This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CPU running at 100% with nothing open [Solved]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thank you in advance for your help!
 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2014-12-17 00:49:05
—————————–
00:49:05.611    OS Version: Windows x64 6.1.7601 Service Pack 1
00:49:05.626    Number of processors: 2 586 0x170A
00:49:05.626    ComputerName: PAMELA-PC  UserName: Pamela
00:49:08.876    Initialize success
00:49:08.970    VM: initialized successfully
00:49:08.970    VM: Intel CPU supported 
00:49:16.138    VM: supported disk I/O iaStor.sys
00:50:36.225    AVAST engine defs: 14121602
00:51:12.530    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
00:51:12.530    Disk 0 Vendor: WDC_WD10 01.0 Size: 953869MB BusType: 8
00:51:12.670    VM: Disk 0 MBR read successfully
00:51:12.670    Disk 0 MBR scan
00:51:12.686    Disk 0 Windows 7 default MBR code
00:51:12.686    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        15360 MB offset 2048
00:51:12.717    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 31459328
00:51:12.717    Disk 0 Boot: NTFS     code=1
00:51:12.733    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       938407 MB offset 31664128
00:51:12.764    Disk 0 scanning C:\Windows\system32\drivers
00:51:22.159    Service scanning
00:51:43.217    Modules scanning
00:51:43.217    Disk 0 trace - called modules:
00:51:43.233    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
00:51:43.249    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80063ee060]
00:51:43.249    3 CLASSPNP.SYS[fffff880013c543f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8005ed6050]
00:51:45.121    AVAST engine scan C:\Windows
00:51:48.397    AVAST engine scan C:\Windows\system32
00:55:56.803    AVAST engine scan C:\Windows\system32\drivers
00:56:08.212    AVAST engine scan C:\Users\Pamela
01:01:00.883    File: C:\Users\Pamela\Desktop\OTL.exe  **INFECTED** Win32:Malware-gen
01:01:39.364    AVAST engine scan C:\ProgramData
01:11:45.232    Disk 0 statistics 4477582/0/22 @ 2.78 MB/s
01:11:45.248    Scan finished successfully
01:13:57.776    Disk 0 MBR has been saved successfully to "C:\Users\Pamela\Desktop\MBR.dat"
01:13:57.776    The log file has been saved successfully to "C:\Users\Pamela\Desktop\aswMBR.txt"
 
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-04-14 17:11:08
—————————–
17:11:08.212    OS Version: Windows x64 6.1.7601 Service Pack 1
17:11:08.212    Number of processors: 2 586 0x170A
17:11:08.213    ComputerName: PAMELA-PC  UserName: Pamela
17:11:09.915    Initialize success
17:11:10.043    VM: initialized successfully
17:11:10.043    VM: Intel CPU supported 
17:11:16.867    VM: supported disk I/O iaStor.sys
17:12:31.549    AVAST engine defs: 16033102
17:12:45.152    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
17:12:45.152    Disk 0 Vendor: WDC_WD10 01.0 Size: 953869MB BusType: 8
17:12:45.261    VM: Disk 0 MBR read successfully
17:12:45.261    Disk 0 MBR scan
17:12:45.261    Disk 0 Windows 7 default MBR code
17:12:45.261    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        15360 MB offset 2048
17:12:45.294    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 31459328
17:12:45.298    Disk 0 Boot: NTFS     code=1
17:12:45.316    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       938407 MB offset 31664128
17:12:45.329    Disk 0 scanning C:\Windows\system32\drivers
17:12:54.873    Service scanning
17:13:17.713    Modules scanning
17:13:17.713    Disk 0 trace - called modules:
17:13:17.729    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
17:13:17.745    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007041700]
17:13:17.745    3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006ad1050]
17:13:20.240    AVAST engine scan C:\Windows
17:13:24.696    AVAST engine scan C:\Windows\system32
17:19:50.194    AVAST engine scan C:\Windows\system32\drivers
17:20:33.033    AVAST engine scan C:\Users\Pamela
17:28:57.243    File: C:\Users\Pamela\Desktop\OTL.exe  **INFECTED** Win32:Malware-gen
17:30:14.734    AVAST engine scan C:\ProgramData
17:41:24.401    Disk 0 statistics 4534681/0/22 @ 1.78 MB/s
17:41:24.417    Scan finished successfully
17:50:47.325    Disk 0 MBR has been saved successfully to "C:\Users\Pamela\Desktop\MBR.dat"
17:50:47.331    The log file has been saved successfully to "C:\Users\Pamela\Desktop\aswMBR.txt"
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-04-2016
Ran by [removed] (administrator) on PAMELA-PC (14-04-2016 17:53:06)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
(Acer Incorporated) C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
(Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\pcCMService.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\pcCMService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
(Acer) C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
(IOI) C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
() C:\Program Files (x86)\Lavasoft\Ad-Aware\AWSC.exe
() C:\Program Files (x86)\Lavasoft\Ad-Aware\AWSC.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Google Inc.) C:\Users\Pamela\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Pamela\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Pamela\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Pamela\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Pamela\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Pamela\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Pamela\AppData\Local\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7981088 2009-07-20] (Realtek Semiconductor)
HKLM\…\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2399632 2011-04-13] (Microsoft Corporation)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-03-19] (Apple Inc.)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe [244480 2009-08-12] (NewTech Infosystems, Inc.)
HKLM-x32\…\Run: [Gateway Photo Frame] => C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe [124416 2009-07-20] (IOI)
HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [186640 2016-03-23] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4431848 2015-12-15] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\MountPoints2: {07bea468-a41f-11df-9111-002511a28efb} - L:\WIN\setup.exe
HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\Winlogon: [Shell] explorer.exe, <==== ATTENTION
HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Gateway.scr [425984 2009-08-05] ()
HKU\S-1-5-18\…\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-03-21] (Microsoft Corporation)
BootExecute: autocheck autochk * lsdelete
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{01D851AE-190A-4595-8EFF-F4DCC3500623}: [DhcpNameServer] [removed] [removed] [removed]
Tcpip\..\Interfaces\{EA8713C9-52CC-42DD-A388-B7B0CCC5398B}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l;=0409&m;=dx4822&r;=173611096206p03c5v195k4891r225
HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l;=0409&m;=dx4822&r;=173611096206p03c5v195k4891r225
HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM-x32 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACGW
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACGW
SearchScopes: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACGW_enUS355
SearchScopes: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACGW_enUS355
SearchScopes: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001 -> {B6C00F51-0364-456B-BD0D-C160848A05DD} URL = hxxp://search.avg.com/?d=4db7dba8&i;=23&tp;=chrome&q;={searchTerms}&lng;={language}&nt;=1
BHO: No Name -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> No File
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-23] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-20] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-23] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-20] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-23] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-23] (Google Inc.)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
 
FireFox:
========
FF ProfilePath: C:\Users\Pamela\AppData\Roaming\Mozilla\Firefox\Profiles\ep3lnpa9.default
FF SelectedSearchEngine: AVG Secure Search
FF Keyword.URL: hxxp://ws.infospace.com/coolchaser_game/ws/redir?_iceUrl=true&user;_id=35278845&tool;_id=60531&qkw;=
FF NetworkProxy: "backup.ftp", "110.139.181.133"
FF NetworkProxy: "backup.ftp_port", 3128
FF NetworkProxy: "backup.gopher", "110.139.181.133"
FF NetworkProxy: "backup.gopher_port", 3128
FF NetworkProxy: "backup.socks", "110.139.181.133"
FF NetworkProxy: "backup.socks_port", 3128
FF NetworkProxy: "backup.ssl", "110.139.181.133"
FF NetworkProxy: "backup.ssl_port", 3128
FF NetworkProxy: "ftp", "110.136.177.96"
FF NetworkProxy: "ftp_port", 8080
FF NetworkProxy: "gopher", "110.136.177.96"
FF NetworkProxy: "gopher_port", 8080
FF NetworkProxy: "http", "110.136.177.96"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "110.136.177.96"
FF NetworkProxy: "socks_port", 8080
FF NetworkProxy: "ssl", "110.136.177.96"
FF NetworkProxy: "ssl_port", 8080
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-09] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-09] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-08-26] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Windows\SysWOW64\npdeployJava1.dll [2015-01-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-20] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-1608746659-3683959345-3987556120-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Pamela\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2013-11-25] (Citrix Online)
FF Plugin HKU\S-1-5-21-1608746659-3683959345-3987556120-1001: @facebook.com/FBPlugin,version=1.0.3 -> C:\Users\Pamela\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll [2010-03-06] ( )
FF Plugin HKU\S-1-5-21-1608746659-3683959345-3987556120-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Pamela\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin HKU\S-1-5-21-1608746659-3683959345-3987556120-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Pamela\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Extension: CSS Reloader - C:\Users\Pamela\AppData\Roaming\Mozilla\Firefox\Profiles\ep3lnpa9.default\Extensions\[removed] [2015-06-19]
FF Extension: ReloadEvery - C:\Users\Pamela\AppData\Roaming\Mozilla\Firefox\Profiles\ep3lnpa9.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2015-06-19]
FF Extension: Gamers Unite! Snag Bar - C:\Users\Pamela\AppData\Roaming\Mozilla\Firefox\Profiles\ep3lnpa9.default\Extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}.xpi [2015-06-19] [not signed]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-07-23] [not signed]
FF HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\Firefox\Extensions: [{5B6AD909-3594-4277-B593-2F1B694BFB34}] - C:\Users\Pamela\AppData\Local\{5B6AD909-3594-4277-B593-2F1B694BFB34}
FF Extension: XULRunner - C:\Users\Pamela\AppData\Local\{5B6AD909-3594-4277-B593-2F1B694BFB34} [2010-12-08] [not signed]
 
Chrome: 
=======
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.7.796\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.7.771\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Users\Pamela\AppData\Local\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll ()
CHR Profile: C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-10]
CHR Extension: (Google Drive) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-27]
CHR Extension: (Google Search) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-02]
CHR Extension: (Google Docs Offline) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]
CHR Extension: (AdBlock) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-20]
CHR Extension: (Pin It Button) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-09-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04]
CHR Extension: (Gmail) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-08]
CHR HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Pamela\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-10-05]
StartMenuInternet: Google Chrome - C:\Users\Pamela\AppData\Local\Google\Chrome\Application\chrome.exe
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4948456 2015-10-06] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1074448 2016-03-23] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-11-20] (AVG Technologies CZ, s.r.o.)
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [5750440 2015-09-04] (Fitbit, Inc.)
R2 Lavasoft Ad-Aware Service; C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2152152 2011-10-29] (Lavasoft Limited)
R2 pcCMService; C:\Program Files (x86)\Common Files\Motive\pcCMService.exe [361472 2012-06-18] (Alcatel-Lucent) [File not signed]
R2 pcCMService64; C:\Program Files\Common Files\Motive\pcCMService.exe [441344 2012-06-18] (Alcatel-Lucent) [File not signed]
S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [158160 2015-05-21] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [209720 2014-11-04] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360400 2015-05-21] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [204704 2015-07-03] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-10-23] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [249296 2015-05-26] (AVG Technologies CZ, s.r.o.)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 Lavasoft Kernexplorer; \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [17152 2011-10-01] ()
R0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [69376 2011-08-18] (Lavasoft AB)
S3 swmsflt; C:\Windows\System32\drivers\swmsflt.sys [30088 2008-08-22] ()
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 VX6000; C:\Windows\System32\DRIVERS\VX6000Xp.sys [2143600 2009-06-30] (Microsoft Corporation
)
S3 MREMP50; \??\C:\PROGRA~2\COMMON~1\Motive\MREMP50.SYS [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MRESP50; \??\C:\PROGRA~2\COMMON~1\Motive\MRESP50.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
S0 nwmt; System32\drivers\jyst.sys [X]
S3 PCTINDIS5X64; \??\C:\Windows\system32\PCTINDIS5X64.SYS [X]
U3 aswMBR; \??\C:\Users\Pamela\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Pamela\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-04-14 17:53 - 2016-04-14 17:53 - 00021842 _____ C:\Users\Pamela\Desktop\FRST.txt
2016-04-14 17:52 - 2016-04-14 17:53 - 00000000 ____D C:\FRST
2016-04-14 17:52 - 2016-04-14 17:52 - 02375168 _____ (Farbar) C:\Users\Pamela\Desktop\FRST64.exe
2016-04-14 17:10 - 2016-04-14 17:10 - 05198336 _____ (AVAST Software) C:\Users\Pamela\Desktop\aswMBR.exe
2016-04-11 01:14 - 2016-04-11 01:14 - 00007602 _____ C:\Users\Pamela\AppData\Local\Resmon.ResmonCfg
2016-04-10 12:21 - 2016-04-10 12:21 - 00001760 _____ C:\Users\Public\Desktop\iTunes.lnk
2016-04-10 12:21 - 2016-04-10 12:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-04-10 12:21 - 2016-04-10 12:21 - 00000000 ____D C:\Program Files\iTunes
2016-04-10 12:21 - 2016-04-10 12:21 - 00000000 ____D C:\Program Files\iPod
2016-04-10 12:21 - 2016-04-10 12:21 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-04-10 12:18 - 2016-04-10 12:18 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2016-04-10 12:18 - 2016-04-10 12:18 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-04-09 15:24 - 2016-04-09 15:24 - 05934784 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2016-04-08 19:56 - 2016-04-08 19:56 - 00000000 __SHD C:\found.000
2016-04-08 00:34 - 2016-04-08 00:35 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-04-08 00:34 - 2016-04-08 00:34 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-04-08 00:34 - 2016-04-08 00:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-04-08 00:34 - 2016-04-08 00:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-04-08 00:34 - 2016-04-08 00:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-04-08 00:34 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-04-08 00:34 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-04-08 00:34 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-04-08 00:33 - 2016-04-08 00:33 - 22851472 _____ (Malwarebytes ) C:\Users\Pamela\Documents\mbam-setup-2.2.1.1043.exe
2016-03-23 03:10 - 2016-03-23 03:10 - 00000000 ____D C:\Users\Pamela\AppData\Local\{66D93A45-7283-4904-8236-1C69A998DFAD}
2016-03-23 03:04 - 2016-03-23 03:06 - 00158676 _____ C:\Windows\ntbtlog.txt
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-04-14 17:50 - 2014-12-17 02:13 - 00004500 _____ C:\Users\Pamela\Desktop\aswMBR.txt
2016-04-14 17:50 - 2014-12-17 02:13 - 00000512 _____ C:\Users\Pamela\Desktop\MBR.dat
2016-04-14 17:22 - 2012-08-03 23:48 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-14 17:17 - 2010-02-05 03:36 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-14 17:04 - 2010-10-29 21:57 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1608746659-3683959345-3987556120-1001UA.job
2016-04-14 16:53 - 2009-07-13 23:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-14 16:53 - 2009-07-13 23:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-14 08:05 - 2015-04-05 03:00 - 00000000 ___SD C:\Windows\system32\GWX
2016-04-14 08:02 - 2009-07-14 00:13 - 00782510 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-14 08:02 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf
2016-04-14 08:00 - 2011-04-23 10:55 - 00000000 ____D C:\ProgramData\MFAData
2016-04-14 07:57 - 2010-10-20 20:29 - 00003622 _____ C:\Windows\System32\Tasks\Ad-Aware Update (Weekly)
2016-04-14 07:55 - 2010-02-05 03:36 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-14 07:54 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-12 23:40 - 2010-10-29 21:57 - 00000860 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1608746659-3683959345-3987556120-1001Core.job
2016-04-11 15:13 - 2010-10-29 21:58 - 00002390 _____ C:\Users\Pamela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-11 15:13 - 2010-10-29 21:58 - 00002382 _____ C:\Users\Pamela\Desktop\Google Chrome.lnk
2016-04-10 12:21 - 2010-01-25 22:26 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-04-10 12:18 - 2010-01-25 22:26 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-04-09 15:24 - 2012-08-03 23:48 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-09 15:24 - 2012-08-03 23:48 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-09 15:24 - 2012-08-03 23:48 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-04-08 19:45 - 2009-07-14 02:45 - 00000000 ____D C:\Windows\ShellNew
2016-04-08 18:39 - 2014-07-27 11:03 - 00003424 _____ C:\Windows\System32\Tasks\Apple Diagnostics
2016-04-07 21:44 - 2015-11-11 10:22 - 00000862 _____ C:\Users\Public\Desktop\AVG.lnk
2016-04-07 21:44 - 2015-11-11 10:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2016-03-23 03:16 - 2010-07-05 01:35 - 00000000 ____D C:\Users\Pamela\AppData\Local\ElevatedDiagnostics
2016-03-23 03:10 - 2015-08-25 22:51 - 00000000 ___RD C:\Users\Pamela\iCloudDrive
2016-03-23 03:09 - 2009-11-29 00:21 - 00000000 ____D C:\Users\Pamela\Tracing
2016-03-23 03:05 - 2011-04-27 03:18 - 00000064 _____ C:\Windows\SysWOW64\rp_stats.dat
2016-03-23 03:05 - 2011-04-27 03:18 - 00000044 _____ C:\Windows\SysWOW64\rp_rules.dat
 
==================== Files in the root of some directories =======
 
2009-12-02 21:19 - 2015-07-26 01:18 - 0000470 _____ () C:\Users\Pamela\AppData\Roaming\wklnhst.dat
2011-12-11 17:10 - 2011-12-11 17:10 - 0001260 ___SH () C:\Users\Pamela\AppData\Local\5o42hc3l58u034
2010-12-08 20:38 - 2010-12-08 20:38 - 0000000 _____ () C:\Users\Pamela\AppData\Local\Jgohanedev.bin
2010-12-08 20:38 - 2010-12-08 20:38 - 0000120 _____ () C:\Users\Pamela\AppData\Local\Mbezivewavadej.dat
2011-12-09 19:50 - 2011-12-09 19:50 - 0001252 ___SH () C:\Users\Pamela\AppData\Local\nlxrgy8n4nqv0odc4cjr8n562o1a
2016-04-11 01:14 - 2016-04-11 01:14 - 0007602 _____ () C:\Users\Pamela\AppData\Local\Resmon.ResmonCfg
2011-12-11 17:10 - 2011-12-11 17:10 - 0001260 ___SH () C:\ProgramData\5o42hc3l58u034
2009-12-08 01:08 - 2009-12-08 01:08 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2011-12-09 19:50 - 2011-12-09 19:50 - 0001252 ___SH () C:\ProgramData\nlxrgy8n4nqv0odc4cjr8n562o1a
 
Some files in TEMP:
====================
C:\Users\Pamela\AppData\Local\Temp\avguirn_081764340859.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-04-08 09:40
 
==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:13-04-2016
Ran by [removed] (2016-04-14 17:53:50)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2009-11-29 04:35:25)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1608746659-3683959345-3987556120-500 - Administrator - Disabled)
Guest (S-1-5-21-1608746659-3683959345-3987556120-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1608746659-3683959345-3987556120-1002 - Limited - Enabled)
Pamela (S-1-5-21-1608746659-3683959345-3987556120-1001 - Administrator - Enabled) => C:\Users\Pamela
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Lavasoft Ad-Watch Live! Anti-Virus (Disabled - Up to date) {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: AVG Anti-Virus Free Edition 2012 (Enabled - Up to date) {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AS: AVG Anti-Virus Free Edition 2012 (Enabled - Up to date) {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Lavasoft Ad-Watch Live! (Disabled - Up to date) {24938260-56EE-C1E5-047B-DC2BDD234BAB}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Ad-Aware (HKLM-x32\…\{385DD1DD-65AA-408D-8E70-74601C2DB7E6}) (Version: 9.5.0 - Lavasoft Limited)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Flash Player 10 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 10.0.22.87 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.2 MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.2.0 - Adobe Systems Incorporated)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{2937FD88-C9D6-4B82-B539-37CD0A572F42}) (Version: 4.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
AVG (HKLM\…\AvgZen) (Version: 1.51.2.3593 - AVG Technologies)
AVG 2013 (HKLM\…\AVG) (Version: 2013.0.3553 - AVG Technologies)
AVG 2013 (Version: 13.0.3553 - AVG Technologies) Hidden
AVG 2013 (Version: 13.0.4477 - AVG Technologies) Hidden
AVG Zen (Version: 1.51.58 - AVG Technologies) Hidden
Backup Manager Advance (x32 Version: 2.0.2.19 - NewTech Infosystems) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 3.11 - Piriform)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Driver Installer (HKLM\…\{08BE46F7-166A-4716-8603-75518EA54B3F}) (Version: 2.3.0.797 - Option NV)
Facebook Plug-In (HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\Facebook Plug-In) (Version:  - Facebook, Inc.)
Fitbit Connect (HKLM-x32\…\{9EC69368-C1C7-48BA-AD93-01EFC142DDF9}) (Version: 2.0.0.6630 - Fitbit Inc.)
FMW 1 (Version: 1.72.2 - AVG Technologies) Hidden
Free Studio version 5.1.4 (HKLM-x32\…\Free Studio_is1) (Version:  - DVDVideoSoft Limited.)
Free YouTube to MP3 Converter version 3.11.33.1005 (HKLM-x32\…\Free YouTube to MP3 Converter_is1) (Version: 3.11.33.1005 - DVDVideoSoft Ltd.)
Gateway Games (HKLM-x32\…\WildTangent gateway Master Uninstall) (Version: 1.0.0.71 - WildTangent)
Gateway InfoCentre (HKLM-x32\…\Gateway InfoCentre) (Version: 3.02.3000 - Gateway Incorporated)
Gateway MyBackup (HKLM-x32\…\InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}) (Version: 2.0.2.19 - NewTech Infosystems)
Gateway Photo Frame [removed] (HKLM-x32\…\Gateway Photo Frame) (Version: 4.2.3.10 - I/O Interconnect)
Gateway Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3002 - Acer Incorporated)
Gateway Registration (HKLM-x32\…\Gateway Registration) (Version: 1.02.3004 - Gateway Incorporated)
Gateway ScreenSaver (HKLM-x32\…\Gateway Screensaver) (Version: 1.1.0812 - Gateway Incorporated)
Gateway Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.01.3014 - Gateway Incorporated)
Google Chrome (HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
GoToMeeting 6.0.0.1259 (HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\GoToMeeting) (Version: 6.0.0.1259 - CitrixOnline)
iCloud (HKLM\…\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3001 - Gateway Incorporated)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version:  - Intel Corporation)
iTunes (HKLM\…\{A31C5565-90D9-4615-AE13-94D86C3836C7}) (Version: 12.3.3.17 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft IntelliPoint 8.1 (HKLM\…\Microsoft IntelliPoint 8.1) (Version: 8.15.406.0 - Microsoft)
Microsoft LifeCam (HKLM\…\{3E061CBA-1DBB-45DD-8873-D100072ADCAD}) (Version: 3.0.215.0 - Microsoft Corporation)
Microsoft Office Home and Business 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Works (HKLM-x32\…\{67E03279-F703-408F-B4BF-46B5FC8D70CD}) (Version: 9.7.0621 - Microsoft Corporation)
MobileMe Control Panel (HKLM\…\{AF5020D9-116A-46AC-A922-087592F37EC9}) (Version: 3.1.8.0 - Apple Inc.)
Mozilla Firefox 39.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 33.1.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 9 Essentials (HKLM-x32\…\{40a87585-3dea-47d0-8aac-c7c19689b431}) (Version:  - Nero AG)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.7 - )
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9.140.248 - Google, Inc.)
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5898 - Realtek Semiconductor Corp.)
Rosetta Stone Version 3 (HKLM-x32\…\{99011A6E-5200-11DE-BDB8-7ACD56D89593}) (Version: 3.4.5.0 - Rosetta Stone Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM-x32\…\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\…\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}) (Version: 9.0.0.623 - AVG Technologies CZ, s.r.o.)
Visual Studio 2008 x64 Redistributables (HKLM-x32\…\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\…\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Welcome Center (HKLM-x32\…\Gateway Welcome Center) (Version: 1.00.3005 - Gateway Incorporated)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\…\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinRAR archiver (HKLM-x32\…\WinRAR archiver) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Pamela\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Pamela\AppData\Local\Citrix\GoToMeeting\1259\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
CustomCLSID: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Pamela\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {00EE99E8-0FBC-4973-BFE6-6836EA0B6FAE} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
Task: {17C067F6-1040-4408-AB48-CCBC5CB6EE15} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {17C96546-6057-49D3-A90E-0D9B0101F569} - System32\Tasks\{A5F4DCE8-7774-4469-B084-A9D9AF31DD70} => pcalua.exe -a C:\Users\Pamela\Documents\Downloads\install_flash_player.exe -d C:\Users\Pamela\Documents\Downloads
Task: {1F5DEA4A-552F-4D83-B488-DED2D9003C91} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-09] (Adobe Systems Incorporated)
Task: {2C73F79E-7734-4E7B-8CA6-A2DE40B0D98C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1608746659-3683959345-3987556120-1001UA => C:\Users\Pamela\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {4E1D3F65-0EF7-454E-9E8D-C66C318618C1} - System32\Tasks\Recovery Management\Burn Notification => C:\Program Files\Gateway\Gateway Recovery Management\NotificationCenter\Notification.exe [2009-07-09] (Acer)
Task: {53630CE3-152A-4126-9AE8-A0B7A2C44169} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {7B58459D-AC6E-4CB7-9FF2-F3D68C3C0220} - System32\Tasks\{E4C0C128-9F84-4437-A971-7C73928AFCF5} => pcalua.exe -a "C:\Users\Pamela\Documents\Downloads\install_flash_player (1).exe" -d C:\Users\Pamela\Documents\Downloads
Task: {8D9500B8-E152-405C-B70E-7E88F85636E1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {934DC91D-C2C6-4507-8933-66BA0C8FB6C8} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2015-12-01] (Apple Inc.)
Task: {9B1E0CDC-515E-439A-9F4D-6844BA965628} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-10-29] (Lavasoft Limited                                                      )
Task: {E793D30D-07AC-40CE-B212-5E752CF34AC6} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-04-13] (Microsoft Corporation)
Task: {F08342A2-4B39-4D62-A5F0-26C74E896893} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1608746659-3683959345-3987556120-1001Core => C:\Users\Pamela\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1608746659-3683959345-3987556120-1001Core.job => C:\Users\Pamela\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1608746659-3683959345-3987556120-1001UA.job => C:\Users\Pamela\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Public\Desktop\Netflix.lnk -> C:\ProgramData\OEM_E471269A730D\Netflix\StartURL.exe () -> hxxp://homepage.gateway.com/redirect.aspx?rid=09000002
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 01329936 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2009-12-29 01:55 - 2009-12-12 16:12 - 00052224 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
2011-08-18 15:25 - 2011-08-18 15:25 - 01101960 _____ () C:\Program Files (x86)\Lavasoft\Ad-Aware\AWSC.exe
2011-08-18 15:25 - 2011-10-01 22:14 - 00589184 _____ () C:\Program Files (x86)\Lavasoft\Ad-Aware\RPAPI.dll
2011-08-18 15:25 - 2011-10-01 22:14 - 00430568 _____ () C:\Program Files (x86)\Lavasoft\Ad-Aware\viprebridge.dll
2011-08-18 15:25 - 2011-08-18 15:25 - 00308560 _____ () C:\Program Files (x86)\Lavasoft\Ad-Aware\Vipre.dll
2012-07-14 22:12 - 2014-12-19 06:01 - 00192376 _____ () C:\ProgramData\Lavasoft\Ad-Aware\Defs\Extended\libBase64.dll
2012-07-14 22:12 - 2014-12-19 06:01 - 00180088 _____ () C:\ProgramData\Lavasoft\Ad-Aware\Defs\Extended\libMachoUniv.dll
2011-10-01 22:13 - 2011-10-01 22:13 - 00508776 _____ () C:\ProgramData\Lavasoft\Ad-Aware\Defs\thorax.aaw
2009-02-02 19:33 - 2009-02-02 19:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\sqlite3.dll
2008-09-28 19:55 - 2008-09-28 19:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\ACE.dll
2009-06-12 18:37 - 2009-06-12 18:37 - 00032768 _____ () C:\Program Files (x86)\Gateway Photo Frame\IOIUSBLib.dll
2009-06-12 18:37 - 2009-06-12 18:37 - 00025088 _____ () C:\Program Files (x86)\Gateway Photo Frame\IOIHIDLib.dll
2015-11-11 10:21 - 2016-04-07 21:43 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
2011-08-18 15:25 - 2011-08-18 15:25 - 00017856 _____ () C:\Program Files (x86)\Lavasoft\Ad-Aware\AWSCUpdate.dll
2016-04-11 15:13 - 2016-04-06 05:04 - 01675928 _____ () C:\Users\Pamela\AppData\Local\Google\Chrome\Application\49.0.2623.112\libglesv2.dll
2016-04-11 15:13 - 2016-04-06 05:04 - 00086168 _____ () C:\Users\Pamela\AppData\Local\Google\Chrome\Application\49.0.2623.112\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Lavasoft Ad-Aware Service => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sndappv2 => ""="service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
 
There are 7461 more sites.
 
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\123simsen.com -> www.123simsen.com
 
There are 7461 more sites.
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2010-10-15 17:34 - 00422663 ____R C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1001namen.com
127.0.0.1 1001namen.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com
127.0.0.1 123simsen.com
127.0.0.1 www.123simsen.com
 
There are 14562 more lines.
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Pamela\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
mpsdrv => Firewall Service is not running.
MpsSvc => Firewall Service is not running.
bfe => Firewall Service is not running.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: AppleSyncNotifier => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Fitbit Connect => "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
MSCONFIG\startupreg: Google Update => "C:\Users\Pamela\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LifeCam => "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: VX6000 => C:\Windows\vVX6000.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{FBA32C37-C0AC-43D4-A30D-B260CB53EE53}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{577457F2-90BF-414F-979A-E14DABAA0258}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{C8691F0E-0E22-48D0-8869-96CE67AA8965}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{37352590-A9A5-4CA4-AAD0-05B649035F0E}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{E58CEE11-07C4-4A39-88D5-64899A165767}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{C8DA5CF0-B21F-4F69-BE47-2586925B2F81}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{F2F0F511-6961-48B0-AD94-CC791DFBB699}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{5F295E4B-337F-4858-AB35-5FAC0AEDA633}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{9D2BE898-CBB6-419B-B154-A54E170A655C}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{B6649051-F9C7-45FC-8402-40980312304D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BF26CEFE-E038-4B16-8ADC-B7FEA217BEFC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C4BC2F82-2AA3-4739-A513-6CB8469F8971}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{A3EB645D-CB37-440A-89F6-7F4BFDEDEDA1}] => (Allow) svchost.exe
FirewallRules: [{A7F5B627-A5F0-4FFB-A802-36C2662A57F6}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [TCP Query User{5BB5269F-6E7E-4BE2-BC26-A311ABCAE09C}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe
FirewallRules: [UDP Query User{33E2BD75-7DB8-4DED-AD07-708E511EB56B}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe
 
==================== Restore Points =========================
 
14-04-2016 08:02:07 Windows Update
Check "winmgmt" service or repair WMI.
 
 
==================== Faulty Device Manager Devices =============
 
Name: Microsoft PS/2 Mouse
Description: Microsoft PS/2 Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/13/2016 02:16:25 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: The volume (K:) was not defragmented because an error was encountered: The request could not be performed because of an I/O device error. (0x8007045D)
 
Error: (04/12/2016 04:37:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8190
 
Error: (04/12/2016 04:37:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8190
 
Error: (04/12/2016 04:37:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (04/12/2016 04:07:08 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7082
 
Error: (04/12/2016 04:07:08 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7082
 
Error: (04/12/2016 04:07:08 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (04/12/2016 03:46:53 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7067
 
Error: (04/12/2016 03:46:53 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7067
 
Error: (04/12/2016 03:46:53 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
System errors:
=============
Error: (04/14/2016 05:14:40 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x800f0902: Update for Windows 7 for x64-based Systems (KB2952664).
 
Error: (04/14/2016 05:14:39 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x800f0902: Security Update for Windows 7 for x64-based Systems (KB3138962).
 
Error: (04/14/2016 03:03:20 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
 
Error: (04/14/2016 02:13:15 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
 
Error: (04/14/2016 02:03:14 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
 
Error: (04/14/2016 01:23:10 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
 
Error: (04/14/2016 01:13:09 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
 
Error: (04/14/2016 12:43:06 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
 
Error: (04/14/2016 11:53:01 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
 
Error: (04/14/2016 11:02:56 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
 
 
==================== Memory info =========================== 
 
Processor: Pentium(R) Dual-Core CPU E5300 @ 2.60GHz
Percentage of memory in use: 52%
Total physical RAM: 6109.14 MB
Available physical RAM: 2896.33 MB
Total Virtual: 12216.49 MB
Available Virtual: 8452.56 MB
 
==================== Drives ================================
 
Drive c: (Gateway) (Fixed) (Total:916.41 GB) (Free:832.15 GB) NTFS
Drive j: () (Fixed) (Total:149.05 GB) (Free:95.02 GB) NTFS
Drive k: () (Fixed) (Total:111.76 GB) (Free:4.05 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 2928213B)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=916.4 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 149.1 GB) (Disk ID: 84B9E9CE)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)
 
========================================================
Disk: 2 (Size: 114.5 GB) (Disk ID: 1AFC7AD1)
Partition 1: (Not Active) - (Size=111.8 GB) - (Type=0C)
 
==================== End of Addition.txt ============================
Hello PGazall

I am Marie Curie and will gladly help you with any malware-related problems.

I will be analysing your logs now and reply with instructions as soon as possible. Please familiarize yourself with the following ground rules in the meanwhile.
  • Read my instructions thoroughly, carry out each step in the given order.
  • Do not make any changes to your system, or run any tools other than those I provided. Do not delete, fix, uninstall, or install anything unless I tell you to.
  • If you are unsure about anything or if you encounter any problems, please stop and inform me about it.
  • Stick with me until I tell you that your computer is clean. Absence of symptoms does not mean that your computer is free of malware.
  • Back up important files before we start.
Please read the following warning before you proceed.
 

[external image: goGMWSt.gif]Backdoor Warning
 
——————————
 
One or more of the identified malware is known to use a backdoor, that allows attackers to remotely control your computer, download/execute files and steal system, financial & personal information.
 
If your computer has been used for online banking, has credit card information or other sensitive data, using a non-compromised computer/device you should immediately change all account information (including those used for Email, eBay, Paypal, online forums, etc).
 
Banking and credit card institutions should be notified of the possible security breach. Please read the following article for more information: How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
 
Whilst the identified malware can be removed, there is no way to guarantee the trustworthiness of your computer unless you reformat your hard drive and reinstall your Operating System. This is due to the nature of the malware, which allows a remote attacker to make any kind of modification. Many experts in the security community believe that once compromised with this type of malware, the best course of action is to reformat/reinstall. Please read the following articles for more information.

  • When should I re-format? How should I reinstall?
  • Help: I Got Hacked. Now What Do I Do?
  • Where to draw the line? When to recommend a format and reinstall?
You now have the choice between cleaning the malware present or reformatting your computer. Ultimately, the decision is yours, and what you're most comfortable with. Once you've read the articles linked above, let me know if you have any questions, and how you wish to proceed.


STEP 1
[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Script
  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    start
    CreateRestorePoint:
    
    zip: System32\drivers\jyst.sys
    Folder: C:\Users\Pamela\AppData\Local\{66D93A45-7283-4904-8236-1C69A998DFAD}
    
    C:\Users\Pamela\AppData\Local\{66D93A45-7283-4904-8236-1C69A998DFAD}
    2009-12-02 21:19 - 2015-07-26 01:18 - 0000470 _____ () C:\Users\Pamela\AppData\Roaming\wklnhst.dat
    2011-12-11 17:10 - 2011-12-11 17:10 - 0001260 ___SH () C:\Users\Pamela\AppData\Local\5o42hc3l58u034
    2010-12-08 20:38 - 2010-12-08 20:38 - 0000000 _____ () C:\Users\Pamela\AppData\Local\Jgohanedev.bin
    2010-12-08 20:38 - 2010-12-08 20:38 - 0000120 _____ () C:\Users\Pamela\AppData\Local\Mbezivewavadej.dat
    2011-12-09 19:50 - 2011-12-09 19:50 - 0001252 ___SH () C:\Users\Pamela\AppData\Local\nlxrgy8n4nqv0odc4cjr8n562o1a
    2011-12-11 17:10 - 2011-12-11 17:10 - 0001260 ___SH () C:\ProgramData\5o42hc3l58u034
    2009-12-08 01:08 - 2009-12-08 01:08 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
    2011-12-09 19:50 - 2011-12-09 19:50 - 0001252 ___SH () C:\ProgramData\nlxrgy8n4nqv0odc4cjr8n562o1a
    
    FirewallRules: [{A3EB645D-CB37-440A-89F6-7F4BFDEDEDA1}] => (Allow) svchost.exe
    CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.7.796\_platform_specific\win_x86\widevinecdmadapter.dll => No File
    CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Pamela\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.7.771\_platform_specific\win_x86\widevinecdmadapter.dll => No File
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
    BHO: No Name -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> No File
    CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
    HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\MountPoints2: {07bea468-a41f-11df-9111-002511a28efb} - L:\WIN\setup.exe
    HKU\S-1-5-21-1608746659-3683959345-3987556120-1001\…\Winlogon: [Shell] explorer.exe, <==== ATTENTION
    
    CMD: ipconfig /flushdns
    EmptyTemp:
    end
  • Click File, Save As and type fixlist.txt as the File Name.
  • Important: The file must be saved in the same location as FRST64.exe.
NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.
  • Double-Click FRST64.exe to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.
STEP 2
File Submission
  • Please go to my channel
  • Click Browse and locate the following file on your Desktop:
    • Upload.zip
  • Click Submit Query.
======================================================

STEP 3
[external image: pfNZP4A.png]Logs
In your next reply please include the following logs.
  • Fixlog.txt

Hi Marie and thank you so much for your help.  I read the articles and I think I should reformat and reinstall.  I have not done anything after reading the articles and I'm really not sure the steps to reformatting and reinstalling.
Thanks again

Pamela

Hello Pamela.

Do you have an installation disc or recovery disc for your operating system?
Do you have a license key?
Do you have an empty USB drive with at least 4 GB free space?

Marie

Hello Pamela,
 
I have not heard back from you in 3 days.

  • Do you still require help?

  • If you require additional time to complete my instructions, please let me know.

  • If after 48 hours you have not replied to this thread it will have to be closed.

  •  

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI