This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Probably infected, popups and ads I don't want or need. [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

 

I've gotten a strange popup both on my mobile phone and my laptop, saying it's from my ISP and that I have been entered in a contest, blah blah blah, but when I called the ISP they said it wasn't.  However, I am not so sure about that.  But, it seems to have died down to maybe once a week on the mobile and not on the computer.

 

Yesterday, I had a popup that took up my entire screen on the laptop which is the computer I am having problems with, Acer Windows 7, Home Premium, AMD 64 bit system.

 

This popup covered the entire screen but had a small graphic in the center stating my computer was being tracked, etc, etc, and to click this big blue button to stop it.   Of course, I know better than to do such a thing.  I took a screen shot of it, which includes the URL that was at the top in the browser in case anyone wants or needs to see that. 

 

About a week ago, I installed a browser extension that is supposed to help one save money and compare prices when I am shopping online, then let me know if there is the same item, sold for less on another website. The thing seemed to be working fine on Amazon which it advertised it could find cheaper if I was contemplating something on there.  It kept telling me what I was looking at was the best price on Amazon.  

 

But, this popup for being tracked seems to have started around the time I installed the extension.  I uninstalled it, yesterday, even though I had shut it off because I was getting little popups at the sides of the screen at the bottom, about stuff that was not shopping or comparing prices and then it seemed like everything went nuts on me.  So I deleted the extension, altogether. 

 

Then I went onto AOL via the web as I don't have the full program installed on this computer, and find I have a huge row of ads going on the right side of the screen which is something I never had before.  After exploring how to shut that off, AOL said I couldn't shut it off, then later gave me a list of all the ads they supposedly allow to be shown so I clicked them all except the 1 AOL ad and told it to block them.  They're not blocked.  It didn't work and I am wondering if this is also related to that extension.

 

So. I know I need to have this computer gone over to see what I've got going on here and fix it if at all possible.

 

Thank you very much!

Hello CoolCat and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

AdwCleaner log
JRT.txt
Frst.txt
Addition.txt


Thanks

Satchfan

 

Thank you.  Starting scans now.

 

I have noticed there are more popups starting plus the computer would not run Windows Update.  I finally shut that off and will not attempt it until the computer is clean and I get the go ahead from you.

OK. Scans are done.  First, after I ran Run Farbar Recovery Scan Tool, I did not tell it to CLEAN OR FIX, whichever button is on the right.  I believe that was what I have been told to do in the past. 

 

# AdwCleaner v6.021 - Logfile created 13/10/2016 at 06:52:06

# Updated on 06/10/2016 by ToolsLib
# Database : 2016-10-13.1 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Chris Blaze - CHELSEA
# Running from : C:\Users\Chris Blaze\Desktop\adwcleaner_6.021.exe
# Mode: Clean
# Support : https://toolslib.net/forum
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
 
 
***** [ Files ] *****
 
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_static.cmptch.com_0.localstorage
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_static.cmptch.com_0.localstorage-journal
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.azlyrics.com_0.localstorage
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.bluemountaineagle.com_0.localstorage
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.bluemountaineagle.com_0.localstorage-journal
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.caremountmedical.com_0.localstorage
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.caremountmedical.com_0.localstorage-journal
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.metrolyrics.com_0.localstorage
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.metrolyrics.com_0.localstorage-journal
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_yoursearch.today_0.localstorage
[-] File deleted: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_yoursearch.today_0.localstorage-journal
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKU\S-1-5-21-1437231282-1839955917-1510631889-1000\Software\APN PIP
[#] Key deleted on reboot: HKCU\Software\APN PIP
[#] Key deleted on reboot: [x64] HKCU\Software\APN PIP
 
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: search.babylon.com
[-] [C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: isearch.avg.com
[-] [C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1] [startup_urls] Deleted: hxxp://search.conduit.com/?ctid=CT3300196&SearchSource;=48&CUI;=UN38189234359725179&UM;=2
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [3394 Bytes] - [13/10/2016 06:52:06]
C:\AdwCleaner\AdwCleaner[R0].txt - [895 Bytes] - [24/06/2015 19:05:24]
C:\AdwCleaner\AdwCleaner[R1].txt - [1011 Bytes] - [24/06/2015 21:32:26]
C:\AdwCleaner\AdwCleaner[R2].txt - [1070 Bytes] - [24/06/2015 21:35:08]
C:\AdwCleaner\AdwCleaner[S0].txt - [953 Bytes] - [24/06/2015 19:13:53]
C:\AdwCleaner\AdwCleaner[S1].txt - [1137 Bytes] - [24/06/2015 21:36:12]
C:\AdwCleaner\AdwCleaner[S2].txt - [3920 Bytes] - [13/10/2016 06:48:47]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3903 Bytes] ##########
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 7 Home Premium x64 
Ran by [removed] (Administrator) on Thu 10/13/2016 at  7:02:01.03
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 17 
 
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\{2C938E8C-B0F8-449F-8358-88557AA38753} (Empty Folder)
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\{4C5CDBD1-A023-4236-9C80-328DC82559C2} (Empty Folder)
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\{54377F5A-0E08-4AE2-BCC8-3DF76E6D2121} (Empty Folder)
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\{6C68E827-32CF-45CB-BA27-82A865C62B48} (Empty Folder)
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\{78FCCB05-57BF-44B2-8ADB-8E3A398D0DF0} (Empty Folder)
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\{8D5FF104-3A1E-4C77-A9F3-CBD1A401D8EA} (Empty Folder)
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\{A63A360B-8E03-4E17-82F3-909A9F839390} (Empty Folder)
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\{A9EB768F-CD3D-46E7-8A92-BDEFB85CE124} (Empty Folder)
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\crashrpt (Folder) 
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\547ENH3K (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8UF14JJO (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\90FBTQO5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Chris Blaze\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F69DD6AC (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\547ENH3K (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8UF14JJO (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\90FBTQO5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F69DD6AC (Temporary Internet Files Folder) 
 
 
 
Registry: 3 
 
Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_82FE0118EE5282E747A80FA8C8B08840 (Registry Value) 
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 10/13/2016 at  7:09:03.97
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10-10-2016
Ran by [removed] (administrator) on CHELSEA (13-10-2016 07:12:04)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-05] (ELAN Microelectronics Corp.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12673128 2011-08-16] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor)
HKLM\…\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-23] (NTI Corporation)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-06-30] (Dritek System Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-12] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM-x32\…\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.)
HKLM-x32\…\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [917584 2016-10-07] (Avira Operations GmbH & Co. KG)
HKLM-x32\…\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [60136 2016-08-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\…\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [293768 2016-07-14] (RealNetworks, Inc.)
HKLM-x32\…\Run: [RealDownloader] => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [714992 2016-07-05] ()
HKU\S-1-5-21-1437231282-1839955917-1510631889-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8686296 2016-03-11] (Piriform Ltd)
HKU\S-1-5-18\…\Run: [] => 0
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealTimes.lnk [2016-07-14]
ShortcutTarget: RealTimes.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpsystray.exe (RealNetworks, Inc.)
Startup: C:\Users\Chris Blaze\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-12-10]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3FA550CF-FFED-4903-85BF-7DE20E6ED189}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{C3899F35-22AA-4ECC-A690-A634B3D89B8E}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-1437231282-1839955917-1510631889-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2016-05-13] (RealDownloader)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-09-05] (Microsoft Corporation)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2016-09-05] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-09-05] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25] (Eyeo GmbH)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2016-05-13] (RealDownloader)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-20] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2016-09-05] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-20] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-09-05] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-09-05] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-09-05] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-09-05] (Microsoft Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
 
FireFox:
========
FF ProfilePath: C:\Users\Chris Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\P3ayBMJC.default [2014-12-13]
FF Extension: (Avira Browser Safety) - C:\Users\Chris Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\P3ayBMJC.default\Extensions\[removed] [2014-12-01] [not signed]
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK => not found
FF Plugin: @cuminas.jp/DjVuPlugin -> C:\Program Files\Cuminas\Document Express DjVu Plug-in\npdjvu.dll [2015-05-08] (Cuminas Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @cuminas.jp/DjVuPlugin -> C:\Program Files (x86)\Cuminas\Document Express DjVu Plug-in\npdjvu.dll [2015-05-08] (Cuminas Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-20] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-09-05] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=18.1.4.135 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2016-07-14] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=18.1.4.135 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2016-07-14] (RealPlayer)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-09-30] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> hxxp://www.google.com/
CHR StartupUrls: Profile 1 -> "hxxp://search.conduit.com/?ctid=CT3300196&SearchSource;=48&CUI;=UN38189234359725179&UM;=2"
CHR Session Restore: Profile 1 -> is enabled.
CHR Profile: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default [2016-10-13]
CHR Extension: (Google Docs) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Drive) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-29]
CHR Extension: (YouTube) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-23]
CHR Extension: (Adblock Plus) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-10-23]
CHR Extension: (Google Search) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]
CHR Extension: (Google Docs Offline) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-02]
CHR Extension: (Pin It Button) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-10-23]
CHR Extension: (Avira SafeSearch) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmiahjidflgnbiadknkmaimfpjkelng [2015-06-16]
CHR Extension: (Mafia Wars Addon) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\llfmkjppmncfcgdebajkjnopgodlcaoe [2015-10-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]
CHR Extension: (Gmail) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-27]
CHR Profile: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1 [2016-10-13]
CHR Extension: (Google Slides) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-03]
CHR Extension: (Google Docs) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-04]
CHR Extension: (Google Drive) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Google Search) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Sheets) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-03]
CHR Extension: (Wolf and the Ice Planet) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gffkhmkbijdmbncaoclaclldnbndflck [2015-09-03]
CHR Extension: (Google Docs Offline) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Pinterest Save Button) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2016-09-22]
CHR Extension: (Mafia Wars Addon) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\llfmkjppmncfcgdebajkjnopgodlcaoe [2016-03-18]
CHR Extension: (AdbIоck Plus) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\llnhkapmbaclpmdcmhcnegelcjccjdca [2016-10-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Gmail) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-04]
CHR Extension: (Chrome Media Router) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-22]
CHR Profile: C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\System Profile [2016-10-09]
CHR Extension: (Google Slides) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-24]
CHR Extension: (Google Docs) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-24]
CHR Extension: (Google Drive) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-24]
CHR Extension: (YouTube) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-24]
CHR Extension: (Google Search) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-24]
CHR Extension: (Google Sheets) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-24]
CHR Extension: (Gmail) - C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-24]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1086040 2016-10-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [475232 2016-10-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [475232 2016-10-07] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1489240 2016-10-07] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [324304 2016-08-19] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2980032 2016-09-05] (Microsoft Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-23] (NTI Corporation)
R2 PaceLicenseDServices; C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2932224 2011-09-08] (PACE Anti-Piracy, Inc.) [File not signed]
R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [32544 2016-05-13] ()
R2 RealTimes Desktop Service; C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [1095440 2016-07-14] (RealNetworks, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [177432 2016-10-07] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [145536 2016-10-07] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-10-22] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [79696 2016-05-13] (Avira Operations GmbH & Co. KG)
S3 cleanhlp; C:\EEK\bin\cleanhlp64.sys [57024 2014-12-14] (Emsisoft GmbH)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 iLokDrvr; C:\Windows\System32\DRIVERS\iLokDrvr.sys [25720 2012-05-02] ()
S3 mmxavs; C:\Windows\System32\Drivers\mmxavs.sys [357968 2011-09-15] (Native Instruments GmbH)
S3 mmxusb_svc; C:\Windows\System32\Drivers\mmxusb.sys [45648 2011-09-15] (Native Instruments GmbH)
R3 NIWinCDEmu; C:\Windows\System32\DRIVERS\NIWinCDEmu.sys [111696 2013-05-16] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-13 07:12 - 2016-10-13 07:17 - 00022586 _____ C:\Users\Chris Blaze\Desktop\FRST.txt
2016-10-13 07:09 - 2016-10-13 07:09 - 00003303 _____ C:\Users\Chris Blaze\Desktop\JRT.txt
2016-10-13 06:48 - 2016-10-13 06:49 - 02407424 _____ (Farbar) C:\Users\Chris Blaze\Desktop\FRST64.exe
2016-10-13 06:46 - 2016-10-13 06:46 - 01631928 _____ (Malwarebytes) C:\Users\Chris Blaze\Desktop\JRT.exe
2016-10-13 06:44 - 2016-10-13 06:44 - 03874368 _____ C:\Users\Chris Blaze\Desktop\adwcleaner_6.021.exe
2016-10-13 06:43 - 2016-10-13 07:06 - 00003030 _____ C:\Users\Chris Blaze\Desktop\1st instructions.txt
2016-10-12 19:48 - 2016-10-12 19:48 - 00002341 _____ C:\Users\Chris Blaze\Desktop\what the tech post.txt
2016-10-12 04:23 - 2016-10-12 04:23 - 00001308 _____ C:\Users\Chris Blaze\Desktop\Lillian's posts and quotes that she would not undo.txt
2016-10-12 03:31 - 2016-10-12 03:31 - 00000000 ____D C:\Users\Chris Blaze\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2016-10-09 22:32 - 2016-10-09 22:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-10-09 22:31 - 2016-10-09 22:31 - 00000000 ____D C:\Program Files\iPod
2016-10-09 22:30 - 2016-10-09 22:32 - 00000000 ____D C:\Program Files\iTunes
2016-10-09 00:38 - 2016-10-09 00:38 - 00000065 _____ C:\Users\Chris Blaze\Desktop\list.txt
2016-10-07 09:26 - 2016-10-07 09:32 - 860107023 _____ C:\Users\Chris Blaze\Desktop\cf.7z
2016-10-07 04:04 - 2016-10-07 04:01 - 00031720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avusbflt.sys
2016-10-03 00:56 - 2016-10-03 00:56 - 00000000 ____D C:\Windows\Trend Micro
2016-10-03 00:36 - 2016-08-22 14:20 - 00332512 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmcomm.sys
2016-10-01 05:54 - 2016-10-01 05:55 - 00000000 ____D C:\Users\Chris Blaze\Downloads\Bonamassa Free CD
2016-09-30 22:03 - 2016-09-30 22:26 - 98872494 _____ C:\Users\Chris Blaze\Desktop\bandicam 2016-09-30 22-03-55-905.avi
2016-09-30 17:20 - 2016-09-30 17:20 - 00003392 _____ C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1437231282-1839955917-1510631889-1000
2016-09-29 04:39 - 2016-09-29 04:39 - 00000084 _____ C:\Users\Chris Blaze\Desktop\LILLIAN.txt
2016-09-28 22:50 - 2016-09-28 22:51 - 00000039 _____ C:\Users\Chris Blaze\Desktop\movie to watch.txt
2016-09-24 04:15 - 2016-09-24 06:22 - 00000000 ____D C:\Users\Chris Blaze\Desktop\lab-results Mercy Coralville
2016-09-20 01:27 - 2016-09-20 01:27 - 00000000 ____D C:\Users\Chris Blaze\Downloads\HIDE STUFF LOL
2016-09-20 01:17 - 2016-09-20 01:21 - 00000000 ____D C:\Users\Chris Blaze\Downloads\Hellgate 05-03-2016
2016-09-20 01:11 - 2016-10-13 01:13 - 00003510 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Chris Blaze
2016-09-20 01:11 - 2016-10-11 19:21 - 00003516 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Chris Blaze
2016-09-20 01:11 - 2016-09-20 01:11 - 00003634 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Chris Blaze
2016-09-20 01:11 - 2016-09-20 01:11 - 00003230 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Chris Blaze
2016-09-19 05:56 - 2016-10-11 00:54 - 00000000 ___RD C:\Users\Chris Blaze\Downloads\Louis and doubles
2016-09-16 06:15 - 2016-09-21 18:49 - 00000000 ____D C:\Users\Chris Blaze\Downloads\Hellgate 05-03-2016-2
2016-09-16 05:30 - 2016-09-17 17:12 - 00000000 ____D C:\Users\Chris Blaze\Downloads\Kathie Pix
2016-09-15 11:24 - 2016-09-16 01:09 - 00000000 ____D C:\Users\Chris Blaze\Desktop\JIM DOWNING
2016-09-15 01:07 - 2016-09-15 01:15 - 00000000 ____D C:\Users\Chris Blaze\Desktop\Steve Scorfina MP3s
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-13 07:12 - 2015-06-24 02:11 - 00000000 ____D C:\FRST
2016-10-13 07:05 - 2014-12-01 16:27 - 00000000 ___RD C:\Users\Chris Blaze\Desktop\Antivirus
2016-10-13 07:04 - 2009-07-13 23:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-10-13 07:04 - 2009-07-13 23:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-10-13 06:55 - 2013-09-20 04:58 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-10-13 06:55 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-10-13 06:52 - 2015-06-24 19:05 - 00000000 ____D C:\AdwCleaner
2016-10-13 06:48 - 2013-03-04 02:18 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-10-13 06:20 - 2013-09-20 04:58 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-10-13 00:07 - 2015-01-15 07:58 - 00000000 ___RD C:\Users\Chris Blaze\Downloads\Graphics
2016-10-13 00:05 - 2016-09-11 22:03 - 00000000 ____D C:\Users\Chris Blaze\Desktop\hose postage
2016-10-13 00:05 - 2016-05-03 23:24 - 00000000 ___RD C:\Users\Chris Blaze\Documents\HELLGATE 2016 TAKE 2
2016-10-13 00:05 - 2015-07-07 23:22 - 00000000 ___RD C:\Users\Chris Blaze\Downloads\mp3s
2016-10-12 21:32 - 2014-12-26 05:26 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-10-12 21:31 - 2015-11-01 20:45 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-10-12 08:07 - 2015-05-04 18:59 - 00000000 ____D C:\Users\Chris Blaze\Documents\Outlook Files
2016-10-12 03:39 - 2015-05-18 21:30 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-10-11 07:48 - 2013-03-04 02:18 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-10-11 07:48 - 2013-03-04 02:18 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-10-11 07:48 - 2011-12-11 01:37 - 00000000 ____D C:\Windows\system32\Macromed
2016-10-11 07:48 - 2011-10-17 20:33 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-11 07:48 - 2011-10-17 20:33 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-10-09 22:30 - 2015-05-15 01:05 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-10-07 04:05 - 2014-12-01 16:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-10-07 04:01 - 2014-12-01 16:25 - 00177432 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2016-10-07 04:01 - 2014-12-01 16:25 - 00145536 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2016-10-06 17:50 - 2009-07-14 00:08 - 00032612 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-10-04 03:45 - 2015-01-04 01:13 - 00000000 ____D C:\Users\Chris Blaze\Documents\Bandicam
2016-10-03 18:34 - 2013-09-20 04:58 - 00002159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-10-03 01:34 - 2016-04-04 04:07 - 01038052 _____ C:\Users\Chris Blaze\AppData\Local\census.cache
2016-10-03 01:32 - 2016-04-04 04:06 - 00186142 _____ C:\Users\Chris Blaze\AppData\Local\ars.cache
2016-10-03 01:15 - 2016-04-04 03:45 - 00000010 _____ C:\Users\Chris Blaze\AppData\Local\sponge.last.runtime.cache
2016-09-20 02:05 - 2013-09-12 22:04 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-09-20 02:01 - 2011-12-11 01:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-09-20 01:21 - 2015-06-26 22:15 - 00076800 ___SH C:\Users\Chris Blaze\Documents\Thumbs.db
2016-09-19 22:10 - 2016-07-14 21:56 - 00000000 ____D C:\Users\Chris Blaze\AppData\Roaming\Real
2016-09-19 22:10 - 2016-07-14 21:54 - 00000000 ____D C:\ProgramData\Real
2016-09-19 01:27 - 2016-03-31 22:43 - 00000000 ___RD C:\Users\Chris Blaze\Documents\Dunrovin 2016
2016-09-16 12:19 - 2016-06-09 03:29 - 00004208 _____ C:\Users\Chris Blaze\Desktop\tags for eagles.txt
2016-09-16 08:47 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\NDF
2016-09-16 05:56 - 2014-12-01 16:33 - 00000000 ____D C:\ProgramData\Package Cache
2016-09-14 03:51 - 2016-02-28 02:58 - 00000000 ___RD C:\Users\Chris Blaze\Desktop\BLM Oregon LaVoy and Bundy
2016-09-13 20:42 - 2009-07-14 00:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
2016-09-13 20:42 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf
 
==================== Files in the root of some directories =======
 
2013-04-12 17:19 - 2013-04-14 01:26 - 0002655 _____ () C:\Program Files (x86)\unins000.dat
2013-04-12 17:19 - 2013-04-14 01:25 - 0685338 _____ () C:\Program Files (x86)\unins000.exe
2016-04-04 04:06 - 2016-10-03 01:32 - 0186142 _____ () C:\Users\Chris Blaze\AppData\Local\ars.cache
2016-04-04 04:07 - 2016-10-03 01:34 - 1038052 _____ () C:\Users\Chris Blaze\AppData\Local\census.cache
2016-04-04 03:27 - 2016-04-04 03:27 - 0000036 _____ () C:\Users\Chris Blaze\AppData\Local\housecall.guid.cache
2013-04-16 13:18 - 2015-09-03 01:17 - 0007609 _____ () C:\Users\Chris Blaze\AppData\Local\resmon.resmoncfg
2016-04-04 03:45 - 2016-10-03 01:15 - 0000010 _____ () C:\Users\Chris Blaze\AppData\Local\sponge.last.runtime.cache
2011-12-11 01:40 - 2011-12-11 01:43 - 0015222 _____ () C:\ProgramData\ArcadeDeluxe5.log
2013-04-12 16:39 - 2013-04-12 16:41 - 0000032 _____ () C:\ProgramData\PS.log
 
Some files in TEMP:
====================
C:\Users\Chris Blaze\AppData\Local\Temp\libeay32.dll
C:\Users\Chris Blaze\AppData\Local\Temp\msvcr120.dll
C:\Users\Chris Blaze\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-08-16 08:42
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-10-2016
Ran by [removed] (13-10-2016 07:18:15)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-03-26 03:41:08)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
73CE8CCE3C8545A2A8EE (S-1-5-21-1437231282-1839955917-1510631889-1003 - Limited - Enabled)
Administrator (S-1-5-21-1437231282-1839955917-1510631889-500 - Administrator - Disabled)
Chris Blaze (S-1-5-21-1437231282-1839955917-1510631889-1000 - Administrator - Enabled) => C:\Users\Chris Blaze
Guest (S-1-5-21-1437231282-1839955917-1510631889-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1437231282-1839955917-1510631889-1005 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avira Antivirus (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (HKLM-x32\…\7-Zip) (Version:  - )
Acer Backup Manager (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.99 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1904 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.0.1904 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3008 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Acer Incorporated)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.04.3504 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.1.0913.2011 - Acer Incorporated)
Adblock Plus for IE (32-bit and 64-bit) (HKLM\…\{77588F59-3C58-4675-8EEE-998E5BC33CF4}) (Version: 1.4 - Eyeo GmbH)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20039 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Amazon Kindle (HKU\S-1-5-21-1437231282-1839955917-1510631889-1000\…\Amazon Kindle) (Version: 1.14.1.43029 - Amazon)
Amazon Music (HKU\S-1-5-21-1437231282-1839955917-1510631889-1000\…\Amazon Amazon Music) (Version: 3.10.0.928 - Amazon Services LLC)
AMD Catalyst Install Manager (HKLM\…\{995841E6-A7D8-2742-606C-98E350507317}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.39 - Atheros Communications Inc.)
Avid Effects (HKLM-x32\…\{A86F1158-A7F7-4E8C-98E3-88F4996E85EB}) (Version: 10.0.0 - Avid Technology, Inc.)
Avira Antivirus (HKLM-x32\…\Avira Antivirus) (Version: 15.0.22.54 - Avira Operations GmbH & Co. KG)
Avira Launcher (HKLM-x32\…\{82dc2ab6-088f-4e0a-8e27-bb829481d3bc}) (Version: 1.2.70.16079 - Avira Operations GmbH & Co. KG)
Avira Launcher (x32 Version: 1.2.70.16079 - Avira Operations GmbH & Co. KG) Hidden
Backup Manager V3 (x32 Version: 3.0.0.99 - NTI Corporation) Hidden
Bandicam (HKLM-x32\…\Bandicam) (Version: 2.1.2.740 - Bandisoft.com)
Bandisoft MPEG-1 Decoder (HKLM-x32\…\BandiMPEG1) (Version:  - Bandisoft.com)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 5.16 - Piriform)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Document Express DjVu Plug-in (HKLM\…\{3677A6FF-9C6F-48B7-B0DC-E958C2FE4FFF}) (Version: 6.1.35472 - Cuminas Corporation)
Dolby Advanced Audio v2 (HKLM-x32\…\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.7000.7 - Dolby Laboratories Inc)
Doxillion Document Converter (HKLM-x32\…\Doxillion) (Version:  - NCH Software)
eBay Worldwide (HKLM-x32\…\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
ETDWare PS/2-X64 8.0.6.3_WHQL (HKLM\…\Elantech) (Version: 8.0.6.3 - ELAN Microelectronic Corp.)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 53.0.2785.143 - Google Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Grammarly (HKLM\…\{F8ADEE0D-3143-4E71-8CCD-9423105A6199}_is1) (Version: 5.0.1.1 - Grammarly)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
Interlok driver setup x64 (HKLM\…\{25613C10-27D2-410B-942B-D922D5C3A7BE}) (Version: 5.9.0 - PACE Anti-Piracy, Inc.)
iTunes (HKLM\…\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.7 - Acer Inc.)
License Support (HKLM-x32\…\InstallShield_{3165EA9B-36CC-499B-96FF-36FC30E10EF4}) (Version: 1.1.1.1524 - PACE Anti-Piracy, Inc.)
License Support (Version: 1.1.1.1524 - PACE Anti-Piracy, Inc.) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\…\O365HomePremRetail - en-us) (Version: 16.0.7167.2060 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-1437231282-1839955917-1510631889-1000\…\SkyDriveSetup.exe) (Version: 17.0.2003.1112 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\…\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\…\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\…\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.19 - Egis Technology Inc.) Hidden
Native Instruments Abbey Road 60s Drums Vintage (HKLM-x32\…\Native Instruments Abbey Road 60s Drums Vintage) (Version:  - Native Instruments)
Native Instruments Conant Gardens (HKLM-x32\…\Native Instruments Conant Gardens) (Version:  - Native Instruments)
Native Instruments Controller Editor (HKLM-x32\…\Native Instruments Controller Editor) (Version:  - Native Instruments)
Native Instruments Dark Pressure (HKLM-x32\…\Native Instruments Dark Pressure) (Version:  - Native Instruments)
Native Instruments Drop Squad (HKLM-x32\…\Native Instruments Drop Squad) (Version:  - Native Instruments)
Native Instruments Drop Squad Sounds (HKLM-x32\…\Native Instruments Drop Squad Sounds) (Version:  - Native Instruments)
Native Instruments Electric Vice (HKLM-x32\…\Native Instruments Electric Vice) (Version:  - Native Instruments)
Native Instruments Guitar Rig 4 (HKLM-x32\…\Native Instruments Guitar Rig 4) (Version:  - Native Instruments)
Native Instruments Guitar Rig Mobile I/O (HKLM-x32\…\Native Instruments Guitar Rig Mobile I/O) (Version:  - Native Instruments)
Native Instruments Guitar Rig Session I/O (HKLM-x32\…\Native Instruments Guitar Rig Session I/O) (Version:  - Native Instruments)
Native Instruments Komplete Elements (HKLM-x32\…\Native Instruments Komplete Elements) (Version:  - Native Instruments)
Native Instruments Kontakt 4 (HKLM-x32\…\Native Instruments Kontakt 4) (Version:  - Native Instruments)
Native Instruments Kontakt Elements Selection R2 (HKLM-x32\…\Native Instruments Kontakt Elements Selection R2) (Version:  - Native Instruments)
Native Instruments Maschine (HKLM-x32\…\Native Instruments Maschine) (Version:  - Native Instruments)
Native Instruments Maschine Controller (HKLM-x32\…\Native Instruments Maschine Controller) (Version:  - Native Instruments)
Native Instruments Maschine Controller MK2 Driver (HKLM-x32\…\Native Instruments Maschine Controller MK2 Driver) (Version:  - Native Instruments)
Native Instruments Maschine Mikro (HKLM-x32\…\Native Instruments Maschine Mikro) (Version:  - Native Instruments)
Native Instruments Maschine Mikro MK2 Driver (HKLM-x32\…\Native Instruments Maschine Mikro MK2 Driver) (Version:  - Native Instruments)
Native Instruments Massive (HKLM-x32\…\Native Instruments Massive) (Version:  - Native Instruments)
Native Instruments Platinum Bounce (HKLM-x32\…\Native Instruments Platinum Bounce) (Version:  - Native Instruments)
Native Instruments Raw Voltage (HKLM-x32\…\Native Instruments Raw Voltage) (Version:  - Native Instruments)
Native Instruments Reaktor 5 (HKLM-x32\…\Native Instruments Reaktor 5) (Version:  - Native Instruments)
Native Instruments Reaktor Elements Selection (HKLM-x32\…\Native Instruments Reaktor Elements Selection) (Version:  - Native Instruments)
Native Instruments Reaktor Spark R2 (HKLM-x32\…\Native Instruments Reaktor Spark R2) (Version:  - Native Instruments)
Native Instruments Rig Kontrol 3 (HKLM-x32\…\Native Instruments Rig Kontrol 3) (Version:  - Native Instruments)
Native Instruments Service Center (HKLM-x32\…\Native Instruments Service Center) (Version:  - Native Instruments)
Native Instruments Solid Bus Comp FX (HKLM-x32\…\Native Instruments Solid Bus Comp FX) (Version: 1.0.1.330 - Native Instruments)
Native Instruments Solid Dynamics FX (HKLM-x32\…\Native Instruments Solid Dynamics FX) (Version: 1.0.1.330 - Native Instruments)
Native Instruments Solid EQ FX (HKLM-x32\…\Native Instruments Solid EQ FX) (Version: 1.0.1.330 - Native Instruments)
Native Instruments Transistor Punch (HKLM-x32\…\Native Instruments Transistor Punch) (Version:  - Native Instruments)
Native Instruments True School (HKLM-x32\…\Native Instruments True School) (Version:  - Native Instruments)
Native Instruments Vintage Heat (HKLM-x32\…\Native Instruments Vintage Heat) (Version:  - Native Instruments)
Next Generation Visualisations (HKLM-x32\…\{2E376AD9-5C49-4F7D-A0BA-6A44E8FA5A3B}) (Version: 1.0.0 -  Microsoft)
NTI Media Maker 9 (HKLM-x32\…\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9002 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.9002 - NTI Corporation) Hidden
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7167.2060 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7167.2060 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7167.2060 - Microsoft Corporation) Hidden
OpenOffice.org 3.1 (HKLM-x32\…\{E6B87DC4-2B3D-4483-ADFF-E483BF718991}) (Version: 3.1.9399 - OpenOffice.org)
RealDownloader (x32 Version: 18.1.4.137 - RealNetworks, Inc.) Hidden
RealDownloader (x32 Version: 18.1.4.144 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (RealTimes) (HKLM-x32\…\RealPlayer 18.1) (Version: 18.1.4 - RealNetworks)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6438 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
reFX Nexus 1.0.0 (HKLM-x32\…\{84D04D4F-2201-4AED-BE9A-FFA62069CA19}_is1) (Version: 1.0.0 - reFX)
reFX Nexus 1.0.9 (HKLM-x32\…\reFX Nexus 1.0.9_is1) (Version:  - )
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Switch Sound File Converter (HKLM-x32\…\Switch) (Version:  - NCH Software)
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
vc2012_redist (x32 Version: 1.0.0.0 - Realnetworks) Hidden
Video Downloader (x32 Version: 1.2.0 - RealNetworks) Hidden
VideoPad Video Editor (HKLM-x32\…\VideoPad) (Version: 3.14 - NCH Software)
Visual C++ 64-bit Redistributables (HKLM-x32\…\InstallShield_{FB03650C-B373-4B20-ACA5-B7BA1A8EEE33}) (Version: 1.1.1.1524 - PACE Anti-Piracy, Inc.)
Visual C++ Redistributables (HKLM-x32\…\InstallShield_{F03117FA-9270-46B0-9666-0B4BC2CDEBF5}) (Version: 1.1.1.1524 - PACE Anti-Piracy, Inc.)
WavePad Sound Editor (HKLM-x32\…\WavePad) (Version:  - NCH Software)
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.02.3504 - Acer Incorporated)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0CACADD2-3622-4B3F-A69E-D170D96F00A4} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1437231282-1839955917-1510631889-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2016-05-13] (RealNetworks, Inc.)
Task: {210B3F04-164A-446B-8F5B-9C358462851B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-09-05] (Microsoft Corporation)
Task: {2888A44F-ABA0-40BF-ACD3-B850455B9E87} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-28] (Egis Technology Inc.)
Task: {2E1515B7-8088-41BB-8CB8-39CD1D8242FE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {2FF6B001-4D02-4A77-BC9C-B4EE8B43F589} - System32\Tasks\RNUpgradeHelperLogonPrompt_Chris Blaze => C:\Users\Chris Blaze\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.04\agent\rnupgagent.exe [2016-09-19] (RealNetworks, Inc.)
Task: {3542F372-EA2C-496D-89EF-66B728B40F20} - System32\Tasks\ReclaimerUpdateFiles_Chris Blaze => C:\Users\Chris Blaze\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.04\agent\rnupgagent.exe [2016-09-19] (RealNetworks, Inc.)
Task: {5BED3104-F0D7-4969-9C4C-54DBF15A18C8} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-28] (Egis Technology Inc.)
Task: {69757E10-C9D6-4BB1-A8A1-4DA695C2417A} - System32\Tasks\{A459FFD7-5C88-4AC7-83CB-93153EBB3983} => pcalua.exe -a "C:\Users\Chris Blaze\Downloads\Nexus v1.0.9 Setup (2).exe" -d "C:\Users\Chris Blaze\Desktop"
Task: {6E31FFA2-0C40-425D-B9D8-7D49A77695BF} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-09-05] (Microsoft Corporation)
Task: {71E0CF5F-6053-4AF1-B3B7-F4E10633AB1C} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1437231282-1839955917-1510631889-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2016-05-13] (RealNetworks, Inc.)
Task: {7E25D9D9-30D1-46BF-B769-EE4394CDF9AE} - System32\Tasks\{040DC036-E7C3-4A5A-9ADF-6E4E3454D8DC} => Chrome.exe 
Task: {7E9E1C74-561F-4A36-B17A-1AF00169EB47} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {86E56FD8-C030-4B30-B607-46D27E2ACBD6} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1437231282-1839955917-1510631889-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2016-05-13] (RealNetworks, Inc.)
Task: {8B2AF8D4-7B8C-4160-A171-9F3EE3F5127E} - System32\Tasks\{ADCE5B3C-0C4C-4666-8910-97C0DD32899D} => pcalua.exe -a C:\Users\CHRISB~1\AppData\Local\Temp\jre-8u31-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 <==== ATTENTION
Task: {9728DA7A-157B-40A8-A4C7-BA43AC873202} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-03-11] (Piriform Ltd)
Task: {BD122214-94C7-4218-A149-9B80BC500628} - System32\Tasks\RNUpgradeHelperResumePrompt_Chris Blaze => C:\Users\Chris Blaze\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.04\agent\rnupgagent.exe [2016-09-19] (RealNetworks, Inc.)
Task: {CB1FD568-1CCA-49F2-AA70-881A97522809} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {CC9E8629-331E-47F1-8DCD-DA84F9930B32} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe
Task: {EEB97180-7B19-44A1-8B1A-F89B51C32BF5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16] (Adobe Systems Incorporated)
Task: {FB6D4DCD-363D-4A8B-A818-86B6177E53F4} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-11] (Adobe Systems Incorporated)
Task: {FD6A4D56-F5D2-486F-8E21-B7401F13D5EC} - System32\Tasks\ReclaimerUpdateXML_Chris Blaze => C:\Users\Chris Blaze\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.04\agent\rnupgagent.exe [2016-09-19] (RealNetworks, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\Chris Blaze\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.html
 
ShortcutWithArgument: C:\Users\Chris Blaze\Desktop\Antivirus\Netflix.lnk -> C:\ProgramData\OEM_E471269A730D\Netflix\StartURL.exe () -> hxxp://homepage.acer.com/redirect.aspx?rid=09000001
ShortcutWithArgument: C:\Users\Chris Blaze\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\AdbIоck Plus.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  –profile-directory="Profile 1" –app-id=llnhkapmbaclpmdcmhcnegelcjccjdca
ShortcutWithArgument: C:\Users\Chris Blaze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Matoaka - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-09-01 18:12 - 2016-09-01 18:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-09-01 18:12 - 2016-09-01 18:12 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-05-13 15:13 - 2016-05-13 15:13 - 00032544 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
2016-03-14 16:11 - 2016-09-05 09:50 - 08921800 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2009-01-21 19:45 - 2009-01-21 19:45 - 01401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll
2011-04-23 20:29 - 2011-04-23 20:29 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2011-04-23 20:29 - 2011-04-23 20:29 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2011-04-23 20:29 - 2011-04-23 20:29 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2016-05-13 15:13 - 2016-05-13 15:13 - 00037688 _____ () C:\Program Files (x86)\Real\UpdateService\DL2UpdatePlugin.dll
2016-05-13 15:13 - 2016-05-13 15:13 - 00039224 _____ () C:\Program Files (x86)\Real\UpdateService\RealDownloaderUpdatePlugin.dll
2016-05-13 15:13 - 2016-05-13 15:13 - 00037192 _____ () C:\Program Files (x86)\Real\UpdateService\VideoDLUpdatePlugin.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Chris Blaze\AppData\Local\Temporary Internet Files:J5NmI6leURLnKx1viNZ1It7 [1970]
AlternateDataStreams: C:\Users\Chris Blaze\AppData\Local\Temporary Internet Files:ZwKYLSnlJp4kMBhrZgrXP [1982]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2014-12-13 21:28 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1437231282-1839955917-1510631889-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Chris Blaze\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{CC40CADD-58A9-4A7A-9B36-06CB01E95039}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{465FCEA8-86FD-4508-BADA-ED2F2777FD75}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{081E3B74-6854-4F27-9F8E-96E2B6DE0C29}] => (Allow) LPort=2869
FirewallRules: [{3E6A09C5-8364-4D8F-8ED1-64F93282386F}] => (Allow) LPort=1900
FirewallRules: [{1A871EC2-76C5-4287-9666-98452E8CAB04}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{D5D565C0-6E29-481C-BC5B-70616B92B37E}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{A298536D-8541-4770-B327-B2EB046EB061}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{E759A14A-8973-4368-BDC6-A270BC43C6DD}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{415C8364-5518-4EFE-9BD7-10BBDF180CAA}] => (Allow) C:\Users\Chris Blaze\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{373A4ABF-6858-4041-B109-5386924E10A3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0E512170-CD84-4D71-97BC-264BD4A07921}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{029BDD9D-98F4-4F79-A726-17FABDE741EE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{898D0716-C1B3-4EF2-9614-EC2DC9968EF6}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{6E98BDC3-2340-4134-A9E6-C400DA2801B8}C:\users\chris blaze\appdata\local\temp\housecall\tmase\nmap\nmap.exe] => (Block) C:\users\chris blaze\appdata\local\temp\housecall\tmase\nmap\nmap.exe
FirewallRules: [UDP Query User{9D810BA8-F1C4-446F-B093-AEF775B7C9AB}C:\users\chris blaze\appdata\local\temp\housecall\tmase\nmap\nmap.exe] => (Block) C:\users\chris blaze\appdata\local\temp\housecall\tmase\nmap\nmap.exe
FirewallRules: [{1AFEDAC2-C44A-49EA-B9FA-02F2A8E87C98}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{0B8218EF-4204-45B9-835B-3D6FC2A305AB}] => (Allow) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [{A65C1B90-63EA-4CE9-BFCB-F0767DF896AC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{360354B4-123B-49F0-B636-FA5744427F64}] => (Allow) C:\Program Files\iTunes\iTunes.exe
 
==================== Restore Points =========================
 
23-09-2016 02:07:37 Windows Update
13-10-2016 07:02:07 JRT Pre-Junkware Removal
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (10/13/2016 06:55:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (10/13/2016 02:32:19 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (10/13/2016 02:31:50 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{8D5E8DA1-0420-4A3B-9B29-8F3A00B32BDF}\recordingmanager.exe".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/12/2016 06:19:48 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).
 
Error: (10/12/2016 05:46:33 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (10/12/2016 05:46:21 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{8D5E8DA1-0420-4A3B-9B29-8F3A00B32BDF}\recordingmanager.exe".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/12/2016 04:34:52 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{8D5E8DA1-0420-4A3B-9B29-8F3A00B32BDF}\recordingmanager.exe".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/12/2016 04:34:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (10/11/2016 10:59:02 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 90080108).
 
Error: (10/11/2016 09:28:41 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).
 
 
System errors:
=============
Error: (10/13/2016 06:53:36 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Windows Update service did not shut down properly after receiving a preshutdown control.
 
Error: (10/13/2016 06:52:06 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (10/13/2016 06:51:50 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Microsoft Office ClickToRun Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
 
Error: (10/13/2016 06:51:39 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
 
Error: (10/13/2016 06:51:37 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (10/13/2016 06:51:37 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The iPod Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (10/13/2016 06:51:36 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Avira Service Host service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (10/13/2016 06:51:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The RealPlayer Update Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (10/13/2016 06:51:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The PACE License Services service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (10/13/2016 06:51:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NTI IScheduleSvc service terminated unexpectedly.  It has done this 1 time(s).
 
 
CodeIntegrity:
===================================
  Date: 2016-03-18 00:35:10.489
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_96f694b33cfd42bf\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2016-03-18 00:35:10.479
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_96f694b33cfd42bf\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2016-03-18 00:35:10.469
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_96f694b33cfd42bf\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2016-03-18 00:35:10.459
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_96f694b33cfd42bf\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2016-03-18 00:35:08.400
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2016-03-18 00:35:08.390
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2016-03-18 00:35:08.381
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2016-03-18 00:35:08.372
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2016-03-18 00:35:04.885
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2016-03-18 00:35:04.873
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
 
==================== Memory info =========================== 
 
Processor: AMD A6-3400M APU with Radeon™ HD Graphics
Percentage of memory in use: 63%
Total physical RAM: 3562.9 MB
Available physical RAM: 1292.15 MB
Total Virtual: 7123.99 MB
Available Virtual: 5185.37 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:449.66 GB) (Free:153.38 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 5E264840)
Partition 1: (Not Active) - (Size=16 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=449.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

after I ran Run Farbar Recovery Scan Tool, I did not tell it to CLEAN OR FIX, whichever button is on the right.  I believe that was what I have been told to do in the past

You had nothing to ‘fix’ or ‘clean’ before I looked at the log.


Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

CloseProcesses:
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK => not found
CHR StartupUrls: Profile 1 -> "hxxp://search.conduit.com/?ctid=CT3300196&SearchSource=48&CUI=UN38189234359725179&UM=2"
Task: {8B2AF8D4-7B8C-4160-A171-9F3EE3F5127E} - System32\Tasks\{ADCE5B3C-0C4C-4666-8910-97C0DD32899D} => pcalua.exe -a C:\Users\CHRISB~1\AppData\Local\Temp\jre-8u31-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 <==== ATTENTION
AlternateDataStreams: C:\Users\Chris Blaze\AppData\Local\Temporary Internet Files:J5NmI6leURLnKx1viNZ1It7 [1970]
AlternateDataStreams: C:\Users\Chris Blaze\AppData\Local\Temporary Internet Files:ZwKYLSnlJp4kMBhrZgrXP [1982]
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
C:\Program Files (x86)\unins000.dat
C:\Program Files (x86)\unins000.exe
C:\Users\Chris Blaze\AppData\Local\ars.cache
C:\Users\Chris Blaze\AppData\Local\census.cache
C:\Users\Chris Blaze\AppData\Local\housecall.guid.cache
C:\Users\Chris Blaze\AppData\Local\resmon.resmoncfg
C:\Users\Chris Blaze\AppData\Local\sponge.last.runtime.cache
C:\ProgramData\ArcadeDeluxe5.log
C:\ProgramData\PS.log
C:\Users\Chris Blaze\AppData\Local\Temp\libeay32.dll
C:\Users\Chris Blaze\AppData\Local\Temp\msvcr120.dll
C:\Users\Chris Blaze\AppData\Local\Temp\sqlite3.dll
C:\Users\CHRISB~1\AppData\Local\Temp\jre-8u31-windows-au.exe
CMD: ipconfig /flushdns
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

================================================

Download zoek.exe to your Desktop:

Important: Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.
 

  • on Windows Vista, 7, 8 and 10, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    autoclean;
    emptyalltemp;
    emptyclsid;
    FFdefaults;
    iedefaults;
    chrdefaults;
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

Logs to include with next post:

Fixlog.txt
zoek-results.log


Thanks

Satchfan

OK, sorry.   Confused.  Am I supposed to copy the text of the 1st box into the Farbar tool or only into Notepad? Or both? Or do I drag and drop the Notepad file into the text box?

 

Sorry for the confusion.  :scratch:

Am I supposed to copy the text of the 1st box into the Farbar tool or only into Notepad? Or both?

 

Copy it into Notepad and save it as Fixlist.txt to your desktop. Then open FRST and hit Fix.

Fix result of Farbar Recovery Scan Tool (x64) Version: 13-10-2016
Ran by [removed] (14-10-2016 06:23:18) Run:3
Running from C:\Users\[removed]\Desktop\New folder
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CloseProcesses:
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK => not found
CHR StartupUrls: Profile 1 -> "hxxp://search.conduit.com/?ctid=CT3300196&SearchSource=48&CUI=UN38189234359725179&UM=2"
Task: {8B2AF8D4-7B8C-4160-A171-9F3EE3F5127E} - System32\Tasks\{ADCE5B3C-0C4C-4666-8910-97C0DD32899D} => pcalua.exe -a C:\Users\CHRISB~1\AppData\Local\Temp\jre-8u31-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 <==== ATTENTION
AlternateDataStreams: C:\Users\Chris Blaze\AppData\Local\Temporary Internet Files:J5NmI6leURLnKx1viNZ1It7 [1970]
AlternateDataStreams: C:\Users\Chris Blaze\AppData\Local\Temporary Internet Files:ZwKYLSnlJp4kMBhrZgrXP [1982]
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
C:\Program Files (x86)\unins000.dat
C:\Program Files (x86)\unins000.exe
C:\Users\Chris Blaze\AppData\Local\ars.cache
C:\Users\Chris Blaze\AppData\Local\census.cache
C:\Users\Chris Blaze\AppData\Local\housecall.guid.cache
C:\Users\Chris Blaze\AppData\Local\resmon.resmoncfg
C:\Users\Chris Blaze\AppData\Local\sponge.last.runtime.cache
C:\ProgramData\ArcadeDeluxe5.log
C:\ProgramData\PS.log
C:\Users\Chris Blaze\AppData\Local\Temp\libeay32.dll
C:\Users\Chris Blaze\AppData\Local\Temp\msvcr120.dll
C:\Users\Chris Blaze\AppData\Local\Temp\sqlite3.dll
C:\Users\CHRISB~1\AppData\Local\Temp\jre-8u31-windows-au.exe
CMD: ipconfig /flushdns
EmptyTemp:
*****************
 
Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\[removed] => value removed successfully
Chrome StartupUrls => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8B2AF8D4-7B8C-4160-A171-9F3EE3F5127E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B2AF8D4-7B8C-4160-A171-9F3EE3F5127E}" => key removed successfully
C:\Windows\System32\Tasks\{ADCE5B3C-0C4C-4666-8910-97C0DD32899D} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{ADCE5B3C-0C4C-4666-8910-97C0DD32899D}" => key removed successfully
C:\Users\Chris Blaze\AppData\Local\Temporary Internet Files => ":J5NmI6leURLnKx1viNZ1It7" ADS could not remove.
C:\Users\Chris Blaze\AppData\Local\Temporary Internet Files => ":ZwKYLSnlJp4kMBhrZgrXP" ADS could not remove.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\CleanHlp" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys" => key removed successfully
C:\Program Files (x86)\unins000.dat => moved successfully
C:\Program Files (x86)\unins000.exe => moved successfully
C:\Users\Chris Blaze\AppData\Local\ars.cache => moved successfully
C:\Users\Chris Blaze\AppData\Local\census.cache => moved successfully
C:\Users\Chris Blaze\AppData\Local\housecall.guid.cache => moved successfully
C:\Users\Chris Blaze\AppData\Local\resmon.resmoncfg => moved successfully
C:\Users\Chris Blaze\AppData\Local\sponge.last.runtime.cache => moved successfully
C:\ProgramData\ArcadeDeluxe5.log => moved successfully
C:\ProgramData\PS.log => moved successfully
C:\Users\Chris Blaze\AppData\Local\Temp\libeay32.dll => moved successfully
C:\Users\Chris Blaze\AppData\Local\Temp\msvcr120.dll => moved successfully
C:\Users\Chris Blaze\AppData\Local\Temp\sqlite3.dll => moved successfully
"C:\Users\CHRISB~1\AppData\Local\Temp\jre-8u31-windows-au.exe" => not found.
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9944456 B
Java, Flash, Steam htmlcache => 492 B
Windows/system/drivers => 5874141 B
Edge => 0 B
Chrome => 620904688 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 0 B
NetworkService => 1150 B
Chris Blaze => 10839196 B
 
RecycleBin => 0 B
EmptyTemp: => 625.6 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 06:23:51 ====
 
 
 
Zoek.exe v5.0.0.1 Updated 19-September-2016
Tool run by Chris Blaze on Fri 10/14/2016 at  6:32:19.33.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Chris Blaze\Desktop\zoek.exe [Scan all users] [Script inserted] 
 
==== System Restore Info ======================
 
10/14/2016 6:36:27 AM Zoek.exe System Restore Point Created Successfully.
 
==== Empty Folders Check ======================
 
C:\PROGRA~2\AVS4YOU deleted successfully
C:\PROGRA~2\Barnes & Noble deleted successfully
C:\PROGRA~3\Evernote deleted successfully
C:\PROGRA~3\{F6D87D2D-FF75-4E85-9BC9-59FC2821F727} deleted successfully
C:\Users\Chris Blaze\AppData\Local\CrashDumps deleted successfully
C:\Users\Chris Blaze\AppData\Local\Cyberlink deleted successfully
C:\Users\Chris Blaze\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\Chris Blaze\AppData\Local\EmieSiteList deleted successfully
C:\Users\Chris Blaze\AppData\Local\EmieUserList deleted successfully
C:\Users\Chris Blaze\AppData\Local\MigWiz deleted successfully
C:\Users\Chris Blaze\AppData\Local\PACE Anti-Piracy deleted successfully
C:\Users\Chris Blaze\AppData\Local\TX0Ff963iC deleted successfully
 
==== Deleting CLSID Registry Keys ======================
 
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-1437231282-1839955917-1510631889-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-1437231282-1839955917-1510631889-1000\Software\Classes\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
 
==== Deleting CLSID Registry Values ======================
 
 
==== Deleting Services ======================
 
 
==== FireFox Fix ======================
 
Deleted from C:\Users\CHRISB~1\AppData\Roaming\Mozilla\Firefox\Profiles\P3ayBMJC.default\prefs.js:
 
Added to C:\Users\CHRISB~1\AppData\Roaming\Mozilla\Firefox\Profiles\P3ayBMJC.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
 
==== Deleting Files \ Folders ======================
 
C:\PROGRA~2\AVS4YOU not found
C:\PROGRA~2\Barnes & Noble not found
C:\PROGRA~3\{F6D87D2D-FF75-4E85-9BC9-59FC2821F727} not found
C:\PROGRA~3\{08BCEE1B-8DEC-401F-989A-111EE3AF2366} deleted
C:\PROGRA~3\{16F41BBA-8EF8-4EDF-8044-32187BCC47D7} deleted
C:\PROGRA~3\{1BE334C4-70A6-4FB8-8AFB-CA2EF7E30F28} deleted
C:\PROGRA~3\{2D899CDA-036D-4C16-BE9C-BE6CDE48A07B} deleted
C:\PROGRA~3\{2E9BA6FD-AB3C-4DE8-A99D-2E396702775D} deleted
C:\PROGRA~3\{30FA7941-4170-4C83-A9A8-FDF01C431704} deleted
C:\PROGRA~3\{32849BA1-784B-4E0B-BB8F-AABEE988E2B0} deleted
C:\PROGRA~3\{453B827B-99D6-45D6-8FD5-02A4384CEA27} deleted
C:\PROGRA~3\{4C99B1DC-0B59-43A6-8537-9CE9286685A3} deleted
C:\PROGRA~3\{53071988-250F-4018-8844-A7E32FB335ED} deleted
C:\PROGRA~3\{58C34507-0A37-4DC0-8136-ECBD9674E89B} deleted
C:\PROGRA~3\{5A23829C-A66E-47B0-AD50-21A3FFE6C325} deleted
C:\PROGRA~3\{5D4AD7AA-51B3-4EF1-8DBC-4D6CBFF4668D} deleted
C:\PROGRA~3\{6495CC1D-C10B-40C5-A92B-241A2B2C8D20} deleted
C:\PROGRA~3\{7F3144B7-67AA-4DD7-BC11-CBA9A40B430D} deleted
C:\PROGRA~3\{929A2A2C-EEDF-4FD7-830C-278E194D1B53} deleted
C:\PROGRA~3\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14} deleted
C:\PROGRA~3\{A32199A3-F9AC-4CB1-B86B-000707CCD970} deleted
C:\PROGRA~3\{AE4E9D9F-140B-4444-9F54-7EF88D1966D3} deleted
C:\PROGRA~3\{B0CAD5CC-867E-473E-B55F-339F9635A45D} deleted
C:\PROGRA~3\{B2CE25ED-AA3A-426F-873C-A958CC21FC03} deleted
C:\PROGRA~3\{B57BCE68-0C0F-48CE-98DB-5E6BF5A4FAE8} deleted
C:\PROGRA~3\{BCE70080-8C44-4FE4-9CEE-9ABE71A36E7E} deleted
C:\PROGRA~3\{C2A6FB07-9A3C-440E-97E0-EB9B404F2A6B} deleted
C:\PROGRA~3\{C5CAF473-C900-4049-BCE5-A93E0EBA7EF2} deleted
C:\PROGRA~3\{CB28D9D3-6B5D-4AFA-BA37-B4AFAAAF71B9} deleted
C:\PROGRA~3\{D4CF3945-D629-4E66-822B-B6E8085F263D} deleted
C:\PROGRA~3\{D9BC4C8F-B86F-45C8-A961-B9FF0910DE40} deleted
C:\PROGRA~3\{ECCA2E41-2653-4A28-BB8F-62B24E1A584D} deleted
C:\PROGRA~3\{F4FF7251-2B0F-48B9-A31D-1930EB197336} deleted
C:\PROGRA~3\{F57C376F-E7ED-4527-9EE2-4D50799418BC} deleted
C:\PROGRA~3\{F7BFF4EE-E380-444D-BF91-DE4716D46130} deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Chris Blaze\AppData\Local\CrashRpt deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Users\CHRISB~1\AppData\Roaming\Mozilla\Firefox\Profiles\P3ayBMJC.default\extensions\[removed] deleted
 
==== Orphaned Tasks deleted from Registry ======================
 
clear.fiMovieService.exe_2243270659 deleted
NCH Software\SwitchReminder deleted
NCH Software\WavePadDowngrade deleted
NCH Software\WavePadReminder deleted
 
==== Firefox Start and Search pages ======================
 
ProfilePath: C:\Users\CHRISB~1\AppData\Roaming\Mozilla\Firefox\Profiles\P3ayBMJC.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
 
==== Firefox Extensions ======================
 
ProfilePath: C:\Users\CHRISB~1\AppData\Roaming\Mozilla\Firefox\Profiles\P3ayBMJC.default
- Undetermined - C:\Users\Chris Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\P3ayBMJC.default\extensions\[removed]
 
==== Firefox Plugins ======================
 
 
==== Chromium Look ======================
 
Google Chrome Version: 46.0.2490.86
 
 
Mafia Wars Addon - Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\llfmkjppmncfcgdebajkjnopgodlcaoe
Wolf and the Ice Planet - Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gffkhmkbijdmbncaoclaclldnbndflck
Mafia Wars Addon - Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\llfmkjppmncfcgdebajkjnopgodlcaoe
Chrome Media Router - Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
 
==== Set IE to Default ======================
 
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Old Start Page"="http://www.google.com"
 
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Old Start Page"="http://www.google.com/"
 
==== All HKLM and HKCU SearchScopes ======================
 
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
 
==== Reset Google Chrome ======================
 
C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Secure Preferences was reset successfully
C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data-journal was reset successfully
 
==== Empty IE Cache ======================
 
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Chris Blaze\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
 
==== Empty FireFox Cache ======================
 
No FireFox Cache found
 
==== Empty Chrome Cache ======================
 
C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Chris Blaze\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
 
==== Empty All Flash Cache ======================
 
Flash Cache Emptied Successfully
 
==== Empty All Java Cache ======================
 
Java Cache cleared successfully
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=361 folders=69 500644775 bytes)
 
==== Empty Temp Folders ======================
 
C:\Users\Chris Blaze\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
 
==== After Reboot ======================
 
==== Empty Temp Folders ======================
 
C:\Windows\Temp successfully emptied
C:\Users\CHRISB~1\AppData\Local\Temp successfully emptied
 
==== Empty Recycle Bin ======================
 
C:\$RECYCLE.BIN successfully emptied
 
==== EOF on Fri 10/14/2016 at  7:10:32.36 ======================
 

I just got back online 8 hours after having posting the logs.  I guess that fix reset all the chrome or google settings?  I have to keep manually opening tabs and lining them up the way I need them to be.  When I signed off, they were all lined up except one which I can't find, now. Also all extensions are gone from the browser.  Should I not reinstall Adware Blocker Plus? I had another for a game that no longer exists and I can't get the extension back for that one. 

 

Otherwise, sol far, the computer is running much, much faster but I am not sure about popups, so far.  I am so used to Ad Blocker taking care of everything, I'm not sure, yet.  Need to be online a bit longer to find out.  Looking pretty good so far!  :thumbup:

Can I reinstall Adbocker-Plus or Adblocker?

 

Yes. However, by default, AdBlock Plus allows "unobtrusive" adverts in order to support the websites. Go here to read more.

 

We’ve flushed the DNS so let’s try to reset the router and then have a look with another tool.

Reset the Router

Let’s try to reset the router to its default configuration.

  • this can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labelled "reset" located on the back of the router.
  • press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
  • if you don’t know the router's default password, you can look it up. here
  • you also need to reconfigure any security settings you had in place prior to the reset.
  • you may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

Note: After resetting your router, it is important to set a non-default password, and if possible, username, on the router. This will assist in eliminating the possibility of the router being hijacked again.

===================================================

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop

  • close all running programs
  • for Windows Vista/7/8/10, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on ‘Report’ and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.
Please post the contents of the RKreport.txt in your next reply.

 

 

 

 

OK, the router does not belong to me.  It is my son's and he uses it for XBOX and XBOX 1 plus a few other systems and also his mobile and mine.   I can't go in there and change anything without his approval because he's worked for literally hours with Microsoft to get it set up just so, to access his games and Twitch plus he uploads 100s of youtube videos and also shoots video via Xbox and the mobile as well.  The only thing belonging to me, here, is the computer.  It's not my ISP, either.  That is something paid for by my ex husband for my son.

 

So, can we go ahead and do the RogueKiller, first, while I figure out and discuss with them about the router?

 

I did find out, last night after I posted, that Avira and the firewall that comes with it were not turned on.  Strange as they always turn back on when I reboot but didn't last night.  When I turned them back on, I am not getting many types of popups at all.

 

As far as Adblocker, I do a lot of video recording, myself, which is then uploaded to youtube.  What I am recording are streaming webcams and in the past, my experience with youtube is that it runs a lot of ads over the video as well as some other streaming sites and Adblocker stops that.   I may be forced to use it, despite it's qualities but will not reinstall it right now.

AdBlocker is fine: all I'm saying is that it won't block all ads.

 

Don't worry about the router but please run RogueKiller.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI