Hi I have a Samsung netbook and its been acting funny running slow and cant do any Microsoft updates it just keeps checking for updates. thanks
dont know whats going on [Solved]
25 min read
Hello portboy123, welcome to WhatTheTech's Malware Removal forum!
My name is Adam. I will be assisting you with your malware-related problems.
If you would allow me to call you by your first name I would prefer that. ![]()
======================================================
Please read through the points below to ensure this process moves as quickly and efficiently as possible.
- Ensure you read through my instructions thoroughly, and carry out each step in the order specified.
- Please do not run any tools or take any steps other than those I provide for you. Independent efforts may make matters worse, and will affect my ability in providing the best set of instructions for you.
- Please backup important files before proceeding with my instructions. Malware removal can be unpredictable at times.
- If you come across any issues whilst following my instructions, please stop and inform me of the issue in as much detail as possible. Please do not hesitate to ask before proceeding.
- Topics are locked if no response is made after 4 days. Please inform me if you require additional time to complete my instructions.
- I will notify you when I believe your computer is free of malware. Please bear in mind, absence of symptoms does not necessarily correlate to absence of malware, so please wait until the "All Clean".
======================================================
Please run the following diagnostic scan so I can ascertain the state of your computer.
STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan
- Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
- Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
- Right-Click FRST.exe or FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the programme run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.
======================================================
STEP 2
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- FRST.txt
- Addition.txt
Hi Adam, My name is Frank thanks for your help. Here are the two
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-02-2016
Ran by [removed] (administrator) on FRANK-PC (15-02-2016 15:22:54)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\BrYNSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
(SEC) C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics) C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_20_0_0_306_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-29] (Microsoft Corporation)
HKLM\…\Run: [BrStsMon00] => C:\Program Files\Browny02\Brother\BrStMonW.exe [4522496 2012-12-27] (Brother Industries, Ltd.)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
BootExecute: autocheck autochk * bootdelete
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL No File
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{EBA4490B-16ED-47D1-987C-2BC8C214AC84}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{F1E76D56-F860-40DE-BCEE-3E9315C8EEB1}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=SMSTDF&pc;=MASM&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=SMSTDF&pc;=MASM&src;=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> DefaultScope {EB525A7B-66CA-402B-B8DA-BB1E06E49712} URL = hxxp://search.yahoo.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {44f44034-6036-4f06-9336-74ec4620edab} URL =
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {71EA7148-F02F-4AAB-96F9-641086FE86F0} URL = hxxp://search.yahoo.com/search?p={searchTerms}&b;={startPage?}&fr;=ie8
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {EB525A7B-66CA-402B-B8DA-BB1E06E49712} URL = hxxp://search.yahoo.com/search?p={searchTerms}
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-09-16] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10] (Microsoft Corporation)
BHO: W2PBrowser Class -> {AA609D72-8482-4076-8991-8CDAE5B93BCB} -> C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll [2010-09-17] ()
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-16] (Oracle Corporation)
DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} hxxp://w4s.work4sure.com/c/ge/w4sgeen9.exe
DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234}
FireFox:
========
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2013-04-02] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-16] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-16] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-12] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-12] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [282112 2012-10-26] (Brother Industries, Ltd.) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [252632 2014-12-11] (Realtek Semiconductor)
S3 Samsung UPD Service; C:\windows\System32\SUPDSvc.exe [131888 2010-08-09] (Samsung Electronics CO., LTD.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\windows\System32\DRIVERS\athr.sys [3208496 2015-05-19] (Qualcomm Atheros Communications, Inc.)
R3 ETD; C:\windows\System32\DRIVERS\ETD.sys [100744 2010-08-30] (ELAN Microelectronics Corp.)
S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R1 MpKsled24cdac; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BDF92A63-A76F-4F25-AAC9-67B94878838A}\MpKsled24cdac.sys [39168 2016-02-14] (Microsoft Corporation)
R3 ProcObsrv; C:\Program Files\Glary Utilities 3\ProcObsrv.sys [11552 2013-09-02] (Glarysoft Ltd)
S3 rtport; C:\windows\system32\drivers\rtport.sys [15656 2011-01-07] (Windows (R) 2003 DDK 3790 provider)
S3 usbbus; C:\windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-11] (LG Electronics Inc.)
S3 UsbDiag; C:\windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-11] (LG Electronics Inc.)
S3 USBModem; C:\windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-11] (LG Electronics Inc.)
S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X]
S1 bvojdtqc; \??\C:\windows\system32\drivers\bvojdtqc.sys [X]
S1 hprykgyo; \??\C:\windows\system32\drivers\hprykgyo.sys [X]
S1 ocqdvltc; \??\C:\windows\system32\drivers\ocqdvltc.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-15 15:22 - 2016-02-15 15:23 - 00011221 _____ C:\Users\Frank\Downloads\FRST.txt
2016-02-15 15:21 - 2016-02-15 15:22 - 00000000 ____D C:\FRST
2016-02-15 15:18 - 2016-02-15 15:18 - 00001056 _____ C:\Users\Frank\Desktop\FRST - Shortcut.lnk
2016-02-15 15:17 - 2016-02-15 15:17 - 01721344 _____ (Farbar) C:\Users\Frank\Downloads\FRST.exe
2016-02-14 16:02 - 2016-02-14 16:02 - 00302011 _____ C:\Users\Frank\Downloads\WindowsUpdateDiagnostic.diagcab
2016-02-14 15:50 - 2016-02-14 15:51 - 00000000 ____D C:\77e0069e7daef456da53122fef246b10
2016-02-14 15:36 - 2016-02-14 15:50 - 239126136 _____ C:\Users\Frank\Downloads\Windows6.1-KB947821-v34-x86 (1).msu
2016-02-14 14:31 - 2016-02-14 14:31 - 00003288 ____N C:\bootsqm.dat
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-15 15:17 - 2009-07-13 23:34 - 00016752 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-15 15:17 - 2009-07-13 23:34 - 00016752 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-15 15:12 - 2012-01-30 10:25 - 00000886 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-15 15:11 - 2012-12-26 12:43 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2016-02-15 11:29 - 2012-01-30 10:25 - 00000882 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-14 20:51 - 2014-09-25 07:36 - 00170200 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-02-14 20:49 - 2014-09-25 07:35 - 00001064 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-02-14 20:49 - 2014-09-25 07:35 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-02-14 20:07 - 2009-07-26 15:06 - 00782510 _____ C:\windows\system32\PerfStringBackup.INI
2016-02-14 20:07 - 2009-07-13 21:37 - 00000000 ____D C:\windows\inf
2016-02-14 20:03 - 2013-06-07 06:56 - 00000320 _____ C:\windows\Tasks\GlaryInitialize 3.job
2016-02-14 20:02 - 2009-07-13 23:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-02-14 16:12 - 2013-01-18 15:09 - 00000000 ____D C:\Users\Frank\AppData\Local\ElevatedDiagnostics
2016-02-12 14:24 - 2009-07-13 21:37 - 00000000 ____D C:\windows\registration
2016-02-12 12:56 - 2009-07-13 23:33 - 00334032 _____ C:\windows\system32\FNTCACHE.DAT
2016-02-12 12:16 - 2013-07-24 08:28 - 00000000 ____D C:\windows\system32\MRT
2016-02-12 12:03 - 2011-02-05 08:43 - 143250520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-02-12 11:24 - 2011-02-05 06:40 - 00000000 ____D C:\Users\Frank\AppData\Local\VirtualStore
2016-02-12 11:04 - 2012-04-02 06:47 - 00796864 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2016-02-12 11:03 - 2011-05-15 13:28 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2012-12-27 14:05 - 2012-12-27 14:06 - 0000020 _____ () C:\Program Files\FullScreensavers.ini
2014-11-17 10:36 - 2015-09-07 10:29 - 0007605 _____ () C:\Users\Frank\AppData\Local\Resmon.ResmonCfg
2015-04-01 12:20 - 2015-04-01 12:20 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2011-02-05 06:47 - 2010-01-16 06:18 - 0131368 _____ () C:\ProgramData\FullRemove.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-10-12 08:49
==================== End of FRST.txt ============================
logs.
Additional scan result of Farbar Recovery Scan Tool (x86) Version:07-02-2016
Ran by [removed] (2016-02-15 15:25:12)
Running from C:\Users\[removed]\Downloads
Microsoft Windows 7 Starter Service Pack 1 (X86) (2011-02-05 11:40:28)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2118264723-1652648626-4119575669-500 - Administrator - Disabled)
Frank (S-1-5-21-2118264723-1652648626-4119575669-1000 - Administrator - Enabled) => C:\Users\Frank
Guest (S-1-5-21-2118264723-1652648626-4119575669-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
„Messenger“ pagalbinė priemonė (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Essentials“ (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Messenger“ (Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Adobe Flash Player 20 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 20.0.0.306 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Atheros Client Installation Program (HKLM\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros)
BatteryLifeExtender (HKLM\…\{EA257ECF-5F72-4461-B890-959394DCD087}) (Version: 1.0.10 - Samsung)
Broadcom 802.11 Network Adapter (HKLM\…\Broadcom 802.11 Network Adapter) (Version: 5.60.48.55 - Broadcom Corporation)
Brother MFL-Pro Suite MFC-J470DW (HKLM\…\{7B4C83B6-17C1-4BFD-B86D-4D7AD4498CBB}) (Version: 1.0.4.0 - Brother Industries, Ltd.)
CCleaner (HKLM\…\CCleaner) (Version: 3.14 - Piriform)
Complément Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Complemento Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
CyberLink YouCam (HKLM\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.3911 - CyberLink Corp.)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Doplnok programu Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Easy Content Share (HKLM\…\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD)
Easy Display Manager (HKLM\…\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.)
Easy Network Manager (HKLM\…\{556EAB35-CD1F-4E94-83CA-D5C9FA2CDA5B}) (Version: 4.4.1 - Samsung)
Easy Resolution Manager (HKLM\…\{18AA278D-E0B9-4F99-ACCC-070978A38453}) (Version: 1.0.9 - Samsung)
Easy SpeedUp Manager (HKLM\…\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.1.0.15 - Samsung Electronics Co.,Ltd.)
EasyBatteryManager (HKLM\…\{607DA1C8-34EC-4D7A-AD83-F8E5C70736DF}) (Version: 4.0.0.4 - Samsung)
EasyFileShare (HKLM\…\{EA76E65F-6679-495A-A8A6-42AD6602ED4C}) (Version: 1.0.11 - Samsung)
Fast Start (HKLM\…\{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}) (Version: 2.2.0.0 - SAMSUNG)
Fotogalerija Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Glary Utilities 3.9.1 (HKLM\…\Glary Utilities 3) (Version: 3.9.1.138 - Glarysoft Ltd)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.29.5 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.2567 - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
Java 8 Update 51 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Java 8 Update 60 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LG Outlook Sync (HKLM\…\{84CA1CCF-5CF7-4ED6-8CFA-77DD5C949505}) (Version: 1.1.0.4 - LG Electronics)
LG USB Modem driver (HKLM\…\{C3ABE126-2BB2-4246-BFE1-6797679B3579}) (Version: - )
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Marvell Miniport Driver (HKLM\…\Marvell Miniport Driver) (Version: 11.24.27.3 - Marvell)
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Assistent (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Companion (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger kísérő (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Pratilac (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Suradnik (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 사이트 공유 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 分享元件 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 浏览器插件 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger-kumppani (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Color Enhancer (HKLM\…\{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Picasa 3 (HKLM\…\Picasa 3) (Version: 3.9 - Google, Inc.)
Poczta usługi Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pomocnik Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7404 - Realtek Semiconductor Corp.)
REALTEK PCIE Wireless LAN Software (HKLM\…\{A5C8BFF2-0044-4500-8BB5-BEB0D2335885}) (Version: 0136.10.0325 - REALTEK Semiconductor Corp.)
Samsung AnyWeb Print (HKLM\…\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 1.1.21.0 - Samsung Electronics Co., Ltd.)
Samsung AnyWeb Print (Version: 1.0 - Samsung Electronics Co., Ltd.) Hidden
Samsung Recovery Solution 5 (HKLM\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.0.7 - Samsung)
Samsung Support Center 1.0 (HKLM\…\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.38 - Samsung)
Samsung Universal Print Driver (HKLM\…\Samsung Universal Print Driver) (Version: 2.01.06.00:16 - Samsung Electronics Co., Ltd.)
Samsung Universal Scan Driver (HKLM\…\Samsung Universal Scan Driver) (Version: 1.2.1.0 - Samsung Electronics Co., Ltd.)
Samsung Update Plus (HKLM\…\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.1.17 - Samsung Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Software Updater (HKLM\…\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION)
Spremljevalec Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
SRS Premium Sound Control Panel (HKLM\…\{2998191E-A35E-47E2-BE38-7702C731D722}) (Version: 1.09.0800 - SRS Labs, Inc.)
User Guide (HKLM\…\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - )
Windows Live Essentials (HKLM\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Yahoo! Install Manager (HKLM\…\YInstHelper) (Version: - )
Yahoo! Internet Mail (HKLM\…\Yahoo! Mail) (Version: - )
Yahoo! Mail Advisor (HKLM\…\Yahoo! Mail Advisor) (Version: - )
Yahoo! Software Update (HKLM\…\Yahoo! Software Update) (Version: - )
Συλλογή φωτογραφιών του Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Компаньон Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Помощник на Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
מסייע Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35200-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35201-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35202-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{36B65F6A-FBA5-4510-ACB3-702C5BE97A80}\InprocServer32 -> C:\Program Files\LG Outlook Sync\OutlookSyncAddIn.dll (TODO: <회사 이름>)
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InprocServer32 -> no filepath
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0FEA48CB-AEB1-4A6E-9422-4442DC050554} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2010-08-04] (Samsung Electronics Co., Ltd.)
Task: {1BD02387-9B77-432C-B583-FFA53BCDD40F} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-05053A95\EPM.exe
Task: {1EF2FEE4-70AE-4986-9270-9EA2D915B1E6} - System32\Tasks\IdlePowerSave => C:\windows\Idle\DetectIdleTask.exe [2010-07-30] (TODO: <회사 이름>)
Task: {233E860F-77DC-48C2-8956-F335C6F22622} - System32\Tasks\{F97BD0B4-3C69-43D9-8F6D-295AD840C03A} => pcalua.exe -a "C:\Users\Frank\AppData\Local\Temp\Temporary Internet Files\Content.IE5\DWLZCYHM\blazingcolorsviz[1].exe" -d C:\Users\Frank\Desktop
Task: {398F427B-6B86-4C52-AAAA-7F071D9A63C1} - System32\Tasks\EasySpeedUpManager => C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager2.exe [2010-08-05] (Samsung Electronics)
Task: {4EF41F74-479E-449A-A0ED-031BD25A8266} - System32\Tasks\{FAB4F085-526A-482F-85C9-AB42B5E82E64} => pcalua.exe -a "C:\Users\Frank\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBNKJXW6\Silverlight.exe" -d C:\Users\Frank\Desktop
Task: {59C7BDB7-EE87-47CB-96E4-CF4A94B8ADD8} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [2011-12-20] (Samsung Electronics)
Task: {5B7E971E-71F8-4F87-A9BB-408B58E0C75D} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe [2010-08-05] (Samsung Electronics Co., Ltd.)
Task: {5DF8AFFB-100B-449A-AF4A-86EB0D0A6E07} - System32\Tasks\GlaryInitialize 3 => C:\Program Files\Glary Utilities 3\Initialize.exe [2013-09-02] (Glarysoft Ltd)
Task: {68BA8254-96BA-4DE6-81C0-9D70BB80B9BD} - System32\Tasks\advSRS5 => C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-08-11] (SEC)
Task: {95490CDD-61E5-43F7-AB98-5DC94D1708BD} - System32\Tasks\{6686E387-EDFA-43DB-8F96-601B4BE0350A} => pcalua.exe -a "C:\Program Files\LG Electronics\LG USB Modem Driver\UninstallShld.exe" -d C:\windows\system32 -c C:\Program Files\LG Electronics\LG USB Modem driver
Task: {9EBCF46C-A069-427D-96E1-A460F813D531} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-12] (Adobe Systems Incorporated)
Task: {C18F2B4D-6A61-4974-80EE-20C4A7CA2A36} - System32\Tasks\BatteryLifeExtender => C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-10-14] (Samsung Electronics. Co. Ltd.)
Task: {CAFD20F1-6B96-4AF6-B1CB-D2DC2D62516C} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-19] (SAMSUNG Electronics co., LTD.)
Task: {D59CCD62-61C3-4A55-B06A-448D2E8FD5E9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-06] (Google Inc.)
Task: {E1D85EC0-EF00-4572-A3AC-9FDBFD680F7A} - System32\Tasks\MovieColorEnhancer => C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe [2010-08-19] (Samsung Electronics Co., Ltd.)
Task: {E30C5E9E-FC9A-4186-AC44-8C24737B1641} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-06] (Google Inc.)
Task: {E915CBF1-4C09-4447-BC30-0C4460F49D9A} - System32\Tasks\SRS Premium Sound => C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel.exe [2010-10-20] (SRS Labs, Inc.)
Task: {FFB28A0E-BBCF-464C-B1E1-04EE9E5212DE} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2011-09-04] (SAMSUNG Electronics)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GlaryInitialize 3.job => C:\Program Files\Glary Utilities 3\Initialize.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2010-11-19 01:09 - 2010-07-05 05:42 - 00203776 _____ () C:\Program Files\Samsung\Movie Color Enhancer\WinCRT.dll
2011-02-05 06:42 - 2008-06-04 18:53 - 00026624 _____ () C:\windows\System32\spd__l.dll
2011-02-05 06:43 - 2010-04-20 18:45 - 00552960 _____ () C:\windows\system32\SnMinDrv.dll
2015-04-23 10:22 - 2009-02-27 15:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
2010-11-19 01:11 - 2006-08-11 22:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll
2010-11-19 01:13 - 2010-05-07 09:22 - 01636864 _____ () C:\Program Files\Samsung\Samsung Recovery Solution 5\Resdll.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:42D9E231
AlternateDataStreams: C:\ProgramData\Temp:5C270C64
AlternateDataStreams: C:\ProgramData\Temp:91EA783C
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:04 - 2009-06-10 16:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000\Control Panel\Desktop\\Wallpaper -> %windir%\web\wallpaper\windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^Users^Frank^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Frank^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: ETDCtrl => %ProgramFiles%\Elantech\ETDCtrl.exe
MSCONFIG\startupreg: HotKeysCmds => C:\windows\system32\hkcmd.exe
MSCONFIG\startupreg: IgfxTray => C:\windows\system32\igfxtray.exe
MSCONFIG\startupreg: Persistence => C:\windows\system32\igfxpers.exe
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: YMailAdvisor => "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{CD2DE1F4-251E-4E0F-8ACE-52B6EB716161}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{BFCBC590-BDB4-4E06-8301-B5A69BBD1A39}] => (Allow) LPort=2869
FirewallRules: [{B49E2138-D3EE-403E-B797-1E32780AC60F}] => (Allow) LPort=1900
FirewallRules: [{33D54809-B2BE-435D-BD1C-600E2D7094CA}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{6F502750-D6FA-4911-9DF2-287315C97284}] => (Allow) C:\Program Files\Windows Live\Mesh\MOE.exe
FirewallRules: [{948C5F2B-D5C2-41B3-98DA-4252D4802DF8}] => (Allow) C:\Windows\System32\SUPDSvc.exe
FirewallRules: [{F3DCBA70-8102-4E0E-BE3A-5E7F04EA97C5}] => (Allow) C:\Windows\System32\SUPDSvc.exe
FirewallRules: [{2BABC92C-A3C0-4620-9A85-1582EAF4FE77}] => (Allow) C:\Program Files\Samsung\Samsung Universal Scan Driver\USDAgent.exe
FirewallRules: [{EB38D767-85B7-4095-8219-8282072ADCD5}] => (Allow) C:\Program Files\Samsung\Samsung Universal Scan Driver\USDAgent.exe
FirewallRules: [{410C8BFE-25E1-4513-8399-FA5D92F9D0A4}] => (Allow) C:\Program Files\Samsung\Samsung Universal Scan Driver\ICCUpdater.exe
FirewallRules: [{BE9FB9C2-071A-4A4C-B068-EC4F008CA2F0}] => (Allow) C:\Program Files\Samsung\Samsung Universal Scan Driver\ICCUpdater.exe
FirewallRules: [{02FD264E-6861-456B-A7D5-EFFAD2704AFD}] => (Allow) C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{E1FFB0A2-F105-4A7D-B755-7056EF45513D}] => (Allow) LPort=54925
==================== Restore Points =========================
12-10-2015 18:11:42 Windows Update
16-10-2015 19:10:31 Windows Update
30-11-2015 08:52:15 Windows Update
07-12-2015 16:06:38 Windows Update
12-02-2016 14:28:50 Windows Update
14-02-2016 16:13:36 Installed Microsoft Fix it 50123
==================== Faulty Device Manager Devices =============
Name: MpKslc99076d2
Description: MpKslc99076d2
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: MpKslc99076d2
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/14/2016 09:43:11 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:11 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.
Context: Windows Application
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:11 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: The gatherer object cannot be initialized.
Context: Windows Application, SystemIndex Catalog
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:11 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in cannot be initialized.
Context: Windows Application, SystemIndex Catalog
Details:
Element not found. (HRESULT : 0x80070490) (0x80070490)
Error: (02/14/2016 09:43:10 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in cannot be initialized.
Context: Windows Application, SystemIndex Catalog
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:10 AM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: The Windows Search Service cannot load the property store information.
Context: Windows Application, SystemIndex Catalog
Details:
The content index database is corrupt. (HRESULT : 0xc0041800) (0xc0041800)
Error: (02/14/2016 09:43:10 AM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:10 AM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: The search service has detected corrupted data files in the index {id=4700}. The service will attempt to automatically correct this problem by rebuilding the index.
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:10 AM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: The Windows Search Service cannot open the Jet property store.
Details:
0x%08x (0xc0041800 - The content index database is corrupt. (HRESULT : 0xc0041800))
Error: (02/14/2016 09:43:10 AM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (2456) Windows: Error -1811 occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00028.log.
System errors:
=============
Error: (02/14/2016 08:02:53 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
Error: (02/14/2016 08:02:50 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
cdrom
Error: (02/14/2016 08:02:29 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (02/14/2016 04:28:15 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D}
Error: (02/14/2016 02:32:54 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
cdrom
Error: (02/14/2016 02:32:33 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (02/14/2016 02:23:22 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Windows Update service did not shut down properly after receiving a preshutdown control.
Error: (02/14/2016 02:15:48 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
Error: (02/14/2016 02:15:46 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
cdrom
Error: (02/14/2016 02:15:22 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
==================== Memory info ===========================
Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz
Percentage of memory in use: 77%
Total physical RAM: 1013.3 MB
Available physical RAM: 224.14 MB
Total Virtual: 2037.3 MB
Available Virtual: 921.23 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:178.61 GB) (Free:141.42 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: C04936A2)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=178.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=13.6 GB) - (Type=27)
Partition 4: (Not Active) - (Size=40.5 GB) - (Type=27)
==================== End of Addition.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version:07-02-2016
Ran by [removed] (2016-02-15 15:25:12)
Running from C:\Users\[removed]\Downloads
Microsoft Windows 7 Starter Service Pack 1 (X86) (2011-02-05 11:40:28)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2118264723-1652648626-4119575669-500 - Administrator - Disabled)
Frank (S-1-5-21-2118264723-1652648626-4119575669-1000 - Administrator - Enabled) => C:\Users\Frank
Guest (S-1-5-21-2118264723-1652648626-4119575669-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
„Messenger“ pagalbinė priemonė (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Essentials“ (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Messenger“ (Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Adobe Flash Player 20 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 20.0.0.306 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Atheros Client Installation Program (HKLM\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros)
BatteryLifeExtender (HKLM\…\{EA257ECF-5F72-4461-B890-959394DCD087}) (Version: 1.0.10 - Samsung)
Broadcom 802.11 Network Adapter (HKLM\…\Broadcom 802.11 Network Adapter) (Version: 5.60.48.55 - Broadcom Corporation)
Brother MFL-Pro Suite MFC-J470DW (HKLM\…\{7B4C83B6-17C1-4BFD-B86D-4D7AD4498CBB}) (Version: 1.0.4.0 - Brother Industries, Ltd.)
CCleaner (HKLM\…\CCleaner) (Version: 3.14 - Piriform)
Complément Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Complemento Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
CyberLink YouCam (HKLM\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.3911 - CyberLink Corp.)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Doplnok programu Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Easy Content Share (HKLM\…\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD)
Easy Display Manager (HKLM\…\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.)
Easy Network Manager (HKLM\…\{556EAB35-CD1F-4E94-83CA-D5C9FA2CDA5B}) (Version: 4.4.1 - Samsung)
Easy Resolution Manager (HKLM\…\{18AA278D-E0B9-4F99-ACCC-070978A38453}) (Version: 1.0.9 - Samsung)
Easy SpeedUp Manager (HKLM\…\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.1.0.15 - Samsung Electronics Co.,Ltd.)
EasyBatteryManager (HKLM\…\{607DA1C8-34EC-4D7A-AD83-F8E5C70736DF}) (Version: 4.0.0.4 - Samsung)
EasyFileShare (HKLM\…\{EA76E65F-6679-495A-A8A6-42AD6602ED4C}) (Version: 1.0.11 - Samsung)
Fast Start (HKLM\…\{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}) (Version: 2.2.0.0 - SAMSUNG)
Fotogalerija Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Glary Utilities 3.9.1 (HKLM\…\Glary Utilities 3) (Version: 3.9.1.138 - Glarysoft Ltd)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.29.5 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.2567 - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
Java 8 Update 51 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Java 8 Update 60 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LG Outlook Sync (HKLM\…\{84CA1CCF-5CF7-4ED6-8CFA-77DD5C949505}) (Version: 1.1.0.4 - LG Electronics)
LG USB Modem driver (HKLM\…\{C3ABE126-2BB2-4246-BFE1-6797679B3579}) (Version: - )
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Marvell Miniport Driver (HKLM\…\Marvell Miniport Driver) (Version: 11.24.27.3 - Marvell)
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Assistent (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Companion (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger kísérő (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Pratilac (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Suradnik (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 사이트 공유 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 分享元件 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 浏览器插件 (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger-kumppani (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Color Enhancer (HKLM\…\{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Picasa 3 (HKLM\…\Picasa 3) (Version: 3.9 - Google, Inc.)
Poczta usługi Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pomocnik Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7404 - Realtek Semiconductor Corp.)
REALTEK PCIE Wireless LAN Software (HKLM\…\{A5C8BFF2-0044-4500-8BB5-BEB0D2335885}) (Version: 0136.10.0325 - REALTEK Semiconductor Corp.)
Samsung AnyWeb Print (HKLM\…\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 1.1.21.0 - Samsung Electronics Co., Ltd.)
Samsung AnyWeb Print (Version: 1.0 - Samsung Electronics Co., Ltd.) Hidden
Samsung Recovery Solution 5 (HKLM\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.0.7 - Samsung)
Samsung Support Center 1.0 (HKLM\…\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.38 - Samsung)
Samsung Universal Print Driver (HKLM\…\Samsung Universal Print Driver) (Version: 2.01.06.00:16 - Samsung Electronics Co., Ltd.)
Samsung Universal Scan Driver (HKLM\…\Samsung Universal Scan Driver) (Version: 1.2.1.0 - Samsung Electronics Co., Ltd.)
Samsung Update Plus (HKLM\…\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.1.17 - Samsung Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Software Updater (HKLM\…\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION)
Spremljevalec Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
SRS Premium Sound Control Panel (HKLM\…\{2998191E-A35E-47E2-BE38-7702C731D722}) (Version: 1.09.0800 - SRS Labs, Inc.)
User Guide (HKLM\…\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - )
Windows Live Essentials (HKLM\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Yahoo! Install Manager (HKLM\…\YInstHelper) (Version: - )
Yahoo! Internet Mail (HKLM\…\Yahoo! Mail) (Version: - )
Yahoo! Mail Advisor (HKLM\…\Yahoo! Mail Advisor) (Version: - )
Yahoo! Software Update (HKLM\…\Yahoo! Software Update) (Version: - )
Συλλογή φωτογραφιών του Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Компаньон Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Помощник на Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
מסייע Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35200-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35201-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35202-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{36B65F6A-FBA5-4510-ACB3-702C5BE97A80}\InprocServer32 -> C:\Program Files\LG Outlook Sync\OutlookSyncAddIn.dll (TODO: <회사 이름>)
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InprocServer32 -> no filepath
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0FEA48CB-AEB1-4A6E-9422-4442DC050554} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2010-08-04] (Samsung Electronics Co., Ltd.)
Task: {1BD02387-9B77-432C-B583-FFA53BCDD40F} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-05053A95\EPM.exe
Task: {1EF2FEE4-70AE-4986-9270-9EA2D915B1E6} - System32\Tasks\IdlePowerSave => C:\windows\Idle\DetectIdleTask.exe [2010-07-30] (TODO: <회사 이름>)
Task: {233E860F-77DC-48C2-8956-F335C6F22622} - System32\Tasks\{F97BD0B4-3C69-43D9-8F6D-295AD840C03A} => pcalua.exe -a "C:\Users\Frank\AppData\Local\Temp\Temporary Internet Files\Content.IE5\DWLZCYHM\blazingcolorsviz[1].exe" -d C:\Users\Frank\Desktop
Task: {398F427B-6B86-4C52-AAAA-7F071D9A63C1} - System32\Tasks\EasySpeedUpManager => C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager2.exe [2010-08-05] (Samsung Electronics)
Task: {4EF41F74-479E-449A-A0ED-031BD25A8266} - System32\Tasks\{FAB4F085-526A-482F-85C9-AB42B5E82E64} => pcalua.exe -a "C:\Users\Frank\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBNKJXW6\Silverlight.exe" -d C:\Users\Frank\Desktop
Task: {59C7BDB7-EE87-47CB-96E4-CF4A94B8ADD8} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [2011-12-20] (Samsung Electronics)
Task: {5B7E971E-71F8-4F87-A9BB-408B58E0C75D} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe [2010-08-05] (Samsung Electronics Co., Ltd.)
Task: {5DF8AFFB-100B-449A-AF4A-86EB0D0A6E07} - System32\Tasks\GlaryInitialize 3 => C:\Program Files\Glary Utilities 3\Initialize.exe [2013-09-02] (Glarysoft Ltd)
Task: {68BA8254-96BA-4DE6-81C0-9D70BB80B9BD} - System32\Tasks\advSRS5 => C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-08-11] (SEC)
Task: {95490CDD-61E5-43F7-AB98-5DC94D1708BD} - System32\Tasks\{6686E387-EDFA-43DB-8F96-601B4BE0350A} => pcalua.exe -a "C:\Program Files\LG Electronics\LG USB Modem Driver\UninstallShld.exe" -d C:\windows\system32 -c C:\Program Files\LG Electronics\LG USB Modem driver
Task: {9EBCF46C-A069-427D-96E1-A460F813D531} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-12] (Adobe Systems Incorporated)
Task: {C18F2B4D-6A61-4974-80EE-20C4A7CA2A36} - System32\Tasks\BatteryLifeExtender => C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-10-14] (Samsung Electronics. Co. Ltd.)
Task: {CAFD20F1-6B96-4AF6-B1CB-D2DC2D62516C} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-19] (SAMSUNG Electronics co., LTD.)
Task: {D59CCD62-61C3-4A55-B06A-448D2E8FD5E9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-06] (Google Inc.)
Task: {E1D85EC0-EF00-4572-A3AC-9FDBFD680F7A} - System32\Tasks\MovieColorEnhancer => C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe [2010-08-19] (Samsung Electronics Co., Ltd.)
Task: {E30C5E9E-FC9A-4186-AC44-8C24737B1641} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-06] (Google Inc.)
Task: {E915CBF1-4C09-4447-BC30-0C4460F49D9A} - System32\Tasks\SRS Premium Sound => C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel.exe [2010-10-20] (SRS Labs, Inc.)
Task: {FFB28A0E-BBCF-464C-B1E1-04EE9E5212DE} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2011-09-04] (SAMSUNG Electronics)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GlaryInitialize 3.job => C:\Program Files\Glary Utilities 3\Initialize.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2010-11-19 01:09 - 2010-07-05 05:42 - 00203776 _____ () C:\Program Files\Samsung\Movie Color Enhancer\WinCRT.dll
2011-02-05 06:42 - 2008-06-04 18:53 - 00026624 _____ () C:\windows\System32\spd__l.dll
2011-02-05 06:43 - 2010-04-20 18:45 - 00552960 _____ () C:\windows\system32\SnMinDrv.dll
2015-04-23 10:22 - 2009-02-27 15:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
2010-11-19 01:11 - 2006-08-11 22:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll
2010-11-19 01:13 - 2010-05-07 09:22 - 01636864 _____ () C:\Program Files\Samsung\Samsung Recovery Solution 5\Resdll.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:42D9E231
AlternateDataStreams: C:\ProgramData\Temp:5C270C64
AlternateDataStreams: C:\ProgramData\Temp:91EA783C
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:04 - 2009-06-10 16:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000\Control Panel\Desktop\\Wallpaper -> %windir%\web\wallpaper\windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^Users^Frank^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Frank^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: ETDCtrl => %ProgramFiles%\Elantech\ETDCtrl.exe
MSCONFIG\startupreg: HotKeysCmds => C:\windows\system32\hkcmd.exe
MSCONFIG\startupreg: IgfxTray => C:\windows\system32\igfxtray.exe
MSCONFIG\startupreg: Persistence => C:\windows\system32\igfxpers.exe
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: YMailAdvisor => "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{CD2DE1F4-251E-4E0F-8ACE-52B6EB716161}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{BFCBC590-BDB4-4E06-8301-B5A69BBD1A39}] => (Allow) LPort=2869
FirewallRules: [{B49E2138-D3EE-403E-B797-1E32780AC60F}] => (Allow) LPort=1900
FirewallRules: [{33D54809-B2BE-435D-BD1C-600E2D7094CA}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{6F502750-D6FA-4911-9DF2-287315C97284}] => (Allow) C:\Program Files\Windows Live\Mesh\MOE.exe
FirewallRules: [{948C5F2B-D5C2-41B3-98DA-4252D4802DF8}] => (Allow) C:\Windows\System32\SUPDSvc.exe
FirewallRules: [{F3DCBA70-8102-4E0E-BE3A-5E7F04EA97C5}] => (Allow) C:\Windows\System32\SUPDSvc.exe
FirewallRules: [{2BABC92C-A3C0-4620-9A85-1582EAF4FE77}] => (Allow) C:\Program Files\Samsung\Samsung Universal Scan Driver\USDAgent.exe
FirewallRules: [{EB38D767-85B7-4095-8219-8282072ADCD5}] => (Allow) C:\Program Files\Samsung\Samsung Universal Scan Driver\USDAgent.exe
FirewallRules: [{410C8BFE-25E1-4513-8399-FA5D92F9D0A4}] => (Allow) C:\Program Files\Samsung\Samsung Universal Scan Driver\ICCUpdater.exe
FirewallRules: [{BE9FB9C2-071A-4A4C-B068-EC4F008CA2F0}] => (Allow) C:\Program Files\Samsung\Samsung Universal Scan Driver\ICCUpdater.exe
FirewallRules: [{02FD264E-6861-456B-A7D5-EFFAD2704AFD}] => (Allow) C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{E1FFB0A2-F105-4A7D-B755-7056EF45513D}] => (Allow) LPort=54925
==================== Restore Points =========================
12-10-2015 18:11:42 Windows Update
16-10-2015 19:10:31 Windows Update
30-11-2015 08:52:15 Windows Update
07-12-2015 16:06:38 Windows Update
12-02-2016 14:28:50 Windows Update
14-02-2016 16:13:36 Installed Microsoft Fix it 50123
==================== Faulty Device Manager Devices =============
Name: MpKslc99076d2
Description: MpKslc99076d2
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: MpKslc99076d2
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/14/2016 09:43:11 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:11 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.
Context: Windows Application
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:11 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: The gatherer object cannot be initialized.
Context: Windows Application, SystemIndex Catalog
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:11 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in cannot be initialized.
Context: Windows Application, SystemIndex Catalog
Details:
Element not found. (HRESULT : 0x80070490) (0x80070490)
Error: (02/14/2016 09:43:10 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in cannot be initialized.
Context: Windows Application, SystemIndex Catalog
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:10 AM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: The Windows Search Service cannot load the property store information.
Context: Windows Application, SystemIndex Catalog
Details:
The content index database is corrupt. (HRESULT : 0xc0041800) (0xc0041800)
Error: (02/14/2016 09:43:10 AM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:10 AM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: The search service has detected corrupted data files in the index {id=4700}. The service will attempt to automatically correct this problem by rebuilding the index.
Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)
Error: (02/14/2016 09:43:10 AM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: The Windows Search Service cannot open the Jet property store.
Details:
0x%08x (0xc0041800 - The content index database is corrupt. (HRESULT : 0xc0041800))
Error: (02/14/2016 09:43:10 AM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (2456) Windows: Error -1811 occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00028.log.
System errors:
=============
Error: (02/14/2016 08:02:53 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
Error: (02/14/2016 08:02:50 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
cdrom
Error: (02/14/2016 08:02:29 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (02/14/2016 04:28:15 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D}
Error: (02/14/2016 02:32:54 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
cdrom
Error: (02/14/2016 02:32:33 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (02/14/2016 02:23:22 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Windows Update service did not shut down properly after receiving a preshutdown control.
Error: (02/14/2016 02:15:48 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
Error: (02/14/2016 02:15:46 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
cdrom
Error: (02/14/2016 02:15:22 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
==================== Memory info ===========================
Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz
Percentage of memory in use: 77%
Total physical RAM: 1013.3 MB
Available physical RAM: 224.14 MB
Total Virtual: 2037.3 MB
Available Virtual: 921.23 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:178.61 GB) (Free:141.42 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: C04936A2)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=178.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=13.6 GB) - (Type=27)
Partition 4: (Not Active) - (Size=40.5 GB) - (Type=27)
==================== End of Addition.txt ============================
Hello Frank,
Malware does not appear to be present on your computer. We will run through a few scans to check for malware/adware, and move onto non-malware troubleshooting should you still be experiencing an issue with slowness and Windows Update.
STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Script
- Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
- Copy the entire contents of the codebox below and paste into the Notepad document.
start CreateRestorePoint: SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> DefaultScope {EB525A7B-66CA-402B-B8DA-BB1E06E49712} URL = hxxp://search.yahoo.com/search?p={searchTerms} SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {44f44034-6036-4f06-9336-74ec4620edab} URL = SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {71EA7148-F02F-4AAB-96F9-641086FE86F0} URL = hxxp://search.yahoo.com/search?p={searchTerms}&b={startPage?}&fr=ie8 SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {EB525A7B-66CA-402B-B8DA-BB1E06E49712} URL = hxxp://search.yahoo.com/search?p={searchTerms} S1 bvojdtqc; \??\C:\windows\system32\drivers\bvojdtqc.sys [X] S1 hprykgyo; \??\C:\windows\system32\drivers\hprykgyo.sys [X] S1 ocqdvltc; \??\C:\windows\system32\drivers\ocqdvltc.sys [X] CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35200-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35201-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35202-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InprocServer32 -> no filepath Task: {233E860F-77DC-48C2-8956-F335C6F22622} - System32\Tasks\{F97BD0B4-3C69-43D9-8F6D-295AD840C03A} => pcalua.exe -a "C:\Users\Frank\AppData\Local\Temp\Temporary Internet Files\Content.IE5\DWLZCYHM\blazingcolorsviz[1].exe" -d C:\Users\Frank\Desktop Task: {4EF41F74-479E-449A-A0ED-031BD25A8266} - System32\Tasks\{FAB4F085-526A-482F-85C9-AB42B5E82E64} => pcalua.exe -a "C:\Users\Frank\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBNKJXW6\Silverlight.exe" -d C:\Users\Frank\Desktop Task: {95490CDD-61E5-43F7-AB98-5DC94D1708BD} - System32\Tasks\{6686E387-EDFA-43DB-8F96-601B4BE0350A} => pcalua.exe -a "C:\Program Files\LG Electronics\LG USB Modem Driver\UninstallShld.exe" -d C:\windows\system32 -c C:\Program Files\LG Electronics\LG USB Modem driver AlternateDataStreams: C:\ProgramData\Temp:42D9E231 AlternateDataStreams: C:\ProgramData\Temp:5C270C64 AlternateDataStreams: C:\ProgramData\Temp:91EA783C CMD: ipconfig /flushdns EmptyTemp: end - Click File, Save As and type fixlist.txt as the File Name.
- Important: The file must be saved in the same location as FRST.exe.
NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.
- Right-Click FRST.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Click Fix.
- A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.
STEP 2
[external image: E3feWj5.png] Junkware Removal Tool (JRT)
- Please download Junkware Removal Tool and save the file to your Desktop.
- Temporarily disable your anti-virus software. For instructions, please refer to the following link.
- Right-Click JRT.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Follow the prompts and allow the scan to run uninterrupted.
- Upon completion, a log (JRT.txt) will open on your desktop.
- Re-enable your anti-virus software.
- Copy the contents of JRT.txt and paste in your next reply.
STEP 3
[external image: BY4dvz9.png] AdwCleaner
- Please download AdwCleaner and save the file to your Desktop.
- Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Follow the prompts.
- Click Scan.
- Upon completion, click Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
- Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab, and click Cleaning.
- Follow the prompts and allow your computer to reboot.
- After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
– File and folder backups are made for items removed using this tool. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[S1].txt.
======================================================
STEP 4
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- Fixlog.txt
- JRT.txt
- AdwCleaner[C1].txt
Hi Adam here are the logs that you requested hope their right in the adwcleaner there were some registry entries that I let go.hope all is good thanks. Fix result of Farbar Recovery Scan Tool (x86) Version:07-02-2016
Ran by [removed] (2016-02-16 20:33:47) Run:3
Running from C:\Users\[removed]\Downloads
[removed]
Boot Mode: Normal
==============================================
fixlist content:
*****************
start
CreateRestorePoint:
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> DefaultScope {EB525A7B-66CA-402B-B8DA-BB1E06E49712} URL = hxxp://search.yahoo.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {44f44034-6036-4f06-9336-74ec4620edab} URL =
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {71EA7148-F02F-4AAB-96F9-641086FE86F0} URL = hxxp://search.yahoo.com/search?p={searchTerms}&b={startPage?}&fr=ie8
SearchScopes: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000 -> {EB525A7B-66CA-402B-B8DA-BB1E06E49712} URL = hxxp://search.yahoo.com/search?p={searchTerms}
S1 bvojdtqc; \??\C:\windows\system32\drivers\bvojdtqc.sys [X]
S1 hprykgyo; \??\C:\windows\system32\drivers\hprykgyo.sys [X]
S1 ocqdvltc; \??\C:\windows\system32\drivers\ocqdvltc.sys [X]
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35200-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35201-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35202-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InprocServer32 -> no filepath
Task: {233E860F-77DC-48C2-8956-F335C6F22622} - System32\Tasks\{F97BD0B4-3C69-43D9-8F6D-295AD840C03A} => pcalua.exe -a "C:\Users\Frank\AppData\Local\Temp\Temporary Internet Files\Content.IE5\DWLZCYHM\blazingcolorsviz[1].exe" -d C:\Users\Frank\Desktop
Task: {4EF41F74-479E-449A-A0ED-031BD25A8266} - System32\Tasks\{FAB4F085-526A-482F-85C9-AB42B5E82E64} => pcalua.exe -a "C:\Users\Frank\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBNKJXW6\Silverlight.exe" -d C:\Users\Frank\Desktop
Task: {95490CDD-61E5-43F7-AB98-5DC94D1708BD} - System32\Tasks\{6686E387-EDFA-43DB-8F96-601B4BE0350A} => pcalua.exe -a "C:\Program Files\LG Electronics\LG USB Modem Driver\UninstallShld.exe" -d C:\windows\system32 -c C:\Program Files\LG Electronics\LG USB Modem driver
AlternateDataStreams: C:\ProgramData\Temp:42D9E231
AlternateDataStreams: C:\ProgramData\Temp:5C270C64
AlternateDataStreams: C:\ProgramData\Temp:91EA783C
CMD: ipconfig /flushdns
EmptyTemp:
end
*****************
Restore point was successfully created.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => key not found.
HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => key not found.
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{44f44034-6036-4f06-9336-74ec4620edab} => key not found.
HKCR\CLSID\{44f44034-6036-4f06-9336-74ec4620edab} => key not found.
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => key not found.
HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => key not found.
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{71EA7148-F02F-4AAB-96F9-641086FE86F0} => key not found.
HKCR\CLSID\{71EA7148-F02F-4AAB-96F9-641086FE86F0} => key not found.
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EB525A7B-66CA-402B-B8DA-BB1E06E49712} => key not found.
HKCR\CLSID\{EB525A7B-66CA-402B-B8DA-BB1E06E49712} => key not found.
bvojdtqc => service not found.
hprykgyo => service not found.
ocqdvltc => service not found.
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35200-8F91-11CE-9DE3-00AA004BB851} => key not found.
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35201-8F91-11CE-9DE3-00AA004BB851} => key not found.
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{0BE35202-8F91-11CE-9DE3-00AA004BB851} => key not found.
HKU\S-1-5-21-2118264723-1652648626-4119575669-1000_Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{233E860F-77DC-48C2-8956-F335C6F22622} => key not found.
C:\Windows\System32\Tasks\{F97BD0B4-3C69-43D9-8F6D-295AD840C03A} => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F97BD0B4-3C69-43D9-8F6D-295AD840C03A} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4EF41F74-479E-449A-A0ED-031BD25A8266} => key not found.
C:\Windows\System32\Tasks\{FAB4F085-526A-482F-85C9-AB42B5E82E64} => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FAB4F085-526A-482F-85C9-AB42B5E82E64} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95490CDD-61E5-43F7-AB98-5DC94D1708BD} => key not found.
C:\Windows\System32\Tasks\{6686E387-EDFA-43DB-8F96-601B4BE0350A} => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6686E387-EDFA-43DB-8F96-601B4BE0350A} => key not found.
"C:\ProgramData\Temp" => ":42D9E231" ADS not found.
"C:\ProgramData\Temp" => ":5C270C64" ADS not found.
"C:\ProgramData\Temp" => ":91EA783C" ADS not found.
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
EmptyTemp: => 7 MB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 20:35:51 ====
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.2 (01.06.2016)
Operating System: Windows 7 Starter x86
Ran by [removed] (Administrator) on Tue 02/16/2016 at 21:03:55.59
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 28
Failed to delete: C:\ProgramData\gametap web player (Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{16113B83-F2A0-42F4-8C17-27E01C5598B3} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{19BAC956-6284-4007-B604-013B05504898} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{37CD34F7-7EFB-43C3-8C53-EEB5CA315047} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{39CABA4A-0D15-4785-A3FF-0CA11C683D2E} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{48E71286-CC20-41C6-8A50-EED5821D12B2} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{7E27624D-C38F-42EB-A9C9-C380B11C5352} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{7FA711A0-FD90-4414-B2D0-BD27A448BA36} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{80F185B3-139C-416C-AF82-1153A76B617D} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{A7086874-0155-47F4-91F7-9C0D62687732} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{A99AC739-A4E4-4673-AAD0-9C2773FE18B4} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{B07436E8-1101-4FDF-943B-7A2585B67A9B} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{B78C82F0-6F59-41AF-9A23-85005C6A3343} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{BF965855-54A0-4CD7-B0B0-0F80DABC4522} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{C94BC0AA-7DEF-4BDB-8296-A87C026FEC68} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{D178FC93-1761-48D7-87BA-F57ADAF0FF91} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{DA3FA42E-61BD-46F8-986E-52F42E8D91C5} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{DF0692C0-5D16-45EC-A97B-69C7ADA3F3FC} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{E29CFAB4-C5B9-4DC8-A9DC-9DDDA7FA04CB} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{E43EF57A-B97A-49A7-8292-8FF0AC74D1C9} (Empty Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\{F398F1C0-F12D-4D00-BD23-8CF1275BECD6} (Empty Folder)
Successfully deleted: C:\Users\Frank\Appdata\LocalLow\yahoocouponaddon (Folder)
Successfully deleted: C:\windows\System32\Tasks\EasySpeedUpManager (Task)
Successfully deleted: C:\windows\wininit.ini (File)
Successfully deleted: C:\Users\Frank\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8FHC8YOK (Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KWVHMHQY (Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L6OUCI54 (Folder)
Successfully deleted: C:\Users\Frank\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N2G9HJG9 (Folder)
Registry: 1
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\YahooAUService (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 02/16/2016 at 21:08:14.76
End of JRT log
# AdwCleaner v5.034 - Logfile created 16/02/2016 at 21:35:57
# Updated 16/02/2016 by Xplode
# Database : 2016-02-16.2 [Server]
# Operating system : Windows 7 Starter Service Pack 1 (x86)
# Username : Frank - FRANK-PC
# Running from : C:\Users\Frank\Downloads\2-16-16 computer repair\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
[-] Service Deleted : YahooAUService
***** [ Folders ] *****
[-] Folder Deleted : C:\ProgramData\GameTap Web Player
***** [ Files ] *****
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKCU\Software\5855dcd8b535ec48
[-] Key Deleted : HKLM\SOFTWARE\5855dcd8b535ec48
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{20E1481B-E285-4ABC-ADC7-AE24842B81CD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0194532A-A99C-4337-937E-2A452C8957BE}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92E5039E-FF1E-4AFB-8F24-87592D20C383}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDMI
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\HDMI
***** [ Web browsers ] *****
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1680 bytes] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Hello Frank,
Those logs look OK. Please run the following scans.
STEP 1
[external image: GfiJrQ9.png] Malwarebytes Anti-Malware (MBAM)
- Open Malwarebytes Anti-Malware and click Update Now.
- Once updated, click the Settings tab, followed by Detection and Protection and tick Scan for rootkits.
- Click the Scan tab, ensure Threat Scan is selected and click Start Scan.
- Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
- If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
- Upon completion of the scan (or after the reboot), click the History tab.
- Click Application Logs and double-click the Scan Log.
- Click Copy to Clipboard and paste the log in your next reply.
STEP 2
[external image: GzlsbnV.png] ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.
- Please download ESET Online Scan and save the file to your Desktop.
- Temporarily disable your anti-virus software. For instructions, please refer to the following link.
- Double-click esetsmartinstaller_enu.exe to run the programme.
- Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
- Agree to the Terms of Use once more and click Start. Allow components to download.
- Place a checkmark next to Enable detection of potentially unwanted applications.
- Click Advanced settings. Place a checkmark next to:
- Scan archives
- Scan for potentially unsafe applications
- Enable Anti-Stealth technology
- Ensure Remove found threats is unchecked.
- Click Start.
- Wait for the scan to finish. Please be patient as this can take some time.
- Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points.
- Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
- Push the Back button.
- Place a checkmark next to [external image: KN1w2nv.png] and click [external image: SzOC1p0.png].
- Re-enable your anti-virus software.
- Copy the contents of the log and paste in your next reply.
======================================================
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- MBAM Scan log
- ESET Online Scan log
Hi Adam, Here is the mbam log im running the ESET scan now
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2/17/2016
Scan Time: 10:06 AM
Logfile:
Administrator: Yes
Version: 2.2.0.1024
Malware Database: v2016.02.17.03
Rootkit Database: v2016.02.08.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Frank
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 321558
Time Elapsed: 47 min, 59 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
Here is the mbam log im running the ESET scan now
![]()
Hi Adam , Here is the ESET scan log. C:\Users\Frank\AppData\LocalLow\Sun\Java\jre1.7.0_17\java_sp.dll a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\Users\Frank\AppData\LocalLow\Sun\Java\jre1.7.0_65\java_sp.dll a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application
C:\Users\Frank\Downloads\ashampoo_photo_commander_8_8.4.0_8416.exe a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\Users\Frank\Downloads\fairylake.exe a variant of Win32/Toolbar.Babylon.A potentially unwanted application
C:\Users\Frank\Downloads\siw.exe a variant of Win32/RemoteAdmin.RemoteExec.AA potentially unsafe application
Hello Frank,
The following files have been flagged by ESET because they bundle other third-party software considered potentially unwanted. We will be dealing with Java shortly - as for the other two files in bold, it's your choice as to whether or not you wish to delete. They are not of concern, but you may still wish to delete.
C:\Users\Frank\AppData\LocalLow\Sun\Java\jre1.7.0_17\java_sp.dll a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\Users\Frank\AppData\LocalLow\Sun\Java\jre1.7.0_65\java_sp.dll a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application
C:\Users\Frank\Downloads\ashampoo_photo_commander_8_8.4.0_8416.exe a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\Users\Frank\Downloads\fairylake.exe a variant of Win32/Toolbar.Babylon.A potentially unwanted application
Did you download the file below?
C:\Users\Frank\Downloads\siw.exe a variant of Win32/RemoteAdmin.RemoteExec.AA potentially unsafe application
We need to update your outdated software. Please let me know if the issues described in your first post (slowness and Windows Update issues) are consistent with the state of your computer now.
STEP 1
[external image: CXrghb6.png] Update Outdated Software
Outdated software contain vulnerabilities that must be patched. Please download and install the latest version of the programme(s) below.
- [external image: j8JVMVP.jpg] Java (watch out for "Optional Offers" or bundled software)
STEP 2
[external image: EtQetiM.png] Remove Outdated Software
- Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
- Search for the following programme(s), right-click and click Uninstall one at a time.
- Note: The programme(s) below may not be present. If this is the case, please skip to the next step.
- Java 8 Update 51
- Java 8 Update 60
- Follow the prompts, and reboot if necessary.
STEP 3
[external image: zANS9oB.png] Disable Java in Your Browser
Due to frequent exploits involving Java vulnerabilities we recommend you disable Java in your browser.
For information on Java exploits vulnerabilities, please read the following article (point #7).
- Click the [external image: 29Fou9c.jpg] Windows Start Button and type Java Control Panel (or javacpl) in the search bar.
- Click on the Java Control Panel. Once opened, click the Security tab.
- Deselect the check box for Enable Java content in the browser. This will disable the Java plug-in in the browser.
- Click Apply. When the [external image: AVOiBNU.jpg] Windows User Account Control (UAC) appears, allow permissions to make the changes.
- Click OK in the Java Plug-in confirmation window.
- Restart your browser(s) for changes to take effect.
- More information can be found here and here.
======================================================
STEP 4
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- Did your programme(s) update successfully?
- What is the state of your computer?
Hi Adam, I did download siw.exe. I uninstalled it today and I also deleted fairylake screen saver and ashampoo photo commander. I did update JAVA and verified it. I also removed Java 8 Update 51 and Java Update 60. I also disabled Java in my Browser. I still cannot get any Microsoft updates. The computer itself seems to run a little better. And I did notice in task manager that one prosessor – svchost.exe is eating up 50% CUP constantly.
Hi Frank,
I still cannot get any Microsoft updates. The computer itself seems to run a little better. And I did notice in task manager that one prosessor – svchost.exe is eating up 50% CUP constantly.
Let's start with Windows Update. Please do the following:
[external image: MgeHyNE.png] SFC /Scannow
- Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
- Copy the bold lines below and paste into the Notepad document:
sfc /scannow
timeout /t 120 /nobreak
copy %windir%\logs\cbs\cbs.log "%userprofile%\desktop\CBS.txt"
del %0
- Click Format. Ensure Wordwrap is unchecked.
- Click File, Save As and name the file sfcscannow.bat.
- Select All Files as the Save as type. Save the file to your Desktop.
- Locate sfcscannow.bat [external image: lmRDSkT.png] on your Desktop. Right-click the file and click [external image: AVOiBNU.jpg] Run as administrator.
- Upon completion, a file (CBS.txt) will be created on your Desktop. Attach this file in your next reply.
- Note: If the file is too large to attach, upload to a service such as Dropbox, One Drive or SendSpace and provide a direct download link in your next reply.
HiAdam don't know if this is right. I did the scan and tried to paste it here but it didn't work so I tried dropbox hope it worked. https://www.dropbox.com/s/cyc0lk911tk2dnx/CBS.txt?dl=0
Hello Frank,
Yes, that's fine. Please do the following:
[external image: bMTzsQ3.png] SFCFix Script (.txt)
Warning: This fix is intended for use on this particular machine. Do not use this fix on any other machine; doing so may cause damage to your Operating System. If you are not the original poster and require assistance, please start your own topic.
- Please download SFCFix and save the file to your Desktop.
- Download SFCScript.txt and save this file to your Desktop.
- Close all open windows.
- SFCFix.exe [external image: bMTzsQ3.png] and SFCScript.txt [external image: aI1XLKB.png] should both be present on your Desktop.
- Drag the file SFCScript.txt onto the file SFCFix.exe and release it.
- SFCFix will now process the script. Upon completion, a file (SFCFix.txt) will be created on your Desktop.
- Copy the contents of the file and paste in your next reply.
Hi Adam, I ran it and it asked for the windows installation cd, this net book did not come with one. Here is the SFCFix.txt log
SFCFix version 2.4.9.2 by niemiro.
Start time: 2016-02-20 12:05:27.736
Microsoft Windows 7 Service Pack 1 - x86
Not using a script file.
PowerCopy::
FIXED: Corruption at C:\windows\winsxs\x86_microsoft-windows-font-truetype-segoeui_31bf3856ad364e35_6.1.7601.18528_none_d2bc881870836261\seguisym.ttf has been successfully repaired from C:\Windows\winsxs\x86_microsoft-windows-font-truetype-segoeui_31bf3856ad364e35_6.1.7601.22045_none_d32d78c989b3ff1e\seguisym.ttf.
The file \\?\C:\windows\winsxs\x86_microsoft-windows-wmi-core-fastprox-dll_31bf3856ad364e35_6.1.7601.17514_none_fd50bd45d7febcf3\fastprox.dll is in use and must be replaced over a reboot.
The file \\?\C:\windows\winsxs\x86_microsoft-windows-wmi-core-wbemcore-dll_31bf3856ad364e35_6.1.7601.17514_none_e3c71ccf3513c780\wbemcore.dll is in use and must be replaced over a reboot.
Successfully pended file for replace over reboot: \\?\C:\windows\winsxs\x86_microsoft-windows-wmi-core-fastprox-dll_31bf3856ad364e35_6.1.7601.17514_none_fd50bd45d7febcf3\fastprox.dll
Successfully pended file for replace over reboot: \\?\C:\windows\winsxs\x86_microsoft-windows-wmi-core-wbemcore-dll_31bf3856ad364e35_6.1.7601.17514_none_e3c71ccf3513c780\wbemcore.dll
PowerCopy:: directive completed successfully.
Reboot:: directive completed successfully.
PostRebootCorruptionDetection::
No hash verification failures detected.
PostRebootCorruptionDetection:: directive completed successfully.
PostRebootRestorePermissions::
Successfully restored ownership for C:\windows\winsxs\x86_microsoft-windows-wmi-core-fastprox-dll_31bf3856ad364e35_6.1.7601.17514_none_fd50bd45d7febcf3\fastprox.dll
Successfully restored permissions on C:\windows\winsxs\x86_microsoft-windows-wmi-core-fastprox-dll_31bf3856ad364e35_6.1.7601.17514_none_fd50bd45d7febcf3\fastprox.dll
Successfully restored ownership for C:\windows\winsxs\x86_microsoft-windows-wmi-core-wbemcore-dll_31bf3856ad364e35_6.1.7601.17514_none_e3c71ccf3513c780\wbemcore.dll
Successfully restored permissions on C:\windows\winsxs\x86_microsoft-windows-wmi-core-wbemcore-dll_31bf3856ad364e35_6.1.7601.17514_none_e3c71ccf3513c780\wbemcore.dll
PostRebootRestorePermissions:: directive completed successfully.
Successfully processed all directives.
SFCFix version 2.4.9.2 by niemiro has completed.
Currently storing 3 datablocks.
Finish time: 2016-02-20 12:15:09.309
———————-EOF———————–
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI