This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

E-Mail Failure Issues - Random Undeliverable E-mails

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone. I am trying to troubleshoot a computer in the office where I do volunteer work for an animal rescue organization. They have been having trouble with e-mails getting sent back as undeliverable but not to everyone. It is random. I ran the ESET online scanner to check things out first. The program ran for an hour, got to the end of the scan, and just prior to generating a log with the list of 6 found threats the program stopped running and shut down. The scan took over an hour. So, I suspect that there may be some sort of virus or malware on this computer that is causing trouble with their e-mail program. I have performed the requested scans and have pasted them below. Any help you can offer with this issue is greatly appreciated.

 

Thanks,

 

The Cat Man

 

aswMBR LOG

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software

Run date: 2016-06-03 17:26:29

—————————–

17:26:29.042    OS Version: Windows x64 6.2.9200

17:26:29.042    Number of processors: 4 586 0x3A09

17:26:29.042    ComputerName: FOFFPC  UserName: Foff

17:26:30.339    Initialze error C000010E - driver not loaded

17:31:31.802    AVAST engine defs: 16060301

17:33:52.092    Service scanning

17:34:16.937    Modules scanning

17:34:16.937    Disk 0 trace - called modules:

17:34:16.937   

17:34:18.140    AVAST engine scan C:\WINDOWS

17:34:20.640    AVAST engine scan C:\WINDOWS\system32

17:37:12.932    AVAST engine scan C:\WINDOWS\system32\drivers

17:37:28.964    AVAST engine scan C:\Users\Foff

17:45:08.898    AVAST engine scan C:\ProgramData

17:53:30.551    Scan finished successfully

17:53:54.193    The log file has been saved successfully to "C:\Users\Foff\Desktop\aswMBR log 1.txt"

 

FRST LOG

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:03-06-2016

Ran by [removed] (administrator) on FOFFPC (03-06-2016 17:55:39)

Running from C:\Users\[removed]\Desktop

[removed]

Platform: Windows 8.1 (Update) (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: IE)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(AMD) C:\WINDOWS\System32\atiesrxx.exe

(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe

(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe

(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe

(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AdminService.exe

(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe

(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\22.6.0.142\n360.exe

() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe

(Atheros) C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe

(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe

(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

(Dell Inc.) C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe

(Microsoft Corporation) C:\WINDOWS\SysWOW64\wbem\WmiPrvSE.exe

(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe

(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe

(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\ramaint.exe

(AMD) C:\WINDOWS\System32\atieclxx.exe

(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\22.6.0.142\n360.exe

(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Toaster.exe

(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

(Qualcomm Atheros) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtTray.exe

(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe

(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe

(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe

(CANON INC.) C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE

(Akamai Technologies, Inc.) C:\Users\Foff\AppData\Local\Akamai\netsession_win.exe

(Akamai Technologies, Inc.) C:\Users\Foff\AppData\Local\Akamai\netsession_win.exe

() C:\Program Files (x86)\Multimedia Card Reader(9106)\Shwicon9106.exe

(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe

(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe

(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe

(Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe

(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe

(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

(Microsoft Corporation) C:\WINDOWS\System32\GWX\GWX.exe

(Microsoft Corporation) C:\WINDOWS\SysWOW64\dllhost.exe

(Microsoft Corporation) C:\WINDOWS\System32\WWAHost.exe

(Microsoft Corporation) C:\WINDOWS\System32\UserAccountBroker.exe

(PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssist\imstrayicon.exe

 

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor)

HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212560 2012-06-13] (Realtek Semiconductor)

HKLM\…\Run: [BtTray] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtTray.exe [757888 2012-07-02] (Qualcomm Atheros)

HKLM\…\Run: [BtvStack] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [127104 2012-07-02] (Qualcomm Atheros Commnucations)

HKLM\…\Run: [LogMeIn GUI] => C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [57928 2012-11-29] (LogMeIn, Inc.)

HKLM\…\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [570152 2014-08-14] (Acronis)

HKLM\…\Run: [MFNetworkScanUtility] => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE [486552 2012-09-27] (CANON INC.)

HKLM-x32\…\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642728 2012-07-05] (Advanced Micro Devices, Inc.)

HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)

HKLM-x32\…\Run: [Shwicon9106] => C:\Program Files (x86)\Multimedia Card Reader(9106)\Shwicon9106.exe [262144 2012-06-28] ()

HKLM-x32\…\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-07] (CyberLink)

HKLM-x32\…\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-04] (CyberLink Corp.)

HKLM-x32\…\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [143888 2012-06-01] (CyberLink Corp.)

HKLM-x32\…\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5234160 2014-10-22] (Acronis)

HKLM-x32\…\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [603904 2014-10-17] (Acronis International GmbH)

HKU\S-1-5-21-2984815994-1181752439-1944922643-1001\…\Run: [Akamai NetSession Interface] => C:\Users\Foff\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)

ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\22.6.0.142\buShell.dll [2016-02-18] (Symantec Corporation)

ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\22.6.0.142\buShell.dll [2016-02-18] (Symantec Corporation)

ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\22.6.0.142\buShell.dll [2016-02-18] (Symantec Corporation)

ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2014-09-09] (Acronis)

ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2014-09-09] (Acronis)

ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2014-09-09] (Acronis)

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] [removed] [removed]

Tcpip\..\Interfaces\{2D6C8A66-13A8-4C7E-8BC1-FF36853152D9}: [DhcpNameServer] [removed] [removed]

Tcpip\..\Interfaces\{ADC4672F-9DEF-4869-BEA4-CAB6EF2A68C7}: [DhcpNameServer] [removed]

 

Internet Explorer:

==================

HKU\S-1-5-21-2984815994-1181752439-1944922643-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/

HKU\S-1-5-21-2984815994-1181752439-1944922643-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com

SearchScopes: HKU\S-1-5-21-2984815994-1181752439-1944922643-1001 -> DefaultScope {3F37605F-3094-45DD-B6AB-707DEEA7CEB4} URL =

SearchScopes: HKU\S-1-5-21-2984815994-1181752439-1944922643-1001 -> {3F37605F-3094-45DD-B6AB-707DEEA7CEB4} URL =

SearchScopes: HKU\S-1-5-21-2984815994-1181752439-1944922643-1001 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o;=APN11913&l;=dis&prt;=NSBU&chn;=1001190&geo;=US&ver;=22&locale;=en_US&gct;=kwd&qsrc;=2869

SearchScopes: HKU\S-1-5-21-2984815994-1181752439-1944922643-1001 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw;={searchTerms}&tbid;=80273&iwk;=275&lng;=en

BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation)

BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll [2012-07-02] (Qualcomm Atheros Commnucations)

BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)

BHO-x32: GoodApp -> {44520b54-9e1a-420b-aac8-b53721cbd53f} -> C:\Program Files (x86)\goodsearchtb\goodsearchDx.dll [2012-12-21] ()

BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation)

BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\IPS\IPSBHO.DLL => No File

BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)

BHO-x32: Updater For GoodApp -> {dd9475f4-a228-4e22-8d37-4b52c2054c31} -> C:\Program Files (x86)\goodsearchtb\auxi\goodsearchAu.dll [2012-12-21] (Visicom Media)

Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation)

Toolbar: HKLM-x32 - GoodApp - {44520b54-9e1a-420b-aac8-b53721cbd53f} - C:\Program Files (x86)\goodsearchtb\goodsearchDx.dll [2012-12-21] ()

Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation)

 

FireFox:

========

FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)

FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)

FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)

FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)

FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-28] (Microsoft Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)

FF HKLM\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.0.124\coFFAddon

FF Extension: Norton Identity Safe - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.0.124\coFFAddon [2016-03-28]

FF HKLM-x32\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.0.124\coFFAddon

 

Chrome:

=======

CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton 360\Engine\22.6.0.142\Exts\Chrome.crx [2016-03-22]

CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

CHR HKLM-x32\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton 360\Engine\22.6.0.142\Exts\Chrome.crx [2016-03-22]

CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

 

==================== Services (Whitelisted) ========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [128640 2012-07-02] (Qualcomm Atheros Commnucations) [File not signed]

R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2572024 2016-03-10] (Dell Inc.)

R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [202488 2016-03-10] (Dell Inc.)

S2 DellDigitalDelivery; c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [173056 2012-06-19] (Dell Products, LP.) [File not signed]

R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc.)

R2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [7168 2012-07-09] (Intel Corporation) [File not signed]

R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)

R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [419336 2016-05-17] (LogMeIn, Inc.)

R2 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [508936 2016-05-17] (LogMeIn, Inc.)

R2 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2012-11-29] (LogMeIn, Inc.)

R2 N360; C:\Program Files (x86)\Norton 360\Engine\22.6.0.142\N360.exe [289080 2016-02-26] (Symantec Corporation)

R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()

R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1919336 2012-08-06] (SoftThinks SAS)

R2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [31928 2016-04-22] (Dell Inc.)

S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)

S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)

R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [77824 2012-06-19] (Atheros) [File not signed]

 

===================== Drivers (Whitelisted) ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-03] (Advanced Micro Devices)

R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\BASHDefs\20160521.001\BHDrvx64.sys [1832176 2016-05-12] (Symantec Corporation)

R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-07-02] (Qualcomm Atheros)

R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1606000.08E\ccSetx64.sys [173808 2015-07-10] (Symantec Corporation)

R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)

R3 DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [23760 2015-01-30] (Dell Computer Corporation)

R3 DellProf; C:\Windows\system32\drivers\DellProf.sys [24240 2015-05-22] (Dell Computer Corporation)

S3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2012-08-05] (OSR Open Systems Resources, Inc.)

S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)

S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)

S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)

R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [497392 2016-05-04] (Symantec Corporation)

R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [156912 2016-05-04] (Symantec Corporation)

R0 file_tracker; C:\Windows\System32\DRIVERS\file_tracker.sys [296736 2014-11-10] (Acronis International GmbH)

R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\IPSDefs\20160602.001\IDSvia64.sys [876248 2016-05-25] (Symantec Corporation)

R2 LMIInfo; C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [16056 2013-06-04] (LogMeIn, Inc.)

S4 LMIRfsClientNP; no ImagePath

R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\VirusDefs\20160603.006\ENG64.SYS [138456 2016-05-17] (Symantec Corporation)

R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\VirusDefs\20160603.006\EX64.SYS [2148056 2016-05-17] (Symantec Corporation)

R1 SRTSP; C:\Windows\System32\Drivers\N360x64\1606000.08E\SRTSP64.SYS [928504 2016-02-23] (Symantec Corporation)

R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1606000.08E\SRTSPX64.SYS [50936 2015-07-10] (Symantec Corporation)

R0 SymEFASI; C:\Windows\System32\drivers\N360x64\1606000.08E\SYMEFASI64.SYS [1621232 2016-02-23] (Symantec Corporation)

S0 SymELAM; C:\Windows\System32\drivers\N360x64\1606000.08E\SymELAM.sys [24192 2015-07-10] (Symantec Corporation)

R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [111344 2015-07-27] (Symantec Corporation)

R1 SymIRON; C:\Windows\system32\drivers\N360x64\1606000.08E\Ironx64.SYS [295664 2016-02-23] (Symantec Corporation)

R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1606000.08E\SYMNETS.SYS [577768 2016-02-23] (Symantec Corporation)

R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1328928 2014-11-10] (Acronis International GmbH)

R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [234784 2014-11-10] (Acronis International GmbH)

S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)

S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)

S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)

R3 WirelessKeyboardFilter; C:\Windows\System32\drivers\WirelessKeyboardFilter.sys [49384 2016-03-29] (Microsoft Corporation)

U3 aswMBR; \??\C:\Users\Foff\AppData\Local\Temp\aswMBR.sys [X]

U3 aswVmm; \??\C:\Users\Foff\AppData\Local\Temp\aswVmm.sys [X]

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-06-03 17:55 - 2016-06-03 17:56 - 00020589 _____ C:\Users\Foff\Desktop\FRST.txt

2016-06-03 17:55 - 2016-06-03 17:55 - 00000000 ____D C:\FRST

2016-06-03 17:53 - 2016-06-03 17:53 - 00000932 _____ C:\Users\Foff\Desktop\aswMBR log 1.txt

2016-06-03 17:25 - 2016-06-03 17:25 - 02384384 _____ (Farbar) C:\Users\Foff\Desktop\FRST64.exe

2016-06-03 17:23 - 2016-06-03 17:23 - 05198336 _____ (AVAST Software) C:\Users\Foff\Desktop\aswMBR.exe

2016-06-03 16:09 - 2016-06-03 16:09 - 00000000 ____D C:\Users\Foff\AppData\Local\ESET

2016-05-31 10:02 - 2016-05-31 10:02 - 00000000 ___RD C:\Users\Foff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices

2016-05-11 14:17 - 2016-04-22 16:54 - 25816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll

2016-05-11 14:17 - 2016-04-22 16:15 - 00571904 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll

2016-05-11 14:17 - 2016-04-22 16:14 - 02893312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll

2016-05-11 14:17 - 2016-04-22 16:08 - 06052864 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll

2016-05-11 14:17 - 2016-04-22 16:06 - 20349952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll

2016-05-11 14:17 - 2016-04-22 16:00 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll

2016-05-11 14:17 - 2016-04-22 15:35 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll

2016-05-11 14:17 - 2016-04-22 15:29 - 02285568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll

2016-05-11 14:17 - 2016-04-22 15:24 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll

2016-05-11 14:17 - 2016-04-22 15:23 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll

2016-05-11 14:17 - 2016-04-22 15:19 - 15414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll

2016-05-11 14:17 - 2016-04-22 15:17 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll

2016-05-11 14:17 - 2016-04-22 15:14 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll

2016-05-11 14:17 - 2016-04-22 15:14 - 00725504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe

2016-05-11 14:17 - 2016-04-22 15:14 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll

2016-05-11 14:17 - 2016-04-22 15:12 - 02131968 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl

2016-05-11 14:17 - 2016-04-22 14:58 - 04611072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll

2016-05-11 14:17 - 2016-04-22 14:58 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll

2016-05-11 14:17 - 2016-04-22 14:54 - 13811200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll

2016-05-11 14:17 - 2016-04-22 14:53 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll

2016-05-11 14:17 - 2016-04-22 14:52 - 02596864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll

2016-05-11 14:17 - 2016-04-22 14:52 - 00693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll

2016-05-11 14:17 - 2016-04-22 14:52 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll

2016-05-11 14:17 - 2016-04-22 14:51 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl

2016-05-11 14:17 - 2016-04-22 14:40 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll

2016-05-11 14:17 - 2016-04-22 14:29 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll

2016-05-11 14:17 - 2016-04-22 14:27 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll

2016-05-11 14:17 - 2016-04-22 14:24 - 01311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll

2016-05-11 14:17 - 2016-04-22 14:23 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll

2016-05-11 14:17 - 2016-03-31 02:50 - 01307328 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll

2016-05-11 14:17 - 2016-03-30 23:40 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll

2016-05-11 14:15 - 2016-04-11 02:21 - 00074584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys

2016-05-11 14:15 - 2016-04-10 03:48 - 00738096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll

2016-05-11 14:15 - 2016-04-10 03:48 - 00613624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll

2016-05-11 14:15 - 2016-04-10 01:37 - 01549144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys

2016-05-11 14:15 - 2016-04-10 00:21 - 01763376 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll

2016-05-11 14:15 - 2016-04-10 00:21 - 01489088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll

2016-05-11 14:15 - 2016-04-10 00:14 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll

2016-05-11 14:15 - 2016-04-09 19:29 - 04169216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys

2016-05-11 14:15 - 2016-04-09 18:07 - 01097728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll

2016-05-11 14:15 - 2016-04-09 17:58 - 00534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll

2016-05-11 14:15 - 2016-04-09 17:50 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll

2016-05-11 14:15 - 2016-04-06 17:13 - 00561960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys

2016-05-11 14:15 - 2016-04-06 17:13 - 00137976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncrypt.dll

2016-05-11 14:15 - 2016-04-06 14:20 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys

2016-05-11 14:15 - 2016-04-06 14:19 - 00401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys

2016-05-11 14:15 - 2016-04-06 14:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys

2016-05-11 14:15 - 2016-04-06 13:49 - 00120384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncrypt.dll

2016-05-11 14:15 - 2016-04-06 13:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll

2016-05-11 14:15 - 2016-04-06 12:57 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll

2016-05-11 14:15 - 2016-04-06 12:52 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll

2016-05-11 14:15 - 2016-04-06 12:20 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll

2016-05-11 14:15 - 2016-04-06 11:48 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll

2016-05-11 14:15 - 2016-03-28 21:42 - 07446368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe

2016-05-11 14:15 - 2016-03-15 21:58 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll

2016-05-11 14:15 - 2016-03-15 21:58 - 00332632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll

2016-05-11 14:15 - 2016-03-14 12:50 - 00316760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys

2016-05-11 14:15 - 2016-03-11 20:49 - 02466136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys

2016-05-11 14:15 - 2016-03-11 20:47 - 00160160 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPHLPAPI.DLL

2016-05-11 14:15 - 2016-03-11 20:47 - 00121912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IPHLPAPI.DLL

2016-05-11 14:15 - 2016-03-10 13:03 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsparse.dll

2016-05-11 14:15 - 2016-03-10 12:55 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll

2016-05-11 14:15 - 2016-03-10 12:52 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll

2016-05-11 14:15 - 2016-03-10 12:48 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsparse.dll

2016-05-11 14:15 - 2016-03-10 12:42 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll

2016-05-11 14:15 - 2016-03-05 13:44 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll

2016-05-11 14:15 - 2016-03-05 13:04 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll

2016-05-11 14:15 - 2016-02-27 14:28 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll

2016-05-11 14:15 - 2016-02-27 13:57 - 03273728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll

2016-05-11 14:15 - 2016-02-27 13:19 - 03820544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll

2016-05-11 14:15 - 2016-02-27 12:32 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-06-03 17:55 - 2012-12-29 11:17 - 00000000 ____D C:\Users\Foff\AppData\Local\CrashDumps

2016-06-03 17:47 - 2015-03-06 13:55 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

2016-06-03 16:58 - 2014-04-28 14:13 - 00003770 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{467AB805-3729-417A-8C50-890E0ECBD48C}

2016-06-03 16:06 - 2013-01-08 21:13 - 00000000 ____D C:\Users\Foff\Documents\Outlook Files

2016-06-03 15:48 - 2015-08-31 10:13 - 00000000 ____D C:\Program Files (x86)\Dell Update

2016-06-03 15:27 - 2013-08-22 09:36 - 00000000 ____D C:\WINDOWS\Inf

2016-06-03 14:46 - 2015-03-06 13:55 - 00000916 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

2016-06-03 10:07 - 2013-01-07 22:25 - 00000000 ____D C:\ProgramData\LogMeIn

2016-06-01 10:47 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\AppReadiness

2016-05-31 10:51 - 2012-12-29 10:06 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2984815994-1181752439-1944922643-1001

2016-05-31 10:12 - 2013-08-22 11:36 - 00000000 ___HD C:\Program Files\WindowsApps

2016-05-31 10:10 - 2012-07-26 03:59 - 00000000 ____D C:\WINDOWS\CbsTemp

2016-05-31 10:07 - 2015-04-13 11:40 - 00000000 ___SD C:\WINDOWS\system32\GWX

2016-05-31 10:02 - 2012-10-26 13:47 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery

2016-05-25 10:21 - 2013-01-08 21:43 - 00000000 ____D C:\Users\Foff\Documents\FOFF

2016-05-17 09:13 - 2014-01-29 12:13 - 00001006 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Control Panel.lnk

2016-05-17 09:13 - 2013-01-07 22:25 - 00000000 ____D C:\Program Files (x86)\LogMeIn

2016-05-17 09:11 - 2013-01-07 22:25 - 00122400 _____ (LogMeIn, Inc.) C:\WINDOWS\system32\LMIRfsClientNP.dll

2016-05-17 09:11 - 2013-01-07 22:25 - 00107008 _____ (LogMeIn, Inc.) C:\WINDOWS\system32\LMIinit.dll

2016-05-16 09:14 - 2013-08-22 09:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM

2016-05-16 09:10 - 2013-08-22 10:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT

2016-05-16 09:10 - 2013-08-22 10:44 - 00419864 _____ C:\WINDOWS\system32\FNTCACHE.DAT

2016-05-13 15:54 - 2015-04-13 11:40 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX

2016-05-13 15:54 - 2014-12-15 11:21 - 00000000 ____D C:\WINDOWS\system32\appraiser

2016-05-13 15:54 - 2014-03-18 05:45 - 00000000 ____D C:\Program Files\Windows Journal

2016-05-13 14:46 - 2013-08-15 11:31 - 00000000 ____D C:\WINDOWS\system32\MRT

2016-05-13 14:40 - 2012-12-29 12:24 - 139319312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

2016-05-13 09:56 - 2015-02-12 11:08 - 00000000 ____D C:\ProgramData\SupportAssistAgent

2016-05-11 16:08 - 2015-03-16 10:14 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe

2016-05-11 16:08 - 2015-03-16 10:14 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

2016-05-11 14:41 - 2015-03-06 13:55 - 00003892 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA

2016-05-11 14:41 - 2015-03-06 13:55 - 00003656 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

2016-05-06 10:07 - 2013-08-22 09:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI

 

==================== Files in the root of some directories =======

 

2015-11-12 18:43 - 2015-11-12 18:43 - 0000017 _____ () C:\Users\Foff\AppData\Local\resmon.resmoncfg

2014-11-10 12:39 - 2014-11-10 12:39 - 0000057 _____ () C:\ProgramData\Ament.ini

2012-10-26 13:46 - 2012-10-26 13:46 - 0000119 _____ () C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log

2012-10-26 13:43 - 2012-10-26 13:44 - 0000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log

2012-10-26 13:44 - 2012-10-26 13:45 - 0000111 _____ () C:\ProgramData\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}.log

2012-10-26 13:43 - 2012-10-26 13:43 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

2012-10-26 13:45 - 2012-10-26 13:46 - 0000108 _____ () C:\ProgramData\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}.log

 

==================== Bamital & volsnap =================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\WINDOWS\system32\winlogon.exe => File is digitally signed

C:\WINDOWS\system32\wininit.exe => File is digitally signed

C:\WINDOWS\explorer.exe => File is digitally signed

C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed

C:\WINDOWS\system32\svchost.exe => File is digitally signed

C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed

C:\WINDOWS\system32\services.exe => File is digitally signed

C:\WINDOWS\system32\User32.dll => File is digitally signed

C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed

C:\WINDOWS\system32\userinit.exe => File is digitally signed

C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed

C:\WINDOWS\system32\rpcss.dll => File is digitally signed

C:\WINDOWS\system32\dnsapi.dll => File is digitally signed

C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed

C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

 

 

LastRegBack: 2016-03-07 12:42

 

==================== End of FRST.txt ============================

 

FRST ADDITION LOG

Additional scan result of Farbar Recovery Scan Tool (x64) Version:03-06-2016

Ran by [removed] (2016-06-03 17:56:24)

Running from C:\Users\[removed]\Desktop

Windows 8.1 (Update) (X64) (2014-04-28 17:35:53)

Boot Mode: Normal

==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-2984815994-1181752439-1944922643-500 - Administrator - Disabled)

Foff (S-1-5-21-2984815994-1181752439-1944922643-1001 - Administrator - Enabled) => C:\Users\Foff

Guest (S-1-5-21-2984815994-1181752439-1944922643-501 - Limited - Disabled)

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Norton 360 (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: Norton 360 (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}

FW: Norton 360 (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

Acronis True Image 2015 (HKLM-x32\…\{EC394A67-873F-4E6B-AD26-3AA71C7DDA4C}Visible) (Version: 18.0.6055 - Acronis)

Acronis True Image 2015 (x32 Version: 18.0.6055 - Acronis) Hidden

Akamai NetSession Interface (HKU\S-1-5-21-2984815994-1181752439-1944922643-1001\…\Akamai) (Version:  - Akamai Technologies, Inc)

AMD Catalyst Install Manager (HKLM\…\{7EF54F6B-68AE-6B96-912A-9B66D2FC765A}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)

Canon MF Toolbox 4.9.1.1.mf17 (HKLM-x32\…\{6767DFEE-8909-453A-B553-C7693912B2EB}) (Version: 4.9.1.1.mf17 - CANON INC.)

Canon MF5900 Series (HKLM\…\{47C39213-7CE2-4eb0-A112-11671C0072A0}) (Version: 3.9.0.1 - CANON INC.)

CyberLink Media Suite Essentials (HKLM-x32\…\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.)

D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden

Dell Backup and Recovery - Support Software (HKLM-x32\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 1.0.0.1 - Dell Inc.)

Dell Backup and Recovery (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.0.0.1 - Dell Inc.)

Dell Customer Connect (HKLM-x32\…\{FEFDCDCF-C49C-45D0-AAF8-5345858ADEC7}) (Version: 1.2.1.0 - Dell Inc.)

Dell Data Vault (Version: 4.3.8.0 - Dell Inc.) Hidden

Dell Digital Delivery (HKLM-x32\…\{D9ED3EFC-AB00-4CE0-ADED-80EE6B1158A7}) (Version: 2.2.2000.0 - Dell Products, LP)

Dell Product Registration (HKLM-x32\…\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.16.1 - Dell Inc.)

Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.2.6793.01 - Dell)

Dell SupportAssistAgent (HKLM-x32\…\{3ED468C2-2235-4747-90AD-A7A34F0FE70A}) (Version: 1.2.2.8 - Dell)

Dell Update (HKLM-x32\…\{DB82968B-57A4-4397-81A5-ECAB21B5DFCD}) (Version: 1.7.1015.0 - Dell Inc.)

Dell WLAN and Bluetooth Client Installation (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Dell Inc.)

GoodApp (HKLM-x32\…\goodsearchtb) (Version: 2.1.5.1 - Visicom Media Inc.)

Google Earth (HKLM-x32\…\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)

Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden

ImgBurn (HKLM-x32\…\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)

Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)

Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)

Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.0.1207 - Intel Corporation)

LogMeIn (HKLM-x32\…\{FA653F5B-483A-4E92-BF75-BB3BBF1D550D}) (Version: 4.1.2634 - LogMeIn, Inc.)

LogMeIn Client (HKLM-x32\…\{D2300C4F-CC9B-4D00-BC53-B4C806A6C7AB}) (Version: 1.3.1675 - LogMeIn, Inc.)

Microsoft Office Home and Business 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)

Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)

Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)

Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)

Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden

Multimedia Card Reader (HKLM-x32\…\InstallShield_{4B3D9AA4-B47A-4349-A64F-04D5A9226D7C}) (Version: 2.2.915.108 - Fitipower)

Multimedia Card Reader (x32 Version: 2.2.915.108 - Fitipower) Hidden

Norton 360 (HKLM-x32\…\N360) (Version: 22.6.0.142 - Symantec Corporation)

Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.200 - Qualcomm Atheros Communications)

Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.)

Realtek USB Audio (HKLM-x32\…\{0A46A65D-89AC-464C-8026-3CD44960BD04}) (Version: 6.3.9600.41 - Realtek Semiconductor Corp.)

Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)

Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {0A9FAA67-ACD5-4A39-939C-C5FAEFDC1871} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2016-04-22] (Dell Inc.)

Task: {0D8A891D-890C-4808-84D8-2F436AB14653} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION

Task: {1274336E-AB06-46B6-A48C-0671C5557CC6} - \Microsoft\Windows\TaskScheduler\Maintenance Configurator -> No File <==== ATTENTION

Task: {1687544D-7247-4F5A-965A-A6E920E55278} - \Microsoft\Windows\TaskScheduler\Manual Maintenance -> No File <==== ATTENTION

Task: {336757EA-A4D3-45EA-B73F-5D23D841F81F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-05-13] (Microsoft Corporation)

Task: {40525C58-79C2-47A1-9AA2-F1D7FC4F0691} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION

Task: {5BDBB5C1-6DAC-4294-844A-EA0E2C160257} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton 360\Upgrade.exe [2016-02-26] (Symantec Corporation)

Task: {5FB388C7-4460-4F07-A634-73317D7EB633} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe

Task: {6F02587F-8A2B-4552-97F6-DEEF229E335B} - \Microsoft\Windows\TaskScheduler\Idle Maintenance -> No File <==== ATTENTION

Task: {9ACEB974-A74C-499A-BBD7-AEDAF658BC8E} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2016-03-24] (PC-Doctor, Inc.)

Task: {9FB55E31-E025-4F1F-A3B8-53A657E48BCB} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\22.6.0.142\SymErr.exe [2016-02-10] (Symantec Corporation)

Task: {B1E8FBA8-83DD-4990-8A5F-AD63F373B04F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-06] (Google Inc.)

Task: {B7992938-01F1-4F40-A0EC-0D23D2F0F152} - \Microsoft\Windows\TaskScheduler\Regular Maintenance -> No File <==== ATTENTION

Task: {B8B1A182-B3EB-4280-911F-71A28FA11F09} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\22.6.0.142\WSCStub.exe [2016-02-26] (Symantec Corporation)

Task: {BF58E14B-1069-43E0-80DD-BB525A2FD9CD} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics => C:\Windows\system32\disksnapshot.exe

Task: {C6E527A0-AF2F-4E0A-8852-315E2B082ED5} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2016-03-24] (PC-Doctor, Inc.)

Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - \Microsoft\Windows\SettingSync\BackupTask -> No File <==== ATTENTION

Task: {D1235827-59FC-4575-8D5D-BD846551C3FF} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\22.6.0.142\SymErr.exe [2016-02-10] (Symantec Corporation)

Task: {D6F4A061-CEFB-4F38-81EC-6E80ECDD3011} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\Windows\System32\LocationNotificationWindows.exe

Task: {E0D7B57E-AFC7-4CFB-9E64-5A45E2E7D3DE} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe

Task: {E102B44C-403D-45EC-B41A-4E6BE21DA0B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-06] (Google Inc.)

Task: {E7845CE8-9E6E-45D6-B755-1B8B94BF4116} - System32\Tasks\Dell\Dell System Registration => C:\Program Files (x86)\System Registration\prodreg.exe [2012-07-09] (Dell, Inc.)

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

 

==================== Shortcuts =============================

 

(The entries could be listed to be restored or removed.)

 

==================== Loaded Modules (Whitelisted) ==============

 

2012-10-26 13:45 - 2012-04-24 22:43 - 00254512 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

2012-07-02 20:28 - 2012-07-02 20:28 - 00384128 _____ () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ContactsApi.dll

2012-06-28 16:39 - 2012-06-28 16:39 - 00262144 _____ () C:\Program Files (x86)\Multimedia Card Reader(9106)\Shwicon9106.exe

2016-03-28 10:37 - 2016-03-23 19:43 - 00111352 _____ () C:\Program Files\Dell\SupportAssist\libCSharpCommonCS.dll

2016-03-28 10:37 - 2016-03-23 19:43 - 00553720 _____ () C:\Program Files\Dell\SupportAssist\libAsapiCSharp.dll

2014-10-22 11:45 - 2014-10-22 11:45 - 00034624 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll

2014-10-22 11:53 - 2014-10-22 11:53 - 00420160 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll

2014-10-22 11:46 - 2014-10-22 11:46 - 00129344 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\EXPAT.dll

2012-10-26 13:38 - 2012-06-26 05:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll

2012-10-26 13:47 - 2012-08-09 14:51 - 02003304 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\STRestoreAPI.dll

2012-10-26 13:47 - 2012-08-06 11:59 - 01153384 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\libxml2.dll

2012-10-26 13:47 - 2012-08-06 11:59 - 00117608 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\zlib1.dll

2012-10-26 13:44 - 2012-06-07 23:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll

2012-06-08 12:34 - 2012-06-08 12:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll

2014-10-22 11:44 - 2014-10-22 11:44 - 00037696 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\qt_icontray_ex.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

 

 

==================== Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

 

==================== Hosts content: ===============================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2013-08-22 09:25 - 2013-08-22 09:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

 

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-21-2984815994-1181752439-1944922643-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Foff\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper

DNS Servers: [removed] - [removed]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Windows Firewall is enabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

(Currently there is no automatic fix for this section.)

 

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139

FirewallRules: [{4EA2BFA3-41A8-43FA-805B-43F4D0DBC820}] => (Allow) C:\Program Files (x86)\goodsearchtb\dtUser.exe

FirewallRules: [{E61742D2-5B12-45A9-A36F-46ED5ABC8294}] => (Allow) C:\Program Files (x86)\goodsearchtb\dtUser.exe

FirewallRules: [UDP Query User{30724531-DF40-4052-BAC4-D9607E8EEAA3}C:\users\foff\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\foff\appdata\local\akamai\netsession_win.exe

FirewallRules: [TCP Query User{FEEE38CE-6908-4355-804B-768C76AF792D}C:\users\foff\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\foff\appdata\local\akamai\netsession_win.exe

FirewallRules: [UDP Query User{68AB5FDD-3C1E-4C7A-AD96-B2D1236C2180}C:\program files (x86)\dell wireless\bluetooth suite\bttray.exe] => (Allow) C:\program files (x86)\dell wireless\bluetooth suite\bttray.exe

FirewallRules: [TCP Query User{9B296FCA-0E97-4809-B761-31AD98ECEBA5}C:\program files (x86)\dell wireless\bluetooth suite\bttray.exe] => (Allow) C:\program files (x86)\dell wireless\bluetooth suite\bttray.exe

FirewallRules: [UDP Query User{B2522265-351A-494E-BEBD-C547FE98E42D}C:\program files (x86)\dell wireless\bluetooth suite\btvstack.exe] => (Allow) C:\program files (x86)\dell wireless\bluetooth suite\btvstack.exe

FirewallRules: [TCP Query User{A7B197EE-108A-4872-B0D2-A03E6B1FE55A}C:\program files (x86)\dell wireless\bluetooth suite\btvstack.exe] => (Allow) C:\program files (x86)\dell wireless\bluetooth suite\btvstack.exe

FirewallRules: [{8EF4C556-4A82-441E-BC4B-B8803C542BB8}] => (Allow) LPort=1900

FirewallRules: [{1DD49869-BDAF-40E2-96ED-984C58DB2DD4}] => (Allow) LPort=2869

FirewallRules: [{6F39305A-9DF5-40D4-ABC6-759B9B6930EB}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

FirewallRules: [{651FFBA4-F8F4-495E-9A01-662A495E9151}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE

FirewallRules: [{545BFF2A-5347-4821-83BE-44E0D9922949}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe

FirewallRules: [{B0206E13-0A9F-4868-BF16-B649A9D532FE}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE

FirewallRules: [{DEA88BD2-B97F-4D23-A777-A3621525594D}] => (Allow) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Win7Ui.exe

FirewallRules: [{F6569546-A60A-4C85-B468-665BB0FA715B}] => (Allow) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtTray.exe

FirewallRules: [{85E82E10-7568-4CC4-886D-A720DE83E0AE}] => (Allow) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtTray.exe

FirewallRules: [{FE85EE32-1166-46E1-AF0C-B466BE7FB0C5}] => (Allow) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Btvstack.exe

FirewallRules: [{092C0665-C5C7-4E7A-8530-284E8ACB252C}] => (Allow) C:\Program Files (x86)\Canon\MF Toolbox Ver4.9\MFTBOX.exe

FirewallRules: [{514F9273-714C-4B7F-A1D3-4F749A923A8D}] => (Allow) C:\Program Files (x86)\Canon\MF Toolbox Ver4.9\MFTBOX.exe

FirewallRules: [{C07E6726-ECF6-49AC-B04E-7260E36C03E0}] => (Allow) C:\Program Files (x86)\Canon\MF Toolbox Ver4.9\MFTBOX.exe

FirewallRules: [{0E6F18B3-237D-480F-A6DB-8643090592DC}] => (Allow) C:\Program Files (x86)\Canon\MF Toolbox Ver4.9\MFTBOX.exe

FirewallRules: [{4ABFC6F3-973D-42F7-AFCF-44860468C62C}] => (Allow) C:\WINDOWS\Camera\Camera.exe

FirewallRules: [{001D3E3D-109B-408D-88CE-CF628CAA9EA6}] => (Allow) C:\WINDOWS\Camera\Camera.exe

FirewallRules: [{D49007EC-615C-4A05-9DE0-5DF75A875218}] => (Allow) C:\WINDOWS\Camera\Camera.exe

FirewallRules: [{4FE70F08-25F3-43B6-81D9-12763894572A}] => (Allow) C:\WINDOWS\Camera\Camera.exe

FirewallRules: [{5F7167B3-92C6-42F6-AA75-6BD5C7EA31AC}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe

FirewallRules: [{E0587FC4-DCA9-4E7F-9B05-6515C1183E94}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe

FirewallRules: [{77CB1F58-2D2A-4227-B9E0-21F1B74D0BCC}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe

FirewallRules: [{5FD22C13-EB4A-4C7B-8F48-4083FF4208C0}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe

 

==================== Restore Points =========================

 

11-04-2016 10:10:13 Windows Update

18-04-2016 10:01:37 Windows Update

25-04-2016 10:06:46 Dell Update: Realtek USB Audio

09-05-2016 10:05:10 Windows Update

13-05-2016 14:36:11 Windows Update

18-05-2016 09:25:37 Windows Update

31-05-2016 10:01:39 Windows Update

 

==================== Faulty Device Manager Devices =============

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (06/03/2016 05:55:11 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: ERUNT.exe, version: 0.0.0.0, time stamp: 0x2a425e19

Faulting module name: ERUNT.exe, version: 0.0.0.0, time stamp: 0x2a425e19

Exception code: 0xc0000005

Fault offset: 0x00005289

Faulting process id: 0x1cd4

Faulting application start time: 0xERUNT.exe0

Faulting application path: ERUNT.exe1

Faulting module path: ERUNT.exe2

Report Id: ERUNT.exe3

Faulting package full name: ERUNT.exe4

Faulting package-relative application ID: ERUNT.exe5

 

Error: (06/03/2016 05:13:37 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: esetonlinescanner_enu.exe, version: 2.0.8.0, time stamp: 0x573dab40

Faulting module name: esetonlinescanner_enu.exe, version: 2.0.8.0, time stamp: 0x573dab40

Exception code: 0xc0000005

Fault offset: 0x001a4894

Faulting process id: 0x1e9c

Faulting application start time: 0xesetonlinescanner_enu.exe0

Faulting application path: esetonlinescanner_enu.exe1

Faulting module path: esetonlinescanner_enu.exe2

Report Id: esetonlinescanner_enu.exe3

Faulting package full name: esetonlinescanner_enu.exe4

Faulting package-relative application ID: esetonlinescanner_enu.exe5

 

Error: (06/02/2016 12:49:59 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FoffPc)

Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail failed with error: -2147024809 See the Microsoft-Windows-TWinUI/Operational log for additional information.

 

Error: (05/31/2016 11:52:01 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )

Description: Failed to schedule Software Protection service for re-start at 2116-05-07T15:51:52Z. Error Code: 0x80071A91.

 

Error: (05/19/2016 01:33:06 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)

Description: There was an error with the Windows Location Provider database

 

Error: (05/10/2016 12:07:46 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18124, time stamp: 0x5641278d

Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000

Exception code: 0xc0000409

Fault offset: 0x00000000

Faulting process id: 0x1a58

Faulting application start time: 0xIEXPLORE.EXE0

Faulting application path: IEXPLORE.EXE1

Faulting module path: IEXPLORE.EXE2

Report Id: IEXPLORE.EXE3

Faulting package full name: IEXPLORE.EXE4

Faulting package-relative application ID: IEXPLORE.EXE5

 

Error: (05/06/2016 10:05:47 AM) (Source: Application Hang) (EventID: 1002) (User: )

Description: The program OUTLOOK.EXE version 14.0.7168.5000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

 

Process ID: 17f8

 

Start Time: 01d1a79fa4e23737

 

Termination Time: 0

 

Application Path: C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE

 

Report Id: 8a5ed0dc-1393-11e6-bed7-68942319851e

 

Faulting package full name:

 

Faulting package-relative application ID:

 

Error: (05/05/2016 02:56:56 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FoffPc)

Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

 

Error: (05/05/2016 02:56:56 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FoffPc)

Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

 

Error: (05/02/2016 01:23:12 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18124, time stamp: 0x5641278d

Faulting module name: ntdll.dll, version: 6.3.9600.18194, time stamp: 0x569515fc

Exception code: 0xc0000017

Fault offset: 0x0008697f

Faulting process id: 0x194c

Faulting application start time: 0xIEXPLORE.EXE0

Faulting application path: IEXPLORE.EXE1

Faulting module path: IEXPLORE.EXE2

Report Id: IEXPLORE.EXE3

Faulting package full name: IEXPLORE.EXE4

Faulting package-relative application ID: IEXPLORE.EXE5

 

 

System errors:

=============

Error: (06/03/2016 04:11:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The eapihdrv service failed to start due to the following error:

%%1275

 

Error: (06/03/2016 04:11:38 PM) (Source: Application Popup) (EventID: 1060) (User: )

Description: \??\C:\Users\Foff\AppData\Local\Temp\ehdrv.sys

 

Error: (06/03/2016 04:11:37 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The eapihdrv service failed to start due to the following error:

%%1275

 

Error: (06/03/2016 04:11:37 PM) (Source: Application Popup) (EventID: 1060) (User: )

Description: \??\C:\Users\Foff\AppData\Local\Temp\ehdrv.sys

 

Error: (06/03/2016 04:11:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The eapihdrv service failed to start due to the following error:

%%1275

 

Error: (06/03/2016 04:11:36 PM) (Source: Application Popup) (EventID: 1060) (User: )

Description: \??\C:\Users\Foff\AppData\Local\Temp\ehdrv.sys

 

Error: (06/02/2016 02:01:30 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )

Description: 4

 

Error: (05/31/2016 02:59:09 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )

Description: 4

 

Error: (05/31/2016 11:52:01 AM) (Source: Ntfs) (EventID: 138) (User: )

Description: The transaction resource manager at C:\ encountered a fatal error and was shut down.  The data contains the error code.

 

Error: (05/25/2016 02:57:22 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )

Description: 4

 

 

==================== Memory info ===========================

 

Processor: Intel(R) Core(TM) i5-3350P CPU @ 3.10GHz

Percentage of memory in use: 31%

Total physical RAM: 8153 MB

Available physical RAM: 5558.84 MB

Total Virtual: 10585 MB

Available Virtual: 5272.83 MB

 

==================== Drives ================================

 

Drive c: (OS) (Fixed) (Total:922.73 GB) (Free:851.96 GB) NTFS

Drive x: (PBR Image) (Fixed) (Total:6.86 GB) (Free:0.25 GB) NTFS

Drive y: (WINRETOOLS) (Fixed) (Total:0.49 GB) (Free:0.22 GB) NTFS

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (Size: 931.5 GB) (Disk ID: 63D039CA)

 

Partition: GPT.

==================== End of Addition.txt ============================

Hi TheCatMan,
 
Welcome to WTT.
 
There are many reasons that e-mails fail or are rejected.  Which is happening with your system.  Are they failing or are the being rejected?  Do the undeliverable e-mails contain attachments?
 
Let's do some cleanup and see how it goes:
 
STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    start
    CreateRestorePoint:
    CMD: ipconfig /flushdns
    EmptyTemp:
    SearchScopes: HKU\S-1-5-21-2984815994-1181752439-1944922643-1001 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11913&l=dis&prt=NSBU&chn=1001190&geo=US&ver=22&locale=en_US&gct=kwd&qsrc=2869
    SearchScopes: HKU\S-1-5-21-2984815994-1181752439-1944922643-1001 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80273&iwk=275&lng=en
    CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
    S4 LMIRfsClientNP; no ImagePath
    U3 aswMBR; \??\C:\Users\Foff\AppData\Local\Temp\aswMBR.sys [X]
    U3 aswVmm; \??\C:\Users\Foff\AppData\Local\Temp\aswVmm.sys [X]
    Task: {0D8A891D-890C-4808-84D8-2F436AB14653} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
    Task: {1274336E-AB06-46B6-A48C-0671C5557CC6} - \Microsoft\Windows\TaskScheduler\Maintenance Configurator -> No File <==== ATTENTION
    Task: {1687544D-7247-4F5A-965A-A6E920E55278} - \Microsoft\Windows\TaskScheduler\Manual Maintenance -> No File <==== ATTENTION
    Task: {40525C58-79C2-47A1-9AA2-F1D7FC4F0691} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
    Task: {6F02587F-8A2B-4552-97F6-DEEF229E335B} - \Microsoft\Windows\TaskScheduler\Idle Maintenance -> No File <==== ATTENTION
    Task: {B7992938-01F1-4F40-A0EC-0D23D2F0F152} - \Microsoft\Windows\TaskScheduler\Regular Maintenance -> No File <==== ATTENTION
    Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - \Microsoft\Windows\SettingSync\BackupTask -> No File <==== ATTENTION
    FirewallRules: [{4EA2BFA3-41A8-43FA-805B-43F4D0DBC820}] => (Allow) C:\Program Files (x86)\goodsearchtb\dtUser.exe
    FirewallRules: [{E61742D2-5B12-45A9-A36F-46ED5ABC8294}] => (Allow) C:\Program Files (x86)\goodsearchtb\dtUser.exe
    end
  • Click File, Save As and type fixlist.txt as the File Name.
  • Important: The file must be saved in the same location as FRST64.exe.

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Right-click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the program.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.
     

STEP 2
[external image: sSxh9jE.png]Junkware Removal Tool (JRT)

  • Please download Junkware Removal Tool and save the file to your Desktop.
  • Temporarily disable your Anti-Virus software. For instructions, please refer to the following link.
  • Right-click JRT.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the program.
  • Follow the prompts and allow the scan to run uninterrupted.
  • Upon completion, a log (JRT.txt) will open on your Desktop.
  • Re-enable your Anti-Virus software.
  • Copy the contents of JRT.txt and paste in your next reply.
     

STEP 3
[external image: eL8MiAP.png]AdwCleaner

  • Please download AdwCleaner and save the file to your Desktop.
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the program.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.

– File and folder backups are made for items removed using this program. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[S1].txt.
 
======================================================

STEP 4
[external image: pfNZP4A.png]Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • Fixlog.txt
  • JRT.txt
  • AdwCleaner[C1].txt

TomK,

 

I have completed the first set of instructions you gave me. When I ran the ADW Cleaner it only picked up registry items. I do not use this computer normally and did not set it up so I was not sure what was supposed to be there and what was not supposed to be there so I removed the checks from all the check boxes. I figured that was the safest and most conservative route. I have included both the S1 and C1 ADW logs for your review.

 

Thanks,

 

The Cat Man

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version:05-06-2016 02

 

Ran by [removed] (2016-06-06 15:49:29) Run:1

 

Running from C:\Users\[removed]\Desktop

 

[removed]

 

Boot Mode: Normal

 

==============================================

 

 

fixlist content:

 

*****************

 

start

 

CreateRestorePoint:

 

CMD: ipconfig /flushdns

 

EmptyTemp:

 

SearchScopes: HKU\S-1-5-21-2984815994-1181752439-1944922643-1001 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11913&l=dis&prt=NSBU&chn=1001190&geo=US&ver=22&locale=en_US&gct=kwd&qsrc=2869

 

SearchScopes: HKU\S-1-5-21-2984815994-1181752439-1944922643-1001 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80273&iwk=275&lng=en

 

CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

 

CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

 

S4 LMIRfsClientNP; no ImagePath

 

U3 aswMBR; \??\C:\Users\Foff\AppData\Local\Temp\aswMBR.sys [X]

 

U3 aswVmm; \??\C:\Users\Foff\AppData\Local\Temp\aswVmm.sys [X]

 

Task: {0D8A891D-890C-4808-84D8-2F436AB14653} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION

 

Task: {1274336E-AB06-46B6-A48C-0671C5557CC6} - \Microsoft\Windows\TaskScheduler\Maintenance Configurator -> No File <==== ATTENTION

 

Task: {1687544D-7247-4F5A-965A-A6E920E55278} - \Microsoft\Windows\TaskScheduler\Manual Maintenance -> No File <==== ATTENTION

 

Task: {40525C58-79C2-47A1-9AA2-F1D7FC4F0691} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION

 

Task: {6F02587F-8A2B-4552-97F6-DEEF229E335B} - \Microsoft\Windows\TaskScheduler\Idle Maintenance -> No File <==== ATTENTION

 

Task: {B7992938-01F1-4F40-A0EC-0D23D2F0F152} - \Microsoft\Windows\TaskScheduler\Regular Maintenance -> No File <==== ATTENTION

 

Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - \Microsoft\Windows\SettingSync\BackupTask -> No File <==== ATTENTION

 

FirewallRules: [{4EA2BFA3-41A8-43FA-805B-43F4D0DBC820}] => (Allow) C:\Program Files (x86)\goodsearchtb\dtUser.exe

 

FirewallRules: [{E61742D2-5B12-45A9-A36F-46ED5ABC8294}] => (Allow) C:\Program Files (x86)\goodsearchtb\dtUser.exe

 

end

 

*****************

 

 

Restore point was successfully created.

 

 

=========  ipconfig /flushdns =========

 

 

 

Windows IP Configuration

 

 

Successfully flushed the DNS Resolver Cache.

 

 

========= End of CMD: =========

 

 

"HKU\S-1-5-21-2984815994-1181752439-1944922643-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}" => key removed successfully

 

HKCR\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => key not found.

 

"HKU\S-1-5-21-2984815994-1181752439-1944922643-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}" => key removed successfully

 

HKCR\CLSID\{C04B7D22-5AEC-4561-8F49-27F6269208F6} => key not found.

 

"HKLM\SOFTWARE\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif" => key removed successfully

 

"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif" => key removed successfully

 

LMIRfsClientNP => service removed successfully

 

aswMBR => service removed successfully

 

aswVmm => service removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0D8A891D-890C-4808-84D8-2F436AB14653}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D8A891D-890C-4808-84D8-2F436AB14653}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\AitAgent" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1274336E-AB06-46B6-A48C-0671C5557CC6}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1274336E-AB06-46B6-A48C-0671C5557CC6}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Maintenance Configurator" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1687544D-7247-4F5A-965A-A6E920E55278}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1687544D-7247-4F5A-965A-A6E920E55278}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Manual Maintenance" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{40525C58-79C2-47A1-9AA2-F1D7FC4F0691}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40525C58-79C2-47A1-9AA2-F1D7FC4F0691}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6F02587F-8A2B-4552-97F6-DEEF229E335B}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F02587F-8A2B-4552-97F6-DEEF229E335B}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Idle Maintenance" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B7992938-01F1-4F40-A0EC-0D23D2F0F152}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7992938-01F1-4F40-A0EC-0D23D2F0F152}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Regular Maintenance" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CFD7C21A-808B-487B-A6EC-8A10E44E8360}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CFD7C21A-808B-487B-A6EC-8A10E44E8360}" => key removed successfully

 

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SettingSync\BackupTask" => key removed successfully

 

HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4EA2BFA3-41A8-43FA-805B-43F4D0DBC820} => value removed successfully

 

HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E61742D2-5B12-45A9-A36F-46ED5ABC8294} => value removed successfully

 

EmptyTemp: => 525.4 MB temporary data Removed.

 

 

 

The system needed a reboot.

 

 

==== End of Fixlog 15:50:19 ====

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

Junkware Removal Tool (JRT) by Malwarebytes

 

Version: 8.0.6 (04.25.2016)

 

Operating System: Windows 8.1 x64

 

Ran by [removed] (Administrator) on Mon 06/06/2016 at 16:05:20.36

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

 

 

File System: 2

 

 

Successfully deleted: C:\WINDOWS\system32\Tasks\PCDEventLauncherTask (Task)

 

Successfully deleted: C:\WINDOWS\system32\Tasks\PCDoctorBackgroundMonitorTask (Task)

 

 

 

 

Registry: 7

 

 

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3F37605F-3094-45DD-B6AB-707DEEA7CEB4} (Registry Key)

 

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} (Registry Key)

 

Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44520b54-9e1a-420b-aac8-b53721cbd53f} (Registry Key)

 

Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd9475f4-a228-4e22-8d37-4b52c2054c31} (Registry Key)

 

Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44520b54-9e1a-420b-aac8-b53721cbd53f} (Registry Key)

 

Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd9475f4-a228-4e22-8d37-4b52c2054c31} (Registry Key)

 

Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{44520b54-9e1a-420b-aac8-b53721cbd53f} (Registry Value)

 

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

Scan was completed on Mon 06/06/2016 at 16:06:44.75

 

End of JRT log

 

 

# AdwCleaner v5.119 - Logfile created 06/06/2016 at 16:11:15

 

# Updated 30/05/2016 by Xplode

 

# Database : 2016-06-06.1 [Server]

 

# Operating system : Windows 8.1  (X64)

 

# Username : Foff - FOFFPC

 

# Running from : C:\Users\Foff\Desktop\AdwCleaner.exe

 

# Option : Scan

 

# Support : http://toolslib.net/forum

 

 

***** [ Services ] *****

 

 

 

***** [ Folders ] *****

 

 

 

***** [ Files ] *****

 

 

 

***** [ DLL ] *****

 

 

 

***** [ WMI ] *****

 

 

 

***** [ Shortcuts ] *****

 

 

 

***** [ Scheduled tasks ] *****

 

 

 

***** [ Registry ] *****

 

 

Key Found : HKLM\SOFTWARE\Classes\CLSID\{0002DF01-0000-0000-C000-000000000046}

 

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{042DA63B-0933-403D-9395-B49307691690}

 

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}

 

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}

 

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}

 

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}

 

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

 

Key Found : HKU\S-1-5-21-2984815994-1181752439-1944922643-1001\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

 

Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com

 

Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\dotomi.com

 

Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\inbox.com

 

Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\nortonsafe.search.ask.com

 

Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com

 

Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.ask.com

 

 

***** [ Web browsers ] *****

 

 

 

*************************

 

 

C:\AdwCleaner\AdwCleaner[S1].txt - [2067 bytes] - [06/06/2016 16:11:15]

 

 

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2140 bytes] ##########

 

 

 

 

# AdwCleaner v5.119 - Logfile created 06/06/2016 at 16:14:31

 

# Updated 30/05/2016 by Xplode

 

# Database : 2016-06-06.1 [Server]

 

# Operating system : Windows 8.1  (X64)

 

# Username : Foff - FOFFPC

 

# Running from : C:\Users\Foff\Desktop\AdwCleaner.exe

 

# Option : Clean

 

# Support : http://toolslib.net/forum

 

 

***** [ Services ] *****

 

 

 

***** [ Folders ] *****

 

 

 

***** [ Files ] *****

 

 

 

***** [ DLLs ] *****

 

 

 

***** [ WMI ] *****

 

 

 

***** [ Shortcuts ] *****

 

 

 

***** [ Scheduled tasks ] *****

 

 

 

***** [ Registry ] *****

 

 

[x] Key Not Deleted : HKLM\SOFTWARE\Classes\CLSID\{0002DF01-0000-0000-C000-000000000046}

 

[x] Key Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{042DA63B-0933-403D-9395-B49307691690}

 

[x] Key Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}

 

[x] Key Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}

 

[x] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}

 

[x] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}

 

[x] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

 

[x] Key Not Deleted : HKU\S-1-5-21-2984815994-1181752439-1944922643-1001\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

 

[x] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com

 

[x] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\dotomi.com

 

[x] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\inbox.com

 

[x] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\nortonsafe.search.ask.com

 

[x] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com

 

[x] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.ask.com

 

 

***** [ Web browsers ] *****

 

 

 

*************************

 

 

:: "Tracing" keys deleted

 

:: Winsock settings cleared

 

 

*************************

 

 

C:\AdwCleaner\AdwCleaner[C1].txt - [2296 bytes] - [06/06/2016 16:14:31]

 

C:\AdwCleaner\AdwCleaner[S1].txt - [2219 bytes] - [06/06/2016 16:11:15]

 

 

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2442 bytes] ##########

Nothing shown on the AdwCleaner logs are "needed", but they aren't "terrible" either.  Mostly resource hogs, but they can "divert" searches also.

 

The bottom line is that all I did with the script if clean up some orphans.  JRT mostly cleared some more and you know about Adwcleaner.

 

Nothing I have found should be responsible for email issues.  Do you have any other information that might be pertinent?

Tom K,

 

E-mail functionality has improved greatly since completing your last instructions. The office manager has only gotten one bounce back today which is from the e-mail address listed in Message 1 below. She is now able to send e-mail to my address so I had her send me a sampling of the bounce back messages she has been receiving from various e-mail addresses. They are pasted below. One of their concerns is that their e-mail server has somehow been blacklisted. I have not started looking any of this stuff up on my own yet. I plan on doing that tonight. If you have any ideas based on what you see below I would greatly appreciate it.

 

Thanks so much for your help.

 

Sincerely,

 

The Cat Man

 

Message 1

 

—–Original Message—–
From: Mail Delivery System
[mailto:[removed]]
Sent: Tuesday, June 7, 2016 9:57 AM
To:
[removed]
Subject: Undelivered Mail Returned to Sender

This is the mail system at host gateway24.websitewelcome.com.

I'm sorry to have to inform you that your message could not be delivered to
one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can delete your own
text from the attached returned message.

                   The mail system

<
[removed]>: host gmail-smtp-in.l.google.com[108.177.10.27] said:
    550-5.7.1 [[removed]      12] Our system has detected that this
    message is 550-5.7.1 likely unsolicited mail. To reduce the amount of
spam
    sent to Gmail, 550-5.7.1 this message has been blocked. Please visit 550
    5.7.1 
https://support.google.com/mail/answer/188131 for more
information.
    p36si8607662otb.220 - gsmtp (in reply to end of DATA command)

 

Message 2

 

I'm sorry to have to inform you that your message could not be delivered to
one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can delete your own
text from the attached returned message.

                   The mail system

<
[removed]>: host cdptpa-pub-iedge-vip.email.rr.com[107.14.166.70]
    refused to talk to me: 421 4.7.1 - Connection refused - <192.185.47.48>
-
    Too many concurrent connections ( <13> ) from source IP

 

Message 3

—–Original Message—–
From: Mail Delivery System
[mailto:[removed]]
Sent: Thursday, December 31, 2015 2:24 PM
To:
[removed]
Subject: Undelivered Mail Returned to Sender

This is the mail system at host gateway20.websitewelcome.com.

I'm sorry to have to inform you that your message could not be delivered to
one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can delete your own
text from the attached returned message.

                   The mail system

<
[removed]>: delivery temporarily suspended: lost connection with
    mta6.am0.yahoodns.net[[removed]] while sending RCPT TO

 

Message 4

 

—–Original Message—–
From: Mail Delivery System
[mailto:[removed]]
Sent: Wednesday, January 27, 2016 1:02 PM
To:
[removed]
Subject: Undelivered Mail Returned to Sender

This is the mail system at host gateway22.websitewelcome.com.

I'm sorry to have to inform you that your message could not be delivered to
one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can delete your own
text from the attached returned message.

                   The mail system

<
[removed]>: host
    cdptpa-pub-iedge-vip.email.rr.com[107.14.166.70] refused to talk to me:
421
    4.7.1 - Connection refused - <192.185.47.109> -  Too many concurrent
    connections ( <30> ) from source IP

 

Message 5


—–Original Message—–
From: Mail Delivery System
[mailto:[removed]]
Sent: Wednesday, January 27, 2016 12:40 PM
To:
[removed]
Subject: Undelivered Mail Returned to Sender

This is the mail system at host gateway36.websitewelcome.com.

I'm sorry to have to inform you that your message could not be delivered to
one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can delete your own
text from the attached returned message.

                   The mail system

<
[removed]>: delivery temporarily suspended: lost connection with
    mta6.am0.yahoodns.net[[removed]] while sending RCPT TO

 

Message 6

 

—–Original Message—–
From: Mail Delivery System
[mailto:[removed]]
Sent: Wednesday, January 27, 2016 2:22 PM
To:
[removed]
Subject: Undelivered Mail Returned to Sender

This is the mail system at host gateway34.websitewelcome.com.

I'm sorry to have to inform you that your message could not be delivered to
one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can delete your own
text from the attached returned message.

                   The mail system

<
[removed]>: delivery temporarily suspended: lost connection
with
    mta7.am0.yahoodns.net[[removed]] while sending RCPT TO

I'm glad to hear things are better, but I'm surprise.

 

Several IP addresses show.  Of course, they are related… but they also appear on some black lists and have been reported as an address that spams thousands of times.  Here is an example report.  https://cleantalk.org/blacklists?record=192.185.51.251 Any of those IP addresses will give you essentially the same report because they are part of the same network.  That particular report is not actually reports as spam email… but rather reports from spamming wordpress sites.  Like blogs.  What is very strange to me as all of those addresses are in Texas and this computer is in Maine.  Perhaps these are spoofed mails that are getting rejected and didn't actually originate from this computer?

 

The first report gives you a link to find why gmail rejected the email.  It "appears" to resemble spam.  There are formulas for this.  Specific words or combinations of words in the title.  Is it forwarded.  Is it a mass mail.  Style of the message.  Honestly, sometimes this type of rejection "clears" itself and the email may got through hours later or the next day.

 

A couple of the reports show the email was blocked because of multiple connections.  The system blocked it because the system was getting flooded with connection requests from the same address.  I don't know why.

 

Some of the reports are simply connection failures.  Again, I don't know what causes that… but I know I get them from time to time and I just resend later and they usually go through.

 

The fact is I just don't know enough about this to be helpful.  But, seeing as how that little bit of straitening up seemed like it helped, let's do a couple more things.

 

STEP 1
[external image: Ky7CZ60.png] Malwarebytes Anti-Malware (MBAM)

  • Your version of MBAM is outdated. Please download the Malwarebytes Anti-Malware setup file to your Desktop.
  • Please download the Malwarebytes Anti-Malware setup file to your Desktop.
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the program. 
  • Open Malwarebytes Anti-Malware. 
  • Click the Settings tab, followed by Detection and Protection and place a checkmark next to Scan for rootkits.
  • Click the Scan tab, ensure Threat Scan is selected and click Start Scan.
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards. 
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs, followed by the first Scan Log.
  • Click Export, followed by Copy to Clipboard. Paste the log in your next reply. 
     

STEP 2
[external image: GzlsbnV.png] ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

  • Please download ESET Online Scan and save the file to your Desktop.
  • Temporarily disable your Anti-Virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the program. 
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Place a checkmark next to Enable detection of potentially unwanted applications.
  • Click Advanced settings. Place a checkmark next to:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Ensure Remove found threats is unchecked.
  • Click Start.
  • Wait for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click List of found threats….  
  • Click Export and save the file to your Desktop, naming it something such as "ESET Scan".
  • Click the Back button.
  • Note: If no threats were found, there will be no log to save. 
  • Place a checkmark next to [external image: KN1w2nv.png] and click [external image: SzOC1p0.png].
  • Re-enable your Anti-Virus software.
  • Copy the contents of the log and paste in your next reply.
     

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs.

  • MBAM Scan log
  • ESET Online Scan log

Tom K,

 

I will try to get this done tomorrow night or Thursday night. My home is 30 miles south of the office so I have to make the trip up there to get this done so please bear with me. I will also talk to the president of the organization and find out more details about who runs the web site and e-mail for the organization. I know that our ISP is Great Works Internet but we do not have e-mail through them.

 

The name of our organization is Friends of Feral Felines in Portland Maine. We do trap, neuter, release work for feral cats. We are a non-profit staffed mostly by volunteers, like myself.

 

Thanks for your help and I will get back to you ASAP.

 

The Cat Man

TomK

 

I have completed the scans that you requested and the logs are pasted below.

Also, I have been receiving my e-mails from the FOFF office manager but she is still getting bounce back messages saying they have been rejected. It is happening with several of our other volunteers as well. I found out today that there has been issues with e-mail since last May.

 

Thanks for your help.

 

The Cat Man

 

MALWAREBYTES LOG

 

Malwarebytes Anti-Malware

www.malwarebytes.org

 

Scan Date: 6/9/2016

Scan Time: 3:56 PM

Logfile: MalwareBytes Scan Log 06_09_2016.txt

Administrator: Yes

 

Version: 2.2.1.1043

Malware Database: v2016.06.09.05

Rootkit Database: v2016.05.27.01

License: Trial

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

 

OS: Windows 8.1

CPU: x64

File System: NTFS

User: Foff

 

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 319734

Time Elapsed: 17 min, 23 sec

 

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Enabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

 

Processes: 0

(No malicious items detected)

 

Modules: 0

(No malicious items detected)

 

Registry Keys: 5

PUP.Optional.InboxToolBar, HKU\S-1-5-21-2984815994-1181752439-1944922643-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{042DA63B-0933-403D-9395-B49307691690}, Quarantined, [7e6be911f6a35adc8e8620685ba79a66],

PUP.Optional.InboxToolBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{612AD33D-9824-4E87-8396-92374E91C4BB}, Quarantined, [8e5b50aa1683ae884751027f7290827e],

PUP.Optional.InboxToolBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{612AD33D-9824-4E87-8396-92374E91C4BB}, Quarantined, [8e5b50aa1683ae884751027f7290827e],

PUP.Optional.InboxToolBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [12d73dbdc6d39d991980ed948b77a25e],

PUP.Optional.InboxToolBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, Quarantined, [d019be3c8514e5510c8ed3aea161cb35],

 

Registry Values: 0

(No malicious items detected)

 

Registry Data: 0

(No malicious items detected)

 

Folders: 0

(No malicious items detected)

 

Files: 0

(No malicious items detected)

 

Physical Sectors: 0

(No malicious items detected)

 

 

(end)

ESET LOG

C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\hstart.exe                a variant of Win32/HiddenStart.A potentially unsafe application

C:\Program Files (x86)\goodsearchtb\dtUser.exe            a variant of Win32/Toolbar.Visicom.C potentially unwanted application

C:\Program Files (x86)\goodsearchtb\goodsearchDx.dll                a variant of Win32/Toolbar.Visicom.B potentially unwanted application

C:\Program Files (x86)\goodsearchtb\goodsearchtb.dll a variant of Win32/Toolbar.Visicom.A potentially unwanted application

C:\Program Files (x86)\goodsearchtb\uninstall.exe         a variant of Win32/Toolbar.Visicom.E potentially unwanted application

C:\Users\Foff\Downloads\SetupImgBurn_2.5.7.0.exe   a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application

Is she sending emails that directly correlate to the rejection notice?  Does she know for sure that she actually sent an email that was bounced?

TomK,

 

All of the bounce back messages that she received were due to e-mails that she typed up and sent from the office computer. Usually she gets the messages shortly after she sends the e-mail. Up until I completed the first steps of clearing things off of the computer based on the instructions you gave me no one was receiving their mail. They all got bounced back which effectively killed our ability to communicate via e-mail. Now most people are getting their mail and are responding but she is still getting bounce back messages. The messages are exactly the same as the ones I posted. It is very strange.

 

The Cat Man

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI