This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System running slow, possible malware?

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HP Compaq 8000 running Win 7 Pro

slow startup, slow operation , it appears the C drive disk space used has grown in size, screen display changes in mid use sometimes 

aswMBR and FRST results pasted below,

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-07-18 16:36:57
—————————–
16:36:57.186    OS Version: Windows 6.1.7601 Service Pack 1
16:36:57.196    Number of processors: 2 586 0x170A
16:36:57.196    ComputerName: PC-MXL0280  UserName: jndinonno
16:37:56.706    Initialize success
16:37:57.198    VM: initialized successfully
16:37:57.208    VM: Intel CPU BiosDisabled
16:40:14.476    AVAST engine defs: 16071801
16:42:35.736    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4
16:42:35.746    Disk 0 Vendor: HDS728080PLA380 PF2OA63A Size: 76293MB BusType: 11
16:42:35.896    Disk 0 MBR read successfully
16:42:35.906    Disk 0 MBR scan
16:42:36.028    Disk 0 Windows 7 default MBR code
16:42:36.048    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS         6000 MB offset 2048
16:42:36.078    Disk 0 default boot code
16:42:36.185    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        70291 MB offset 12290048
16:42:36.270    Disk 0 scanning sectors +156247952
16:42:36.503    Disk 0 scanning C:\windows\system32\drivers
16:43:04.237    Service scanning
16:43:24.008    Service MpKsl41b11dbf c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D158A5B6-59D3-40C0-A5B8-5B668C88B6DC}\MpKsl41b11dbf.sys **LOCKED** 32
16:43:43.637    Modules scanning
16:43:43.637    Disk 0 trace - called modules:
16:43:43.647    ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys
16:43:43.647    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85c3a228]
16:43:43.647    3 CLASSPNP.SYS[88dc659e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0x85723908]
16:43:44.077    AVAST engine scan C:\windows
16:43:47.009    AVAST engine scan C:\windows\system32
16:48:52.623    AVAST engine scan C:\windows\system32\drivers
16:49:17.276    AVAST engine scan C:\Users\jndinonno
16:52:04.085    Disk 0 MBR has been saved successfully to "C:\Users\jndinonno\Desktop\MBR.dat"
16:52:04.125    The log file has been saved successfully to "C:\Users\jndinonno\Desktop\aswMBR.txt"

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-07-2016
Ran by [removed] (administrator) on PC-MXL0280 (18-07-2016 16:55:08)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgcsrvx.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgwdsvcx.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgui.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgemcx.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_21_0_0_242_ActiveX.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\…\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguirnx.exe [186640 2016-06-21] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [AVG_UI] => C:\Program Files\AVG\Av\avgui.exe [5351184 2016-06-29] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\…\MountPoints2: D - D:\Autorun.exe
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\…\MountPoints2: {5aec79a5-ad61-11e5-b3fd-0023240a3369} - J:\LaunchU3.exe -a
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\ssText3d.scr [293888 2010-11-20] (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-4252558748-1657619972-2942562243-1001] => localhost:8080
AutoConfigURL: [S-1-5-21-4252558748-1657619972-2942562243-1001] => localhost:8080
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{55D1C7AC-33B4-4BD8-B4DC-A42D2B45F190}: [DhcpNameServer] 192.168.1.254

Internet Explorer:
==================
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpage.com/
SearchScopes: HKU\S-1-5-21-4252558748-1657619972-2942562243-1001 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://search.yahoo.com/search?ei=ISO-8859-1&fr;=chr-vmn&type;=egames3_1yach&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-4252558748-1657619972-2942562243-1001 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://search.yahoo.com/search?ei=ISO-8859-1&fr;=chr-vmn&type;=egames3_1yach&q;={searchTerms}
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_77\bin\ssv.dll [2016-04-18] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-18] (Oracle Corporation)
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} hxxp://www.shockwave.com/content/zuma/sis/popcaploader_v10.cab

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_11_5_502_118.dll [2015-01-25] ()
FF Plugin: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-18] (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2012-12-12] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-19]
CHR Extension: (Google Drive) - C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-19]
CHR Extension: (YouTube) - C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-03-19]
CHR Extension: (Gmail) - C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-19]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AvgAMPS; C:\Program Files\AVG\Av\avgamps.exe [637944 2016-06-29] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files\AVG\Av\avgidsagent.exe [4092672 2016-06-29] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [890128 2016-06-21] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\Av\avgwdsvcx.exe [594904 2016-06-29] (AVG Technologies CZ, s.r.o.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 Avgdiskx; C:\windows\System32\DRIVERS\avgdiskx.sys [134912 2016-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\windows\System32\DRIVERS\avgidsdriverx.sys [255744 2016-06-09] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\windows\System32\DRIVERS\avgidshx.sys [201472 2016-06-01] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\windows\System32\DRIVERS\avgidsshimx.sys [31664 2015-11-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\windows\System32\DRIVERS\avgldx86.sys [212736 2016-06-01] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\windows\System32\DRIVERS\avglogx.sys [287008 2016-02-16] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\windows\System32\DRIVERS\avgmfx86.sys [191744 2016-06-02] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\windows\System32\DRIVERS\avgrkx86.sys [47360 2016-06-01] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\windows\System32\DRIVERS\avgtdix.sys [217344 2016-06-01] (AVG Technologies CZ, s.r.o.)
R0 Avgunivx; C:\windows\System32\DRIVERS\avgunivx.sys [65280 2016-06-01] (AVG Technologies CZ, s.r.o.)
S3 EsgScanner; C:\windows\System32\DRIVERS\EsgScanner.sys [19984 2016-01-18] ()
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R1 MpKsl41b11dbf; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D158A5B6-59D3-40C0-A5B8-5B668C88B6DC}\MpKsl41b11dbf.sys [39168 2016-07-18] (Microsoft Corporation)
S3 MxEF; C:\windows\system32\drivers\MxEF32.sys [81920 2011-08-15] (Matrox Graphics Inc.)
S3 MxEFLF; C:\windows\system32\drivers\MxEFLF32.sys [80384 2011-08-15] (Matrox Graphics Inc.)
S3 MxEFUF; C:\windows\system32\drivers\MxEFUF32.sys [108544 2011-08-15] (Matrox Graphics Inc.)
S3 MxEMgr; C:\windows\system32\drivers\MxEMgr32.sys [92192 2011-08-16] (Matrox Graphics Inc.)
S3 SWDUMon; C:\windows\System32\DRIVERS\SWDUMon.sys [22728 2016-04-18] (SlimWare Utilities, Inc.)
S3 RtlWlanu; system32\DRIVERS\rtwlanu.sys [X]
U3 aswMBR; \??\C:\Users\JNDINO~1\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\JNDINO~1\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-07-18 16:54 - 2016-07-18 16:54 - 00022441 _____ C:\Users\jndinonno\Desktop\Addition.txt
2016-07-18 16:53 - 2016-07-18 16:55 - 00010041 _____ C:\Users\jndinonno\Desktop\FRST.txt
2016-07-18 16:53 - 2016-07-18 16:55 - 00000000 ____D C:\FRST
2016-07-18 16:52 - 2016-07-18 16:52 - 00002103 _____ C:\Users\jndinonno\Desktop\aswMBR.txt
2016-07-18 16:52 - 2016-07-18 16:52 - 00000512 _____ C:\Users\jndinonno\Desktop\MBR.dat
2016-07-18 16:35 - 2016-07-18 16:35 - 01741824 _____ (Farbar) C:\Users\jndinonno\Desktop\FRST.exe
2016-07-18 16:32 - 2016-07-18 16:32 - 05198336 _____ (AVAST Software) C:\Users\jndinonno\Desktop\aswMBR.exe
2016-07-18 16:31 - 2016-07-18 16:31 - 05198336 _____ (AVAST Software) C:\Users\jndinonno\Downloads\aswMBR.exe
2016-07-10 16:08 - 2016-07-10 16:08 - 00688992 _____ (Swearware) C:\Users\jndinonno\Downloads\dds.scr
2016-07-10 15:43 - 2016-07-10 15:43 - 00000000 ____D C:\Users\jndinonno\AppData\Roaming\SparkTrust
2016-07-10 15:42 - 2016-07-10 15:58 - 00000000 ____D C:\ProgramData\SparkTrust
2016-07-10 14:49 - 2016-07-10 14:49 - 00000000 ____D C:\Users\jndinonno\AppData\Roaming\Panda Security

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-07-18 16:11 - 2009-07-13 23:34 - 00025680 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-07-18 16:11 - 2009-07-13 23:34 - 00025680 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-07-18 16:09 - 2015-09-15 16:20 - 00000000 ____D C:\ProgramData\MFAData
2016-07-18 16:04 - 2009-07-13 23:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-07-15 16:41 - 2016-01-28 18:12 - 00000913 _____ C:\Users\Public\Desktop\AVG Protection.lnk
2016-07-15 16:41 - 2016-01-28 18:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2016-07-14 17:28 - 2016-04-04 15:22 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-07-13 16:05 - 2010-11-20 16:01 - 00713888 _____ C:\windows\system32\PerfStringBackup.INI
2016-07-13 16:05 - 2009-07-13 21:37 - 00000000 ____D C:\windows\inf
2016-07-10 15:35 - 2015-11-08 08:51 - 00000000 ____D C:\Users\jndinonno\AppData\Local\AvgSetupLog
2016-07-10 15:05 - 2015-03-14 17:12 - 00069488 _____ C:\Users\jndinonno\AppData\Local\GDIPFONTCACHEV1.DAT
2016-07-10 15:05 - 2009-07-13 23:33 - 00320768 _____ C:\windows\system32\FNTCACHE.DAT
2016-07-10 15:02 - 2015-03-14 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
2016-07-10 15:01 - 2015-03-14 12:47 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-07-06 19:39 - 2015-01-25 10:28 - 00400552 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2016-06-19 17:28 - 2016-05-11 20:54 - 00000906 _____ C:\windows\Rtcwplat.INI
2016-06-19 17:27 - 2016-05-11 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Return to Castle Wolfenstein - Platinum Edition

==================== Files in the root of some directories =======

2015-09-15 15:56 - 2015-09-15 15:56 - 6420480 _____ () C:\Program Files\GUTAC46.tmp
2016-07-10 15:43 - 2016-07-10 15:57 - 0000115 _____ () C:\Users\jndinonno\AppData\Roaming\LogFile.txt
2015-07-04 15:14 - 2015-07-04 17:51 - 0001462 _____ () C:\Users\jndinonno\AppData\Local\seed.log

Some files in TEMP:
====================
C:\Users\jndinonno\AppData\Local\Temp\avguirn_081822105457.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_082005766906.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_08678561444.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_08875019647.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_0894033522.exe
C:\Users\jndinonno\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\jndinonno\AppData\Local\Temp\{488B1925-1C11-4BD2-B75E-6C0B09FE41BA}.exe

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-07-08 18:10

==================== End of FRST.txt ============================

 

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 18-07-2016
Ran by [removed] (2016-07-18 16:55:26)
Running from C:\Users\[removed]\Desktop
Microsoft Windows 7 Professional  Service Pack 1 (X86) (2015-03-14 16:42:26)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-4252558748-1657619972-2942562243-500 - Administrator - Disabled)
Guest (S-1-5-21-4252558748-1657619972-2942562243-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4252558748-1657619972-2942562243-1003 - Limited - Enabled)
jndinonno (S-1-5-21-4252558748-1657619972-2942562243-1001 - Administrator - Enabled) => C:\Users\jndinonno

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AV: AVG AntiVirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20050 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM\…\Adobe Flash Player Plugin) (Version: 11.5.502.118 - Adobe Systems Incorporated)
Adobe Flash Player 21 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 21.0.0.242 - Adobe Systems Incorporated)
AVG (Version: 16.91.7688 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4627 - AVG Technologies) Hidden
AVG Protection (HKLM\…\AVG) (Version: 2016.91.7688 - AVG Technologies)
FMW 1 (Version: 1.102.4 - AVG Technologies) Hidden
Google Update Helper (Version: 1.3.21.115 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2555 - Intel Corporation)
Java 8 Update 77 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
K-Lite Mega Codec Pack 9.4.0 (HKLM\…\KLiteCodecPack_is1) (Version: 9.4.0 - )
LibreOffice 4.0.0.3 (HKLM\…\{8EA569F1-97AF-4C3E-A0CB-4846C2D35A81}) (Version: 4.0.0.3 - The Document Foundation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{CA8A885F-E95B-3FC6-BB91-F4D9377C7686}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
NVIDIA PhysX (HKLM\…\{1C4551A6-4743-4093-91E4-1477CD655043}) (Version: 9.09.0203 - NVIDIA Corporation)
Visual Studio 2012 x86 Redistributables (HKLM\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.5 (HKLM\…\VLC media player) (Version: 2.0.5 - VideoLAN)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {3EDD6BE6-F18D-4529-BCB8-A88C127C5C2A} - System32\Tasks\{549ADB0D-5803-4C05-8230-C578E9C45DB2} => pcalua.exe -a D:\AUTORUN.EXE -d D:\
Task: {530552B9-0625-4250-9849-47BBF657EAB7} - System32\Tasks\{B3D02667-810A-45E4-9121-17F064257326} => pcalua.exe -a D:\Launch.exe -d D:\
Task: {7E711CFB-10BA-4E2D-BE49-9F779681CB68} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {89004A4F-D66C-4B28-A59B-DC5372E1DD88} - System32\Tasks\{28A0B97E-FE6D-46D8-A747-D76974ABB84A} => pcalua.exe -a D:\setup\rsrc\Autorun.exe -d D:\
Task: {983A35D8-28B4-4CCB-B9E8-5930BDF6064C} - System32\Tasks\{01A390F8-7802-4C2C-8C9E-0F64AAF1140C} => pcalua.exe -a D:\Launch.exe -d D:\
Task: {BB91FA11-EA2B-4E11-B536-6689F7149523} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2016-03-20] (Oracle Corporation)
Task: {D451111B-DAB4-4BE1-9053-DC026CEE44EA} - System32\Tasks\{8D36B067-EA32-4531-B04B-41712C5B7BAD} => pcalua.exe -a D:\setup\rsrc\Autorun.exe -d D:\
Task: {FCE9D161-145E-4CB2-B309-BBAFB41D2636} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\jndinonno\AppData\Local\Microsoft\Windows\GameExplorer\{5259B043-6F4D-4B1F-907F-F17C15BD6AF7}\SupportTasks\1\Support.lnk -> hxxp://techsupport.ea.com/
Shortcut: C:\Users\jndinonno\AppData\Local\Microsoft\Windows\GameExplorer\{5259B043-6F4D-4B1F-907F-F17C15BD6AF7}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.battlefieldvietnam.ea.com/

==================== Loaded Modules (Whitelisted) ==============

2016-01-28 18:10 - 2016-04-13 12:37 - 40500224 _____ () C:\Program Files\AVG\UiDll\2171\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:04 - 2009-06-10 16:39 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\jndinonno\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{EF2159CE-4E19-4DE3-8063-A630701BC948}] => (Allow) LPort=1542
FirewallRules: [{972078FE-F776-4B4B-A319-CA631CA5FF79}] => (Allow) LPort=1542
FirewallRules: [{24C123BC-4266-41EA-878E-64B4DF235E2A}] => (Allow) LPort=53
FirewallRules: [{DCACB5AA-6AEA-4E81-B88C-E7553C89CB66}] => (Allow) LPort=67
FirewallRules: [{C57F6107-AD8B-4DD6-9606-6021CC00ABE3}] => (Allow) LPort=68
FirewallRules: [{FAC73D9E-E0DB-4DFC-9E2B-293DC9CD4F4E}] => (Allow) LPort=53
FirewallRules: [{1D589291-6FFD-43E4-9F43-083C82617AA3}] => (Allow) LPort=53
FirewallRules: [TCP Query User{DE6B0BF0-CD67-4A1C-A182-D3BA48D05B55}C:\program files\ea games\mohaa\moh_breakthrough.exe] => (Allow) C:\program files\ea games\mohaa\moh_breakthrough.exe
FirewallRules: [UDP Query User{508449E1-7C7D-4CC7-8829-2B8F454C36C2}C:\program files\ea games\mohaa\moh_breakthrough.exe] => (Allow) C:\program files\ea games\mohaa\moh_breakthrough.exe
FirewallRules: [TCP Query User{CFFE12D2-3AC3-44AF-B84F-F24BE6C8D939}C:\program files\ea games\mohaa\mohaa.exe] => (Allow) C:\program files\ea games\mohaa\mohaa.exe
FirewallRules: [UDP Query User{89526612-2754-4E55-BE9F-B5A866A2417A}C:\program files\ea games\mohaa\mohaa.exe] => (Allow) C:\program files\ea games\mohaa\mohaa.exe
FirewallRules: [TCP Query User{8B4EB969-BF23-4753-B7AF-F8C96F7D371D}C:\program files\ea games\battlefield vietnam\bfvietnam.exe] => (Allow) C:\program files\ea games\battlefield vietnam\bfvietnam.exe
FirewallRules: [UDP Query User{E232E712-56F5-4006-B800-1A394B0D0310}C:\program files\ea games\battlefield vietnam\bfvietnam.exe] => (Allow) C:\program files\ea games\battlefield vietnam\bfvietnam.exe
FirewallRules: [TCP Query User{8F3E7797-FF56-44CC-964F-98FB62D1F609}C:\program files\ea games\mohaa\moh_spearhead.exe] => (Allow) C:\program files\ea games\mohaa\moh_spearhead.exe
FirewallRules: [UDP Query User{4D68700E-DC54-457C-A171-6756A1D620FD}C:\program files\ea games\mohaa\moh_spearhead.exe] => (Allow) C:\program files\ea games\mohaa\moh_spearhead.exe
FirewallRules: [{37E8B1EE-D83F-4D9A-88A8-E2BFE3A31BDD}] => (Allow) C:\Program Files\AVG\Av\avgmfapx.exe
FirewallRules: [{E73A364D-F2BF-43E3-AAE5-7F4B1BF7F3BF}] => (Allow) C:\Program Files\AVG\Av\avgmfapx.exe
FirewallRules: [TCP Query User{2899FA4F-4CC1-4D51-9BCA-D26342499228}C:\program files\wolfenstein - enemy territory\et.exe] => (Allow) C:\program files\wolfenstein - enemy territory\et.exe
FirewallRules: [UDP Query User{0CAC7AF5-8B9E-408C-96DE-22D548D35C07}C:\program files\wolfenstein - enemy territory\et.exe] => (Allow) C:\program files\wolfenstein - enemy territory\et.exe
FirewallRules: [{ECE204ED-CD5C-44EB-874A-B3840A56EA7C}] => (Allow) C:\Program Files\AVG\Av\avgnsx.exe
FirewallRules: [{D576E899-BCB7-4F69-B3D2-47A4E8EAB806}] => (Allow) C:\Program Files\AVG\Av\avgnsx.exe
FirewallRules: [{BE6A8B73-F576-4EF0-8984-D8F85E6F3005}] => (Allow) C:\Program Files\AVG\Av\avgdiagex.exe
FirewallRules: [{91E64870-A3BC-4C21-9234-1EE402FF0756}] => (Allow) C:\Program Files\AVG\Av\avgdiagex.exe
FirewallRules: [{71F923DE-9460-4DE8-AF0E-04EDB7E90B76}] => (Allow) C:\Program Files\AVG\Av\avgemcx.exe
FirewallRules: [{F09E7A69-A641-4959-A6D2-1CE31341F185}] => (Allow) C:\Program Files\AVG\Av\avgemcx.exe

==================== Restore Points =========================

12-05-2016 15:54:58 Windows Update
18-05-2016 11:31:04 Windows Update
27-05-2016 15:56:12 Windows Update
02-06-2016 17:53:30 Windows Update
15-06-2016 21:31:47 Scheduled Checkpoint
16-06-2016 15:42:20 Windows Update
21-06-2016 18:32:37 Windows Update
27-06-2016 17:17:54 Windows Update
01-07-2016 18:05:54 Windows Update
08-07-2016 18:17:34 Scheduled Checkpoint
10-07-2016 13:45:16 Windows Update
10-07-2016 14:54:34 Removed Clifford Phonics
10-07-2016 14:55:05 Removed Sesame Street - Learn, Play & Grow.
10-07-2016 14:58:43 Removed Medal of Honor Allied Assault™ Spearhead
10-07-2016 14:59:55 Removed Medal of Honor Allied Assault™ Breakthrough
10-07-2016 15:01:54 Removed Medal of Honor Allied Assault
10-07-2016 16:22:02 Windows Update
14-07-2016 21:36:31 Windows Update

==================== Faulty Device Manager Devices =============

Name: PS/2 Compatible Mouse
Description: PS/2 Compatible Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

==================== Event log errors: =========================

Application errors:
==================
Error: (07/18/2016 04:05:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/16/2016 10:10:48 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/15/2016 04:06:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/14/2016 10:48:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/14/2016 09:35:51 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/14/2016 05:17:51 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/13/2016 04:03:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/12/2016 08:56:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/12/2016 04:02:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2016 04:18:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

System errors:
=============
Error: (07/15/2016 04:41:29 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The AVGIDSAgent service terminated with service-specific error %%-536753635.

Error: (07/13/2016 05:13:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 116.12.0.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.6.0305.00

 Source Path: 4.6.0305.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (07/13/2016 05:13:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 1.225.1232.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.6.0305.00

 Source Path: 4.6.0305.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (07/13/2016 05:13:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 1.225.1232.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.6.0305.00

 Source Path: 4.6.0305.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (07/13/2016 05:13:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 1.225.1232.0

 Update Source: %NT AUTHORITY59

 Update Stage: 4.6.0305.00

 Source Path: 4.6.0305.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\SYSTEM

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (07/13/2016 04:02:56 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 116.12.0.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.6.0305.00

 Source Path: 4.6.0305.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (07/13/2016 04:02:56 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 1.225.1232.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.6.0305.00

 Source Path: 4.6.0305.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (07/13/2016 04:02:56 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 1.225.1232.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.6.0305.00

 Source Path: 4.6.0305.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (07/13/2016 04:02:55 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 1.225.1232.0

 Update Source: %NT AUTHORITY59

 Update Stage: 4.6.0305.00

 Source Path: 4.6.0305.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\SYSTEM

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (07/12/2016 09:06:56 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 116.12.0.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.6.0305.00

 Source Path: 4.6.0305.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
Percentage of memory in use: 72%
Total physical RAM: 1993.25 MB
Available physical RAM: 541.31 MB
Total Virtual: 3986.49 MB
Available Virtual: 2067.6 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:68.64 GB) (Free:12.97 GB) NTFS
Drive r: (Recovery) (Fixed) (Total:5.86 GB) (Free:1.54 GB) NTFS ==>[system with boot components (obtained from drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 74.5 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=5.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=68.6 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

AV: Microsoft Security Essentials (Enabled - Up to date)
AV: AVG AntiVirus (Enabled - Up to date)

It is inadvisable to have more than one Anti-Virus installed on your computer at the same time. Doing so may:
  • Cause conflicts, negatively impacting the effectiveness of each Anti-Virus installed.
  • Trigger false-positives.
  • Trigger false-negatives, where neither programme detects malware.
  • Cause system instability/performance issues. Your system may lock up or slow down due to both software attempting to access the same file at the same time.
  • Please remove all but one Anti-Virus from your computer.

    ~~~~~~~~~~~~~~~~~~~`
    Please remove/uninstall
    Java 8 Update 77
    It's out of date and very vulnerable

    ~~~~~~~~~~~~~~~~~~~~~~~

    Do you connect through a Proxy setting?

    ProxyServer: [S-1-5-21-4252558748-1657619972-2942562243-1001] => localhost:8080
    AutoConfigURL: [S-1-5-21-4252558748-1657619972-2942562243-1001] => localhost:8080


    ~~~~~~~~~~~~~~~~~~~~~~~

    Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
    To do this highlight the contents of the box and right click on it and select copy.
    Paste this into the open notepad. save it to the Desktop as fixlist.txt
    NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
    It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


    [external image: FRSTfix.JPG]


    start
    CreateRestorePoint:
    CloseProcesses:
    HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpage.com/
    SearchScopes: HKU\S-1-5-21-4252558748-1657619972-2942562243-1001 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://search.yahoo.com/search?ei=ISO-8859-1&fr=chr-vmn&type=egames3_1yach&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-4252558748-1657619972-2942562243-1001 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://search.yahoo.com/search?ei=ISO-8859-1&fr=chr-vmn&type=egames3_1yach&q={searchTerms}
    BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_77\bin\ssv.dll [2016-04-18] (Oracle Corporation)
    BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-18] (Oracle Corporation)
    FF Plugin: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-18] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-18] (Oracle Corporation)
    2016-07-10 15:43 - 2016-07-10 15:43 - 00000000 ____D C:\Users\jndinonno\AppData\Roaming\SparkTrust
    2016-07-10 15:42 - 2016-07-10 15:58 - 00000000 ____D C:\ProgramData\SparkTrust
    C:\Users\jndinonno\AppData\Local\Temp\avguirn_081822105457.exe
    C:\Users\jndinonno\AppData\Local\Temp\avguirn_082005766906.exe
    C:\Users\jndinonno\AppData\Local\Temp\avguirn_08678561444.exe
    C:\Users\jndinonno\AppData\Local\Temp\avguirn_08875019647.exe
    C:\Users\jndinonno\AppData\Local\Temp\avguirn_0894033522.exe
    C:\Users\jndinonno\AppData\Local\Temp\jre-8u77-windows-au.exe
    C:\Users\jndinonno\AppData\Local\Temp\{488B1925-1C11-4BD2-B75E-6C0B09FE41BA}.exe
    CMD: ipconfig /flushdns
    CMD: netsh int ipv4 reset
    CMD: netsh int ipv6 reset
    Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
    Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f

    Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
    Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
    End

    Open FRST/FRST64 and press the > Fix < button just once and wait.
    If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
    When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~`

Please download the Malwarebytes Anti-Malware setup file to your Desktop.

OR from this location Malwarebytes' Anti-Malware
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs, followed by the first Scan Log.
  • Click Export, followed by Copy to Clipboard. Paste the log in your next reply.

  • ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~``

    [external image: BY4dvz9.png]AdwCleaner
    • Please download AdwCleaner and save the file to your Desktop.
    • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
    • Follow the prompts.
    • Click [external image: A49sxPr.png]Scan.
    • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
    • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
    • Click [external image: MqHawIb.png]Clean.
    • Follow the prompts and allow your computer to reboot.
    • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
    – File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

    please post
    Fixlog.txt
    malwarebytes log
    AdwCleaner[C1].txt

 

Good afternoon,

 

I could not copy to clipboard the malwarebytes log so I saved it as text, I didn't remove anything yet w/ the AdwCleaner. I do not know the difference between Proxyserver and AutoConfigURL. I did disable the Microsoft Security Essentials and removed the Java 8 Update 77.

 

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 20-07-2016
Ran by [removed] (2016-07-20 16:49:05) Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal

==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpage.com/
SearchScopes: HKU\S-1-5-21-4252558748-1657619972-2942562243-1001 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://search.yahoo.com/search?ei=ISO-8859-1&fr=chr-vmn&type=egames3_1yach&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4252558748-1657619972-2942562243-1001 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://search.yahoo.com/search?ei=ISO-8859-1&fr=chr-vmn&type=egames3_1yach&q={searchTerms}
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_77\bin\ssv.dll [2016-04-18] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-18] (Oracle Corporation)
FF Plugin: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-18] (Oracle Corporation)
2016-07-10 15:43 - 2016-07-10 15:43 - 00000000 ____D C:\Users\jndinonno\AppData\Roaming\SparkTrust
2016-07-10 15:42 - 2016-07-10 15:58 - 00000000 ____D C:\ProgramData\SparkTrust
C:\Users\jndinonno\AppData\Local\Temp\avguirn_081822105457.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_082005766906.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_08678561444.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_08875019647.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_0894033522.exe
C:\Users\jndinonno\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\jndinonno\AppData\Local\Temp\{488B1925-1C11-4BD2-B75E-6C0B09FE41BA}.exe
CMD: ipconfig /flushdns
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f

Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
End

*****************

Restore point was successfully created.
Processes closed successfully.
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
"HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}" => key removed successfully.
HKCR\CLSID\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found.
"HKCR\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => key removed successfully.

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/20/2016
Scan Time: 4:58 PM
Logfile: malwarebytes scanning history log.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.07.20.11
Rootkit Database: v2016.05.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: jndinonno

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 243893
Time Elapsed: 6 min, 11 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)

(end)

 

***** [ Scheduled tasks ] *****

***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\PopCapLoader.PopCapLoaderCtrl2
Key Found : HKLM\SOFTWARE\Classes\PopCapLoader.PopCapLoaderCtrl2.1
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E4E3E0F8-CD30-4380-8CE9-B96904BDEFCA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FE8A736F-4124-4D9C-B4B1-3B12381EFABE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C9C5DEAF-0A1F-4660-8279-9EDFAD6FEFE1}
Key Found : HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Found : HKCU\Software\SlimWare Utilities Inc
Key Found : HKCU\Software\SparkTrust\SparkTrust PC Cleaner Plus
Key Found : HKCU\Software\SparkTrust\UNS\SparkTrust PC Cleaner Plus
Key Found : HKLM\SOFTWARE\SlimWare Utilities Inc
Key Found : HKLM\SOFTWARE\SparkTrust\SparkTrust PC Cleaner Plus
Key Found : HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Software\SlimWare Utilities Inc
Key Found : HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Software\SparkTrust\SparkTrust PC Cleaner Plus
Key Found : HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Software\SparkTrust\UNS\SparkTrust PC Cleaner Plus

***** [ Web browsers ] *****

[C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com

*************************

C:\AdwCleaner\AdwCleaner[S1].txt - [2667 bytes] - [20/07/2016 17:16:43]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2740 bytes] ##########

Please run AdwCleaner again, allow it to clean the items found this time.
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner make sure all items have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
  • – File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.



    ~~~~~~~~~~~~~~~~~~~~~

    Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
    To do this highlight the contents of the box and right click on it and select copy.
    Paste this into the open notepad. save it to the Desktop as fixlist.txt
    NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
    It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


    [external image: FRSTfix.JPG]

     

    start
    CreateRestorePoint:
    CloseProcesses:
    ProxyServer: [S-1-5-21-4252558748-1657619972-2942562243-1001] => localhost:8080
    AutoConfigURL: [S-1-5-21-4252558748-1657619972-2942562243-1001] => localhost:8080
    EmptyTemp:
    End


    Open FRST/FRST64 and press the > Fix < button just once and wait.
    If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
    When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`


    What we can do now is run an online scan with Eset, a good trusted scanner, reliable and thorough.
    The settings I suggest will also show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
    This scanner can take quite a bit of time to run, depending of course how full your computer is.

    Ensure your external and/or USB drives are inserted during the scan.


    Please run this Free Online Virus Scanner from ESET
    • Please be patient.
    • Turn off the real-time scanner of any existing antivirus program before performing the online scan. Here's how
    • You want the Online One-Time Scan
    • Note: It will run using Internet Explorer, Firefox or Chome.
    • Tick the box next to YES, I accept the Terms of Use.
    • When/if prompted by UAC, 'Do you want to allow this app to make changes to your PC?', please choose Yes
    • Click Start
    • When asked, allow the activex control to install
    • Click Start
    • Make sure that the option Remove found threats is NOT TICKED, and the option Scan unwanted applications is checked
    • Click Scan
    • Wait for the scan to finish
    • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    please post these 3 logs when finished.

Her are the three logs requested a few days ago. My apologies for the delayed response.

# AdwCleaner v5.201 - Logfile created 21/07/2016 at 18:08:25
# Updated 30/06/2016 by ToolsLib
# Database : 2016-07-21.2 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (X86)
# Username : jndinonno - PC-MXL0280
# Running from : C:\Users\jndinonno\Desktop\AdwCleaner.exe
# Option : Clean
# Support : https://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : swdumon

***** [ Folders ] *****

[-] Folder Deleted : C:\ProgramData\SparkTrust
[#] Folder Deleted : C:\ProgramData\Application Data\SparkTrust
[-] Folder Deleted : C:\Users\Public\Documents\Downloaded Installers
[-] Folder Deleted : C:\Users\jndinonno\AppData\Roaming\SparkTrust

***** [ Files ] *****

[-] File Deleted : C:\windows\Downloaded Program Files\popcaploader.inf
[-] File Deleted : C:\windows\system32\drivers\swdumon.sys

***** [ DLLs ] *****

***** [ WMI ] *****

***** [ Shortcuts ] *****

***** [ Scheduled tasks ] *****

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\PopCapLoader.PopCapLoaderCtrl2
[-] Key Deleted : HKLM\SOFTWARE\Classes\PopCapLoader.PopCapLoaderCtrl2.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E4E3E0F8-CD30-4380-8CE9-B96904BDEFCA}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE8A736F-4124-4D9C-B4B1-3B12381EFABE}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C9C5DEAF-0A1F-4660-8279-9EDFAD6FEFE1}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
[-] Key Deleted : HKCU\Software\SlimWare Utilities Inc
[-] Key Deleted : HKCU\Software\SparkTrust\SparkTrust PC Cleaner Plus
[-] Key Deleted : HKCU\Software\SparkTrust\UNS\SparkTrust PC Cleaner Plus
[-] Key Deleted : HKLM\SOFTWARE\SlimWare Utilities Inc
[-] Key Deleted : HKLM\SOFTWARE\SparkTrust\SparkTrust PC Cleaner Plus

***** [ Web browsers ] *****

[-] [C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [2572 bytes] - [21/07/2016 18:08:26]
C:\AdwCleaner\AdwCleaner[S1].txt - [2819 bytes] - [20/07/2016 17:16:43]
C:\AdwCleaner\AdwCleaner[S2].txt - [2892 bytes] - [21/07/2016 18:05:39]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2791 bytes] ##########

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 20-07-2016
Ran by [removed] (2016-07-21 18:51:40) Run:2
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal

==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
ProxyServer: [S-1-5-21-4252558748-1657619972-2942562243-1001] => localhost:8080
AutoConfigURL: [S-1-5-21-4252558748-1657619972-2942562243-1001] => localhost:8080
EmptyTemp:
End

*****************

Restore point was successfully created.
Processes closed successfully.
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully.
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => value not found.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5715548 B
Java, Flash, Steam htmlcache => 506 B
Windows/system/drivers => 405689992 B
Edge => 0 B
Chrome => 1052363 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 87829 B
LocalService => 0 B
NetworkService => 62049036 B
jndinonno => 15343841203 B

RecycleBin => 0 B
EmptyTemp: => 14.7 GB temporary data Removed.

================================

The system needed a reboot.

==== End of Fixlog 18:53:58 ====

 

C:\Users\jndinonno\AppData\Local\Avg\AWL\StartUp Manager\Disabled objects\PowerReg Scheduler.exe Win32/PowerReg potentially unsafe application 
 

System appears ok. I have not experienced any screen flashing and fonts changing while the pc is in use. Still not sure why the amount of space in the C drive has grown. From the logs posted did you see any issues?

Do you have any other advice or programs I should be using?

 
I'll post a few things in Preventive tips

DelFix
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
************************************
  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP
  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: 6YRrgUC.png]Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: jv4nhMJ.png]NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png]Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: j1OLIec.png]SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • [external image: sHjS79L.png]Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.
  • [external image: JEP5iWI.png]Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

Blue screen event happened yesterday  here's some info   OS VERSION 6.1.76.1.2.1.0.256.48  C/Windows/ Minidump072816-49779-01.dmp

and C/Users/jndinonno/Appdata/Local/Temp wer-93912-0.systemdata.xm

 

Cause for alarm? or shall I still go ahead and remove disinfection tools?

Blue screen event happened yesterday  here's some info   OS VERSION 6.1.76.1.2.1.0.256.48  C/Windows/ Minidump072816-49779-01.dmp

and C/Users/jndinonno/Appdata/Local/Temp wer-93912-0.systemdata.xm

 

Cause for alarm? or shall I still go ahead and remove disinfection tools?

 

I hope it doesn't happen again.  From what I'm finding on the net is it's very possible a driver is going boink.

 

Has nothing to do with what we've done, or you would had had alerts out the yang yang.

 

It's safe at this time to run delfix.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI