This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infection installs PCSpeedup Browserair YTDownloader Homegroup [Solved

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

 

I appreciate your help more than I can say and am grateful to you for providing this tremendous resource. 

 

I'm infected with something that starts installing appications and popping up shortcuts on my desktop.

 

The first time it popped up, it installed BrowserAir, PCSpeedup and a couple of other programs I can't rmember the names of.  I installed Malwarebytes and Spybot and they seemed to do the trick, finding the infection and removing the nasty bits.  My browsers would not connect to the internet and Windows Defender was turned off by my "administrator" (it's my home machine) set group policy.  I found a forum which gave me a couple of scripts to restore internet access to my browsers.  I did not figure out how to turn Windows Defender back on and I planned to address that issue soon, so I thought everything was fine.

 

Today, it started installing applications again.  This time, it was PCSpeedup, YT Downloader, Homegroup and a couple of others I didn't catch.  I have user account control set to High so I have to provide admin approval to install anything, but this little baddie has worked around that.  I ran Malwarebytes four times and it found thousands of files, including trojans and malware.  I als ran Spybot.  I am happy to post the logs for those scans if you would like to look at them. 

 

Thank you for your help.  The log files you asked for are below.

 

Here is my ASWmbr log:

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-11-11 11:33:42
—————————–
11:33:42.047    OS Version: Windows x64 6.2.9200
11:33:42.047    Number of processors: 4 586 0x3D04
11:33:42.047    ComputerName: SONOFSPUDBORT  UserName: Jimmy James
11:33:42.828    Initialize success
11:33:42.844    VM: initialized successfully
11:33:42.844    VM: Intel CPU supported
11:33:43.938    VM: disk I/O iaStorA.sys
11:47:06.647    AVAST engine defs: 15111102
12:04:03.572    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000032
12:04:03.572    Disk 0 Vendor: ST1000LM024_HN-M101MBB 2BA30003 Size: 953869MB BusType: 11
12:04:03.685    Disk 0 MBR read successfully
12:04:03.685    Disk 0 MBR scan
12:04:03.685    Disk 0 unknown MBR code
12:04:03.685    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
12:04:03.717    Disk 0 scanning C:\Windows\system32\drivers
12:04:09.686    Service scanning
12:04:25.442    Modules scanning
12:04:25.442    Disk 0 trace - called modules:
12:04:25.521    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll iaStorA.sys
12:04:25.521    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe0010b6a95a0]
12:04:25.521    3 CLASSPNP.SYS[fffff801315a5170] -> nt!IofCallDriver -> [0xffffe00107a2f660]
12:04:25.521    5 ACPI.sys[fffff80130b64c21] -> nt!IofCallDriver -> \Device\00000032[0xffffe00108f14060]
12:04:26.114    AVAST engine scan C:\Windows
12:04:27.364    AVAST engine scan C:\Windows\system32
12:06:11.459    AVAST engine scan C:\Windows\system32\drivers
12:06:18.631    AVAST engine scan C:\Users\Jimmy James
12:06:22.819    File: C:\Users\Jimmy James\AppData\Local\Installer\Install_29098\DCnscFFFF.tmp  **INFECTED** Win32:Malware-gen
12:06:22.897    File: C:\Users\Jimmy James\AppData\Local\Installer\Install_29217\DCnscFFFF.tmp  **INFECTED** Win32:Malware-gen
12:11:05.308    AVAST engine scan C:\ProgramData
12:12:28.403    Disk 0 statistics 3601825/0/0 @ 523.42 MB/s
12:12:28.419    Scan finished successfully
12:13:26.067    Disk 0 MBR has been saved successfully to "C:\Users\Jimmy James\Desktop\MBR.dat"
12:13:26.067    The log file has been saved successfully to "C:\Users\Jimmy James\Desktop\aswMBR.txt"


Here is my FRST log:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by [removed] (administrator) on SONOFSPUDBORT (11-11-2015 12:14:37)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe
(Intel(R) Corporation) C:\Program Files (x86)\Common Files\Intel\RSDCM\bin\win32\RealSenseDCM.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
() C:\Program Files\TrueColor\TrueColorALS.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Entertainment Experience) C:\Program Files\TrueColor\TrueColorUI.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elan\USB\ETDUSBCtrl.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elan\USB\ETDUSBCtrlHelper.exe
() C:\Program Files (x86)\GreenTree Applications\PDF to Word Converter\PDFToWordConverterUpdateChecker.exe
(Intel(R) Corporation) C:\Program Files (x86)\Common Files\Intel\RSDCM\bin\win32\RealSenseInfo.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7646936 2014-10-14] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1396592 2014-09-01] (Realtek Semiconductor)
HKLM\…\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5793048 2014-10-08] (Dell Inc.)
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322712 2014-10-09] (Intel Corporation)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\…\Run: [TrueColor UI] => C:\Program Files\TrueColor\TrueColorUI.exe [19491792 2014-12-25] (Entertainment Experience)
HKLM\…\Run: [ETDUSBWare] => C:\Program Files\Elan\USB\ETDUSBCtrl.exe [869320 2010-06-18] (ELAN Microelectronic Corp.)
HKLM-x32\…\Run: [Intel(R) RealSense(TM) SDK info server] => C:\Program Files (x86)\Common Files\Intel\RSDCM\bin\win32\RealSenseInfo.exe [17592 2014-11-12] (Intel(R) Corporation)
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\Run: [Google Update] => C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-24] (Google Inc.)
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\Run: [PDFToWordConverterUpdateChecker] => C:\Program Files (x86)\GreenTree Applications\PDF to Word Converter\PDFToWordConverterUpdateChecker.exe [116224 2015-03-19] ()
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
AppInit_DLLs: C:\ProgramData\FlashBeat\FlashBeat64.dll => No File
AppInit_DLLs-x32: C:\ProgramData\FlashBeat\FlashBeat32.dll => No File
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 [removed]
Tcpip\..\Interfaces\{665A4D14-14AE-4E65-9CC9-60E4EC09AD78}: [DhcpNameServer] 192.168.0.1 [removed]

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
SearchScopes: HKLM -> DefaultScope {3AEE68F1-2444-4B79-8A19-5A0E4F15FA24} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1714133512-296453273-4189880979-1001 -> {24CD5258-20D7-4FB3-AF67-A3A12172F64D} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:{language}:{referrer:source}&ie;={inputEncoding?}&oe;={outputEncoding?}
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default
FF DefaultSearchEngine.US: Google
FF Homepage: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-10-10] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-10-10] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin HKU\S-1-5-21-1714133512-296453273-4189880979-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Jimmy James\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1714133512-296453273-4189880979-1001: @talk.google.com/O1DPlugin -> C:\Users\Jimmy James\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1714133512-296453273-4189880979-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-1714133512-296453273-4189880979-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF user.js: detected! => C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\user.js [2015-10-31]
FF Plugin ProgramFiles/Appdata: C:\Users\Jimmy James\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Jimmy James\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\Extensions\[removed] [2015-06-14]
FF Extension: Adblock Plus - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-24]
FF Extension: No Name - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\extensions\[removed] [not found]
FF Extension: No Name - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\extensions\[removed] [not found]
FF Extension: No Name - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [not found]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18584 2014-10-09] (Intel Corporation)
R2 iBtSiva; C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe [121304 2014-08-25] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [328296 2014-11-23] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [132896 2014-10-10] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [158496 2014-10-10] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [265936 2014-06-18] ()
R2 RealSenseDCM; C:\Program Files (x86)\Common Files\Intel\RSDCM\bin\win32\RealSenseDCM.exe [1147064 2014-11-12] (Intel(R) Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [292568 2014-09-04] (Realtek Semiconductor)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 TrueColorALS; C:\Program Files\TrueColor\TrueColorALS.exe [94160 2014-12-25] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816656 2014-06-18] (Intel® Corporation)
S2 6e9452be; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\CutterFoobar\CutterFoobar.dll",serv
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc [X] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc [X] <==== ATTENTION

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-11-20] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [141624 2014-05-13] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1424184 2014-06-17] (Motorola Solutions, Inc.)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-24] (OSR Open Systems Resources, Inc.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 iaLPSS_GPIO; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [35832 2014-06-10] (Intel Corporation)
R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [120312 2014-06-10] (Intel Corporation)
S3 iaLPSS_SPI; C:\Windows\System32\drivers\iaLPSS_SPI.sys [100856 2014-06-10] (Intel Corporation)
S3 iaLPSS_UART2; C:\Windows\System32\drivers\iaLPSS_UART2.sys [143864 2014-06-10] (Intel Corporation)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [220104 2014-08-25] (Intel Corporation)
R3 IntelDFUACPI; C:\Windows\System32\drivers\IntelDFUACPI.sys [24456 2014-09-09] (Intel(R) Corporation)
R3 IXCamera; C:\Windows\system32\DRIVERS\RealSenseDCM.sys [59312 2014-11-12] (Intel(R) Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverx64.sys [129312 2014-10-10] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3488744 2014-07-29] (Intel Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 PCDSRVC{3B54B31B-D06B6431-06020200}_0; \??\c:\program files\dell\supportassist\pcdsrvc_x64.pkms [X]
U3 aswMBR; \??\C:\Users\JIMMYJ~1\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\JIMMYJ~1\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Three Months Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-11 12:14 - 2015-11-11 12:14 - 00017116 _____ C:\Users\Jimmy James\Desktop\FRST.txt
2015-11-11 12:14 - 2015-11-11 12:14 - 00000000 ____D C:\Users\Jimmy James\Desktop\FRST-OlderVersion
2015-11-11 12:13 - 2015-11-11 12:14 - 00000000 ____D C:\FRST
2015-11-11 12:13 - 2015-11-11 12:13 - 00002265 _____ C:\Users\Jimmy James\Desktop\aswMBR.txt
2015-11-11 12:13 - 2015-11-11 12:13 - 00000512 _____ C:\Users\Jimmy James\Desktop\MBR.dat
2015-11-11 09:34 - 2015-11-11 12:14 - 02198528 _____ (Farbar) C:\Users\Jimmy James\Desktop\FRST64.exe
2015-11-11 09:23 - 2015-11-11 09:23 - 05198336 _____ (AVAST Software) C:\Users\Jimmy James\Desktop\aswMBR.exe
2015-11-11 08:29 - 2015-11-11 08:29 - 00003274 _____ C:\Windows\System32\Tasks\runTask
2015-11-11 08:29 - 2015-11-11 08:29 - 00003178 _____ C:\Windows\System32\Tasks\updateTask
2015-11-11 08:25 - 2015-11-11 11:32 - 00001042 _____ C:\Windows\Tasks\tXnxIXs16.job
2015-11-11 08:25 - 2015-11-11 08:35 - 00000000 ____D C:\Users\Jimmy James\AppData\Roaming\RunDir
2015-11-11 08:25 - 2015-11-11 08:25 - 00004072 _____ C:\Windows\System32\Tasks\tXnxIXs16
2015-11-11 08:24 - 2015-11-11 11:32 - 00000382 ____H C:\Windows\Tasks\EQNAKGAOSGAVHUAN.job
2015-11-11 08:24 - 2015-11-11 11:32 - 00000370 _____ C:\Windows\Tasks\CWOBUGTNCV1.job
2015-11-11 08:24 - 2015-11-11 08:24 - 00003402 _____ C:\Windows\System32\Tasks\EQNAKGAOSGAVHUAN
2015-11-11 08:24 - 2015-11-11 08:24 - 00002884 _____ C:\Windows\System32\Tasks\CWOBUGTNCV1
2015-11-11 08:24 - 2015-11-11 08:24 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\CrashRpt
2015-11-11 08:13 - 2015-11-11 08:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-11-11 08:13 - 2015-11-11 08:13 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-11-10 19:11 - 2015-10-30 16:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-10 19:11 - 2015-10-30 16:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-10 19:11 - 2015-10-30 16:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-10 19:11 - 2015-10-30 16:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-10 19:11 - 2015-10-30 16:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-10 19:11 - 2015-10-30 15:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-11-10 19:11 - 2015-10-30 15:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-11-10 19:11 - 2015-10-30 15:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-11-10 19:11 - 2015-10-30 15:39 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-11-10 19:11 - 2015-10-30 15:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-11-10 19:11 - 2015-10-30 15:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-10 19:11 - 2015-10-30 15:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-10 19:11 - 2015-10-30 15:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-10 19:11 - 2015-10-30 15:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-10 19:11 - 2015-10-30 15:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-11-10 19:11 - 2015-10-30 15:14 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-11-10 19:11 - 2015-10-30 15:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-11-10 19:11 - 2015-10-30 15:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-11-10 19:11 - 2015-10-30 15:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-10 19:11 - 2015-10-30 14:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-11-10 19:11 - 2015-10-30 14:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-11-10 19:11 - 2015-10-30 14:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-11-10 19:11 - 2015-10-30 14:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-11-10 19:11 - 2015-10-20 14:54 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-10 19:11 - 2015-10-20 07:53 - 03705856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-10 19:11 - 2015-10-20 07:36 - 02243072 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-10 19:11 - 2015-10-20 07:35 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-10 19:11 - 2015-10-20 07:34 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2015-11-10 19:11 - 2015-10-20 07:34 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-10 19:11 - 2015-10-20 07:34 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-10 19:11 - 2015-10-20 07:33 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-10 19:11 - 2015-10-20 07:14 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-10 19:11 - 2015-10-20 07:13 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-10 19:11 - 2015-10-20 07:13 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-10 19:11 - 2015-10-20 07:13 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-10 19:11 - 2015-10-14 16:02 - 07455064 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-10 19:11 - 2015-10-14 16:02 - 01659560 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-11-10 19:11 - 2015-10-14 16:02 - 01519592 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-11-10 19:11 - 2015-10-14 16:02 - 01487008 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-11-10 19:11 - 2015-10-14 16:02 - 01355848 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-11-10 19:11 - 2015-10-08 09:08 - 01083904 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2015-11-10 19:11 - 2015-08-10 11:15 - 00845312 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2015-11-10 19:11 - 2015-08-10 11:06 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2015-11-10 19:11 - 2015-08-10 10:49 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2015-11-10 19:11 - 2015-08-10 09:56 - 00272384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2015-11-10 19:11 - 2015-08-10 09:46 - 00561664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2015-11-10 19:10 - 2015-10-17 07:19 - 04176384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-06 18:58 - 2015-11-06 18:58 - 00000000 ____D C:\Users\Jimmy James\Downloads\wetransfer-07d291
2015-11-03 21:45 - 2015-11-03 21:45 - 00008697 _____ C:\Users\Jimmy James\AppData\Local\recently-used.xbel
2015-11-03 21:01 - 2015-11-03 21:01 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\webkit
2015-11-01 22:14 - 2013-08-22 06:25 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts.20151101-221403.backup
2015-11-01 20:02 - 2015-11-01 20:02 - 00002668 _____ C:\Windows\wininit.ini
2015-11-01 19:47 - 2015-11-01 19:47 - 00000000 ____D C:\Program Files\Common Files\AV
2015-11-01 19:47 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Program Files\Post Win10 Spybot-install.exe
2015-11-01 19:41 - 2015-11-11 08:45 - 00001398 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D; Start Center.lnk
2015-11-01 19:41 - 2015-11-01 22:10 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-11-01 19:41 - 2015-11-01 19:58 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-11-01 19:41 - 2015-11-01 19:41 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2015-11-01 19:41 - 2015-11-01 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-11-01 19:41 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2015-11-01 19:38 - 2015-11-11 08:45 - 00001217 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TempoPerfect Metronome Software.lnk
2015-11-01 19:36 - 2015-11-11 08:45 - 00001187 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crescendo Music Notation Editor.lnk
2015-11-01 19:36 - 2015-11-11 08:45 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MixPad Multitrack Recording Software.lnk
2015-11-01 19:36 - 2015-11-11 08:45 - 00001141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk
2015-11-01 19:36 - 2015-11-09 08:07 - 00000000 ____D C:\Windows\System32\Tasks\NCH Software
2015-11-01 19:36 - 2015-11-09 08:07 - 00000000 ____D C:\Users\Jimmy James\AppData\Roaming\NCH Software
2015-11-01 19:36 - 2015-11-01 19:38 - 00000000 ____D C:\ProgramData\NCH Software
2015-11-01 19:36 - 2015-11-01 19:38 - 00000000 ____D C:\Program Files (x86)\NCH Software
2015-11-01 19:36 - 2015-11-01 19:36 - 00000000 ____D C:\Users\Jimmy James\Documents\Mixpad Projects
2015-11-01 19:35 - 2015-11-01 19:35 - 00657176 _____ (NCH Software) C:\Users\Jimmy James\Downloads\crescendosetup.exe
2015-11-01 19:32 - 2015-11-01 19:33 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Jimmy James\Downloads\spybot-2.4.exe
2015-11-01 11:15 - 2015-11-01 11:15 - 00007606 _____ C:\Users\Jimmy James\AppData\Local\Resmon.ResmonCfg
2015-10-31 08:46 - 2015-11-11 08:45 - 00001425 _____ C:\Users\Jimmy James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-10-31 07:00 - 2015-10-31 08:11 - 00000000 ____D C:\Users\Jimmy James\AppData\Roaming\Store
2015-10-31 07:00 - 2015-10-31 07:18 - 00004760 _____ C:\Windows\SysWOW64\Rasigusxu.ini
2015-10-31 07:00 - 2015-10-31 07:18 - 00002472 _____ C:\Windows\SysWOW64\RasigusxuOff.ini
2015-10-31 07:00 - 2015-10-31 07:18 - 00002472 _____ C:\Windows\system32\RasigusxuOff.ini
2015-10-31 06:59 - 2015-10-31 06:59 - 00000000 ____D C:\Windows\system32\togm
2015-10-31 06:59 - 2015-10-31 06:59 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\Tempfolder
2015-10-31 06:58 - 2015-11-11 08:35 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-10-31 06:58 - 2015-11-11 08:25 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-10-31 06:58 - 2015-10-31 08:10 - 00000000 ____D C:\Users\Jimmy James\AppData\LocalLow\Company
2015-10-31 06:58 - 2015-10-31 06:58 - 00003348 _____ C:\Windows\System32\Tasks\Bhikesd
2015-10-31 06:58 - 2015-10-31 06:58 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\globalUpdate
2015-10-31 06:58 - 2015-10-31 06:58 - 00000000 ____D C:\uninst
2015-10-31 06:53 - 2015-11-11 11:32 - 00000382 ____H C:\Windows\Tasks\DXMBGGVCJRPOAFAX.job
2015-10-31 06:53 - 2015-10-31 06:53 - 00003402 _____ C:\Windows\System32\Tasks\DXMBGGVCJRPOAFAX
2015-10-31 06:53 - 2015-10-31 06:53 - 00000000 ____D C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2015-10-31 05:02 - 2015-10-31 05:02 - 00186880 _____ (TODO: ) C:\Windows\system32\rsrcs.dll
2015-10-27 05:45 - 2015-10-30 09:20 - 10289664 _____ C:\Users\Jimmy James\Downloads\2310UrinaryFA15WEB.ppt
2015-10-22 19:30 - 2015-10-22 19:31 - 47743094 _____ C:\Users\Jimmy James\Downloads\20151022 Balad of the Beauty Queen master.wav
2015-10-15 03:41 - 2015-10-15 03:41 - 10962432 _____ C:\Users\Jimmy James\Downloads\2310GIFA15LectWEB.ppt
2015-10-14 09:40 - 2015-09-24 09:42 - 00348672 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll
2015-10-14 09:40 - 2015-09-24 09:40 - 00737280 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2015-10-14 09:40 - 2015-08-26 19:43 - 22372152 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-10-14 09:40 - 2015-08-26 19:42 - 19795904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-10-14 09:40 - 2015-08-07 14:40 - 01736520 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-10-14 09:40 - 2015-08-07 14:40 - 01499920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-10-14 09:39 - 2015-09-10 10:18 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-10-14 09:39 - 2015-09-10 10:06 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-10-14 09:39 - 2015-09-10 09:51 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-10-14 09:39 - 2015-09-10 09:37 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-10-14 09:39 - 2015-09-10 09:37 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-10-14 09:39 - 2015-09-10 09:35 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-10-14 09:39 - 2015-09-10 09:28 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-10-14 09:39 - 2015-09-10 09:21 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-10-14 09:39 - 2015-09-10 09:19 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-10-14 09:39 - 2015-09-10 09:17 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-10-14 09:39 - 2015-09-10 09:17 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-10-14 09:39 - 2015-09-10 09:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-10-14 09:39 - 2015-09-10 09:05 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-10-14 09:39 - 2015-09-10 08:57 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-10-14 09:39 - 2015-09-10 08:55 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-10-14 09:39 - 2015-09-10 08:55 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-10-12 08:15 - 2015-10-12 08:20 - 214620220 _____ C:\Users\Jimmy James\Downloads\wetransfer-07d291.zip
2015-10-08 20:23 - 2015-10-08 21:15 - 00000000 ____D C:\Users\Jimmy James\Documents\DCJB tunes
2015-10-06 22:22 - 2015-11-08 00:03 - 00000000 ____D C:\Users\Jimmy James\AppData\Roaming\vlc
2015-10-06 22:22 - 2015-10-06 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-10-06 22:21 - 2015-10-06 22:21 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2015-10-06 22:14 - 2015-10-06 22:18 - 28849904 _____ C:\Users\Jimmy James\Downloads\vlc-2.2.1-win32.exe
2015-10-06 10:05 - 2015-10-06 10:06 - 10188288 _____ C:\Users\Jimmy James\Downloads\2310ResFA15WEB.ppt
2015-10-05 22:26 - 2015-10-06 22:23 - 00000000 ____D C:\Users\Jimmy James\Downloads\Skyfall (2012) [1080p]
2015-10-05 22:00 - 2015-10-06 01:11 - 00000000 ____D C:\Users\Jimmy James\Downloads\Shaolin Soccer (2001) 720p 5.1 [Uncut HK Version] Blu-ray
2015-09-27 11:32 - 2015-09-27 11:32 - 00014799 _____ C:\Users\Jimmy James\Downloads\Literature Inventory 8-30-15.xlsx
2015-09-26 15:07 - 2015-09-26 15:13 - 65376256 _____ C:\Users\Jimmy James\Downloads\calibre-2.39.0.msi
2015-09-26 14:46 - 2015-09-26 14:46 - 07370240 _____ C:\Users\Jimmy James\Downloads\2310VesselsCircFA2015WEB.ppt
2015-09-24 20:17 - 2015-09-24 20:17 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\PDFEditor
2015-09-24 20:15 - 2015-09-24 20:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF to Word Converter
2015-09-24 20:15 - 2015-09-24 20:15 - 00000000 ____D C:\Program Files (x86)\GreenTree Applications
2015-09-24 20:10 - 2015-09-24 20:11 - 24837416 _____ C:\Users\Jimmy James\Downloads\PdfToWordConverterSetup.exe
2015-09-21 14:53 - 2015-09-20 11:47 - 00026525 _____ C:\Users\Jimmy James\Documents\Personal%20Statement%206th%20draft.doc_0.odt
2015-09-18 15:52 - 2015-09-18 16:12 - 268589235 _____ C:\Users\Jimmy James\Downloads\corrales 19th tunes.zip
2015-09-15 11:23 - 2015-09-15 11:24 - 16055296 _____ C:\Users\Jimmy James\Downloads\2310HeartTwoFA15WEB.ppt
2015-09-09 21:22 - 2015-07-30 10:18 - 00268288 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-09-09 21:22 - 2015-07-30 09:22 - 00230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-09-09 21:21 - 2015-09-09 21:21 - 04883456 _____ C:\Users\Jimmy James\Downloads\2310HeartOneFA15WEB.ppt
2015-09-09 21:21 - 2015-09-01 19:55 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-09 21:21 - 2015-09-01 19:50 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-09 21:21 - 2015-09-01 19:17 - 00301568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-09 21:21 - 2015-09-01 19:13 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-09 21:21 - 2015-08-03 14:15 - 00074928 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-09-09 21:21 - 2015-08-03 14:15 - 00065600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-09-09 21:21 - 2015-08-01 07:22 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-09-09 21:21 - 2015-07-31 20:47 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2015-09-09 21:21 - 2015-07-31 20:45 - 00182784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2015-09-09 21:21 - 2015-07-31 20:38 - 01265152 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-09 21:21 - 2015-07-31 20:37 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2015-09-09 21:21 - 2015-07-31 20:37 - 00359936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2015-09-09 21:21 - 2015-07-22 07:34 - 02775552 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-09 21:21 - 2015-07-22 07:33 - 01728000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2015-09-09 21:21 - 2015-07-22 07:25 - 02461184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-09 21:21 - 2015-07-22 07:25 - 01546752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2015-09-09 21:21 - 2015-07-18 11:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2015-09-09 21:21 - 2015-07-18 11:29 - 00655872 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2015-09-09 21:21 - 2015-07-18 11:29 - 00148480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shacct.dll
2015-09-09 21:21 - 2015-07-18 11:27 - 00520192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2015-09-09 21:21 - 2015-07-13 20:27 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\tzsync.exe
2015-09-08 05:28 - 2015-09-08 05:28 - 05416960 _____ C:\Users\Jimmy James\Downloads\2310bloodFA15WEB.ppt
2015-08-25 15:20 - 2015-08-25 15:20 - 00931408 _____ (Google Inc.) C:\Users\Jimmy James\Downloads\GoogleVoiceAndVideoSetup(1).exe
2015-08-24 13:24 - 2015-11-11 11:41 - 00000960 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001UA.job
2015-08-24 13:24 - 2015-11-07 22:41 - 00000908 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001Core.job
2015-08-24 13:24 - 2015-09-16 21:36 - 00003918 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001UA
2015-08-24 13:24 - 2015-09-16 21:36 - 00003538 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001Core
2015-08-24 13:24 - 2015-08-24 13:24 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\Google
2015-08-24 13:23 - 2015-08-24 13:23 - 00931408 _____ (Google Inc.) C:\Users\Jimmy James\Downloads\GoogleVoiceAndVideoSetup.exe
2015-08-13 19:42 - 2015-08-13 19:43 - 41940504 _____ (Dell Inc.) C:\Users\Jimmy James\Downloads\5548_Input_Driver_CG1DK_WN32_1.3.20.55679_A02.EXE

==================== Three Months Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-11 12:12 - 2015-06-14 14:23 - 00000304 _____ C:\Windows\Tasks\GamerForest Support.job
2015-11-11 12:00 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\system32\sru
2015-11-11 11:54 - 2015-06-14 14:23 - 00000312 _____ C:\Windows\Tasks\GamerForest Updater.job
2015-11-11 11:51 - 2015-02-16 06:15 - 01967272 _____ C:\Windows\WindowsUpdate.log
2015-11-11 11:38 - 2015-06-14 14:13 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1714133512-296453273-4189880979-1001
2015-11-11 11:31 - 2014-11-20 21:42 - 00865408 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-11 11:26 - 2015-02-16 06:16 - 00006469 _____ C:\Windows\SysWOW64\Gms.log
2015-11-11 11:23 - 2013-08-22 07:46 - 00021599 _____ C:\Windows\setupact.log
2015-11-11 11:23 - 2013-08-22 07:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-11 11:22 - 2015-07-01 21:11 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-11 11:22 - 2014-11-20 21:32 - 00669586 _____ C:\Windows\PFRO.log
2015-11-11 10:28 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\AppReadiness
2015-11-11 10:26 - 2013-08-22 08:20 - 00000000 ____D C:\Windows\CbsTemp
2015-11-11 10:23 - 2015-06-14 14:23 - 00000338 _____ C:\Windows\Tasks\UpdaterEX.job
2015-11-11 10:19 - 2015-06-20 16:50 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-11 09:11 - 2013-08-22 06:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-11-11 08:48 - 2013-08-22 07:44 - 00362576 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-11 08:47 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\FileManager
2015-11-11 08:45 - 2015-06-21 08:11 - 00000949 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-11-11 08:45 - 2015-06-15 14:13 - 00001026 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-11-11 08:45 - 2015-06-14 15:14 - 00000303 _____ C:\Users\Jimmy James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Control Panel.lnk
2015-11-11 08:45 - 2015-06-14 14:08 - 00001425 _____ C:\Users\Jimmy James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet-Explorer.lnk
2015-11-11 08:45 - 2015-06-14 14:07 - 00000445 _____ C:\Users\Jimmy James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-11-11 08:45 - 2015-06-14 14:07 - 00000443 _____ C:\Users\Jimmy James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-11-11 08:45 - 2015-02-16 06:13 - 00000712 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk
2015-11-11 08:35 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\Resources
2015-11-10 21:01 - 2015-07-28 16:11 - 00000000 ____D C:\Users\Jimmy James\Documents\OT Application stuff
2015-11-10 21:00 - 2015-06-25 08:13 - 00634880 ___SH C:\Users\Jimmy James\Downloads\Thumbs.db
2015-11-10 19:22 - 2015-07-01 21:11 - 00003718 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-11-07 06:20 - 2015-06-14 14:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-06 19:33 - 2013-08-22 08:36 - 00000000 ___RD C:\Windows\Offline Web Pages
2015-11-04 12:33 - 2015-06-17 22:18 - 00194560 ___SH C:\Users\Jimmy James\Desktop\Thumbs.db
2015-11-03 22:23 - 2015-06-17 22:18 - 00000000 ____D C:\Users\Jimmy James\Documents\Other James Stuff
2015-11-03 21:58 - 2015-06-21 08:11 - 00000000 ____D C:\Users\Jimmy James\.gimp-2.8
2015-11-03 21:45 - 2015-06-21 08:13 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\gtk-2.0
2015-10-31 15:26 - 2015-06-14 14:14 - 00000000 ____D C:\ProgramData\EPSON
2015-10-31 09:14 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\IME
2015-10-31 07:59 - 2015-07-29 20:51 - 00074240 ___SH C:\Users\Jimmy James\Documents\Thumbs.db
2015-10-31 07:38 - 2015-06-20 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-10-31 07:38 - 2015-06-20 16:50 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-31 06:59 - 2015-02-16 05:48 - 00657920 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2015-10-31 06:59 - 2015-02-16 05:48 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2015-10-29 12:47 - 2015-08-04 12:57 - 00000000 ____D C:\Users\Jimmy James\Documents\E-Books
2015-10-20 17:56 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\rescache
2015-10-19 06:45 - 2015-06-21 09:06 - 00000000 ____D C:\Users\Jimmy James\Downloads\moms_typewriter
2015-10-18 08:26 - 2013-08-22 08:36 - 00000000 ___RD C:\Windows\ToastData
2015-10-15 21:51 - 2014-11-21 05:47 - 00810488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-10-15 21:51 - 2014-11-21 05:47 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-15 18:43 - 2015-06-18 18:47 - 00000000 ____D C:\Windows\system32\MRT
2015-10-15 18:37 - 2015-06-18 18:47 - 143481208 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Files in the root of some directories =======

2015-11-01 19:47 - 2015-07-28 17:52 - 0821920 _____ (Safer-Networking Ltd.                                       ) C:\Program Files\Post Win10 Spybot-install.exe
2015-08-09 12:23 - 2015-08-09 12:23 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2015-06-17 22:33 - 2015-06-17 22:33 - 1994592 _____ (BitTorrent Inc.) C:\Program Files (x86)\uTorrent.exe
2015-04-14 09:28 - 2015-04-14 09:28 - 0004387 _____ () C:\Users\Jimmy James\AppData\Roaming\tXnxIXs16
2015-11-03 21:45 - 2015-11-03 21:45 - 0008697 _____ () C:\Users\Jimmy James\AppData\Local\recently-used.xbel
2015-11-01 11:15 - 2015-11-01 11:15 - 0007606 _____ () C:\Users\Jimmy James\AppData\Local\Resmon.ResmonCfg
2015-02-16 05:59 - 2015-02-16 05:59 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll
[2015-02-16 05:48] - [2015-10-31 06:59] - 0657920 ____A (Microsoft Corporation) D393329F1AF5D5DDAF94F0E2F6314305

C:\Windows\SysWOW64\dnsapi.dll
[2015-02-16 05:48] - [2015-10-31 06:59] - 0498688 ____A (Microsoft Corporation) 3D13CE0D2E4EC79F6E7D4623D521225E

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-11-11 09:08

==================== End of FRST.txt ============================

 

Here is the Addition.txt:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by [removed] (2015-11-11 12:15:13)
Running from C:\Users\[removed]\Desktop
Windows 8.1 (X64) (2015-06-14 21:07:12)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1714133512-296453273-4189880979-500 - Administrator - Disabled)
Guest (S-1-5-21-1714133512-296453273-4189880979-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1714133512-296453273-4189880979-1003 - Limited - Enabled)
Jimmy James (S-1-5-21-1714133512-296453273-4189880979-1001 - Administrator - Enabled) => C:\Users\Jimmy James

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 19 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Audacity 2.1.0 (HKLM-x32\…\Audacity_is1) (Version: 2.1.0 - Audacity Team)
calibre (HKLM-x32\…\{6C086582-8A0F-49D8-9E0D-82AAF2912118}) (Version: 2.33.0 - Kovid Goyal)
Crescendo Music Notation Editor (HKLM-x32\…\Crescendo) (Version: 1.63 - NCH Software)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.1.6664.10 - Dell)
Dell System Detect (HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\73f463568823ebbe) (Version: 6.4.0.7 - Dell)
EPSON WorkForce 545 Series Printer Uninstall (HKLM\…\EPSON WorkForce 545 Series) (Version:  - SEIKO EPSON Corporation)
ETD Ware USB-x64 7.0.5.1_X09 (HKLM\…\Elan) (Version: 7.0.5.1 - ELAN Microelectronics Corp.)
FlashBeat (HKLM-x32\…\FlashBeat) (Version:  - ) <==== ATTENTION
Foxit Cloud (HKLM-x32\…\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 3.7.143.923 - Foxit Software Inc.)
Foxit Reader (HKLM-x32\…\Foxit Reader_is1) (Version: 7.1.5.425 - Foxit Software Inc.)
FSS Audio Converter version 1.0.8.1 (HKLM-x32\…\FSS Audio Converter_is1) (Version: 1.0.8.1 - FreeSmartSoft)
GIMP 2.8.14 (HKLM\…\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Talk Plugin (HKLM-x32\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Intel 3D Camera settings (HKLM-x32\…\InstallShield_{435B06FD-39B3-4DD8-84FE-5CAE06109B9A}) (Version: 0.0.0.2 - )
Intel 3D Camera settings (x32 Version: 0.0.0.2 - ) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.30.1072 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4013 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.5.0.1056 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\…\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Intel(R) WiDi (HKLM\…\{5BBC7722-E4D9-4406-A8B9-1E11A23B9EAF}) (Version: 5.0.32.0 - Intel Corporation)
Intel(R) Wireless Bluetooth(R)(patch version 17.1.1431.1) (HKLM\…\{302600C1-6BDF-4FD1-1407-148929CC1385}) (Version: 17.1.1407.0480 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{694000a5-c594-49d2-b6e4-ef3960120b0f}) (Version: 17.1.0 - Intel Corporation)
Intel® RealSense™ Depth Camera Manager  (x86): Intel® RealSense™ 3D camera IO module (x32 Version: 1.2.14.28436 - Intel Corporation) Hidden
Intel® RealSense™ Depth Camera Manager  (x86): Intel® RealSense™ Depth Camera Manager Service (x32 Version: 1.2.14.28436 - Intel Corporation) Hidden
Intel® RealSense™ Depth Camera Manager  (x86): Intel® RealSense™ SDK info server (x32 Version: 1.2.14.28436 - Intel Corporation) Hidden
Intel® RealSense™ Depth Camera Manager (HKLM-x32\…\ARP_for_prd_dcm_runtime_1.2.14.28436) (Version: 1.2.14.28436 - Intel Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Maxx Audio Installer (x64) (Version: 1.6.4616.61 - Waves Audio Ltd.) Hidden
Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\…\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\…\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
MixPad Multitrack Recording Software (HKLM-x32\…\MixPad) (Version: 3.93 - NCH Software)
Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
OpenOffice 4.1.1 (HKLM-x32\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
PDF to Word Converter 1.7 (HKLM\…\{d7403750-6760-411b-98aa-347ae8ceb5ee}) (Version: 1.7 - GreenTree Applications SRL)
Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.16.014 - Dell Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7363 - Realtek Semiconductor Corp.)
Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
System NotifierV25.10 (HKLM-x32\…\System NotifierV25.10) (Version: 1.36.01.22 - HQ-VideoV25.10) <==== ATTENTION
TempoPerfect Metronome Software (HKLM-x32\…\TempoPerfect) (Version: 4.08 - NCH Software)
True Color (HKLM-x32\…\{55c734b2-fcff-447e-81cc-a6f04ebf09fc}) (Version: 6.0.0.6 - Entertainment Experience)
True Color (Version: 6.0.0.6 - Entertainment Experience LLC) Hidden
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
WavePad Sound Editor (HKLM-x32\…\WavePad) (Version: 6.33 - NCH Software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1714133512-296453273-4189880979-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1714133512-296453273-4189880979-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1714133512-296453273-4189880979-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1714133512-296453273-4189880979-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)

==================== Restore Points =========================

14-10-2015 09:47:33 Windows Update
27-10-2015 12:58:39 Scheduled Checkpoint
31-10-2015 15:25:58 Removed Microsoft Silverlight
31-10-2015 16:42:58 Restore Operation
01-11-2015 20:02:22 Cleaner (Spybot - Search & Destroy 2.4, administrator privileges
09-11-2015 12:46:56 Scheduled Checkpoint

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 06:25 - 2015-11-01 22:14 - 00450771 ____R C:\Windows\system32\Drivers\etc\hosts

127.0.0.1    www.007guard.com
127.0.0.1    007guard.com
127.0.0.1    008i.com
127.0.0.1    www.008k.com
127.0.0.1    008k.com
127.0.0.1    www.00hq.com
127.0.0.1    00hq.com
127.0.0.1    010402.com
127.0.0.1    www.032439.com
127.0.0.1    032439.com
127.0.0.1    www.0scan.com
127.0.0.1    0scan.com
127.0.0.1    1000gratisproben.com
127.0.0.1    www.1000gratisproben.com
127.0.0.1    1001namen.com
127.0.0.1    www.1001namen.com
127.0.0.1    100888290cs.com
127.0.0.1    www.100888290cs.com
127.0.0.1    www.100sexlinks.com
127.0.0.1    100sexlinks.com
127.0.0.1    10sek.com
127.0.0.1    www.10sek.com
127.0.0.1    www.1-2005-search.com
127.0.0.1    1-2005-search.com
127.0.0.1    123fporn.info
127.0.0.1    www.123fporn.info
127.0.0.1    123haustiereundmehr.com
127.0.0.1    www.123haustiereundmehr.com
127.0.0.1    123moviedownload.com
127.0.0.1    www.123moviedownload.com

There are 15463 more lines.


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0167BF76-CBB5-43F4-BBB7-CDC320D968A9} - \WindApp Update -> No File <==== ATTENTION
Task: {10ED87AE-CD7F-4497-8C20-DF9AE57A22CE} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-09-01] (Realtek Semiconductor)
Task: {174A1342-C45E-445D-9DAD-87CFBFC2A2CC} - \ShopperPro -> No File <==== ATTENTION
Task: {1A832373-1A58-4E30-BCC1-E01C0AEB0285} - System32\Tasks\GamerForest Support => C:\Users\JIMMYJ~1\AppData\Local\GAMERF~1\gfore_run.exe
Task: {27A78A90-5F8D-4158-A511-E8FC8FEFD510} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {2F316D90-9020-4BED-B3B7-A508CDD1A1B1} - System32\Tasks\updateTask => c:\task.vbs
Task: {2F81DD38-A148-482B-BF4F-589D2FCDE0EE} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-05-25] (PC-Doctor, Inc.)
Task: {41E81E27-256B-4EDE-B666-6591775B6A11} - \Inst_Rep -> No File <==== ATTENTION
Task: {4416F6A9-DD45-429E-A3EC-3966606136F0} - \Selection Tools Update -> No File <==== ATTENTION
Task: {4698E670-E7F4-453F-A1E6-413B73C7D672} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {4CFC4C6D-4DE9-49E5-A163-C8D808D526F6} - System32\Tasks\EQNAKGAOSGAVHUAN => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: {513E5C0F-3359-4152-9BF7-AF78A2005944} - \Inst_Rep -> No File <==== ATTENTION
Task: {565198ED-CF75-437D-B6AA-2F8CEBC2C3E2} - \SwiftSearch Auto Updater 1.10.0.25 Core -> No File <==== ATTENTION
Task: {5755B931-1B42-4ED9-A985-FA7AFB8DAFAC} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {59151597-0BB5-45C4-9EA4-2CB08A722AB0} - System32\Tasks\CWOBUGTNCV1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {631C89B4-2CA0-45F4-B118-607F2104F002} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001Core => C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-24] (Google Inc.)
Task: {6ED6E732-8E56-4251-84EB-562D2E118F0F} - System32\Tasks\DXMBGGVCJRPOAFAX => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: {76588F62-0374-407B-BAA7-6DD85B2B62A2} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
Task: {8464AC3A-CB37-4418-8752-C0127A3E4F3E} - \SPDriver -> No File <==== ATTENTION
Task: {8E492037-835C-4C17-BFED-602D49842E0F} - System32\Tasks\runTask => %TEMP%/Updater.exe
Task: {8FD3E658-2E05-4B99-A39E-F7D2D22DB00B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001UA => C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-24] (Google Inc.)
Task: {9C0246F6-487F-4AC9-9D04-FDE709750E19} - \SwiftSearch Auto Updater 1.10.0.25 Core -> No File <==== ATTENTION
Task: {A2BF6AFF-A016-4A98-B072-F0CF5F11366C} - System32\Tasks\tXnxIXs16 => C:\Users\Jimmy James\AppData\Roaming\tXnxIXs16.exe <==== ATTENTION
Task: {A48D8F0C-978D-472A-9DF8-2E7F4C5B041D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {AABD1DF7-663E-49EB-A94B-3AF35217D2CC} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {AC4A8A5E-A592-4D4F-87DF-831563E62AA5} - System32\Tasks\Chromium => C:\Users\JIMMYJ~1\AppData\Local\Chromium\APPLIC~1\450242~1.0\INSTAL~1\UNINST~1.EXE
Task: {AEBB7099-90D4-444A-A993-FF4DAD2B523A} - System32\Tasks\Bhikesd => C:\PROGRA~1\SHOPPE~1\Haitp.bat
Task: {B02B99BB-4454-47DB-BF3E-94991AE21791} - System32\Tasks\GamerForest Updater => C:\Users\Jimmy James\AppData\Local\GamerForest\updater.exe
Task: {B26010EB-65CF-4E46-8AE2-C3C8C862DDDE} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update -> No File <==== ATTENTION
Task: {BB114104-5147-4B36-B193-8638577898BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-10] (Adobe Systems Incorporated)
Task: {D22C13F2-C30B-4A77-835A-25495B337EED} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {D74558BC-9809-4AFC-9768-96DA5CAF74FC} - System32\Tasks\FSSUpdaterService => C:\Users\Jimmy James\AppData\Roaming\UpdaterService\FSSUpdaterService.exe [2014-12-14] () <==== ATTENTION
Task: {D960479F-FAD4-4200-9AB4-D1C69C1B5C61} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update -> No File <==== ATTENTION
Task: {DDC1FF8E-3625-493D-B532-467E134CEBF9} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2015-05-25] (PC-Doctor, Inc.)
Task: {E2B898F8-DA92-4A1A-8BDE-BF33C0671662} - \SPBIW_UpdateTask_Time_323535383538343738362d50372d5a456c37325a347841 -> No File <==== ATTENTION
Task: {F8186CD8-A232-4524-86EC-041461165530} - System32\Tasks\UpdaterEX => C:\Users\JIMMYJ~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Chromium.job => C:\Users\JIMMYJ~1\AppData\Local\Chromium\APPLIC~1\450242~1.0\INSTAL~1\UNINST~1.EXE
Task: C:\Windows\Tasks\CWOBUGTNCV1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\DXMBGGVCJRPOAFAX.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\EQNAKGAOSGAVHUAN.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\GamerForest Support.job => C:\Users\JIMMYJ~1\AppData\Local\GAMERF~1\gfore_run.exe
Task: C:\Windows\Tasks\GamerForest Updater.job => C:\Users\Jimmy James\AppData\Local\GamerForest\updater.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001Core.job => C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001UA.job => C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\tXnxIXs16.job => C:\Users\Jimmy James\AppData\Roaming\tXnxIXs16.exe <==== ATTENTION
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\JIMMYJ~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

==================== Loaded Modules (Whitelisted) ==============

2014-11-14 15:51 - 2014-11-14 15:51 - 00466432 _____ () C:\Windows\system32\DPPPlugin.dll
2014-12-25 00:27 - 2014-12-25 00:27 - 00094160 _____ () C:\Program Files\TrueColor\TrueColorALS.exe
2015-02-16 05:30 - 2014-11-23 23:24 - 00456808 _____ () C:\Windows\system32\igfxTray.exe
2015-03-19 03:19 - 2015-03-19 03:19 - 00116224 _____ () C:\Program Files (x86)\GreenTree Applications\PDF to Word Converter\PDFToWordConverterUpdateChecker.exe
2015-11-01 19:41 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2015-11-01 19:41 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2015-11-01 19:41 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2015-11-01 19:41 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2015-11-01 19:41 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2014-10-10 10:37 - 2014-10-10 10:37 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\gfore => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Rasigusxu => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\win8gfore => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WWatcherProxy => ""="service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com

There are 7866 more sites.

IE trusted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\dell.com -> dell.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\123simsen.com -> www.123simsen.com

There are 7866 more sites.


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1714133512-296453273-4189880979-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jimmy James\Pictures\Jemez Mountain Beauty.jpg
DNS Servers: 192.168.0.1 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{3D73F5E4-8F82-463F-94DA-6BA1917CCE65}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{F0E2173A-B620-4A98-9AA7-C8DFA0EC4DBE}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{51176830-06B7-45A3-A69C-4FEADEA0D0B6}] => (Allow) C:\Users\Jimmy James\AppData\Local\Chromium\Application\chrome.exe
FirewallRules: [{951A1D84-669C-4609-A353-36839E6F3540}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1164A575-FA50-40E1-A02B-06034AE321FE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BCD73466-3997-42D1-91DE-0B55D92D7AD4}] => (Allow) C:\Users\Jimmy James\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D3E8DDDC-0DAC-4CD3-9F38-57BC075D90FC}] => (Allow) C:\Users\Jimmy James\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A5E8F02F-E006-45EA-9A88-EC50AA099728}] => (Allow) C:\Program Files (x86)\MyBrowser\MyBrowser\Application\mybrowser.exe
FirewallRules: [{038B50D6-58E0-4E27-8895-727D8A1FE47C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A2C5CDB1-C03E-4EEF-9BA1-E88BA8C3C5CD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service

==================== Faulty Device Manager Devices =============

Name: Realtek PCIe FE Family Controller
Description: Realtek PCIe FE Family Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: RTL8168
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/11/2015 11:33:34 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program aswMBR.exe version 1.0.1.2252 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: ecc

Start Time: 01d11caf689fb82b

Termination Time: 4294967295

Application Path: C:\Users\Jimmy James\Desktop\aswMBR.exe

Report Id: b65d45be-88a2-11e5-8279-91fe15208fb9

Faulting package full name:

Faulting package-relative application ID:

Error: (11/11/2015 08:55:55 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program gentlemjmp_ieeuu.tmp version 51.52.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: c80

Start Time: 01d11c99627f33cc

Termination Time: 4294967295

Application Path: C:\Users\JIMMYJ~1\AppData\Local\Temp\is-4OVKB.tmp\gentlemjmp_ieeuu.tmp

Report Id: af547ba2-888c-11e5-8277-f7617aae1286

Faulting package full name:

Faulting package-relative application ID:

Error: (11/11/2015 08:51:34 AM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (3664) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.

Error: (11/11/2015 08:46:27 AM) (Source: TrueColorALS) (EventID: 4) (User: )
Description: TrueColorALSCUISDKaccess(): Getting access to the pipe failed. Error:1073741825 (0x40000001) and Error: 2 (0x2)

Error: (11/11/2015 08:30:09 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: spbia.exe, version: 1.0.0.4, time stamp: 0x562fc085
Faulting module name: spbia.exe, version: 1.0.0.4, time stamp: 0x562fc085
Exception code: 0xc0000005
Fault offset: 0x000000000000a746
Faulting process id: 0xbf4
Faulting application start time: 0xspbia.exe0
Faulting application path: spbia.exe1
Faulting module path: spbia.exe2
Report Id: spbia.exe3
Faulting package full name: spbia.exe4
Faulting package-relative application ID: spbia.exe5

Error: (11/11/2015 08:26:38 AM) (Source: MsiInstaller) (EventID: 11316) (User: SonofSpudbort)
Description: Product: globalupdate Helper – Error 1316. The specified account already exists.

Error: (11/11/2015 08:25:49 AM) (Source: MsiInstaller) (EventID: 11316) (User: SonofSpudbort)
Description: Product: globalupdate Helper – Error 1316. The specified account already exists.

Error: (11/07/2015 08:57:16 PM) (Source: TrueColorALS) (EventID: 4) (User: )
Description: TrueColorALSCUISDKaccess(): Getting access to the pipe failed. Error:1073741825 (0x40000001) and Error: 2 (0x2)

Error: (11/03/2015 07:06:14 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (11/02/2015 06:27:06 PM) (Source: TrueColorALS) (EventID: 4) (User: )
Description: TrueColorALSCUISDKaccess(): Getting access to the pipe failed. Error:1073741825 (0x40000001) and Error: 2 (0x2)


System errors:
=============
Error: (11/11/2015 11:26:10 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The globalUpdate Update Service (globalUpdate) service failed to start due to the following error:
%%2

Error: (11/11/2015 11:24:08 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (11/11/2015 11:24:08 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (60000 milliseconds) while waiting for the CutterFoobar service to connect.

Error: (11/11/2015 09:15:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The globalUpdate Update Service (globalUpdate) service failed to start due to the following error:
%%2

Error: (11/11/2015 09:13:10 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (11/11/2015 09:13:09 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (60000 milliseconds) while waiting for the CutterFoobar service to connect.

Error: (11/11/2015 09:10:59 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240055: Security Update for Microsoft .NET Framework 4.5.1 and 4.5.2 for Windows 8.1 for x64-based Systems (KB3097997).

Error: (11/11/2015 09:09:11 AM) (Source: DCOM) (EventID: 10010) (User: SonofSpudbort)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (11/11/2015 09:08:41 AM) (Source: DCOM) (EventID: 10010) (User: SonofSpudbort)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (11/11/2015 08:52:35 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The globalUpdate Update Service (globalUpdate) service failed to start due to the following error:
%%2


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-5200U CPU @ 2.20GHz
Percentage of memory in use: 13%
Total physical RAM: 12203.33 MB
Available physical RAM: 10558.8 MB
Total Virtual: 25003.33 MB
Available Virtual: 23250.34 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:922.87 GB) (Free:834.74 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 5C29CDFB)

Partition: GPT.

==================== End of Addition.txt ============================

 

 

 

:welcome:

 

You have one heavily infected computer, you may have gotten all of this from the game sites and if you downloaded anything via the torrents.  You have a legit file we need to fix but we can do that later.

 

 

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 

Start
CloseProcesses:
CreateRestorePoint:
HKLM-x32\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
C:\Program Files (x86)\YTDownloader
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
AppInit_DLLs: C:\ProgramData\FlashBeat\FlashBeat64.dll => No File
AppInit_DLLs-x32: C:\ProgramData\FlashBeat\FlashBeat32.dll => No File
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {3AEE68F1-2444-4B79-8A19-5A0E4F15FA24} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FF Extension: No Name - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\extensions\[removed] [not found]
FF Extension: No Name - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\extensions\[removed] [not found]
FF Extension: No Name - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [not found]
S2 6e9452be; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\CutterFoobar\CutterFoobar.dll",serv
c:\Program Files (x86)\CutterFoobar
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc [X] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc [X] <==== ATTENTION
C:\Program Files (x86)\globalUpdate
2015-11-11 08:25 - 2015-11-11 11:32 - 00001042 _____ C:\Windows\Tasks\tXnxIXs16.job
2015-11-11 08:25 - 2015-11-11 08:25 - 00004072 _____ C:\Windows\System32\Tasks\tXnxIXs16
2015-11-11 08:24 - 2015-11-11 11:32 - 00000382 ____H C:\Windows\Tasks\EQNAKGAOSGAVHUAN.job
2015-11-11 08:24 - 2015-11-11 11:32 - 00000370 _____ C:\Windows\Tasks\CWOBUGTNCV1.job
2015-11-11 08:24 - 2015-11-11 08:24 - 00003402 _____ C:\Windows\System32\Tasks\EQNAKGAOSGAVHUAN
2015-11-11 08:24 - 2015-11-11 08:24 - 00002884 _____ C:\Windows\System32\Tasks\CWOBUGTNCV1
2015-11-01 22:14 - 2013-08-22 06:25 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts.20151101-221403.backup
2015-10-31 06:58 - 2015-10-31 06:58 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\globalUpdate
2015-06-17 22:33 - 2015-06-17 22:33 - 1994592 _____ (BitTorrent Inc.) C:\Program Files (x86)\uTorrent.exe
C:\Program Files (x86)\uTorrent.exe
Task: {0167BF76-CBB5-43F4-BBB7-CDC320D968A9} - \WindApp Update -> No File <==== ATTENTION
Task: {174A1342-C45E-445D-9DAD-87CFBFC2A2CC} - \ShopperPro -> No File <==== ATTENTION
Task: {27A78A90-5F8D-4158-A511-E8FC8FEFD510} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {41E81E27-256B-4EDE-B666-6591775B6A11} - \Inst_Rep -> No File <==== ATTENTION
Task: {4416F6A9-DD45-429E-A3EC-3966606136F0} - \Selection Tools Update -> No File <==== ATTENTION
Task: {4CFC4C6D-4DE9-49E5-A163-C8D808D526F6} - System32\Tasks\EQNAKGAOSGAVHUAN => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: {513E5C0F-3359-4152-9BF7-AF78A2005944} - \Inst_Rep -> No File <==== ATTENTION
Task: {565198ED-CF75-437D-B6AA-2F8CEBC2C3E2} - \SwiftSearch Auto Updater 1.10.0.25 Core -> No File <==== ATTENTION
Task: {5755B931-1B42-4ED9-A985-FA7AFB8DAFAC} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {59151597-0BB5-45C4-9EA4-2CB08A722AB0} - System32\Tasks\CWOBUGTNCV1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {6ED6E732-8E56-4251-84EB-562D2E118F0F} - System32\Tasks\DXMBGGVCJRPOAFAX => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: {8464AC3A-CB37-4418-8752-C0127A3E4F3E} - \SPDriver -> No File <==== ATTENTION
Task: {8E492037-835C-4C17-BFED-602D49842E0F} - System32\Tasks\runTask => %TEMP%/Updater.exe
Task: {9C0246F6-487F-4AC9-9D04-FDE709750E19} - \SwiftSearch Auto Updater 1.10.0.25 Core -> No File <==== ATTENTION
Task: {A2BF6AFF-A016-4A98-B072-F0CF5F11366C} - System32\Tasks\tXnxIXs16 => C:\Users\Jimmy James\AppData\Roaming\tXnxIXs16.exe <==== ATTENTION
Task: {AEBB7099-90D4-444A-A993-FF4DAD2B523A} - System32\Tasks\Bhikesd => C:\PROGRA~1\SHOPPE~1\Haitp.bat
Task: {B02B99BB-4454-47DB-BF3E-94991AE21791} - System32\Tasks\GamerForest Updater => C:\Users\Jimmy James\AppData\Local\GamerForest\updater.exe
Task: {B26010EB-65CF-4E46-8AE2-C3C8C862DDDE} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update -> No File <==== ATTENTION
Task: {D74558BC-9809-4AFC-9768-96DA5CAF74FC} - System32\Tasks\FSSUpdaterService => C:\Users\Jimmy James\AppData\Roaming\UpdaterService\FSSUpdaterService.exe [2014-12-14] () <==== ATTENTION
Task: {D960479F-FAD4-4200-9AB4-D1C69C1B5C61} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update -> No File <==== ATTENTION
Task: {E2B898F8-DA92-4A1A-8BDE-BF33C0671662} - \SPBIW_UpdateTask_Time_323535383538343738362d50372d5a456c37325a347841 -> No File <==== ATTENTION
Task: {F8186CD8-A232-4524-86EC-041461165530} - System32\Tasks\UpdaterEX => C:\Users\JIMMYJ~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\CWOBUGTNCV1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\DXMBGGVCJRPOAFAX.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\EQNAKGAOSGAVHUAN.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\GamerForest Support.job => C:\Users\JIMMYJ~1\AppData\Local\GAMERF~1\gfore_run.exe
Task: C:\Windows\Tasks\GamerForest Updater.job => C:\Users\Jimmy James\AppData\Local\GamerForest\updater.exe
Task: C:\Windows\Tasks\tXnxIXs16.job => C:\Users\Jimmy James\AppData\Roaming\tXnxIXs16.exe <==== ATTENTION
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\JIMMYJ~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
FirewallRules: [{BCD73466-3997-42D1-91DE-0B55D92D7AD4}] => (Allow) C:\Users\Jimmy James\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D3E8DDDC-0DAC-4CD3-9F38-57BC075D90FC}] => (Allow) C:\Users\Jimmy James\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A5E8F02F-E006-45EA-9A88-EC50AA099728}] => (Allow) C:\Program Files (x86)\MyBrowser\MyBrowser\Application\mybrowser.exe
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
 
 
 
 
 
 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
[external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
===============================================================================
 
Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
 
 
[external image: 0841859c-1a35-4dbd-b41a-e720629e3e22_zps]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
 
 
 
 

Wow, Ken…thank you for the quick and detailed response.  I actually think I picked up this infection by using Ant Videos to rip videos of myself playing music from YouTube (no kidding).  I was trying to rip a video a fan had recently posted and got a dialog box saying I needed to update the video encoder or Ant Videos wouldn't be able to download.  I naively authorized installation of the encoder and all the trouble began a couple of days later. 

 

I dutifully followed all your instructions to the letter, with the exception of downloading MalwareBytes since I already had it installed. 

 

Here are the logs you asked for:

 

–

 

Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by [removed] (2015-11-11 23:17:04) Run:1
Running from C:\Users\[removed]\Desktop\infection stuff
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM-x32\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
C:\Program Files (x86)\YTDownloader
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
AppInit_DLLs: C:\ProgramData\FlashBeat\FlashBeat64.dll => No File
AppInit_DLLs-x32: C:\ProgramData\FlashBeat\FlashBeat32.dll => No File
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {3AEE68F1-2444-4B79-8A19-5A0E4F15FA24} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FF Extension: No Name - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\extensions\[removed] [not found]
FF Extension: No Name - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\extensions\[removed] [not found]
FF Extension: No Name - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [not found]
S2 6e9452be; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\CutterFoobar\CutterFoobar.dll",serv
c:\Program Files (x86)\CutterFoobar
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc [X] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc [X] <==== ATTENTION
C:\Program Files (x86)\globalUpdate
2015-11-11 08:25 - 2015-11-11 11:32 - 00001042 _____ C:\Windows\Tasks\tXnxIXs16.job
2015-11-11 08:25 - 2015-11-11 08:25 - 00004072 _____ C:\Windows\System32\Tasks\tXnxIXs16
2015-11-11 08:24 - 2015-11-11 11:32 - 00000382 ____H C:\Windows\Tasks\EQNAKGAOSGAVHUAN.job
2015-11-11 08:24 - 2015-11-11 11:32 - 00000370 _____ C:\Windows\Tasks\CWOBUGTNCV1.job
2015-11-11 08:24 - 2015-11-11 08:24 - 00003402 _____ C:\Windows\System32\Tasks\EQNAKGAOSGAVHUAN
2015-11-11 08:24 - 2015-11-11 08:24 - 00002884 _____ C:\Windows\System32\Tasks\CWOBUGTNCV1
2015-11-01 22:14 - 2013-08-22 06:25 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts.20151101-221403.backup
2015-10-31 06:58 - 2015-10-31 06:58 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\globalUpdate
2015-06-17 22:33 - 2015-06-17 22:33 - 1994592 _____ (BitTorrent Inc.) C:\Program Files (x86)\uTorrent.exe
C:\Program Files (x86)\uTorrent.exe
Task: {0167BF76-CBB5-43F4-BBB7-CDC320D968A9} - \WindApp Update -> No File <==== ATTENTION
Task: {174A1342-C45E-445D-9DAD-87CFBFC2A2CC} - \ShopperPro -> No File <==== ATTENTION
Task: {27A78A90-5F8D-4158-A511-E8FC8FEFD510} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {41E81E27-256B-4EDE-B666-6591775B6A11} - \Inst_Rep -> No File <==== ATTENTION
Task: {4416F6A9-DD45-429E-A3EC-3966606136F0} - \Selection Tools Update -> No File <==== ATTENTION
Task: {4CFC4C6D-4DE9-49E5-A163-C8D808D526F6} - System32\Tasks\EQNAKGAOSGAVHUAN => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: {513E5C0F-3359-4152-9BF7-AF78A2005944} - \Inst_Rep -> No File <==== ATTENTION
Task: {565198ED-CF75-437D-B6AA-2F8CEBC2C3E2} - \SwiftSearch Auto Updater 1.10.0.25 Core -> No File <==== ATTENTION
Task: {5755B931-1B42-4ED9-A985-FA7AFB8DAFAC} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {59151597-0BB5-45C4-9EA4-2CB08A722AB0} - System32\Tasks\CWOBUGTNCV1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {6ED6E732-8E56-4251-84EB-562D2E118F0F} - System32\Tasks\DXMBGGVCJRPOAFAX => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: {8464AC3A-CB37-4418-8752-C0127A3E4F3E} - \SPDriver -> No File <==== ATTENTION
Task: {8E492037-835C-4C17-BFED-602D49842E0F} - System32\Tasks\runTask => %TEMP%/Updater.exe
Task: {9C0246F6-487F-4AC9-9D04-FDE709750E19} - \SwiftSearch Auto Updater 1.10.0.25 Core -> No File <==== ATTENTION
Task: {A2BF6AFF-A016-4A98-B072-F0CF5F11366C} - System32\Tasks\tXnxIXs16 => C:\Users\Jimmy James\AppData\Roaming\tXnxIXs16.exe <==== ATTENTION
Task: {AEBB7099-90D4-444A-A993-FF4DAD2B523A} - System32\Tasks\Bhikesd => C:\PROGRA~1\SHOPPE~1\Haitp.bat
Task: {B02B99BB-4454-47DB-BF3E-94991AE21791} - System32\Tasks\GamerForest Updater => C:\Users\Jimmy James\AppData\Local\GamerForest\updater.exe
Task: {B26010EB-65CF-4E46-8AE2-C3C8C862DDDE} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update -> No File <==== ATTENTION
Task: {D74558BC-9809-4AFC-9768-96DA5CAF74FC} - System32\Tasks\FSSUpdaterService => C:\Users\Jimmy James\AppData\Roaming\UpdaterService\FSSUpdaterService.exe [2014-12-14] () <==== ATTENTION
Task: {D960479F-FAD4-4200-9AB4-D1C69C1B5C61} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update -> No File <==== ATTENTION
Task: {E2B898F8-DA92-4A1A-8BDE-BF33C0671662} - \SPBIW_UpdateTask_Time_323535383538343738362d50372d5a456c37325a347841 -> No File <==== ATTENTION
Task: {F8186CD8-A232-4524-86EC-041461165530} - System32\Tasks\UpdaterEX => C:\Users\JIMMYJ~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\CWOBUGTNCV1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\DXMBGGVCJRPOAFAX.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\EQNAKGAOSGAVHUAN.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\GamerForest Support.job => C:\Users\JIMMYJ~1\AppData\Local\GAMERF~1\gfore_run.exe
Task: C:\Windows\Tasks\GamerForest Updater.job => C:\Users\Jimmy James\AppData\Local\GamerForest\updater.exe
Task: C:\Windows\Tasks\tXnxIXs16.job => C:\Users\Jimmy James\AppData\Roaming\tXnxIXs16.exe <==== ATTENTION
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\JIMMYJ~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
FirewallRules: [{BCD73466-3997-42D1-91DE-0B55D92D7AD4}] => (Allow) C:\Users\Jimmy James\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D3E8DDDC-0DAC-4CD3-9F38-57BC075D90FC}] => (Allow) C:\Users\Jimmy James\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A5E8F02F-E006-45EA-9A88-EC50AA099728}] => (Allow) C:\Program Files (x86)\MyBrowser\MyBrowser\Application\mybrowser.exe
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\YTDownloader => value removed successfully
"C:\Program Files (x86)\YTDownloader" => not found.
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\Software\Microsoft\Windows\CurrentVersion\Run\\YTDownloader => value removed successfully
"C:\ProgramData\FlashBeat\FlashBeat64.dll" => Value data removed successfully.
"C:\ProgramData\FlashBeat\FlashBeat32.dll" => Value data removed successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully
C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\extensions\[removed] => path removed successfully
C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\extensions\[removed] => path removed successfully
C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} => path removed successfully
6e9452be => service removed successfully
"c:\Program Files (x86)\CutterFoobar" => not found.
globalUpdate => service removed successfully
globalUpdatem => service removed successfully
C:\Program Files (x86)\globalUpdate => moved successfully
C:\Windows\Tasks\tXnxIXs16.job => moved successfully
C:\Windows\System32\Tasks\tXnxIXs16 => moved successfully
C:\Windows\Tasks\EQNAKGAOSGAVHUAN.job => moved successfully
C:\Windows\Tasks\CWOBUGTNCV1.job => moved successfully
C:\Windows\System32\Tasks\EQNAKGAOSGAVHUAN => moved successfully
C:\Windows\System32\Tasks\CWOBUGTNCV1 => moved successfully
C:\Windows\system32\Drivers\etc\hosts.20151101-221403.backup => moved successfully
C:\Users\Jimmy James\AppData\Local\globalUpdate => moved successfully
C:\Program Files (x86)\uTorrent.exe => moved successfully
"C:\Program Files (x86)\uTorrent.exe" => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0167BF76-CBB5-43F4-BBB7-CDC320D968A9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0167BF76-CBB5-43F4-BBB7-CDC320D968A9}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WindApp Update => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{174A1342-C45E-445D-9DAD-87CFBFC2A2CC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{174A1342-C45E-445D-9DAD-87CFBFC2A2CC}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperPro => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{27A78A90-5F8D-4158-A511-E8FC8FEFD510}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27A78A90-5F8D-4158-A511-E8FC8FEFD510}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{41E81E27-256B-4EDE-B666-6591775B6A11}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41E81E27-256B-4EDE-B666-6591775B6A11}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Inst_Rep => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4416F6A9-DD45-429E-A3EC-3966606136F0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4416F6A9-DD45-429E-A3EC-3966606136F0}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Selection Tools Update => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4CFC4C6D-4DE9-49E5-A163-C8D808D526F6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CFC4C6D-4DE9-49E5-A163-C8D808D526F6}" => key removed successfully
C:\Windows\System32\Tasks\EQNAKGAOSGAVHUAN => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EQNAKGAOSGAVHUAN" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{513E5C0F-3359-4152-9BF7-AF78A2005944}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{513E5C0F-3359-4152-9BF7-AF78A2005944}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Inst_Rep => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{565198ED-CF75-437D-B6AA-2F8CEBC2C3E2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{565198ED-CF75-437D-B6AA-2F8CEBC2C3E2}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SwiftSearch Auto Updater 1.10.0.25 Core => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5755B931-1B42-4ED9-A985-FA7AFB8DAFAC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5755B931-1B42-4ED9-A985-FA7AFB8DAFAC}" => key removed successfully
C:\Windows\System32\Tasks\SystemToolsDailyTest => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SystemToolsDailyTest" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{59151597-0BB5-45C4-9EA4-2CB08A722AB0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{59151597-0BB5-45C4-9EA4-2CB08A722AB0}" => key removed successfully
C:\Windows\System32\Tasks\CWOBUGTNCV1 => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CWOBUGTNCV1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6ED6E732-8E56-4251-84EB-562D2E118F0F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6ED6E732-8E56-4251-84EB-562D2E118F0F}" => key removed successfully
C:\Windows\System32\Tasks\DXMBGGVCJRPOAFAX => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DXMBGGVCJRPOAFAX" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8464AC3A-CB37-4418-8752-C0127A3E4F3E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8464AC3A-CB37-4418-8752-C0127A3E4F3E}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPDriver => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8E492037-835C-4C17-BFED-602D49842E0F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E492037-835C-4C17-BFED-602D49842E0F}" => key removed successfully
C:\Windows\System32\Tasks\runTask => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\runTask" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9C0246F6-487F-4AC9-9D04-FDE709750E19}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9C0246F6-487F-4AC9-9D04-FDE709750E19}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SwiftSearch Auto Updater 1.10.0.25 Core => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A2BF6AFF-A016-4A98-B072-F0CF5F11366C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A2BF6AFF-A016-4A98-B072-F0CF5F11366C}" => key removed successfully
C:\Windows\System32\Tasks\tXnxIXs16 => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\tXnxIXs16" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AEBB7099-90D4-444A-A993-FF4DAD2B523A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEBB7099-90D4-444A-A993-FF4DAD2B523A}" => key removed successfully
C:\Windows\System32\Tasks\Bhikesd => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bhikesd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B02B99BB-4454-47DB-BF3E-94991AE21791}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B02B99BB-4454-47DB-BF3E-94991AE21791}" => key removed successfully
C:\Windows\System32\Tasks\GamerForest Updater => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GamerForest Updater" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B26010EB-65CF-4E46-8AE2-C3C8C862DDDE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B26010EB-65CF-4E46-8AE2-C3C8C862DDDE}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SwiftSearch Auto Updater 1.10.0.25 Pending Update => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{D74558BC-9809-4AFC-9768-96DA5CAF74FC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D74558BC-9809-4AFC-9768-96DA5CAF74FC}" => key removed successfully
C:\Windows\System32\Tasks\FSSUpdaterService => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FSSUpdaterService" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D960479F-FAD4-4200-9AB4-D1C69C1B5C61}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D960479F-FAD4-4200-9AB4-D1C69C1B5C61}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SwiftSearch Auto Updater 1.10.0.25 Pending Update => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E2B898F8-DA92-4A1A-8BDE-BF33C0671662}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2B898F8-DA92-4A1A-8BDE-BF33C0671662}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_323535383538343738362d50372d5a456c37325a347841 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F8186CD8-A232-4524-86EC-041461165530}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8186CD8-A232-4524-86EC-041461165530}" => key removed successfully
C:\Windows\System32\Tasks\UpdaterEX => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UpdaterEX" => key removed successfully
C:\Windows\Tasks\CWOBUGTNCV1.job => not found.
C:\Windows\Tasks\DXMBGGVCJRPOAFAX.job => moved successfully
C:\Windows\Tasks\EQNAKGAOSGAVHUAN.job => not found.
C:\Windows\Tasks\GamerForest Support.job => moved successfully
C:\Windows\Tasks\GamerForest Updater.job => moved successfully
C:\Windows\Tasks\tXnxIXs16.job => not found.
C:\Windows\Tasks\UpdaterEX.job => moved successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BCD73466-3997-42D1-91DE-0B55D92D7AD4} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D3E8DDDC-0DAC-4CD3-9F38-57BC075D90FC} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A5E8F02F-E006-45EA-9A88-EC50AA099728} => value removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

EmptyTemp: => 959.7 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 23:17:33 ====

 

–

 

# AdwCleaner v5.019 - Logfile created 11/11/2015 at 23:30:18
# Updated 08/11/2015 by Xplode
# Database : 2015-11-09.1 [Server]
# Operating system : Windows 8.1  (x64)
# Username : Jimmy James - SONOFSPUDBORT
# Running from : C:\Users\Jimmy James\Desktop\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\GreenTree Applications
[-] Folder Deleted : C:\ProgramData\28341ff220e0446c9fff27c4493d622e
[-] Folder Deleted : C:\ProgramData\c2018c0f00002407
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF to Word Converter
[-] Folder Deleted : C:\Users\Jimmy James\AppData\Roaming\Store
[-] Folder Deleted : C:\Users\Jimmy James\AppData\Roaming\updaterservice
[-] Folder Deleted : C:\Users\Jimmy James\AppData\Roaming\RunDir

***** [ Files ] *****

[-] File Deleted : C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\user.js

***** [ DLLs ] *****

[-] File Disinfected : C:\Windows\SysNative\dnsapi.dll
[-] File Disinfected : C:\Windows\SysWOW64\dnsapi.dll

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : updateTask

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
[-] Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [PDFToWordConverterUpdateChecker]
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5}
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Directory\shell\Add event reminder
[-] Key Deleted : HKLM\SOFTWARE\Classes\Directory\Background\shell\Add event reminder
[-] Key Deleted : HKLM\SOFTWARE\Classes\DesktopBackground\Shell\Add event reminder
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\NetTcpHandler
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\jg.exe
[-] Key Deleted : HKLM\SOFTWARE\d9d69885-71aa-7709-4fd4-67d8838f402d
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
[-] Key Deleted : HKCU\Software\Driver Pro
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\InstalledBrowserExtensions
[-] Key Deleted : HKCU\Software\Store
[-] Key Deleted : HKCU\Software\Tutorials
[-] Key Deleted : HKCU\Software\UpdaterEX
[-] Key Deleted : HKCU\Software\WTools
[-] Key Deleted : HKCU\Software\__SP__browser_name__SP__
[-] Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key Deleted : HKCU\Software\AppDataLow\Software\SmartWeb
[-] Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
[-] Key Deleted : HKLM\SOFTWARE\SearchModule
[-] Key Deleted : HKLM\SOFTWARE\Linkey
[-] Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key Deleted : HKLM\SOFTWARE\NetTcpHandler
[-] Key Deleted : HKLM\SOFTWARE\NtSvcHandler
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBeat
[-] Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : [x64] HKLM\SOFTWARE\SearchModule
[-] Key Deleted : [x64] HKLM\SOFTWARE\Linkey
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d7403750-6760-411b-98aa-347ae8ceb5ee}
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key Deleted : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_

***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [8931 bytes] ##########
 

–

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 8.1 x64
Ran by [removed] on Wed 11/11/2015 at 23:43:49.71
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks

Successfully deleted: [Task] C:\Windows\system32\tasks\PCDEventLauncherTask
Successfully deleted: [Task] C:\Windows\system32\tasks\PCDoctorBackgroundMonitorTask



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer



~~~ Files



~~~ Folders

Successfully deleted: [Folder] C:\Users\Jimmy James\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\Users\Jimmy James\Appdata\Local\installer
Successfully deleted: [Folder] C:\Users\Jimmy James\Appdata\LocalLow\company





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 11/11/2015 at 23:45:26.12
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

–

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 11/11/2015
Scan Time: 11:51 PM
Logfile:
Administrator: Yes

Version: 2.2.0.1024
Malware Database: v2015.11.12.01
Rootkit Database: v2015.11.04.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Jimmy James

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 321949
Time Elapsed: 6 min, 26 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 3
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\INSTALLER\PRODUCTS\93BAD29AC2E44034A96BCB446EB8552E, Quarantined, [8c95b0cd404bb77f96e2f8e0d42f936d],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INSTALLER\PRODUCTS\93BAD29AC2E44034A96BCB446EB8552E, Quarantined, [4bd639447417e05686f29246d52e946c],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INSTALLER\PRODUCTS\93BAD29AC2E44034A96BCB446EB8552E, Quarantined, [25fc3548f09b2412e79114c453b07987],

Registry Values: 3
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\INSTALLER\PRODUCTS\93BAD29AC2E44034A96BCB446EB8552E|ProductName, Consumer Input Update Helper, Quarantined, [8c95b0cd404bb77f96e2f8e0d42f936d]
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INSTALLER\PRODUCTS\93BAD29AC2E44034A96BCB446EB8552E|ProductName, Consumer Input Update Helper, Quarantined, [4bd639447417e05686f29246d52e946c]
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INSTALLER\PRODUCTS\93BAD29AC2E44034A96BCB446EB8552E|ProductName, Consumer Input Update Helper, Quarantined, [25fc3548f09b2412e79114c453b07987]

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 3
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\RasigusxuOff.ini, Quarantined, [ad74c5b899f2092dd8b114c46c9711ef],
PUP.Optional.Winsock.WnskRST, C:\Windows\SysWOW64\Rasigusxu.ini, Quarantined, [1a075a23abe0a195602903d528db29d7],
PUP.Optional.Winsock.WnskRST, C:\Windows\SysWOW64\RasigusxuOff.ini, Quarantined, [021fb2cb6b209a9cdfaacc0c0102d828],

Physical Sectors: 0
(No malicious items detected)


(end)

 

–

 

 

 

 

Awww shucks.  Thanks.   :blush: 

 

Here is the FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by [removed] (administrator) on SONOFSPUDBORT (12-11-2015 09:41:32)
Running from C:\Users\[removed]\Desktop\infection stuff
[removed] Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel(R) Corporation) C:\Program Files (x86)\Common Files\Intel\RSDCM\bin\win32\RealSenseDCM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7646936 2014-10-14] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1396592 2014-09-01] (Realtek Semiconductor)
HKLM\…\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5793048 2014-10-08] (Dell Inc.)
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322712 2014-10-09] (Intel Corporation)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\…\Run: [TrueColor UI] => C:\Program Files\TrueColor\TrueColorUI.exe [19491792 2014-12-25] (Entertainment Experience)
HKLM\…\Run: [ETDUSBWare] => C:\Program Files\Elan\USB\ETDUSBCtrl.exe [869320 2010-06-18] (ELAN Microelectronic Corp.)
HKLM-x32\…\Run: [Intel(R) RealSense(TM) SDK info server] => C:\Program Files (x86)\Common Files\Intel\RSDCM\bin\win32\RealSenseInfo.exe [17592 2014-11-12] (Intel(R) Corporation)
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\Run: [Google Update] => C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-24] (Google Inc.)
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 [removed]
Tcpip\..\Interfaces\{665A4D14-14AE-4E65-9CC9-60E4EC09AD78}: [DhcpNameServer] 192.168.0.1 [removed]

Internet Explorer:
==================
HKU\S-1-5-21-1714133512-296453273-4189880979-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1714133512-296453273-4189880979-1001 -> {24CD5258-20D7-4FB3-AF67-A3A12172F64D} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:{language}:{referrer:source}&ie;={inputEncoding?}&oe;={outputEncoding?}

FireFox:
========
FF ProfilePath: C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default
FF DefaultSearchEngine.US: Google
FF Homepage: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-10-10] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-10-10] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin HKU\S-1-5-21-1714133512-296453273-4189880979-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Jimmy James\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1714133512-296453273-4189880979-1001: @talk.google.com/O1DPlugin -> C:\Users\Jimmy James\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1714133512-296453273-4189880979-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-1714133512-296453273-4189880979-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Jimmy James\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Jimmy James\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\Extensions\[removed] [2015-06-14]
FF Extension: Adblock Plus - C:\Users\Jimmy James\AppData\Roaming\Mozilla\Firefox\Profiles\2b8jmlp2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-24]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18584 2014-10-09] (Intel Corporation)
S2 iBtSiva; C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe [121304 2014-08-25] (Intel Corporation)
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [328296 2014-11-23] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel(R) Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [132896 2014-10-10] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [158496 2014-10-10] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [265936 2014-06-18] ()
R2 RealSenseDCM; C:\Program Files (x86)\Common Files\Intel\RSDCM\bin\win32\RealSenseDCM.exe [1147064 2014-11-12] (Intel(R) Corporation)
S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [292568 2014-09-04] (Realtek Semiconductor)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S2 TrueColorALS; C:\Program Files\TrueColor\TrueColorALS.exe [94160 2014-12-25] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816656 2014-06-18] (Intel® Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-11-20] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [141624 2014-05-13] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1424184 2014-06-17] (Motorola Solutions, Inc.)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-24] (OSR Open Systems Resources, Inc.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 iaLPSS_GPIO; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [35832 2014-06-10] (Intel Corporation)
R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [120312 2014-06-10] (Intel Corporation)
S3 iaLPSS_SPI; C:\Windows\System32\drivers\iaLPSS_SPI.sys [100856 2014-06-10] (Intel Corporation)
S3 iaLPSS_UART2; C:\Windows\System32\drivers\iaLPSS_UART2.sys [143864 2014-06-10] (Intel Corporation)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [220104 2014-08-25] (Intel Corporation)
R3 IntelDFUACPI; C:\Windows\System32\drivers\IntelDFUACPI.sys [24456 2014-09-09] (Intel(R) Corporation)
R3 IXCamera; C:\Windows\system32\DRIVERS\RealSenseDCM.sys [59312 2014-11-12] (Intel(R) Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverx64.sys [129312 2014-10-10] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3488744 2014-07-29] (Intel Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 PCDSRVC{3B54B31B-D06B6431-06020200}_0; \??\c:\program files\dell\supportassist\pcdsrvc_x64.pkms [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Three Months Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-11 23:23 - 2015-11-11 23:30 - 00000000 ____D C:\AdwCleaner
2015-11-11 12:50 - 2015-11-12 00:12 - 00000000 ____D C:\Users\Jimmy James\Desktop\infection stuff
2015-11-11 12:13 - 2015-11-12 09:41 - 00000000 ____D C:\FRST
2015-11-11 08:13 - 2015-11-11 08:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-11-11 08:13 - 2015-11-11 08:13 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-11-10 19:11 - 2015-10-30 16:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-10 19:11 - 2015-10-30 16:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-10 19:11 - 2015-10-30 16:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-10 19:11 - 2015-10-30 16:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-10 19:11 - 2015-10-30 16:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-10 19:11 - 2015-10-30 15:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-11-10 19:11 - 2015-10-30 15:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-11-10 19:11 - 2015-10-30 15:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-11-10 19:11 - 2015-10-30 15:39 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-11-10 19:11 - 2015-10-30 15:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-11-10 19:11 - 2015-10-30 15:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-10 19:11 - 2015-10-30 15:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-10 19:11 - 2015-10-30 15:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-10 19:11 - 2015-10-30 15:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-10 19:11 - 2015-10-30 15:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-11-10 19:11 - 2015-10-30 15:14 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-11-10 19:11 - 2015-10-30 15:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-11-10 19:11 - 2015-10-30 15:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-11-10 19:11 - 2015-10-30 15:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-10 19:11 - 2015-10-30 14:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-11-10 19:11 - 2015-10-30 14:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-11-10 19:11 - 2015-10-30 14:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-11-10 19:11 - 2015-10-30 14:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-11-10 19:11 - 2015-10-20 14:54 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-10 19:11 - 2015-10-20 07:53 - 03705856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-10 19:11 - 2015-10-20 07:36 - 02243072 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-10 19:11 - 2015-10-20 07:35 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-10 19:11 - 2015-10-20 07:34 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2015-11-10 19:11 - 2015-10-20 07:34 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-10 19:11 - 2015-10-20 07:34 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-10 19:11 - 2015-10-20 07:33 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-10 19:11 - 2015-10-20 07:14 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-10 19:11 - 2015-10-20 07:13 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-10 19:11 - 2015-10-20 07:13 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-10 19:11 - 2015-10-20 07:13 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-10 19:11 - 2015-10-14 16:02 - 07455064 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-10 19:11 - 2015-10-14 16:02 - 01659560 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-11-10 19:11 - 2015-10-14 16:02 - 01519592 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-11-10 19:11 - 2015-10-14 16:02 - 01487008 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-11-10 19:11 - 2015-10-14 16:02 - 01355848 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-11-10 19:11 - 2015-10-08 09:08 - 01083904 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2015-11-10 19:11 - 2015-08-10 11:15 - 00845312 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2015-11-10 19:11 - 2015-08-10 11:06 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2015-11-10 19:11 - 2015-08-10 10:49 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2015-11-10 19:11 - 2015-08-10 09:56 - 00272384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2015-11-10 19:11 - 2015-08-10 09:46 - 00561664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2015-11-10 19:10 - 2015-10-17 07:19 - 04176384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-06 18:58 - 2015-11-06 18:58 - 00000000 ____D C:\Users\Jimmy James\Downloads\wetransfer-07d291
2015-11-03 21:45 - 2015-11-03 21:45 - 00008697 _____ C:\Users\Jimmy James\AppData\Local\recently-used.xbel
2015-11-03 21:01 - 2015-11-03 21:01 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\webkit
2015-11-01 20:02 - 2015-11-01 20:02 - 00002668 _____ C:\Windows\wininit.ini
2015-11-01 19:47 - 2015-11-01 19:47 - 00000000 ____D C:\Program Files\Common Files\AV
2015-11-01 19:47 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Program Files\Post Win10 Spybot-install.exe
2015-11-01 19:41 - 2015-11-11 08:45 - 00001398 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D; Start Center.lnk
2015-11-01 19:41 - 2015-11-01 22:10 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-11-01 19:41 - 2015-11-01 19:58 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-11-01 19:41 - 2015-11-01 19:41 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2015-11-01 19:41 - 2015-11-01 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-11-01 19:41 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2015-11-01 19:38 - 2015-11-11 08:45 - 00001217 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TempoPerfect Metronome Software.lnk
2015-11-01 19:36 - 2015-11-11 08:45 - 00001187 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crescendo Music Notation Editor.lnk
2015-11-01 19:36 - 2015-11-11 08:45 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MixPad Multitrack Recording Software.lnk
2015-11-01 19:36 - 2015-11-11 08:45 - 00001141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk
2015-11-01 19:36 - 2015-11-09 08:07 - 00000000 ____D C:\Windows\System32\Tasks\NCH Software
2015-11-01 19:36 - 2015-11-09 08:07 - 00000000 ____D C:\Users\Jimmy James\AppData\Roaming\NCH Software
2015-11-01 19:36 - 2015-11-01 19:38 - 00000000 ____D C:\ProgramData\NCH Software
2015-11-01 19:36 - 2015-11-01 19:38 - 00000000 ____D C:\Program Files (x86)\NCH Software
2015-11-01 19:36 - 2015-11-01 19:36 - 00000000 ____D C:\Users\Jimmy James\Documents\Mixpad Projects
2015-11-01 19:35 - 2015-11-01 19:35 - 00657176 _____ (NCH Software) C:\Users\Jimmy James\Downloads\crescendosetup.exe
2015-11-01 19:32 - 2015-11-01 19:33 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Jimmy James\Downloads\spybot-2.4.exe
2015-11-01 11:15 - 2015-11-01 11:15 - 00007606 _____ C:\Users\Jimmy James\AppData\Local\Resmon.ResmonCfg
2015-10-31 08:46 - 2015-11-11 08:45 - 00001425 _____ C:\Users\Jimmy James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-10-31 06:59 - 2015-10-31 06:59 - 00000000 ____D C:\Windows\system32\togm
2015-10-31 06:59 - 2015-10-31 06:59 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\Tempfolder
2015-10-31 06:58 - 2015-11-11 08:25 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-10-31 06:58 - 2015-10-31 06:58 - 00000000 ____D C:\uninst
2015-10-31 05:02 - 2015-10-31 05:02 - 00186880 _____ (TODO: ) C:\Windows\system32\rsrcs.dll
2015-10-27 05:45 - 2015-10-30 09:20 - 10289664 _____ C:\Users\Jimmy James\Downloads\2310UrinaryFA15WEB.ppt
2015-10-22 19:30 - 2015-10-22 19:31 - 47743094 _____ C:\Users\Jimmy James\Downloads\20151022 Balad of the Beauty Queen master.wav
2015-10-15 03:41 - 2015-10-15 03:41 - 10962432 _____ C:\Users\Jimmy James\Downloads\2310GIFA15LectWEB.ppt
2015-10-14 09:40 - 2015-09-24 09:42 - 00348672 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll
2015-10-14 09:40 - 2015-09-24 09:40 - 00737280 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2015-10-14 09:40 - 2015-08-26 19:43 - 22372152 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-10-14 09:40 - 2015-08-26 19:42 - 19795904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-10-14 09:40 - 2015-08-07 14:40 - 01736520 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-10-14 09:40 - 2015-08-07 14:40 - 01499920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-10-14 09:39 - 2015-09-10 10:18 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-10-14 09:39 - 2015-09-10 10:06 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-10-14 09:39 - 2015-09-10 09:51 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-10-14 09:39 - 2015-09-10 09:37 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-10-14 09:39 - 2015-09-10 09:37 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-10-14 09:39 - 2015-09-10 09:35 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-10-14 09:39 - 2015-09-10 09:28 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-10-14 09:39 - 2015-09-10 09:21 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-10-14 09:39 - 2015-09-10 09:19 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-10-14 09:39 - 2015-09-10 09:17 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-10-14 09:39 - 2015-09-10 09:17 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-10-14 09:39 - 2015-09-10 09:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-10-14 09:39 - 2015-09-10 09:05 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-10-14 09:39 - 2015-09-10 08:57 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-10-14 09:39 - 2015-09-10 08:55 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-10-14 09:39 - 2015-09-10 08:55 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-10-12 08:15 - 2015-10-12 08:20 - 214620220 _____ C:\Users\Jimmy James\Downloads\wetransfer-07d291.zip
2015-10-08 20:23 - 2015-10-08 21:15 - 00000000 ____D C:\Users\Jimmy James\Documents\DCJB tunes
2015-10-06 22:22 - 2015-11-08 00:03 - 00000000 ____D C:\Users\Jimmy James\AppData\Roaming\vlc
2015-10-06 22:22 - 2015-10-06 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-10-06 22:21 - 2015-10-06 22:21 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2015-10-06 22:14 - 2015-10-06 22:18 - 28849904 _____ C:\Users\Jimmy James\Downloads\vlc-2.2.1-win32.exe
2015-10-06 10:05 - 2015-10-06 10:06 - 10188288 _____ C:\Users\Jimmy James\Downloads\2310ResFA15WEB.ppt
2015-10-05 22:26 - 2015-10-06 22:23 - 00000000 ____D C:\Users\Jimmy James\Downloads\Skyfall (2012) [1080p]
2015-10-05 22:00 - 2015-10-06 01:11 - 00000000 ____D C:\Users\Jimmy James\Downloads\Shaolin Soccer (2001) 720p 5.1 [Uncut HK Version] Blu-ray
2015-09-27 11:32 - 2015-09-27 11:32 - 00014799 _____ C:\Users\Jimmy James\Downloads\Literature Inventory 8-30-15.xlsx
2015-09-26 15:07 - 2015-09-26 15:13 - 65376256 _____ C:\Users\Jimmy James\Downloads\calibre-2.39.0.msi
2015-09-26 14:46 - 2015-09-26 14:46 - 07370240 _____ C:\Users\Jimmy James\Downloads\2310VesselsCircFA2015WEB.ppt
2015-09-24 20:17 - 2015-09-24 20:17 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\PDFEditor
2015-09-24 20:10 - 2015-09-24 20:11 - 24837416 _____ C:\Users\Jimmy James\Downloads\PdfToWordConverterSetup.exe
2015-09-21 14:53 - 2015-09-20 11:47 - 00026525 _____ C:\Users\Jimmy James\Documents\Personal%20Statement%206th%20draft.doc_0.odt
2015-09-18 15:52 - 2015-09-18 16:12 - 268589235 _____ C:\Users\Jimmy James\Downloads\corrales 19th tunes.zip
2015-09-15 11:23 - 2015-09-15 11:24 - 16055296 _____ C:\Users\Jimmy James\Downloads\2310HeartTwoFA15WEB.ppt
2015-09-09 21:22 - 2015-07-30 10:18 - 00268288 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-09-09 21:22 - 2015-07-30 09:22 - 00230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-09-09 21:21 - 2015-09-09 21:21 - 04883456 _____ C:\Users\Jimmy James\Downloads\2310HeartOneFA15WEB.ppt
2015-09-09 21:21 - 2015-09-01 19:55 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-09 21:21 - 2015-09-01 19:50 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-09 21:21 - 2015-09-01 19:17 - 00301568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-09 21:21 - 2015-09-01 19:13 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-09 21:21 - 2015-08-03 14:15 - 00074928 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-09-09 21:21 - 2015-08-03 14:15 - 00065600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-09-09 21:21 - 2015-08-01 07:22 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-09-09 21:21 - 2015-07-31 20:47 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2015-09-09 21:21 - 2015-07-31 20:45 - 00182784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2015-09-09 21:21 - 2015-07-31 20:38 - 01265152 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-09 21:21 - 2015-07-31 20:37 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2015-09-09 21:21 - 2015-07-31 20:37 - 00359936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2015-09-09 21:21 - 2015-07-22 07:34 - 02775552 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-09 21:21 - 2015-07-22 07:33 - 01728000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2015-09-09 21:21 - 2015-07-22 07:25 - 02461184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-09 21:21 - 2015-07-22 07:25 - 01546752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2015-09-09 21:21 - 2015-07-18 11:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2015-09-09 21:21 - 2015-07-18 11:29 - 00655872 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2015-09-09 21:21 - 2015-07-18 11:29 - 00148480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shacct.dll
2015-09-09 21:21 - 2015-07-18 11:27 - 00520192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2015-09-09 21:21 - 2015-07-13 20:27 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\tzsync.exe
2015-09-08 05:28 - 2015-09-08 05:28 - 05416960 _____ C:\Users\Jimmy James\Downloads\2310bloodFA15WEB.ppt
2015-08-25 15:20 - 2015-08-25 15:20 - 00931408 _____ (Google Inc.) C:\Users\Jimmy James\Downloads\GoogleVoiceAndVideoSetup(1).exe
2015-08-24 13:24 - 2015-11-12 09:41 - 00000960 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001UA.job
2015-08-24 13:24 - 2015-11-07 22:41 - 00000908 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001Core.job
2015-08-24 13:24 - 2015-09-16 21:36 - 00003918 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001UA
2015-08-24 13:24 - 2015-09-16 21:36 - 00003538 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001Core
2015-08-24 13:24 - 2015-08-24 13:24 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\Google
2015-08-24 13:23 - 2015-08-24 13:23 - 00931408 _____ (Google Inc.) C:\Users\Jimmy James\Downloads\GoogleVoiceAndVideoSetup.exe

==================== Three Months Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-12 09:40 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\system32\sru
2015-11-12 09:39 - 2015-02-16 06:15 - 01053487 _____ C:\Windows\WindowsUpdate.log
2015-11-12 09:38 - 2015-02-16 06:16 - 00011724 _____ C:\Windows\SysWOW64\Gms.log
2015-11-12 00:42 - 2015-06-20 16:50 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-12 00:22 - 2015-07-01 21:11 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-11 23:58 - 2015-06-14 14:13 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1714133512-296453273-4189880979-1001
2015-11-11 23:42 - 2014-11-20 21:42 - 00865408 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-11 23:37 - 2013-08-22 07:46 - 00021831 _____ C:\Windows\setupact.log
2015-11-11 23:37 - 2013-08-22 07:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-11 23:18 - 2014-11-20 21:32 - 00669944 _____ C:\Windows\PFRO.log
2015-11-11 10:28 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\AppReadiness
2015-11-11 10:26 - 2013-08-22 08:20 - 00000000 ____D C:\Windows\CbsTemp
2015-11-11 09:11 - 2013-08-22 06:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-11-11 08:48 - 2013-08-22 07:44 - 00362576 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-11 08:47 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\FileManager
2015-11-11 08:45 - 2015-06-21 08:11 - 00000949 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-11-11 08:45 - 2015-06-15 14:13 - 00001026 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-11-11 08:45 - 2015-06-14 15:14 - 00000303 _____ C:\Users\Jimmy James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Control Panel.lnk
2015-11-11 08:45 - 2015-06-14 14:08 - 00001425 _____ C:\Users\Jimmy James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet-Explorer.lnk
2015-11-11 08:45 - 2015-06-14 14:07 - 00000445 _____ C:\Users\Jimmy James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-11-11 08:45 - 2015-06-14 14:07 - 00000443 _____ C:\Users\Jimmy James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-11-11 08:45 - 2015-02-16 06:13 - 00000712 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk
2015-11-11 08:35 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\Resources
2015-11-10 21:01 - 2015-07-28 16:11 - 00000000 ____D C:\Users\Jimmy James\Documents\OT Application stuff
2015-11-10 21:00 - 2015-06-25 08:13 - 00634880 ___SH C:\Users\Jimmy James\Downloads\Thumbs.db
2015-11-10 19:22 - 2015-07-01 21:11 - 00003718 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-11-07 06:20 - 2015-06-14 14:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-06 19:33 - 2013-08-22 08:36 - 00000000 ___RD C:\Windows\Offline Web Pages
2015-11-04 12:33 - 2015-06-17 22:18 - 00194560 ___SH C:\Users\Jimmy James\Desktop\Thumbs.db
2015-11-03 22:23 - 2015-06-17 22:18 - 00000000 ____D C:\Users\Jimmy James\Documents\Other James Stuff
2015-11-03 21:58 - 2015-06-21 08:11 - 00000000 ____D C:\Users\Jimmy James\.gimp-2.8
2015-11-03 21:45 - 2015-06-21 08:13 - 00000000 ____D C:\Users\Jimmy James\AppData\Local\gtk-2.0
2015-10-31 15:26 - 2015-06-14 14:14 - 00000000 ____D C:\ProgramData\EPSON
2015-10-31 09:14 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\IME
2015-10-31 07:59 - 2015-07-29 20:51 - 00074240 ___SH C:\Users\Jimmy James\Documents\Thumbs.db
2015-10-31 07:38 - 2015-06-20 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-10-31 07:38 - 2015-06-20 16:50 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-29 12:47 - 2015-08-04 12:57 - 00000000 ____D C:\Users\Jimmy James\Documents\E-Books
2015-10-20 17:56 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\rescache
2015-10-19 06:45 - 2015-06-21 09:06 - 00000000 ____D C:\Users\Jimmy James\Downloads\moms_typewriter
2015-10-18 08:26 - 2013-08-22 08:36 - 00000000 ___RD C:\Windows\ToastData
2015-10-15 21:51 - 2014-11-21 05:47 - 00810488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-10-15 21:51 - 2014-11-21 05:47 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-15 18:43 - 2015-06-18 18:47 - 00000000 ____D C:\Windows\system32\MRT
2015-10-15 18:37 - 2015-06-18 18:47 - 143481208 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Files in the root of some directories =======

2015-11-01 19:47 - 2015-07-28 17:52 - 0821920 _____ (Safer-Networking Ltd.                                       ) C:\Program Files\Post Win10 Spybot-install.exe
2015-08-09 12:23 - 2015-08-09 12:23 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2015-04-14 09:28 - 2015-04-14 09:28 - 0004387 _____ () C:\Users\Jimmy James\AppData\Roaming\tXnxIXs16
2015-11-03 21:45 - 2015-11-03 21:45 - 0008697 _____ () C:\Users\Jimmy James\AppData\Local\recently-used.xbel
2015-11-01 11:15 - 2015-11-01 11:15 - 0007606 _____ () C:\Users\Jimmy James\AppData\Local\Resmon.ResmonCfg
2015-02-16 05:59 - 2015-02-16 05:59 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Jimmy James\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-11-11 09:08

==================== End of FRST.txt ============================

 

And additions.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by [removed] (2015-11-12 09:41:56)
Running from C:\Users\[removed]\Desktop\infection stuff
Windows 8.1 (X64) (2015-06-14 21:07:12)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1714133512-296453273-4189880979-500 - Administrator - Disabled)
Guest (S-1-5-21-1714133512-296453273-4189880979-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1714133512-296453273-4189880979-1003 - Limited - Enabled)
Jimmy James (S-1-5-21-1714133512-296453273-4189880979-1001 - Administrator - Enabled) => C:\Users\Jimmy James

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 19 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Audacity 2.1.0 (HKLM-x32\…\Audacity_is1) (Version: 2.1.0 - Audacity Team)
calibre (HKLM-x32\…\{6C086582-8A0F-49D8-9E0D-82AAF2912118}) (Version: 2.33.0 - Kovid Goyal)
Crescendo Music Notation Editor (HKLM-x32\…\Crescendo) (Version: 1.63 - NCH Software)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.1.6664.10 - Dell)
Dell System Detect (HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\73f463568823ebbe) (Version: 6.4.0.7 - Dell)
EPSON WorkForce 545 Series Printer Uninstall (HKLM\…\EPSON WorkForce 545 Series) (Version:  - SEIKO EPSON Corporation)
ETD Ware USB-x64 7.0.5.1_X09 (HKLM\…\Elan) (Version: 7.0.5.1 - ELAN Microelectronics Corp.)
Foxit Cloud (HKLM-x32\…\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 3.7.143.923 - Foxit Software Inc.)
Foxit Reader (HKLM-x32\…\Foxit Reader_is1) (Version: 7.1.5.425 - Foxit Software Inc.)
FSS Audio Converter version 1.0.8.1 (HKLM-x32\…\FSS Audio Converter_is1) (Version: 1.0.8.1 - FreeSmartSoft)
GIMP 2.8.14 (HKLM\…\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Talk Plugin (HKLM-x32\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Intel 3D Camera settings (HKLM-x32\…\InstallShield_{435B06FD-39B3-4DD8-84FE-5CAE06109B9A}) (Version: 0.0.0.2 - )
Intel 3D Camera settings (x32 Version: 0.0.0.2 - ) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.30.1072 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4013 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.5.0.1056 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\…\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Intel(R) WiDi (HKLM\…\{5BBC7722-E4D9-4406-A8B9-1E11A23B9EAF}) (Version: 5.0.32.0 - Intel Corporation)
Intel(R) Wireless Bluetooth(R)(patch version 17.1.1431.1) (HKLM\…\{302600C1-6BDF-4FD1-1407-148929CC1385}) (Version: 17.1.1407.0480 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{694000a5-c594-49d2-b6e4-ef3960120b0f}) (Version: 17.1.0 - Intel Corporation)
Intel® RealSense™ Depth Camera Manager  (x86): Intel® RealSense™ 3D camera IO module (x32 Version: 1.2.14.28436 - Intel Corporation) Hidden
Intel® RealSense™ Depth Camera Manager  (x86): Intel® RealSense™ Depth Camera Manager Service (x32 Version: 1.2.14.28436 - Intel Corporation) Hidden
Intel® RealSense™ Depth Camera Manager  (x86): Intel® RealSense™ SDK info server (x32 Version: 1.2.14.28436 - Intel Corporation) Hidden
Intel® RealSense™ Depth Camera Manager (HKLM-x32\…\ARP_for_prd_dcm_runtime_1.2.14.28436) (Version: 1.2.14.28436 - Intel Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Maxx Audio Installer (x64) (Version: 1.6.4616.61 - Waves Audio Ltd.) Hidden
Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\…\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\…\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
MixPad Multitrack Recording Software (HKLM-x32\…\MixPad) (Version: 3.93 - NCH Software)
Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
OpenOffice 4.1.1 (HKLM-x32\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.16.014 - Dell Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7363 - Realtek Semiconductor Corp.)
Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
System NotifierV25.10 (HKLM-x32\…\System NotifierV25.10) (Version: 1.36.01.22 - HQ-VideoV25.10) <==== ATTENTION
TempoPerfect Metronome Software (HKLM-x32\…\TempoPerfect) (Version: 4.08 - NCH Software)
True Color (HKLM-x32\…\{55c734b2-fcff-447e-81cc-a6f04ebf09fc}) (Version: 6.0.0.6 - Entertainment Experience)
True Color (Version: 6.0.0.6 - Entertainment Experience LLC) Hidden
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
WavePad Sound Editor (HKLM-x32\…\WavePad) (Version: 6.33 - NCH Software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1714133512-296453273-4189880979-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1714133512-296453273-4189880979-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1714133512-296453273-4189880979-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1714133512-296453273-4189880979-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Jimmy James\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)

==================== Restore Points =========================

14-10-2015 09:47:33 Windows Update
27-10-2015 12:58:39 Scheduled Checkpoint
31-10-2015 15:25:58 Removed Microsoft Silverlight
31-10-2015 16:42:58 Restore Operation
01-11-2015 20:02:22 Cleaner (Spybot - Search & Destroy 2.4, administrator privileges
09-11-2015 12:46:56 Scheduled Checkpoint
11-11-2015 23:17:07 Restore Point Created by FRST

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 06:25 - 2015-11-11 23:17 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {10ED87AE-CD7F-4497-8C20-DF9AE57A22CE} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-09-01] (Realtek Semiconductor)
Task: {1A832373-1A58-4E30-BCC1-E01C0AEB0285} - System32\Tasks\GamerForest Support => C:\Users\JIMMYJ~1\AppData\Local\GAMERF~1\gfore_run.exe
Task: {4698E670-E7F4-453F-A1E6-413B73C7D672} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {631C89B4-2CA0-45F4-B118-607F2104F002} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001Core => C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-24] (Google Inc.)
Task: {76588F62-0374-407B-BAA7-6DD85B2B62A2} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
Task: {8FD3E658-2E05-4B99-A39E-F7D2D22DB00B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001UA => C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-24] (Google Inc.)
Task: {A48D8F0C-978D-472A-9DF8-2E7F4C5B041D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {AABD1DF7-663E-49EB-A94B-3AF35217D2CC} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {AC4A8A5E-A592-4D4F-87DF-831563E62AA5} - System32\Tasks\Chromium => C:\Users\JIMMYJ~1\AppData\Local\Chromium\APPLIC~1\450242~1.0\INSTAL~1\UNINST~1.EXE
Task: {BB114104-5147-4B36-B193-8638577898BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-10] (Adobe Systems Incorporated)
Task: {D22C13F2-C30B-4A77-835A-25495B337EED} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Chromium.job => C:\Users\JIMMYJ~1\AppData\Local\Chromium\APPLIC~1\450242~1.0\INSTAL~1\UNINST~1.EXE
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001Core.job => C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1714133512-296453273-4189880979-1001UA.job => C:\Users\Jimmy James\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2014-11-14 15:51 - 2014-11-14 15:51 - 00466432 _____ () C:\Windows\system32\DPPPlugin.dll
2015-11-01 19:41 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2015-11-01 19:41 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2015-11-01 19:41 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2015-11-01 19:41 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2015-11-01 19:41 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2014-10-10 10:37 - 2014-10-10 10:37 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\gfore => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Rasigusxu => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\win8gfore => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WWatcherProxy => ""="service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com

There are 7866 more sites.

IE trusted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\dell.com -> dell.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1714133512-296453273-4189880979-1001\…\123simsen.com -> www.123simsen.com

There are 7866 more sites.


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1714133512-296453273-4189880979-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jimmy James\Pictures\Jemez Mountain Beauty.jpg
DNS Servers: 192.168.0.1 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{3D73F5E4-8F82-463F-94DA-6BA1917CCE65}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{F0E2173A-B620-4A98-9AA7-C8DFA0EC4DBE}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{51176830-06B7-45A3-A69C-4FEADEA0D0B6}] => (Allow) C:\Users\Jimmy James\AppData\Local\Chromium\Application\chrome.exe
FirewallRules: [{951A1D84-669C-4609-A353-36839E6F3540}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1164A575-FA50-40E1-A02B-06034AE321FE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{038B50D6-58E0-4E27-8895-727D8A1FE47C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A2C5CDB1-C03E-4EEF-9BA1-E88BA8C3C5CD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service

==================== Faulty Device Manager Devices =============

Name: Realtek PCIe FE Family Controller
Description: Realtek PCIe FE Family Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: RTL8168
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/11/2015 11:17:06 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {9ec175f7-94f3-44f7-b473-20d0930d1281}

Error: (11/11/2015 01:33:07 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (11/11/2015 11:33:34 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program aswMBR.exe version 1.0.1.2252 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: ecc

Start Time: 01d11caf689fb82b

Termination Time: 4294967295

Application Path: C:\Users\Jimmy James\Desktop\aswMBR.exe

Report Id: b65d45be-88a2-11e5-8279-91fe15208fb9

Faulting package full name:

Faulting package-relative application ID:

Error: (11/11/2015 08:55:55 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program gentlemjmp_ieeuu.tmp version 51.52.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: c80

Start Time: 01d11c99627f33cc

Termination Time: 4294967295

Application Path: C:\Users\JIMMYJ~1\AppData\Local\Temp\is-4OVKB.tmp\gentlemjmp_ieeuu.tmp

Report Id: af547ba2-888c-11e5-8277-f7617aae1286

Faulting package full name:

Faulting package-relative application ID:

Error: (11/11/2015 08:51:34 AM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (3664) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.

Error: (11/11/2015 08:46:27 AM) (Source: TrueColorALS) (EventID: 4) (User: )
Description: TrueColorALSCUISDKaccess(): Getting access to the pipe failed. Error:1073741825 (0x40000001) and Error: 2 (0x2)

Error: (11/11/2015 08:30:09 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: spbia.exe, version: 1.0.0.4, time stamp: 0x562fc085
Faulting module name: spbia.exe, version: 1.0.0.4, time stamp: 0x562fc085
Exception code: 0xc0000005
Fault offset: 0x000000000000a746
Faulting process id: 0xbf4
Faulting application start time: 0xspbia.exe0
Faulting application path: spbia.exe1
Faulting module path: spbia.exe2
Report Id: spbia.exe3
Faulting package full name: spbia.exe4
Faulting package-relative application ID: spbia.exe5

Error: (11/11/2015 08:26:38 AM) (Source: MsiInstaller) (EventID: 11316) (User: SonofSpudbort)
Description: Product: globalupdate Helper – Error 1316. The specified account already exists.

Error: (11/11/2015 08:25:49 AM) (Source: MsiInstaller) (EventID: 11316) (User: SonofSpudbort)
Description: Product: globalupdate Helper – Error 1316. The specified account already exists.

Error: (11/07/2015 08:57:16 PM) (Source: TrueColorALS) (EventID: 4) (User: )
Description: TrueColorALSCUISDKaccess(): Getting access to the pipe failed. Error:1073741825 (0x40000001) and Error: 2 (0x2)


System errors:
=============
Error: (11/11/2015 11:44:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (11/11/2015 11:44:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) Dynamic Application Loader Host Interface Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/11/2015 11:44:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® ME Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/11/2015 11:44:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Bluetooth OBEX Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/11/2015 11:44:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Bluetooth Device Monitor service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/11/2015 11:44:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.

Error: (11/11/2015 11:44:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Spybot-S&D; 2 Security Center Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (11/11/2015 11:44:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) PROSet/Wireless Zero Configuration Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/11/2015 11:44:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The TrueColorALS service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/11/2015 11:44:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Spybot-S&D; 2 Updating Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-5200U CPU @ 2.20GHz
Percentage of memory in use: 13%
Total physical RAM: 12203.33 MB
Available physical RAM: 10582.5 MB
Total Virtual: 25003.33 MB
Available Virtual: 23422.86 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:922.87 GB) (Free:835.71 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 5C29CDFB)

Partition: GPT.

==================== End of Addition.txt ============================

Hi Jimmy

 

GamerForest Support  <–This is running as a task, are you aware of it, is it something you use, if not we can fix it, let me know

 

Also the two files I said that we had to fix, there fixed so not to worry about them

 

How is your system behaving now ?????

I have no idea where Gamerforest came from.  I don't do the gaming thing.  Is it possible it came preinstalled on my machine?  Either way, I would be happy to get rid of it. 

 

My system is behaving perfectly, but then again, it was behaving perfectly after I tried to clean it the first time (before I contacted this forum). 

 

Once again, I truly appreciate your help.  Thank you. 

Here  ya go

 

 

 
Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint: 
Task: {1A832373-1A58-4E30-BCC1-E01C0AEB0285} - System32\Tasks\GamerForest Support => C:\Users\JIMMYJ~1\AppData\Local\GAMERF~1\gfore_run.exe
C:\Users\JIMMYJ~1\AppData\Local\GAMERF~1
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Thank you again!

 

I have a couple of dumb questions: first, how do I turn Windows Defender back on?  It says my system administrator has disabled it.  I have anti-malware applications installed, but no anti-virus. 

 

Second, can you recommend a video ripper that won't infect my machine with a bunch of junk?  As I mentioned, I was using Ant Videos, a plug-in for Firefox, and I think it was responsible for my infection.

 

Here's the fixlog.txt:

 

Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by [removed] (2015-11-12 10:43:48) Run:2
Running from C:\Users\[removed]\Desktop\infection stuff
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
Task: {1A832373-1A58-4E30-BCC1-E01C0AEB0285} - System32\Tasks\GamerForest Support => C:\Users\JIMMYJ~1\AppData\Local\GAMERF~1\gfore_run.exe
C:\Users\JIMMYJ~1\AppData\Local\GAMERF~1
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
*****************

Processes closed successfully.
Restore point was successfully created.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1A832373-1A58-4E30-BCC1-E01C0AEB0285}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A832373-1A58-4E30-BCC1-E01C0AEB0285}" => key removed successfully
C:\Windows\System32\Tasks\GamerForest Support => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GamerForest Support" => key removed successfully
"C:\Users\JIMMYJ~1\AppData\Local\GAMERF~1" => not found.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

EmptyTemp: => 46 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 10:44:10 ====

Open Windows Defender by right clicking on the icon and select RUN AS ADMINISTRATOR

 

When it opens , up on the top right look for the setting tab and open it, then select Real Time Protection and use the slider to turn it on

 

 

As far as software for ripping video, I am afraid I am not into that so dont know what to tell you but you can post here in our Consumer Electronics forum and see what they advise 

http://forums.whatthetech.com/index.php?showforum=130

 

 

Double click on AdwCleaner.exe to run the tool again.
  •  
  • Click on the Uninstall button.
  • Click Yes when asked are you sure you want to uninstall.
  • Both AdwCleaner.exe, its folder and all logs will be removed.
 
 
 
==========================================================
 
 
Please download DelFix and save the file to your Desktop.
 
[external image: DelFix_zps139e2ea1.jpg]
 
  •  
  • Windows XP Double Click DelFix.exe to run the program. 
  • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
  • Checkmark " Remove Disinfection Tools"
  • Click the Run button
 
 
This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
 
 
 
 
So How did I get infected in the first place <– Some reading for you to keep yourself safe online
 
 
Safe Surfn
Ken
 
 
 

Thank you once again.  Your help is immeasurable. 

 

I can't run Windows Defender, even as an admin.  I get the following message when I try:

 

This app is turned off by group policy

If you're using another app to check for malicious or unwanted software,

use security and maintenance to check that app's status.

To allow this app to run, contact your security administrator

to enable the program via group policy

Are you running any other anti virus software on your system ( not anti malware) if you are Windows Defender will be turned off by default

 

Go to Start > Run and type in services.msc and enter on your keyboard, when the services tab loads look for Windows Defender , double click it and make sure the start up type is Automatic

 

If this dont work we may have to fix the registry but let try the above first

I only have anti-malware installed on my system.  Spybot and Malwarebytes, 

 

I went into my registry and edited HLKM/SOFTWARE/Policies/Microsoft/Windows Defender, changing the value on Disable Anti-Spyware to 0.

 

Then Windows Defender started, but would not let me turn it on.  Here's the error message:

 

The service couldn't be started.  
The group or resource is not in the correct state to perform
the requested operation.
Error code: 0x8007139f

Then I received your reply and went to Services.  Both WD Services and WD Network Services displayed greyed-out startup option pull-down menus.  I then tried to start Windows Defender services and got this message:

Windows could not start the Windows Defender Service on Local Computer.

Error 577: Windows cannot verify the digital signature for this file.  A
recent hardware or software change might have installed a file that is
signed incorrectly or damaged, or that might be malicious software
from an unknown source.

Good Morning Jimmy,

 

One thing I know for sure is that with all the malware you had on this system that one of them turned Windows Defender off and disabled it.  I have googled this to death and one of the suggestions is to make sure your system is completely free of malware.  So lets run a free online virus scanner and see what it comes up with. Looking over the errors on your FRST Additions logs points to some errors regarding malware we already removed. Some times the best way to go after getting pretty infected is to format your drive and reinstall the OS then your assured that its nice and clean and everything is working.

 

 

 
ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan
 
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
 
 
  •  
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
  • Click the [external image: esetOnline.png] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    •  
  • Click on [external image: esetSmartInstall.png] to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the [external image: esetSmartInstallDesktopIcon.png] icon on your desktop.
 
  • Check [external image: esetAcceptTerms.png]
  • Click the [external image: esetStart.png] button.
  • Accept any security warnings from your browser.
  • Check [external image: esetScanArchives.png]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: esetListThreats.png]
  • Push [external image: esetExport.png], and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: esetBack.png] button.
  • Push [external image: esetFinish.png]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.

I was getting ready to install windows 10 anyway, but is there a chance my wonderfully important data files might be infected too? 

 

Here's the ESET results:

 

C:\Users\Jimmy James\AppData\Roaming\tXnxIXs16    JS/Toolbar.Crossrider.C potentially unwanted application
C:\Users\Jimmy James\Documents\Other James Stuff\Teacher Man\.Trashes\1380234446\ppt templates for quiz_10924_i30101747_il345.exe    a variant of Win32/Amonetize.DT potentially unwanted application
 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI