This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

svchost process pegs the CPU at 100%

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi.

 

I have an old Windows XP PC with all of the service packs installed. Recently, I've noticed that shortly after the computer boots, the svchost process pegs the CPU at 100% and it never stops. I can kill the process in the task manager, but then I can't hear any sound from applications like Windows Media player or YouTube in a web browser.

 

Here's the HijackThis log:

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:07:00 AM, on 11/18/2016
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Charlie Duffy.CD-HOME\My Documents\Downloads\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [VMM Mode Selection] C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_03A0228FD8C23B53A1BDEC1177168E69] "C:\Program Files\Google\Chrome\Application\chrome.exe" –no-startup-window
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Verizon Wireless Software Utility Application for Android – Samsung.lnk = C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Verizon\UA_ar\UA.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Verizon Wireless Software Utility Application for Android – Samsung.lnk = C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Verizon\UA_ar\UA.exe (User 'Default user')
O4 - Startup: Verizon Wireless Software Utility Application for Android – Samsung.lnk = C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Verizon\UA_ar\UA.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1361332591468
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: bw+0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\3.11.334\McCHSvc.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 19880 bytes

Hi

Backup the Registry


Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.
  • Please download the installer for Registry Backup from here or here and save to your desktop.
  • Right-click on tweaking.com_registry_backup_setup.exe and select Run as Administrator >> Follow the prompts for a default installation
  • Ensure the option Open "Tweaking.com - Registry Backup" When Install Completes is selected >> Next > >> Finish
  • Once the GUI(graphical user interface) has appeared/loaded:-
[external image: TCRB-1.jpg]
  • Click on Backup Now >> once the process is complete the below will be displayed in the GUI:-
[external image: TBRB-2.jpg]
  • Close Tweaking.com - Registry Backup
Note: There will now be a folder at the root of the Hard-Drive named C:\RegBackup, do not delete this as it is the actual backup just created.

A tutorial for Registry Backup explaining the various features be viewed HERE


``````````````````````````````````````````````````````

Instruction for producing the Farbar Recovery Scan Tool (FRST) and aswMBR logs

Farbar Log

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note:
You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

(A simple way to check your system: Start –> Computer (right click) –> Properties
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Please make sure All Users is checked
  • Do not check
    *List BCD
    *Drivers MD5
    *Shortcut txt
Or your logs will be too long to post.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please don't run the Farbar Recovery Scan Tool (FRST.txt) from your "Downloads" folder or from "Temporary Internet Files"
  • Please copy and paste log into your topic.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please attach that along with the FRST.txt into your reply.
aswMBR Log

Important! Please do NOT perform any fix options offered in aswMBR, we just need to see the report.

Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.
  • If a prompt stating: The computer supports "Virtualization Technology" appears select Yes
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the Save Log button, save the logfile to your desktop and post its contents in your reply with the Farbar (FRST) log.

FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-11-2016
Ran by [removed] (administrator) on CD-HOME (18-11-2016 19:35:21)
Running from C:\Documents and Settings\[removed]\Desktop
[removed] Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Logitech Inc.) C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Skype Technologies S.A.) C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Logitech Inc.                    ) C:\PROGRA~1\Logitech\MOUSEW~1\system\EM_EXEC.EXE
(Avance Logic, Inc.) C:\WINDOWS\SOUNDMAN.EXE
(Logitech Inc.) C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Logitech) C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [zBrowser Launcher] => C:\Program Files\Logitech\iTouch\iTouch.exe [892928 2004-03-18] (Logitech Inc.)
HKLM\…\Run: [EM_EXEC] => C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE [28672 2002-07-09] (Logitech Inc.                    )
HKLM\…\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [46592 2002-08-15] (Avance Logic, Inc.)
HKLM\…\Run: [LogitechCommunicationsManager] => C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe [497200 2006-06-26] (Logitech Inc.)
HKLM\…\Run: [VMM Mode Selection] => C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe [43520 2011-02-14] ()
HKLM\…\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [nwiz] => nwiz.exe /install
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKU\S-1-5-21-790525478-789336058-1606980848-1003\…\Run: [LDM] => C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [36864 2012-04-12] (Logitech)
HKU\S-1-5-21-790525478-789336058-1606980848-1003\…\Run: [Xvid] => C:\Program Files\Xvid\CheckUpdate.exe [8192 2011-01-17] ()
HKU\S-1-5-21-790525478-789336058-1606980848-1003\…\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-08-21] (Google Inc.)
HKU\S-1-5-21-790525478-789336058-1606980848-1003\…\Run: [GoogleChromeAutoLaunch_03A0228FD8C23B53A1BDEC1177168E69] => C:\Program Files\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.)
Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk [2012-04-12]
ShortcutTarget: Logitech Desktop Messenger.lnk -> C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-08-09]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk [2012-04-12]
ShortcutTarget: Logitech Desktop Messenger.lnk -> C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-08-09]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Documents and Settings\Charlie Duffy.CD-HOME\Start Menu\Programs\Startup\Verizon Wireless Software Utility Application for Android – Samsung.lnk [2013-12-23]
ShortcutTarget: Verizon Wireless Software Utility Application for Android – Samsung.lnk -> C:\Documents and Settings\Administrator.CD-HOME\Application Data\Verizon\UA_ar\UA.exe (No File)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{D3E608BF-6EC0-4FBD-AA5F-50F3F9C78270}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-790525478-789336058-1606980848-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-790525478-789336058-1606980848-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKU\S-1-5-21-790525478-789336058-1606980848-1003 - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
URLSearchHook: [S-1-5-21-790525478-789336058-1606980848-500] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-790525478-789336058-1606980848-1003 -> DefaultScope {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=mkg028
SearchScopes: HKU\S-1-5-21-790525478-789336058-1606980848-1003 -> {A21A27D6-0D01-4E3F-9D8C-12AD0BE0236A} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=7D129D98-ADF9-46E1-B559-0FAFC3DFABCB&apn_sauid=BAF6973D-7D33-43E6-A63C-9D2E4B9136D7
SearchScopes: HKU\S-1-5-21-790525478-789336058-1606980848-1003 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=mkg028
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-22] (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-22] (Google Inc.)
Toolbar: HKU\S-1-5-21-790525478-789336058-1606980848-1003 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-22] (Google Inc.)
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: bw+0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw+0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw-0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw-0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw00 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw00s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw10 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw10s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw20 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw20s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw30 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw30s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw40 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw40s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw50 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw50s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw60 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw60s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw70 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw70s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw80 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw80s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw90 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bw90s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwa0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwa0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwb0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwb0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwc0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwc0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwd0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwd0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwe0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwe0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwf0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwf0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwg0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwg0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwh0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwh0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwi0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwi0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwj0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwj0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwk0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwk0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwl0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwl0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwm0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwm0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwn0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwn0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwo0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwo0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwp0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwp0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwq0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwq0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwr0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwr0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bws0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bws0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwt0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwt0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwu0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwu0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwv0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwv0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bww0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bww0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwx0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwx0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwy0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwy0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwz0 - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: bwz0s - {ab07ad51-a2e5-489e-a029-9bc50d21e5b7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: offline-8876480 - {AB07AD51-A2E5-489E-A029-9BC50D21E5B7} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll [2012-04-12] (Logitech)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-04-08] (Skype Technologies)

FireFox:
========
FF Extension: (Skype Click to Call) - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2016-10-20] [not signed]
FF Extension: (Skype Click to Call) - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2016-10-20] [not signed]
FF Extension: (Multi-process staged rollout) - C:\Program Files\Mozilla Firefox\browser\features\[removed] [2016-10-20] [not signed]
FF Extension: (Pocket) - C:\Program Files\Mozilla Firefox\browser\features\[removed] [2016-10-20] [not signed]
FF Extension: (Web Compat) - C:\Program Files\Mozilla Firefox\browser\features\[removed] [2016-10-20] [not signed]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-02-20] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-11] ()
FF Plugin: @Microsoft.com/DownloadManager,version=1.1 -> C:\WINDOWS\ [] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-790525478-789336058-1606980848-1003: @yahoo.com/BrowserPlus,version=2.9.8 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll [2010-10-19] (Yahoo! Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2013-06-14] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2013-06-14] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2013-06-14] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2013-06-14] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2013-06-14] (Apple Inc.)

Chrome:
=======
CHR Profile: C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default [2016-02-29]
CHR Extension: (Google Slides) - C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-29]
CHR Extension: (Google Docs) - C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-29]
CHR Extension: (Google Drive) - C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-29]
CHR Extension: (YouTube) - C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-29]
CHR Extension: (Google Search) - C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-29]
CHR Extension: (Google Sheets) - C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-29]
CHR Extension: (Google Docs Offline) - C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-29]
CHR Extension: (Skype Click to Call) - C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-02-29]
CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-29]
CHR Extension: (Gmail) - C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-29]
CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ATTENTION: => Could not perform signature verification. Cryptographic Service is not running.

R2 LVPrcSrv; c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe [99888 2006-06-26] (Logitech Inc.)
S2 LVSrvLauncher; C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe [91696 2006-06-26] (Logitech Inc.)
R2 Skype C2C Service; C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\3.11.334\McCHSvc.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [667255 2002-08-31] (Avance Logic, Inc.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 itchfltr; C:\WINDOWS\System32\DRIVERS\itchfltr.sys [12953 2004-03-10] (Logitech, Inc.)
R3 l8042pr2; C:\WINDOWS\System32\DRIVERS\L8042Pr2.sys [50862 2002-07-09] (Logitech, Inc.)
R3 LKbdFlt2; C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys [6030 2002-07-09] (Logitech, Inc.)
S3 LVcKap; C:\WINDOWS\System32\DRIVERS\LVcKap.sys [1587632 2006-06-26] (Logitech Inc.)
S3 LVMVDrv; C:\WINDOWS\System32\DRIVERS\LVMVDrv.sys [1952816 2006-06-26] (Logitech Inc.)
R3 LVPr2Mon; C:\WINDOWS\System32\drivers\LVPr2Mon.sys [23472 2006-06-26] ()
S3 LVUSBSta; C:\WINDOWS\System32\DRIVERS\LVUSBSta.sys [38960 2006-06-22] (Logitech Inc.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 pepifilter; C:\WINDOWS\System32\DRIVERS\lv302af.sys [12080 2006-06-22] (Logitech Inc.)
S3 PID_08A0; C:\WINDOWS\System32\DRIVERS\LV302AV.SYS [720176 2006-06-22] (Logitech Inc.)
R3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-18 19:35 - 2016-11-18 19:35 - 00029481 _____ C:\Documents and Settings\Charlie Duffy.CD-HOME\Desktop\FRST.txt
2016-11-18 19:27 - 2016-11-18 19:35 - 00000000 ____D C:\FRST
2016-11-18 19:26 - 2016-11-18 19:26 - 01761280 _____ (Farbar) C:\Documents and Settings\Charlie Duffy.CD-HOME\Desktop\FRST.exe
2016-11-18 19:20 - 2016-11-18 19:20 - 00000000 ____D C:\RegBackup
2016-11-18 19:18 - 2016-11-18 19:18 - 00023968 _____ C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2016-11-18 19:18 - 2016-11-18 19:18 - 00017590 _____ C:\WINDOWS\Tweaking.com - Registry Backup Setup Log.txt
2016-11-18 19:18 - 2016-11-18 19:18 - 00001876 _____ C:\Documents and Settings\All Users.WINDOWS\Desktop\Tweaking.com - Registry Backup.lnk
2016-11-18 19:18 - 2016-11-18 19:18 - 00000000 ____D C:\Program Files\Tweaking.com
2016-11-18 19:18 - 2016-11-18 19:18 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Tweaking.com
2016-11-18 19:18 - 2016-11-18 19:18 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Tweaking.com
2016-10-26 18:15 - 2016-10-26 18:15 - 05488320 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2016-10-20 23:31 - 2016-10-21 11:50 - 00000000 ____D C:\Program Files\Mozilla Firefox

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-18 19:35 - 2016-02-29 21:26 - 00000000 ____D C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Temp
2016-11-18 19:27 - 2014-01-05 15:16 - 00000000 ____D C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\temp
2016-11-18 19:22 - 2012-04-12 21:56 - 00032424 _____ C:\WINDOWS\SchedLgU.Txt
2016-11-18 19:22 - 2012-04-12 21:56 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-11-18 19:15 - 2012-08-21 21:38 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-11-18 19:15 - 2012-04-12 23:57 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-11-18 19:07 - 2014-03-19 12:17 - 00088566 _____ C:\WINDOWS\system32\nvapps.xml
2016-11-18 19:07 - 2008-04-14 07:00 - 00013740 _____ C:\WINDOWS\system32\wpa.dbl
2016-11-18 19:06 - 2014-03-06 18:03 - 00000238 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2016-11-18 19:06 - 2012-08-21 21:38 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-11-18 19:06 - 2012-04-12 23:11 - 00000051 _____ C:\WINDOWS\iTouch.ini
2016-11-18 19:06 - 2011-12-08 23:53 - 01439766 _____ C:\itouch_crash_info.txt
2016-11-18 00:20 - 2012-04-12 22:01 - 00000178 ___SH C:\Documents and Settings\Charlie Duffy.CD-HOME\ntuser.ini
2016-11-17 23:38 - 2012-04-15 19:24 - 00167936 _____ C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-11-11 12:08 - 2012-04-13 21:20 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2016-11-11 12:08 - 2012-04-13 21:20 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2016-11-11 12:08 - 2011-10-23 11:50 - 00000000 ____D C:\Program Files\Yahoo!
2016-11-11 12:06 - 2012-04-12 23:05 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Logitech
2016-11-11 12:06 - 2012-04-12 23:05 - 00000000 ____D C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Logitech
2016-11-11 11:42 - 2014-09-06 12:08 - 00000000 ____D C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Adobe
2016-11-11 11:42 - 2012-04-12 23:57 - 00796352 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-11-11 11:42 - 2012-04-12 23:57 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-11-11 11:41 - 2011-10-23 10:49 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-11-06 14:30 - 2012-04-12 17:37 - 00513832 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-10-25 15:13 - 2013-01-11 12:05 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2016-10-21 18:49 - 2012-05-10 23:03 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service

==================== Files in the root of some directories =======

2016-02-29 22:33 - 2016-02-29 22:33 - 0005632 _____ () C:\Documents and Settings\Administrator.CD-HOME\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Some files in TEMP:
====================
C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Temp\IadHide5.dll
C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Temp\quickcamENU.exe


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => MD5 is legit
C:\WINDOWS\system32\winlogon.exe => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\User32.dll => MD5 is legit
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\dnsapi.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit

==================== End of FRST.txt ============================

Addition.txt

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 18-11-2016
Ran by [removed] (18-11-2016 19:35:54)
Running from C:\Documents and Settings\[removed]\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) (2012-04-13 02:54:37)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-790525478-789336058-1606980848-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator.CD-HOME
Charlie Duffy (S-1-5-21-790525478-789336058-1606980848-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Charlie Duffy.CD-HOME
Guest (S-1-5-21-790525478-789336058-1606980848-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-790525478-789336058-1606980848-1000 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-790525478-789336058-1606980848-1002 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)


==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.22beta (HKLM\…\7-Zip) (Version:  - )
Adobe Flash Player 23 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 23.0.0.205 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Apple Application Support (HKLM\…\{F5266D28-E0B2-4130-BFC5-EE155AD514DC}) (Version: 2.3 - Apple Inc.)
Apple Software Update (HKLM\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Avance AC'97 Audio (HKLM\…\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version:  - )
Cisco WebEx Meetings (HKLM\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Google Chrome (HKLM\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.31.5 - Google Inc.) Hidden
K-Lite Mega Codec Pack 8.6.0 (HKLM\…\KLiteCodecPack_is1) (Version: 8.6.0 - )
Logitech Desktop Messenger (HKLM\…\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}) (Version: 2.30.04 - Logitech, Inc.)
Logitech iTouch Software (HKLM\…\{036AA4D4-6D32-11D4-9875-00105ACE7734}) (Version:  - )
Logitech MouseWare 9.71  (HKLM\…\{5809E7CF-4DCF-11D4-9875-00105ACE7734}) (Version:  - )
Logitech Resource Center (HKLM\…\Logitech Resource Center) (Version:  - )
Logitech® Camera Driver (HKLM\…\QcDrv) (Version:  - )
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.11.376.2 - McAfee, Inc.)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Download Manager (HKLM\…\{654977DB-0001-0002-0001-EABD228DDE8B}) (Version: 1.2.1 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Standard 2007 (HKLM\…\STANDARDR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\…\Wudf01000) (Version:  - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 49.0.2 (x86 en-US) (HKLM\…\Mozilla Firefox 49.0.2 (x86 en-US)) (Version: 49.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 49.0.2.6136 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Notepad++ (HKLM\…\Notepad++) (Version: 6.8.6 - Notepad++ Team)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version:  - )
QuickTime (HKLM\…\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.9.0 - SAMSUNG Electronics Co., Ltd.)
Skype Click to Call (HKLM\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 6.16 (HKLM\…\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
SUABnR (HKLM\…\InstallShield_{2485354C-6B65-4978-BB91-CCE61442377B}) (Version: 1.1.0.13103_1 - Samsung Electronics Co., Ltd.)
SUABnR (Version: 1.1.0.13103_1 - Samsung Electronics Co., Ltd.) Hidden
Tweaking.com - Registry Backup (HKLM\…\Tweaking.com - Registry Backup) (Version: 3.5.2 - Tweaking.com)
UMVPLStandalone (Version: 10.00.1439 - Logitech Inc.) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Verizon Wireless Software Upgrade Assistant - Samsung(ar) (HKLM\…\{267B6912-6F26-4FFD-9342-8E84A7B26151}) (Version: 2.13.1103 - Samsung Electronics Co., Ltd.)
Verizon Wireless Software Utility Application for Android - Samsung (HKLM\…\{2E6FA5CA-1597-4219-AF62-D9B061E7C448}) (Version: 2.13.1101 - Samsung Electronics Co., Ltd.)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Genuine Advantage Notifications (KB905474) (HKLM\…\WgaNotify) (Version: 1.9.0040.0 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version:  - )
Windows Media Player 11 (HKLM\…\Windows Media Player) (Version:  - )
WinRAR 4.20 (32-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Xvid Video Codec (HKLM\…\Xvid Video Codec 1.3.1) (Version: 1.3.2 - )
Yahoo! BrowserPlus 2.9.8 (HKU\S-1-5-21-790525478-789336058-1606980848-1003\…\Yahoo! BrowserPlus) (Version:  - Yahoo! Inc.)
Yahoo! Software Update (HKLM\…\Yahoo! Software Update) (Version:  - )
Yahoo! Toolbar (HKLM\…\Yahoo! Companion) (Version:  - Yahoo! Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0000002F-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Dropbox\bin\Dropbox.exe /autoplay = (the data entry has 9 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{04EBE69E-2DED-44F6-9854-9A3988F751ED}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Dropbox\Update\1.3.5 (the data entry has 25 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{05C3F9E2-1E76-439F-9E37-9020946A191A}\InprocServer32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVMaEnum.dll (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{09303D01-B159-4F1B-A2B8-CA3117B8FA1B}\InprocServer32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVMaEnum.dll (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Dropbox\Update\1.3.2 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0BE35204-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{54B2BE72-FEC7-443D-BAE9-3E70E618A7D8}\InprocServer32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVMaEnum.dll (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{6CE4B8A6-4DB5-4F63-8013-1197503692EF}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\YBPAddon_2.9.8.dll (Yahoo! Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{73CA2532-42DE-449F-8C8A-229B8AAF3B68}\InprocServer32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVMaEnum.dll (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{949DB7D2-36F2-4CCA-8CA8-A3A6D4E5911C}\InprocServer32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVMaEnum.dll (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{A50A1B09-943D-4A78-B08D-56072A602ABD}\InprocServer32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVComCX.dll (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{C9448C44-BEFB-4941-8457-E5C4314D3D96}\localserver32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{CAF933C7-C65A-46D2-AA63-1FC84EB43954}\InprocServer32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVMaEnum.dll (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{CC9E9F9A-11A4-49DD-B468-782AFDE5607E}\InprocServer32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVMaEnum.dll (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{CD89D352-5A13-49F8-9EB5-7E6D1FB0CD57}\localserver32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Dropbox\Update\1.3.2 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{DB20D0C0-4CEF-11D0-8B17-00AA00211961}\localserver32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{DB20D0C3-4CEF-11D0-8B17-00AA00211961}\localserver32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}\localserver32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Dropbox\bin\Dropbox.exe /wiacallbac (the data entry has 12 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{E7A37920-253C-4FF1-B169-298A7CE6CAA9}\localserver32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Dropbox\bin\Dropbox.exe => No File
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{E8ACF719-FFDE-4EE1-8923-48BDA8569FCC}\localserver32 -> C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe (Logitech Inc.)
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2014-05-12 04:49 - 2014-05-12 04:49 - 00260608 _____ () C:\Program Files\Notepad++\NppShell_06.dll
2006-10-22 11:22 - 2006-10-22 11:22 - 00212992 _____ () C:\WINDOWS\system32\nvapi.dll
2011-10-23 12:07 - 2012-04-12 23:46 - 00061496 _____ () C:\Program Files\Logitech\Desktop Messenger\8876480\7.2.0.157-8876480SL\Program\clntutil.dll
2011-10-23 12:07 - 2012-04-12 23:46 - 00147493 _____ () C:\Program Files\Logitech\Desktop Messenger\8876480\7.2.0.157-8876480SL\Program\BWfiles.dll
2011-10-23 12:07 - 2012-04-12 23:46 - 00553001 _____ () C:\Program Files\Logitech\Desktop Messenger\8876480\7.2.0.157-8876480SL\Program\BWDocMapExt.dll
2011-10-23 12:07 - 2012-04-12 23:46 - 00114688 _____ () C:\Program Files\Logitech\Desktop Messenger\8876480\7.2.0.157-8876480SL\Program\bwscriptext.dll
2008-04-14 07:00 - 2013-01-02 01:49 - 01292288 _____ () C:\WINDOWS\system32\quartz.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2008-04-14 07:00 - 2016-06-28 21:04 - 00000070 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1       localhost
0.0.0.1    mssplus.mcafee.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-790525478-789336058-1606980848-1003\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
HKU\S-1-5-21-790525478-789336058-1606980848-500\Control Panel\Desktop\\Wallpaper -> (None)
DNS Servers: 192.168.1.1
sharedaccess => Firewall Service is not running.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

DomainProfile\AuthorizedApplications: [C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe] => Enabled:Logitech Desktop Messenger
StandardProfile\AuthorizedApplications: [C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe] => Enabled:Logitech Desktop Messenger
StandardProfile\AuthorizedApplications: [C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe] => Enabled:Yahoo! Messenger
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE] => Enabled:Microsoft Office Outlook
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe] => Enabled:WebKit
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Dropbox\bin\Dropbox.exe] => Enabled:Dropbox
StandardProfile\AuthorizedApplications: [C:\Program Files\Skype\Phone\Skype.exe] => Enabled:Skype
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)

==================== Restore Points =========================

ATTENTION: System Restore is disabled
Check "winmgmt" service or repair WMI.


==================== Faulty Device Manager Devices =============

Name: Mass Storage Controller
Description: Mass Storage Controller
Class Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/16/2016 12:43:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 49.0.2.6136, faulting module mozglue.dll, version 49.0.2.6136, fault address 0x0000e83e.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (11/11/2016 01:41:08 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 49.0.2.6136, faulting module mozglue.dll, version 49.0.2.6136, fault address 0x0000e83e.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (11/09/2016 02:29:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 49.0.2.6136, faulting module mozglue.dll, version 49.0.2.6136, fault address 0x0000e83e.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (11/04/2016 04:35:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 49.0.2.6136, faulting module mozglue.dll, version 49.0.2.6136, fault address 0x0000e83e.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (11/02/2016 07:15:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 49.0.2.6136, faulting module mozglue.dll, version 49.0.2.6136, fault address 0x0000e83e.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (11/02/2016 07:15:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 49.0.2.6136, faulting module mozglue.dll, version 49.0.2.6136, fault address 0x0000e83e.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (11/02/2016 12:41:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 49.0.2.6136, faulting module mozglue.dll, version 49.0.2.6136, fault address 0x0000e83e.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (11/02/2016 12:37:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 49.0.2.6136, faulting module mozglue.dll, version 49.0.2.6136, fault address 0x0000e83e.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (11/02/2016 12:35:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 49.0.2.6136, faulting module mozglue.dll, version 49.0.2.6136, fault address 0x0000e83e.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (10/24/2016 03:45:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 49.0.2.6136, faulting module mozglue.dll, version 49.0.2.6136, fault address 0x0000e83e.
Processing media-specific event for [plugin-container.exe!ws!]


System errors:
=============
Error: (11/18/2016 07:24:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Network Connections service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/18/2016 07:24:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Workstation service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/17/2016 11:34:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Server service terminated unexpectedly.  It has done this 1 time(s).

Error: (11/17/2016 11:34:39 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Help and Support service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 100 milliseconds: Restart the service.

Error: (11/17/2016 10:47:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Automatic Updates service terminated unexpectedly.  It has done this 2 time(s).

Error: (11/17/2016 10:47:21 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Management Instrumentation service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (11/17/2016 10:47:21 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Themes service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (11/17/2016 10:47:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The System Event Notification service terminated unexpectedly.  It has done this 2 time(s).

Error: (11/17/2016 10:47:21 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Task Scheduler service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (11/17/2016 10:47:21 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Help and Support service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 100 milliseconds: Restart the service.


==================== Memory info ===========================

Processor:  Intel(R) Pentium(R) 4 CPU 2.53GHz
Percentage of memory in use: 75%
Total physical RAM: 511.48 MB
Available physical RAM: 127.05 MB
Total Virtual: 1250.2 MB
Available Virtual: 770.2 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:28.63 GB) (Free:7.28 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:76.32 GB) (Free:22.47 GB) NTFS
Drive g: (My Passport) (Fixed) (Total:465.65 GB) (Free:398.78 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 28.6 GB) (Disk ID: 52A052A0)
Partition 1: (Active) - (Size=28.6 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 76.3 GB) (Disk ID: 5D565D56)
Partition 1: (Not Active) - (Size=76.3 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 465.8 GB) (Disk ID: 44FDFE06)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=0C)

==================== End of Addition.txt ============================

aswMBR.txt

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-11-18 19:38:23
—————————–
19:38:23.320    OS Version: Windows 5.1.2600 Service Pack 3
19:38:23.320    Number of processors: 1 586 0x207
19:38:23.320    ComputerName: CD-HOME  UserName:
19:38:24.008    Initialize success
19:38:24.102    VM: initialized successfully
19:38:24.102    VM: Intel CPU virtualization not supported
19:40:51.917    The log file has been saved successfully to "C:\Documents and Settings\Charlie Duffy.CD-HOME\Desktop\aswMBR.txt"

 

I should mention that the Tweaking.com registry backup tool found some errors while backing up the registry. I'm not sure if those are in the logs or not.

I should mention that the Tweaking.com registry backup tool found some errors while backing up the registry. I'm not sure if those are in the logs or not.

No they were not listed but I was able to see a few listed by FRST.

Can you attempt to turn on system restore?
http://www.bleepingcomputer.com/tutorials/windows-xp-system-restore-guide/#enable

~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Running from C:\Documents and Settings\[removed]\Desktop

We need to move Farbar's to it's own folder on desktop.

Please go to your downloads C:\Documents and Settings\Charlie Duffy.CD-HOME\Desktop folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-790525478-789336058-1606980848-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
URLSearchHook: [S-1-5-21-790525478-789336058-1606980848-500] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-790525478-789336058-1606980848-1003 -> {A21A27D6-0D01-4E3F-9D8C-12AD0BE0236A} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=7D129D98-ADF9-46E1-B559-0FAFC3DFABCB&apn_sauid=BAF6973D-7D33-43E6-A63C-9D2E4B9136D7
C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Temp\IadHide5.dll
C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Temp\quickcamENU.exe
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0000002F-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Dropbox\bin\Dropbox.exe /autoplay = (the data entry has 9 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{04EBE69E-2DED-44F6-9854-9A3988F751ED}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Dropbox\Update\1.3.5 (the data entry has 25 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Dropbox\Update\1.3.2 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0BE35204-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Dropbox\Update\1.3.2 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}\localserver32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Dropbox\bin\Dropbox.exe /wiacallbac (the data entry has 12 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{E7A37920-253C-4FF1-B169-298A7CE6CAA9}\localserver32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Dropbox\bin\Dropbox.exe => No File
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
CMD: C:\ComboFix.txt
EmptyTemp:
Hosts:
End


Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
    In order to use AdwCleaner, you have to agree the Eula:
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
– File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please download Junkware Removal Tool
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
~~~~~~~
please post
Fixlog.txt
AdwCleaner[C1].txt
JRT.txt

Here's fixlog.txt:

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 19-11-2016 01
Ran by [removed] (19-11-2016 18:51:29) Run:1
Running from C:\Documents and Settings\[removed]\Desktop
[removed] Boot Mode: Normal

==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-790525478-789336058-1606980848-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
URLSearchHook: [S-1-5-21-790525478-789336058-1606980848-500] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-790525478-789336058-1606980848-1003 -> {A21A27D6-0D01-4E3F-9D8C-12AD0BE0236A} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=7D129D98-ADF9-46E1-B559-0FAFC3DFABCB&apn_sauid=BAF6973D-7D33-43E6-A63C-9D2E4B9136D7
C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Temp\IadHide5.dll
C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Temp\quickcamENU.exe
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0000002F-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Dropbox\bin\Dropbox.exe /autoplay = (the data entry has 9 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{04EBE69E-2DED-44F6-9854-9A3988F751ED}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Dropbox\Update\1.3.5 (the data entry has 25 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Dropbox\Update\1.3.2 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0BE35204-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Dropbox\Update\1.3.2 (the data entry has 26 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}\localserver32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Dropbox\bin\Dropbox.exe /wiacallbac (the data entry has 12 more characters).
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{E7A37920-253C-4FF1-B169-298A7CE6CAA9}\localserver32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Application Data\Dropbox\bin\Dropbox.exe => No File
CustomCLSID: HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Application Data\Google\Update\1.3.21 (the data entry has 26 more characters).
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
CMD: C:\ComboFix.txt
EmptyTemp:
Hosts:
End
*****************

Error: (0) Failed to create a restore point.
Processes closed successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
Could not restore Default URLSearchHook.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKU\S-1-5-21-790525478-789336058-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A21A27D6-0D01-4E3F-9D8C-12AD0BE0236A}" => key removed successfully.
HKCR\CLSID\{A21A27D6-0D01-4E3F-9D8C-12AD0BE0236A} => key not found.
C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Temp\IadHide5.dll => moved successfully
C:\Documents and Settings\Charlie Duffy.CD-HOME\Local Settings\Temp\quickcamENU.exe => moved successfully
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0000002F-0000-0000-C000-000000000046}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020420-0000-0000-C000-000000000046}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020421-0000-0000-C000-000000000046}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020422-0000-0000-C000-000000000046}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020423-0000-0000-C000-000000000046}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020424-0000-0000-C000-000000000046}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{00020425-0000-0000-C000-000000000046}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{04EBE69E-2DED-44F6-9854-9A3988F751ED}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{0BE35204-8F91-11CE-9DE3-00AA004BB851}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{E7A37920-253C-4FF1-B169-298A7CE6CAA9}" => key removed successfully.
"HKU\S-1-5-21-790525478-789336058-1606980848-1003_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}" => key removed successfully.

========= netsh int ipv4 reset =========

The following command was not found: int ipv4 reset.

========= End of CMD: =========


========= netsh int ipv6 reset =========

IPv6 is not installed.


========= End of CMD: =========


========= C:\ComboFix.txt =========


========= End of CMD: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 9801 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache => 0 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/dllcache/drivers => 20191533 B
Edge => 0 B
Chrome => 9484611 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default User.WINDOWS => 66164 B
All Users.WINDOWS => 0 B
systemprofile => 2202315 B
LocalService.NT AUTHORITY => 9727844 B
NetworkService.NT AUTHORITY => 4146711 B
Charlie Duffy.CD-HOME => 942512351 B
Administrator.CD-HOME => 1764229 B

RecycleBin => -85 B
EmptyTemp: => 944.2 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 18:58:52 ====

When I was running Adw Cleaner the first time it crashed while fixing so I ran it twice. It found 90 threats the first time and 89 threats the second time. I'm posting both log files.

 

This is AdwCleaner[S1].txt:

 

# AdwCleaner v6.030 - Logfile created 19/11/2016 at 19:08:10
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-11-19.2 [Server]
# Operating System : Microsoft Windows XP Service Pack 3 (X86)
# Username : Administrator - CD-HOME
# Running from : C:\Documents and Settings\Charlie Duffy.CD-HOME\Desktop\AdwCleaner.exe
# Mode: Scan
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****

Service Found:  YahooAUService


***** [ Folders ] *****

Folder Found:  C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
Folder Found:  C:\Documents and Settings\All Users.WINDOWS\Documents\Downloaded Installers
Folder Found:  C:\Program Files\Yahoo!\Companion


***** [ Files ] *****

File Found:  C:\Program Files\Yahoo!\Common\unyt.exe


***** [ DLL ] *****

No malicious DLLs found.


***** [ WMI ] *****

No malicious keys found.


***** [ Shortcuts ] *****

No infected shortcut found.


***** [ Scheduled Tasks ] *****

No malicious task found.


***** [ Registry ] *****

Key Found:  HKLM\SOFTWARE\Classes\BackWeb.Client.ScriptHelper-8876480
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.Protector
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.Protector.1
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho.1
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
Key Found:  HKLM\SOFTWARE\Classes\Sample.BrowserHandler
Key Found:  HKLM\SOFTWARE\Classes\Sample.BrowserHandler.1
Key Found:  HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample
Key Found:  HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample.1
Key Found:  HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
Key Found:  HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
Key Found:  HKLM\SOFTWARE\Classes\yt.CacheLoader
Key Found:  HKLM\SOFTWARE\Classes\yt.CacheLoader.1
Key Found:  HKLM\SOFTWARE\Classes\yt.Clickstream
Key Found:  HKLM\SOFTWARE\Classes\yt.Clickstream.1
Key Found:  HKLM\SOFTWARE\Classes\yt.YTHelper
Key Found:  HKLM\SOFTWARE\Classes\yt.YTHelper.2
Key Found:  HKLM\SOFTWARE\Classes\yt.YTNavAssistPlugin
Key Found:  HKLM\SOFTWARE\Classes\yt.YTNavAssistPlugin.1
Key Found:  HKLM\SOFTWARE\Classes\yt.YToolbarBand
Key Found:  HKLM\SOFTWARE\Classes\yt.YToolbarBand.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoSearchAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoSearchAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoUpdaterAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoUpdaterAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBCustomizerAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBCustomizerAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBGeneralAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBGeneralAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBMessengerAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBMessengerAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBSingleInstanceAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBSingleInstanceAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\YTNavAssist.NameSpaceCF
Key Found:  HKLM\SOFTWARE\Classes\YTNavAssist.NameSpaceCF.1
Key Found:  HKLM\SOFTWARE\Classes\YTNavAssist.NameSpacePP
Key Found:  HKLM\SOFTWARE\Classes\YTNavAssist.NameSpacePP.1
Key Found:  HKLM\SOFTWARE\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
Key Found:  HKLM\SOFTWARE\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Key Found:  HKLM\SOFTWARE\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{1E57256D-9F39-4267-AB39-D7813D644C5A}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{31371420-098D-4C0E-A11E-EBEC2305DD01}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{3A06AA27-D94B-48C2-BB55-9FD0FF2120E3}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{46140CE4-76FE-440E-AE88-4C2272BC05C7}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{9F9C4C5C-2BA8-4E00-A697-9F710BB1026B}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{3C16E079-E4C7-493C-BE9F-E0F2BB0B7430}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{6EB4349D-4333-442F-ACA4-4C72AF28B6ED}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{7DB8B625-DBF0-4491-B544-5A06F7B17BB4}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{8E74A0AE-F0ED-47ED-A940-A8E99687646B}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{9DE77B51-89F6-468E-9402-16050382E950}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
Key Found:  HKLM\SOFTWARE\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
Key Found:  HKLM\SOFTWARE\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
Key Found:  HKU\.DEFAULT\Software\Yahoo\Companion
Key Found:  HKU\S-1-5-21-790525478-789336058-1606980848-1003\Software\SlimWare Utilities Inc
Key Found:  HKU\S-1-5-21-790525478-789336058-1606980848-1003\Software\Yahoo\Companion
Key Found:  HKU\S-1-5-21-790525478-789336058-1606980848-1003\Software\Yahoo\YFriendsBar
Key Found:  HKU\S-1-5-18\Software\Yahoo\Companion
Key Found:  HKLM\SOFTWARE\SlimWare Utilities Inc
Key Found:  HKLM\SOFTWARE\Yahoo\Companion
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yahoo! Companion
Key Found:  HKLM\SOFTWARE\Classes\AppID\yt.DLL
Key Found:  HKLM\SOFTWARE\Classes\AppID\ytbbroker.EXE


***** [ Web browsers ] *****

No malicious Firefox based browser items found.
No malicious Chromium based browser items found.

*************************

\AdwCleaner\AdwCleaner[R0].txt - [3461 Bytes] - [16/12/2013 22:30:31]
\AdwCleaner\AdwCleaner[R1].txt - [3478 Bytes] - [28/12/2013 15:08:08]
\AdwCleaner\AdwCleaner[R2].txt - [3538 Bytes] - [05/01/2014 15:19:37]
\AdwCleaner\AdwCleaner[S0].txt - [3663 Bytes] - [05/01/2014 15:23:22]
\AdwCleaner\AdwCleaner[S1].txt - [7561 Bytes] - [19/11/2016 19:08:10]

########## EOF - \AdwCleaner\AdwCleaner[S1].txt - [7632 Bytes] ##########
 

AdwCleaner[S2].txt:

 

# AdwCleaner v6.030 - Logfile created 19/11/2016 at 19:14:11
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-11-19.2 [Server]
# Operating System : Microsoft Windows XP Service Pack 3 (X86)
# Username : Administrator - CD-HOME
# Running from : C:\Documents and Settings\Charlie Duffy.CD-HOME\Desktop\AdwCleaner.exe
# Mode: Scan
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****

No malicious services found.


***** [ Folders ] *****

Folder Found:  C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
Folder Found:  C:\Documents and Settings\All Users.WINDOWS\Documents\Downloaded Installers
Folder Found:  C:\Program Files\Yahoo!\Companion


***** [ Files ] *****

File Found:  C:\Program Files\Yahoo!\Common\unyt.exe


***** [ DLL ] *****

No malicious DLLs found.


***** [ WMI ] *****

No malicious keys found.


***** [ Shortcuts ] *****

No infected shortcut found.


***** [ Scheduled Tasks ] *****

No malicious task found.


***** [ Registry ] *****

Key Found:  HKLM\SOFTWARE\Classes\BackWeb.Client.ScriptHelper-8876480
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.Protector
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.Protector.1
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho.1
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
Key Found:  HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
Key Found:  HKLM\SOFTWARE\Classes\Sample.BrowserHandler
Key Found:  HKLM\SOFTWARE\Classes\Sample.BrowserHandler.1
Key Found:  HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample
Key Found:  HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample.1
Key Found:  HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
Key Found:  HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
Key Found:  HKLM\SOFTWARE\Classes\yt.CacheLoader
Key Found:  HKLM\SOFTWARE\Classes\yt.CacheLoader.1
Key Found:  HKLM\SOFTWARE\Classes\yt.Clickstream
Key Found:  HKLM\SOFTWARE\Classes\yt.Clickstream.1
Key Found:  HKLM\SOFTWARE\Classes\yt.YTHelper
Key Found:  HKLM\SOFTWARE\Classes\yt.YTHelper.2
Key Found:  HKLM\SOFTWARE\Classes\yt.YTNavAssistPlugin
Key Found:  HKLM\SOFTWARE\Classes\yt.YTNavAssistPlugin.1
Key Found:  HKLM\SOFTWARE\Classes\yt.YToolbarBand
Key Found:  HKLM\SOFTWARE\Classes\yt.YToolbarBand.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoSearchAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoSearchAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoUpdaterAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoUpdaterAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBCustomizerAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBCustomizerAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBGeneralAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBGeneralAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBMessengerAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBMessengerAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBSingleInstanceAssistant
Key Found:  HKLM\SOFTWARE\Classes\ytbbroker.YTBSingleInstanceAssistant.1
Key Found:  HKLM\SOFTWARE\Classes\YTNavAssist.NameSpaceCF
Key Found:  HKLM\SOFTWARE\Classes\YTNavAssist.NameSpaceCF.1
Key Found:  HKLM\SOFTWARE\Classes\YTNavAssist.NameSpacePP
Key Found:  HKLM\SOFTWARE\Classes\YTNavAssist.NameSpacePP.1
Key Found:  HKLM\SOFTWARE\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
Key Found:  HKLM\SOFTWARE\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Key Found:  HKLM\SOFTWARE\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{1E57256D-9F39-4267-AB39-D7813D644C5A}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{31371420-098D-4C0E-A11E-EBEC2305DD01}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{3A06AA27-D94B-48C2-BB55-9FD0FF2120E3}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{46140CE4-76FE-440E-AE88-4C2272BC05C7}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{9F9C4C5C-2BA8-4E00-A697-9F710BB1026B}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{3C16E079-E4C7-493C-BE9F-E0F2BB0B7430}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{6EB4349D-4333-442F-ACA4-4C72AF28B6ED}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{7DB8B625-DBF0-4491-B544-5A06F7B17BB4}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{8E74A0AE-F0ED-47ED-A940-A8E99687646B}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{9DE77B51-89F6-468E-9402-16050382E950}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
Key Found:  HKLM\SOFTWARE\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
Key Found:  HKLM\SOFTWARE\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
Key Found:  HKU\.DEFAULT\Software\Yahoo\Companion
Key Found:  HKU\S-1-5-21-790525478-789336058-1606980848-1003\Software\SlimWare Utilities Inc
Key Found:  HKU\S-1-5-21-790525478-789336058-1606980848-1003\Software\Yahoo\Companion
Key Found:  HKU\S-1-5-21-790525478-789336058-1606980848-1003\Software\Yahoo\YFriendsBar
Key Found:  HKU\S-1-5-18\Software\Yahoo\Companion
Key Found:  HKLM\SOFTWARE\SlimWare Utilities Inc
Key Found:  HKLM\SOFTWARE\Yahoo\Companion
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yahoo! Companion
Key Found:  HKLM\SOFTWARE\Classes\AppID\yt.DLL
Key Found:  HKLM\SOFTWARE\Classes\AppID\ytbbroker.EXE


***** [ Web browsers ] *****

No malicious Firefox based browser items found.
No malicious Chromium based browser items found.

*************************

\AdwCleaner\AdwCleaner[R0].txt - [3461 Bytes] - [16/12/2013 22:30:31]
\AdwCleaner\AdwCleaner[R1].txt - [3478 Bytes] - [28/12/2013 15:08:08]
\AdwCleaner\AdwCleaner[R2].txt - [3538 Bytes] - [05/01/2014 15:19:37]
\AdwCleaner\AdwCleaner[S0].txt - [3663 Bytes] - [05/01/2014 15:23:22]
\AdwCleaner\AdwCleaner[S1].txt - [7709 Bytes] - [19/11/2016 19:08:10]
\AdwCleaner\AdwCleaner[S2].txt - [7630 Bytes] - [19/11/2016 19:14:11]

########## EOF - \AdwCleaner\AdwCleaner[S2].txt - [7701 Bytes] ##########
 

When I ran the JRT tool I did it as administrator by right clicking and then running as admin. But in the command prompt window it told me that it runs best when in admin mode even though I ran it as an administrator. So I told it to proceed and then it tried to create a restore point which is was not able to do. Here is the log:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Microsoft Windows XP x86
Ran by [removed] (Limited) on Sat 11/19/2016 at 19:28:58.29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 0




Registry: 1

Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 11/19/2016 at 19:31:23.31
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Did you allow AdwCleaner to quarantine what it found?

Please download the Malwarebytes Anti-Malware setup file to your Desktop.

OR from this location Malwarebytes' Anti-Malware
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs, followed by the first Scan Log.
  • Click Export, followed by Copy to Clipboard. Paste the log in your next reply.

~~

This repair may take some hours !!!

Tweaking.com - Windows Repair All-In-One (Portable)

- Download Windows Repair All-In-One (Portable Version) from http://www.bleepingcomputer.com/download/windows-repair-all-in-one/
to Desktop.

- Disable all your antivirus and antimalware software - see how to do that here.
- Right click on 🖼Click to load external image (QfBzvq1.png) and select Run as Administrator (XP users just double click) to start Windows Repair All-In-One.
(Windows Vista/7/8 users: Accept UAC warning if it is enabled.)

- A window will appear. Click Step 2.
[external image: 2f8o60N.png]

- Click the Open Pre-Scan button, then click Start Scan. Wait for Windows Repair to finish scanning.

- Depending on which error Windows Repair found, click Repair Reparse Point or Repair Environment Variable accordingly. When the button changes to "Done!", click the close button to return to Windows Repair.

- Go to Step 3, then click Check in the See If Check Disk Is Needed.

- If Windows Repair stated that errors are found, click Open Check Disk At Next Boot. Choose (/R) Fixes errors on the disk also locate bad sectors and recovers readable information, then click Add To Next Boot. Reboot the computer to let Windows check the disk.
[external image: Ymy7crZ.png]

- Go to Step 4, then click Do It.
[external image: zDtdN75.png]

- Go to Step 5. Under System Restore click Create.
[external image: f7lEe1N.png]

- Go to Repairs and click Open Repairs. Leave all checkmarks as they are, then click Start Repairs.
[external image: PGv2vtD.png]

- By default Windows Repair All-In-One will create a "Logs" folder in its folder on the Desktop. Please post the contents of the log in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI