdwCleaner from here and save it to your desktop.
- run AdwCleaner
- when it has finished, select Clean
- if it asks to reboot, allow the reboot
- on reboot a log will be produced; please attach the content of the log to your next reply.
===================================================
Download and run Junkware Removal Tool
[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
- shut down your protection software now to avoid potential conflicts.
- run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
- the tool will open and start scanning your system
- please be patient as this can take a while to complete depending on your system's specifications
- on completion, a log (JRT.txt) is saved to your desktop and will automatically open
- post the contents of JRT.txt into your next message.
===================================================
Run Farbar Recovery Scan Tool
Please run FRST again and post the new log.
Logs to include with next post:
AdwCleaner log
JRT.txt
New Frst.txt
Thanks
Satchfan
The "wordwrap" setting was not checked, anything else I should check before I copy and paste the next logs?
Thanks, Dustin
Thanks Satchfan,
(This message looks right in the preview so hopefully it won't reformat when I post)
# AdwCleaner v5.019 - Logfile created 11/11/2015 at 08:39:39
# Updated 08/11/2015 by Xplode
# Database : 2015-11-09.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Owner - DJHAROLD
# Running from : C:\Users\Owner\Downloads\adwcleaner_5.019.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
[-] Service Deleted : consumerinput_update
[-] Service Deleted : consumerinput_updatem
[-] Service Deleted : pcregservice
[-] Service Deleted : ShieldSoft
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files\CouponDownloader
[-] Folder Deleted : C:\Program Files\pcreg
[-] Folder Deleted : C:\Program Files (x86)\AnyProtectEx
[-] Folder Deleted : C:\Program Files (x86)\Bench
[-] Folder Deleted : C:\Program Files (x86)\Conduit
[-] Folder Deleted : C:\Program Files (x86)\coupon downloader
[-] Folder Deleted : C:\Program Files (x86)\PC Speed Maximizer
[-] Folder Deleted : C:\Program Files (x86)\predm
[-] Folder Deleted : C:\Program Files (x86)\Consumer Input
[-] Folder Deleted : C:\Program Files (x86)\Yahoo!\Companion
[-] Folder Deleted : C:\ProgramData\apn
[-] Folder Deleted : C:\ProgramData\Ask
[-] Folder Deleted : C:\ProgramData\Babylon
[-] Folder Deleted : C:\ProgramData\Browser Manager
[-] Folder Deleted : C:\ProgramData\Conduit
[-] Folder Deleted : C:\ProgramData\DSearchLink
[-] Folder Deleted : C:\ProgramData\Yahoo! Companion
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Conduit
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Wajam
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Consumer Input
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajbijfenhocdombdaghijgbodhiipopm
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Temp\apn
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\BabylonToolbar
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\HPAppData
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\PriceGong
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\ShopAtHome
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\Babylon
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\file scout
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\ShopAtHome
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\ShieldSoft
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\Yahoo!\Companion
[-] Folder Deleted : C:\Users\Owner\Documents\ShopToWin
[#] Folder Deleted : C:\Windows\SysNative\Tasks\pcreg
***** [ Files ] *****
[-] File Deleted : C:\END
[-] File Deleted : C:\user.js
[-] File Deleted : C:\user.js
[-] File Deleted : C:\Program Files (x86)\Mozilla Firefox\user.js
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pbjikboenpfhbbejgkoklgkhjpfogcam_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pbjikboenpfhbbejgkoklgkhjpfogcam_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ajbijfenhocdombdaghijgbodhiipopm_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ajbijfenhocdombdaghijgbodhiipopm_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_mapsgalaxy.dl.mywebsearch.com_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_mapsgalaxy.dl.mywebsearch.com_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\LocalLow\SkwConfig.bin
[-] File Deleted : C:\Users\Owner\AppData\Roaming\aps.scan.quick.results
[-] File Deleted : C:\Users\Owner\AppData\Roaming\aps.scan.results
[-] File Deleted : C:\Users\Owner\AppData\Roaming\aps.uninstall.scan.results
[-] File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default\user.js
[-] File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default\user.js
[-] File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
[-] File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
[-] File Deleted : C:\Windows\SysNative\drivers\netfilter64.sys
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
[-] Task Deleted : APSnotifierPP1
[-] Task Deleted : APSnotifierPP2
[-] Task Deleted : APSnotifierPP3
[-] Task Deleted : ConsumerInputUpdateTaskMachineCore
[-] Task Deleted : ConsumerInputUpdateTaskMachineUA
[-] Task Deleted : pcreg
***** [ Registry ] *****
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
[-] Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [iLivid]
[-] Key Deleted : HKLM\SOFTWARE\Classes\*\shell\filescout
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor
[-] Key Deleted : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\dcabho.Dca
[-] Key Deleted : HKLM\SOFTWARE\Classes\dcabho.Dca.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [pcreg]
[-] Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [pcreg]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ShopAtHomeWatcher]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ShopAtHomeUpdater]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [fst_us_63]
[-] Key Deleted : HKCU\Software\5a53d7d1e634eb12
[-] Key Deleted : HKLM\SOFTWARE\5a53d7d1e634eb12
[-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3291327
[-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3316070
[-] Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [ConsumerInput@Compete]
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{40A61B9E-B111-46EE-A1F2-C1100192BA48}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{76481128-CCDC-4073-8F65-B06F23B138FC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E2C1A522-B8E1-45D1-B316-F5625004A28C}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
[-] Key Deleted : HKCU\Software\AnyProtect
[-] Key Deleted : HKCU\Software\APN PIP
[-] Key Deleted : HKCU\Software\BABSOLUTION
[-] Key Deleted : HKCU\Software\BrowserMngr
[-] Key Deleted : HKCU\Software\Compete
[-] Key Deleted : HKCU\Software\coupon downloader
[-] Key Deleted : HKCU\Software\DataMngr
[+] Key Deleted : HKCU\Software\DataMngr_Toolbar
[-] Key Deleted : HKCU\Software\ilivid
[-] Key Deleted : HKCU\Software\IM
[-] Key Deleted : HKCU\Software\ImInstaller
[-] Key Deleted : HKCU\Software\InstallCore
[-] Key Deleted : HKCU\Software\iVIDI Plugin
[-] Key Deleted : HKCU\Software\pc speed maximizer
[-] Key Deleted : HKCU\Software\powerpack
[-] Key Deleted : HKCU\Software\SweetIM
[-] Key Deleted : HKCU\Software\Tutorials
[-] Key Deleted : HKCU\Software\TutoTag
[-] Key Deleted : HKCU\Software\iVIDI.org
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Compete
[-] Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
[-] Key Deleted : HKCU\Software\AppDataLow\Software\CouponDownloader
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Freecause
[-] Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\AdvertisingSupport
[-] Key Deleted : HKLM\SOFTWARE\Babylon
[-] Key Deleted : HKLM\SOFTWARE\BrowserMngr
[-] Key Deleted : HKLM\SOFTWARE\CompeteInc
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\DataMngr
[-] Key Deleted : HKLM\SOFTWARE\FreeSoftToday
[-] Key Deleted : HKLM\SOFTWARE\InstallIQ
[-] Key Deleted : HKLM\SOFTWARE\SweetIM
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Consumer Input Installer
[-] Key Deleted : [x64] HKLM\SOFTWARE\CouponDownloader
[-] Key Deleted : [x64] HKLM\SOFTWARE\LevelQualityWatcher
[-] Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork
[-] Key Deleted : HKU\.DEFAULT\Software\BrowserMngr
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\coupon downloader
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\CouponDownloader
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{47AE1BA9-0BD1-44F4-88AE-45F8F7B605EF}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}
***** [ Web browsers ] *****
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxps://search.yahoo.com/?type=444990&fr=spigot-nt-gc");
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : aaaaaiabcopkplhgaedhbloeejhhankf
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ajbijfenhocdombdaghijgbodhiipopm
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : jpmbfleldcgkldadpdinhjjopdfpjfjp
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : pbjikboenpfhbbejgkoklgkhjpfogcam
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [15703 bytes] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on Wed 11/11/2015 at 8:51:23.84
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\Windows\system32\tasks\CIMT_S-1-5-21-2250843709-3518569377-988331573-1002
Successfully deleted: [Task] C:\Windows\system32\tasks\EasySpeedUpManager
Successfully deleted: [Task] C:\Windows\Tasks\CIMT_S-1-5-21-2250843709-3518569377-988331573-1002.job
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
~~~ Files
Successfully deleted: [File] C:\Users\Owner\Appdata\Local\proxy.log
Successfully deleted: [File] C:\Windows\SysWOW64\sho293F.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho2945.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho2B92.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho3D2A.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho513A.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho8761.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\sho87E.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoA377.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoB3AC.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoB45D.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoBDB5.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoBFDA.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoC171.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoD86A.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoDAB5.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoE30C.tmp
Successfully deleted: [File] C:\Windows\SysWOW64\shoF7C8.tmp
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Owner\Appdata\Local\{3322171E-8314-4C3D-944C-D43367347B3F}
Successfully deleted: [Empty Folder] C:\Users\Owner\Appdata\Local\{61EBAB25-96EA-45A1-BCB9-8AB45A83BC63}
Successfully deleted: [Empty Folder] C:\Users\Owner\Appdata\Local\{9F478891-DEE9-4AB9-8E5F-BD548970449C}
Successfully deleted: [Empty Folder] C:\Users\Owner\Appdata\Local\{C2741235-F38B-4EC4-9A03-5DE82ECE7138}
Successfully deleted: [Empty Folder] C:\Users\Owner\Appdata\Local\{F0F1928C-0926-4DD4-8B38-ECE4975886BA}
Successfully deleted: [Folder] C:\ai_recyclebin
Successfully deleted: [Folder] C:\Program Files (x86)\consumer input
Successfully deleted: [Folder] C:\Program Files (x86)\Shop to Win 36
Successfully deleted: [Folder] C:\Program Files (x86)\strongvault online backup
Successfully deleted: [Folder] C:\Program Files\004
Successfully deleted: [Folder] C:\ProgramData\best buy pc app
Successfully deleted: [Folder] C:\ProgramData\strongvault online backup
Successfully deleted: [Folder] C:\Users\Owner\Appdata\Local\best buy pc app
Successfully deleted: [Folder] C:\Users\Owner\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\Users\Owner\Appdata\Local\strongvault online backup
Successfully deleted: [Folder] C:\Users\Owner\AppData\Roaming\compete
Successfully deleted: [Folder] C:\Windows\SysWOW64\ai_recyclebin
~~~ Chrome
[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
pbjikboenpfhbbejgkoklgkhjpfogcam
[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 11/11/2015 at 8:58:00.50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by [removed] (administrator) on DJHAROLD (11-11-2015 10:57:31)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avp.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avpui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11660904 2010-11-30] (Realtek Semiconductor)
HKLM\…\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-11-01] (Intel(R) Corporation)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2817872 2012-04-25] (ELAN Microelectronics Corp.)
HKLM\…\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.)
HKLM\…\Run: [pcreg] => C:\Program Files\pcreg\service.exe
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-08-13] (Apple Inc.)
HKLM-x32\…\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-01] (CyberLink)
HKLM-x32\…\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2010-08-25] (cyberlink)
HKLM-x32\…\Run: [Samsung PanelMgr] => C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] ()
HKLM-x32\…\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-09] (Microsoft Corporation)
HKLM-x32\…\Run: [MaxMenuMgr] => C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [185640 2009-05-01] (Seagate LLC)
HKLM-x32\…\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-09-23] (Apple Inc.)
HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.)
HKLM-x32\…\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
Winlogon\Notify\DfLogon: LogonDll.dll [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKLM\…\Policies\Explorer: [NoDrives] 524288
HKLM\…\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Run: [BackupAgent] => C:\Program Files (x86)\Strongvault Online Backup\BackupAgent.exe
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Run: [NVIDIA nTune] => "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\MountPoints2: {3e04a122-3e0b-11e0-8fec-806e6f6e6963} - E:\Autorun.exe
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\…\Policies\Explorer: [HideSCAHealth] 1
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2012-06-20]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk [2014-02-04]
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-02-06]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-02-06]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{5C6A50C2-DA0F-433D-A99D-E6EA9BB7587B}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{673CB153-F46F-45C4-9695-9F8CC0C87D90}: [DhcpNameServer] [removed] [removed]
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
HKU\S-1-5-21-2250843709-3518569377-988331573-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/
SearchScopes: HKLM-x32 -> DefaultScope {7102907D-3ADD-49A3-809A-E7D6000A2745} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2250843709-3518569377-988331573-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-09-29] (Microsoft Corporation)
BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-10-28] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-28] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14] (CANON INC.)
BHO-x32: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-26] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-14] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation)
BHO-x32: W2PBrowser Class -> {AA609D72-8482-4076-8991-8CDAE5B93BCB} -> C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll [2010-09-16] ()
BHO-x32: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-10-28] (Microsoft Corporation)
BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-14] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14] (CANON INC.)
Toolbar: HKU\S-1-5-21-2250843709-3518569377-988331573-1002 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default
FF DefaultSearchEngine: Yahoo!
FF DefaultSearchEngine.US: Yahoo!
FF SelectedSearchEngine: Yahoo!
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-10] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-07-30] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-14] (Oracle Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-20] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-26] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2250843709-3518569377-988331573-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Owner\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\88eh50c9.default\searchplugins\shield Yahoo!.xml [2015-11-09]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-02-06] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-02-06] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-02-06] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-06-20] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed]
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\[removed] [2015-02-22] [not signed]
FF HKU\S-1-5-21-2250843709-3518569377-988331573-1002\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-06]
CHR Extension: (Google Docs) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-06]
CHR Extension: (Google Drive) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Adblock Plus) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-09-26]
CHR Extension: (Google Search) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Kaspersky Protection) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-02-23]
CHR Extension: (Google Sheets) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-06]
CHR Extension: (Google Docs Offline) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-01]
CHR Extension: (Do Not Disturb!) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilnddakjdkpofoablibghfikpeknhbia [2015-02-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-27]
CHR Extension: (Gmail) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30]
CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKLM-x32\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 AVP15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avp.exe [194000 2015-06-23] (Kaspersky Lab ZAO)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2780856 2015-10-07] (Microsoft Corporation)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [246256 2010-08-24] (CyberLink)
U2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [408576 2010-08-31] (Red Bend Ltd.) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-11-01] ()
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2057736 2015-09-07] (Electronic Arts)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [911872 2010-08-31] (Intel(R) Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [247016 2015-06-23] (Kaspersky Lab UK Ltd)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-23] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [64368 2015-06-23] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [159960 2015-06-23] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [225976 2015-07-01] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [831672 2015-10-06] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [39280 2015-06-23] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [40304 2015-06-23] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [39280 2015-06-23] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [24944 2015-06-23] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [65208 2015-06-23] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [85360 2015-06-23] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [190648 2015-10-06] (Kaspersky Lab ZAO)
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [52320 2013-03-14] (hxxp://libusb-win32.sourceforge.net)
S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2011-02-21] (Windows (R) 2003 DDK 3790 provider)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 ALSysIO; \??\C:\Users\Owner\AppData\Local\Temp\ALSysIO64.sys [X]
S3 WinRing0_1_2_0; \??\C:\Users\Owner\AppData\Local\Temp\tmpA3EC.tmp [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-11 08:58 - 2015-11-11 08:58 - 00003981 _____ C:\Users\Owner\Desktop\JRT.txt
2015-11-11 08:50 - 2015-11-11 08:50 - 01801288 _____ (Malwarebytes) C:\Users\Owner\Downloads\JRT.exe
2015-11-11 08:35 - 2015-11-11 08:39 - 00000000 ____D C:\AdwCleaner
2015-11-11 08:34 - 2015-11-11 08:34 - 01712128 _____ C:\Users\Owner\Downloads\adwcleaner_5.019.exe
2015-11-10 21:39 - 2015-11-10 21:39 - 05286088 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-11-10 11:22 - 2015-11-10 11:22 - 00002527 _____ C:\Users\Owner\Desktop\aswMBR.txt
2015-11-10 11:22 - 2015-11-10 11:22 - 00000512 _____ C:\Users\Owner\Desktop\MBR.dat
2015-11-09 20:24 - 2015-11-09 20:25 - 00046268 _____ C:\Users\Owner\Downloads\Addition.txt
2015-11-09 20:21 - 2015-11-11 10:57 - 00025231 _____ C:\Users\Owner\Downloads\FRST.txt
2015-11-09 20:16 - 2015-11-11 10:57 - 00000000 ____D C:\FRST
2015-11-09 20:16 - 2015-11-09 20:19 - 00001447 _____ C:\Users\Owner\Desktop\FRST64 - Shortcut.lnk
2015-11-09 20:16 - 2015-11-09 20:16 - 00001447 _____ C:\Users\Owner\Desktop\aswMBR - Shortcut.lnk
2015-11-09 20:16 - 2015-11-09 20:16 - 00001420 _____ C:\Users\Owner\Desktop\dds - Shortcut.lnk
2015-11-09 20:13 - 2015-11-09 20:13 - 02198528 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
2015-11-09 20:10 - 2015-11-09 20:10 - 00027362 _____ C:\Users\Owner\Desktop\dds.txt
2015-11-09 20:10 - 2015-11-09 20:10 - 00006604 _____ C:\Users\Owner\Desktop\attach.txt
2015-11-09 20:08 - 2015-11-09 20:08 - 05198336 _____ (AVAST Software) C:\Users\Owner\Downloads\aswMBR.exe
2015-11-09 20:05 - 2015-11-09 20:05 - 00688992 ____R (Swearware) C:\Users\Owner\Downloads\dds.scr
2015-11-09 19:48 - 2015-11-09 19:48 - 00000000 ____D C:\Users\Owner\AppData\Local\Macromedia
2015-11-09 19:38 - 2015-11-09 19:53 - 00000000 ____D C:\Users\Owner\AppData\Local\Mozilla
2015-11-09 19:37 - 2015-11-09 19:37 - 00001166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-11-09 19:37 - 2015-11-09 19:37 - 00001154 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-11-09 19:37 - 2015-11-09 19:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-09 19:35 - 2015-11-09 19:35 - 00243656 _____ C:\Users\Owner\Downloads\Firefox Setup Stub 42.0.exe
2015-11-06 19:24 - 2015-11-06 19:24 - 00000000 ___HD C:\OneDriveTemp
2015-11-05 17:03 - 2015-11-05 17:03 - 02077392 _____ (Microsoft Corporation) C:\Users\Owner\Downloads\IE11-Windows6.1 (2).exe
2015-11-05 16:59 - 2015-11-05 16:59 - 02077392 _____ (Microsoft Corporation) C:\Users\Owner\Downloads\IE11-Windows6.1 (1).exe
2015-11-03 22:22 - 2015-11-03 22:22 - 00000000 ____D C:\Users\Owner\Desktop\2015 FALL FAMILY PICS
2015-10-28 16:27 - 2015-10-28 16:27 - 01089320 _____ (Unity Technologies ApS) C:\Users\Owner\Downloads\UnityWebPlayer.exe
2015-10-25 19:28 - 2015-10-25 19:29 - 00000000 ____D C:\Users\Owner\Desktop\10-20-15
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-11 10:59 - 2011-02-06 02:30 - 00000050 _____ C:\Windows\system32\SupplicantTest.log
2015-11-11 10:54 - 2011-09-21 21:56 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-11-11 10:38 - 2012-05-01 18:06 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-11 09:58 - 2011-02-06 19:20 - 01136077 _____ C:\Windows\WindowsUpdate.log
2015-11-11 09:29 - 2009-07-13 22:45 - 00022976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-11 09:29 - 2009-07-13 22:45 - 00022976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-11 08:53 - 2013-11-28 11:20 - 00013206 _____ C:\Windows\IE11_main.log
2015-11-11 08:52 - 2013-09-04 19:54 - 00000000 ___RD C:\Users\Owner\SkyDrive
2015-11-11 08:50 - 2009-07-13 23:13 - 00006458 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-11 08:43 - 2011-02-06 03:41 - 01003622 _____ C:\Windows\PFRO.log
2015-11-11 08:43 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-11 08:43 - 2009-07-13 22:51 - 00129233 _____ C:\Windows\setupact.log
2015-11-11 08:40 - 2012-08-17 09:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-11 08:40 - 2012-06-20 12:15 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Yahoo!
2015-11-11 08:39 - 2012-06-20 12:14 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2015-11-10 21:41 - 2012-05-01 18:06 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-10 21:41 - 2011-09-25 18:57 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-04 21:08 - 2013-02-13 20:42 - 00000000 ____D C:\ProgramData\CanonIJPLM
2015-11-03 22:59 - 2011-09-18 22:14 - 00000000 ____D C:\Users\Owner\AppData\Local\CrashDumps
2015-11-02 23:29 - 2014-08-10 13:06 - 00002164 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-11-02 15:56 - 2014-05-18 08:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
2015-11-02 15:55 - 2014-05-18 08:19 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Real
2015-11-02 15:55 - 2014-05-18 08:19 - 00000000 ____D C:\Program Files (x86)\Real
2015-11-02 15:54 - 2014-09-02 17:46 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-02 15:54 - 2014-05-18 08:18 - 00000000 ____D C:\ProgramData\Real
2015-11-02 14:59 - 2012-11-07 01:08 - 00000000 ____D C:\Users\Owner\AppData\Local\Unity
2015-11-02 14:48 - 2014-05-18 08:37 - 00000000 ____D C:\temp
2015-11-01 22:38 - 2015-01-01 16:32 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-10-28 11:04 - 2013-09-04 19:24 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-10-20 23:02 - 2014-11-25 19:02 - 00000000 ____D C:\Users\Owner\Desktop\EmmaKatelynn
2015-10-20 21:14 - 2014-01-01 19:03 - 00461824 ___SH C:\Users\Owner\Desktop\Thumbs.db
2015-10-20 20:53 - 2015-09-29 18:27 - 00000000 ____D C:\Users\Owner\Desktop\Camera
2015-10-15 10:15 - 2013-03-07 21:10 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
==================== Files in the root of some directories =======
2013-07-15 20:29 - 2013-07-15 20:28 - 2409984 _____ () C:\Program Files\PX5 Advanced Sound Editor.msi
2013-08-17 13:06 - 2013-08-18 10:10 - 0000496 _____ () C:\Users\Owner\AppData\Roaming\UserMetrics.osl
2012-08-09 00:23 - 2012-08-09 00:23 - 0022440 _____ () C:\Users\Owner\AppData\Local\190833628_Setup.crx
2012-08-09 14:09 - 2012-08-09 14:09 - 0022440 _____ () C:\Users\Owner\AppData\Local\240382890_Setup.crx
2012-08-22 17:35 - 2012-08-22 17:35 - 0022440 _____ () C:\Users\Owner\AppData\Local\8976367_Setup.crx
2012-08-17 09:47 - 2012-08-17 09:46 - 0022440 _____ () C:\Users\Owner\AppData\Local\91735345_Setup.crx
2013-10-23 12:25 - 2013-10-23 12:25 - 0000017 _____ () C:\Users\Owner\AppData\Local\resmon.resmoncfg
2013-07-24 14:25 - 2013-07-24 14:25 - 0000000 _____ () C:\ProgramData\2c233b353d3d352c_c
2012-06-20 10:31 - 2012-06-20 12:43 - 0001248 _____ () C:\ProgramData\hpzinstall.log
2011-02-06 02:46 - 2011-02-06 02:46 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2011-02-06 02:42 - 2011-02-06 02:43 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2011-02-06 02:39 - 2011-02-06 02:42 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
2011-02-06 02:43 - 2011-02-06 02:44 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2011-02-06 02:44 - 2011-02-06 02:45 - 0000108 _____ () C:\ProgramData\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}.log
Some files in TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\APNSetup.exe
C:\Users\Owner\AppData\Local\Temp\autorun.dll
C:\Users\Owner\AppData\Local\Temp\C071.exe
C:\Users\Owner\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\lowproc.exe
C:\Users\Owner\AppData\Local\Temp\sqlite3.dll
C:\Users\Owner\AppData\Local\Temp\stubhelper.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-11-10 00:33
==================== End of FRST.txt ============================
They were fine thanks.
Hopefully things have already improved somewhat but we still have work to do.
I have to pop out for a while but will check the new FRST log and post the next set of instructions later.
Meanwhile, you need to move Farbar Recovery Scan Tool to your desktop otherwise any "fix" I ask you to run will not work.
- go to your Downloads folder and locate Farbar Recovery Scan Tool
- right click and select Cut
- go to an empty spot on your desktop, right click and select Paste
Farbar Recovery Scan Tool should now be on your desktop.
Satchfan
YESSSS! already seeing drastic improvement! All programs you have had me install are moved to the desktop. No worries, I understand you have your own life to enjoy or work away lol.
Thanks again,
Dustin
As I said in the previous post, please make sure you have moved FRST to your desktop before following these instructions.
Run Farbar Recovery Scan Tool
Open notepad. Please copy the contents of the code box below and paste it into Notepad.
HKLM\…\Run: [pcreg] => C:\Program Files\pcreg\service.exe
HKLM-x32\…\Run: [] => [X]
Winlogon\Notify\DfLogon: LogonDll.dll [X]
HKLM\…\Policies\Explorer: [NoDrives] 524288
SearchScopes: HKLM-x32 -> DefaultScope {7102907D-3ADD-49A3-809A-E7D6000A2745} URL =
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
CHR HKLM\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKLM-x32\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
S3 ALSysIO; \??\C:\Users\Owner\AppData\Local\Temp\ALSysIO64.sys [X]
S3 WinRing0_1_2_0; \??\C:\Users\Owner\AppData\Local\Temp\tmpA3EC.tmp [X]
CMD: ipconfig /flushdns
EmptyTemp:
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
- save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
- run FRST64 then click Fix just once and wait
- it will create a log (Fixlog.txt); please post it to your reply.
================================================
Download Malwarebytes-Anti-Malware
Click here.
- double-click mbam-setup.exe and follow the prompts to install the program – (Note: Vista & Windows 7 users, please right-click and select “Run as Administrator”)
- select the “Scan” tab at the top
- there are three scan types; choose Threat Scan, then click on Scan
- when the scan is complete, if no malicious items are found you can close the program
- if malicious items are found be sure that everything is checked and click Quarantine
- when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
- the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
- copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
Logs to include with the next post:
Fixlog.txt
Mbam.txt
Can you tell me what outstanding problems you have.
Satchfan
Satchfan,
I can't create new folders
Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by [removed] (2015-11-11 17:30:57) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
fixlist content:
*****************
HKLM\…\Run: [pcreg] => C:\Program Files\pcreg\service.exe
HKLM-x32\…\Run: [] => [X]
Winlogon\Notify\DfLogon: LogonDll.dll [X]
HKLM\…\Policies\Explorer: [NoDrives] 524288
SearchScopes: HKLM-x32 -> DefaultScope {7102907D-3ADD-49A3-809A-E7D6000A2745} URL =
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
CHR HKLM\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
CHR HKLM-x32\…\Chrome\Extension: [mgjkknncnlepghplinfpikcijdbmidbg] - C:\Users\Owner\AppData\Local\8976367_Setup.crx [2012-08-22]
S3 ALSysIO; \??\C:\Users\Owner\AppData\Local\Temp\ALSysIO64.sys [X]
S3 WinRing0_1_2_0; \??\C:\Users\Owner\AppData\Local\Temp\tmpA3EC.tmp [X]
CMD: ipconfig /flushdns
EmptyTemp:
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\pcreg => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DfLogon" => key removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDrives => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758} => value removed successfully
"HKLM\SOFTWARE\Google\Chrome\Extensions\mgjkknncnlepghplinfpikcijdbmidbg" => key removed successfully
C:\Users\Owner\AppData\Local\8976367_Setup.crx => moved successfully
"HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\Google\Chrome\Extensions\mgjkknncnlepghplinfpikcijdbmidbg" => key removed successfully
"C:\Users\Owner\AppData\Local\8976367_Setup.crx" => not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mgjkknncnlepghplinfpikcijdbmidbg" => key removed successfully
"C:\Users\Owner\AppData\Local\8976367_Setup.crx" => not found.
ALSysIO => service removed successfully
WinRing0_1_2_0 => service removed successfully
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
EmptyTemp: => 12 GB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 17:32:31 ====
##########################################################################################################
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 11/11/2015
Scan Time: 5:42 PM
Logfile: MBAM.txt
Administrator: Yes
Version: 2.2.0.1024
Malware Database: v2015.11.11.08
Rootkit Database: v2015.11.04.02
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Owner
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 436491
Time Elapsed: 40 min, 46 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 143
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\APPID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassSvc, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [ecd8e894117acf673ea654da649e3ec2],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\APPID\{D5FA0C65-08BE-4F86-B30F-2E285694863A}, Quarantined, [7c4803797c0fac8ac16742f5c73bb848],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D5FA0C65-08BE-4F86-B30F-2E285694863A}, Quarantined, [7c4803797c0fac8ac16742f5c73bb848],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{D5FA0C65-08BE-4F86-B30F-2E285694863A}, Quarantined, [7c4803797c0fac8ac16742f5c73bb848],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\APPID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3COMClassService, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3COMClassService.1.0, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3COMClassService, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3COMClassService.1.0, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3COMClassService, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3COMClassService.1.0, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [21a3b2cadfac241290559797010150b0],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0C6D49F4-6E41-4632-BE86-F210D5D894BA}, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback.1.0, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebMachineFallback, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback.1.0, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebMachineFallback.1.0, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{0C6D49F4-6E41-4632-BE86-F210D5D894BA}, Quarantined, [f2d27ffd1d6e3ff775663df1768c0000],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0DC6DC6C-048E-4B03-8F2D-7D6B90571172}, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreMachineClass.1, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreMachineClass, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreMachineClass, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoreMachineClass, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreMachineClass.1, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoreMachineClass.1, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{0DC6DC6C-048E-4B03-8F2D-7D6B90571172}, Quarantined, [3b89b2ca880346f07e772d09fc065da3],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1AB0B6A3-9BC5-419B-B86D-40FA2998A131}, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreClass.1, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreClass, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreClass, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoreClass, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreClass.1, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoreClass.1, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{1AB0B6A3-9BC5-419B-B86D-40FA2998A131}, Quarantined, [4c78215b266582b469732e0058aa7f81],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3A40DF53-EB22-49FE-9246-8084403424E7}, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine.1.0, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CredentialDialogMachine, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine.1.0, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CredentialDialogMachine.1.0, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3A40DF53-EB22-49FE-9246-8084403424E7}, Quarantined, [3391c1bb672471c51bc2db53bf43de22],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3DBBAB3C-4077-4EC4-BF2C-E89C7784846A}, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebSvc.1.0, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebSvc, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebSvc, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebSvc, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebSvc.1.0, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebSvc.1.0, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3DBBAB3C-4077-4EC4-BF2C-E89C7784846A}, Quarantined, [c6fe5b2147441b1b08d634fac83a34cc],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5CF02202-6278-47EE-9947-C2D0A057EABD}, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.ProcessLauncher.1.0, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.ProcessLauncher, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.ProcessLauncher, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.ProcessLauncher, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.ProcessLauncher.1.0, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.ProcessLauncher.1.0, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{5CF02202-6278-47EE-9947-C2D0A057EABD}, Quarantined, [9b29621a0d7eb77f7e611f0fb44e11ef],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{65BF611F-85CD-4E7F-966C-853573462C14}, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{65BF611F-85CD-4E7F-966C-853573462C14}, Quarantined, [358fed8f672460d69a461b13d62c9c64],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\DcaHost.DcaHost.1, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\DcaHost.DcaHost, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DcaHost.DcaHost, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\DcaHost.DcaHost, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DcaHost.DcaHost.1, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\DcaHost.DcaHost.1, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}, Quarantined, [03c1eb9184072e0814e391a5df235ca4],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{87A125E5-B663-496F-954E-488A82FAC012}, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoCreateAsync.1.0, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoCreateAsync, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoCreateAsync, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoCreateAsync, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoCreateAsync.1.0, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoCreateAsync.1.0, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{87A125E5-B663-496F-954E-488A82FAC012}, Quarantined, [bb09b0cc57341125944d58d63ac8fb05],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8AF9C44C-E497-4776-A7EF-F6455F982825}, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachine, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{8AF9C44C-E497-4776-A7EF-F6455F982825}, Quarantined, [21a318648efde65032b00b2356ac7888],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D4F484EE-BF68-4B61-AB83-C1E0EF88D876}, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachine.1.0, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachine, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachine, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebMachine, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachine.1.0, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebMachine.1.0, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D4F484EE-BF68-4B61-AB83-C1E0EF88D876}, Quarantined, [7b490c700f7c072f98602c0a2ed4dd23],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine.1.0, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInput.OneClickProcessLauncherMachine, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine.1.0, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInput.OneClickProcessLauncherMachine.1.0, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}, Quarantined, [cafac2baddae072f36b03df1cf334fb1],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\INTERFACE\{C015D269-0F4E-4B52-A91F-721F6DAC9437}, Quarantined, [9f253f3d6d1e3402ec3193a406fc10f0],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}, Quarantined, [d9eb5c204e3d59dd95889c9b857d19e7],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C015D269-0F4E-4B52-A91F-721F6DAC9437}, Quarantined, [d9eb5c204e3d59dd95889c9b857d19e7],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C015D269-0F4E-4B52-A91F-721F6DAC9437}, Quarantined, [d9eb5c204e3d59dd95889c9b857d19e7],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}, Quarantined, [d7ede696e5a61e1853cafc3bea18b34d],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}, Quarantined, [5a6a6a12cbc075c11a03013608fa32ce],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\APPID\ConsumerInputUpdate.exe, Quarantined, [7450d5a7c9c223130952c79ea0634bb5],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\APPID\dca-host.exe, Quarantined, [269e06766c1f41f5a907693c4eb5ce32],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\ConsumerInputUpdate.exe, Quarantined, [566eb5c7bfcc78be2b308ed7739036ca],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\dca-host.exe, Quarantined, [5b69ec90fd8e2a0ce8c8e9bc4fb40cf4],
PUP.Optional.BrowserGuardian, HKLM\SOFTWARE\WOW6432NODE\Browser Guardian, Quarantined, [695bcab2b2d904328d3cf56b2cd7d32d],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\ConsumerInput, Quarantined, [7b4978046c1f46f0cb91214409fa956b],
PUP.Optional.SavingsExplorer, HKLM\SOFTWARE\WOW6432NODE\Savings Explorer, Quarantined, [457f3a42a5e60b2b3c6be3a89a697789],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\ConsumerInputUpdate.exe, Quarantined, [17ad8cf0ed9e092d9cbf86dfd42f7090],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\dca-host.exe, Quarantined, [3a8a7a02c4c7e650268a683de61d29d7],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\com.compete.cinm, Quarantined, [913378043c4f38fe1d964f541be808f8],
PUP.Optional.Ividi, HKU\S-1-5-21-2250843709-3518569377-988331573-1000\SOFTWARE\iVIDI Plugin, Quarantined, [7c48aece4d3e4ee837e07503de25f010],
PUP.Optional.Ividi, HKU\S-1-5-21-2250843709-3518569377-988331573-1000\SOFTWARE\iVIDI.org, Quarantined, [42823547503b4beb7c9ccfa9da29e51b],
PUP.Optional.ConsumerInput, HKU\S-1-5-21-2250843709-3518569377-988331573-1002\SOFTWARE\ConsumerInput, Quarantined, [ebd95a22eba058dedb7e96cfd42f3bc5],
Registry Values: 8
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}|AppPath, C:\Program Files (x86)\Consumer Input\InternetExplorer, Quarantined, [a3213b41dbb0d75fcbe90f9422e144bc]
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\Mysearchdial\1.8.29.0\, Quarantined, [6b5975077a11f73f0ec9067b6b98f40c]
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}|AppPath, C:\Program Files (x86)\Consumer Input\InternetExplorer, Quarantined, [c7fd6418c1ca8da9f0c4c3e0bc47e818]
PUP.Optional.Perion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{988FB558-B56F-4CE6-9A67-5B3F04B5F064}, v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Windows\System32\dmwu.exe|Name=dmwu|, Quarantined, [c9fb4933e6a5ff37b810fbdae122b64a]
PUP.Optional.Perion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{A61DDF12-3250-4263-9375-67B9E7080AC3}, v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Windows\System32\dmwu.exe|Name=dmwu|, Quarantined, [457f7606028952e4e1e7785dd42fb749]
PUP.Optional.Perion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{52BD859B-2D82-4D5B-AC8D-E187D1163F17}, v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Windows\SysWOW64\ARFC\wrtc.exe|Name=wrtc|, Quarantined, [17ad572538537fb748670fc7bd46bd43]
PUP.Optional.Perion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{E4756446-ADA3-4A70-9F0D-89F79C723832}, v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Windows\SysWOW64\ARFC\wrtc.exe|Name=wrtc|, Quarantined, [e3e1a4d86427c175f3bc1eb8de257987]
PUM.Optional.LowRiskFileTypes, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ASSOCIATIONS|LowRiskFileTypes, .zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.log;, Quarantined, [b014512b2a61c47200bf6d6038cb867a]
Registry Data: 0
(No malicious items detected)
Folders: 1
PUP.Optional.Ividi, C:\Program Files (x86)\iVIDI.org plugin, Quarantined, [556f87f59eed0a2c976c29417f8307f9],
Files: 5
PUP.Optional.Ividi, C:\Program Files (x86)\iVIDI.org plugin\IEhelperActiveX.dll, Quarantined, [2f953c402b60063029843df003fdee12],
PUP.Optional.Conduit, C:\temp\embededstub_new2.exe, Quarantined, [f2d288f41e6d76c02571240836ca8d73],
PUP.Optional.ExcitingApps, C:\temp\guardian.exe, Quarantined, [70547dffc2c952e47e580a1db8498e72],
PUP.Optional.CouponDownloader, C:\temp\t_ff.exe, Quarantined, [5272d9a34d3eb284f8aa7daf38c86b95],
PUP.Optional.RocketFuel, C:\Users\Owner\Downloads\Xvid_RocketFuelInstaller.exe, Quarantined, [41835c20a5e644f2831d130f1de7f30d],
Physical Sectors: 0
(No malicious items detected)
(end)
How are you trying to create a new folder, ie are you using right-click or by using the "File > New Folder" menu in Windows Explorer?
Can you tell me how your computer is running now.
Satchfan
The computer seems to be running quite well, I have been able to do several things it was giving me problems with before
Dustin
Let’s try using a command prompt to try and create a new folder.
To do this, follow the steps below:
- click on Start, then in the search box type CMD
- right-click, on cmd and from the menu that appears, click on Run as administrator
- type the following in the command prompt:
mkdir folderName (replace “folderName” with the folder name of your choice)
Check if the folder has been created on the C drive
Yes, it will let me create folders that way
There is a registry fix we could try but first I’d like you to check your system files:
- click on Start, All Programs. Accessories, then right click on Command Prompt and click on Run as administrator
- type in sfc /scannow in the command window and press Enter - note the space between the c and the /
- if any files require replacing SFC will replace them. You may be asked to insert your Windows 7 Disk for this process to continue. This can be done with a borrowed Windows 7 disk if you don't have one.
- be patient because the scan may take some time.
- allow the scan to run and when completed, reboot the system.
Let me know the result.
Satchfan
I ran the sfc scan and it says "Windows Resource Protection found corrupt files but was unable to fix some of them". It also gave me a log, but it is quite long so I will only post if you would want to see it.
Dustin
We need to see what can't be fixed:
- click on Start, All Programs. Accessories, then right click on Command Prompt and click on Run as administrator
- type in the following command, (or better still. copy and paste), then press Enter
findstr /c:"[SR]" %windir%\logs\cbs\cbs.log >%userprofile%\Desktop\sfcdetails.txt
- close the cmd prompt by typing Exit and then pressing the return key
- click on the sfcdetails.txt file that has just been placed on your desktop and copy/paste the findings in your next reply.
Thanks
Satchfan
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI