This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop badly infected

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was given a laptop by a friend of mine. She didn't use it anymore because her kids had gotten a LOT of viruses on it. Need help to either clean it, or preferably just do a factory reset. I tried that first but couldn't get anywhere. Here are the required scans.

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-12-27 09:08:44
—————————–
09:08:45.012    OS Version: Windows x64 6.1.7601 Service Pack 1
09:08:45.012    Number of processors: 2 586 0x2505
09:08:45.012    ComputerName: TERESA-PC  UserName: Teresa
09:08:53.389    Initialize success
09:11:42.895    AVAST engine defs: 16122700
09:36:25.222    The log file has been saved successfully to "C:\Users\Teresa\Desktop\aswMBR.txt"

 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-12-2016
Ran by [removed] (administrator) on TERESA-PC (27-12-2016 16:58:18)
Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VITUUM5Z
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode:
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\Re-markit-soft\Re-markitw.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(COMPANYVERS_NAME) C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39barsvc.exe
(COMPANYVERS_NAME) C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5abarsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccsvchst.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
() C:\Program Files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
(Novatel Wireless Inc.) C:\Program Files (x86)\Novatel Wireless\Drivers\NWHelper.exe
() C:\Program Files (x86)\Re-markit-soft\Re-markitBG175.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
() C:\Program Files (x86)\CDDCF87A-3EAD-40C4-8099-34C6869D3E9D\SupraSavingsService64.exe
() C:\Program Files\003\vxlsnyaiet64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccsvchst.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exe
(Microsoft Corporation) C:\Windows\System32\CompatTel\wicainventory.exe
(Facebook Inc.) C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe
() C:\Program Files (x86)\Re-markit-soft\Re-markitj73.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-22] (Acer Incorporated)
HKLM\…\Run: [MyWebFace Home Page Guard 64 bit] => C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\AppIntegrator64.exe [485448 2014-02-12] ( )
HKLM-x32\…\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1092688 2011-03-31] (Dritek System Inc.)
HKLM-x32\…\Run: [Bell Canada Connection Manager] => C:\Program Files (x86)\Bell\Mobile Connect\MobileConnect.exe [87576 2011-06-15] (Bell)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.)
HKLM-x32\…\Run: [MapsGalaxy Search Scope Monitor] => C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrchMn.exe [38440 2012-01-29] (MindSpark)
HKLM-x32\…\Run: [MapsGalaxy_39 Browser Plugin Loader] => C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39brmon.exe [30096 2012-01-29] (VER_COMPANY_NAME)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM-x32\…\Run: [Browser companion helper] => C:\Program Files (x86)\BrowserCompanion\BCHelper.exe [187696 2011-12-15] (Blabbers Communications LTD)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-09-09] (Apple Inc.)
HKLM-x32\…\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKLM-x32\…\Run: [MyWebFace EPM Support] => C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5amedint.exe [12872 2014-02-12] (Mindspark Interactive Network, Inc.)
HKLM-x32\…\Run: [MyWebFace Search Scope Monitor] => C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5aSrchMn.exe [55368 2014-02-12] (Mindspark)
HKLM-x32\…\Run: [MyWebFace_5a Browser Plugin Loader] => C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5abrmon.exe [61512 2014-02-12] (VER_COMPANY_NAME)
HKLM-x32\…\Run: [MyWebFace_5a Browser Plugin Loader 64] => C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5abrmon64.exe [71752 2014-02-12] (VER_COMPANY_NAME)
HKLM-x32\…\Run: [fst_ca_99] => [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Run: [Facebook Update] => C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-11] (Facebook Inc.)
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.)
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Run: [PriceMeterW] => "C:\Users\Teresa\AppData\Local\PriceMeter\pricemeterw.exe"
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [135112 2014-05-09] (PC Utilities Software Limited)
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_15_0_0_152_Plugin.exe [854192 2014-09-11] (Adobe Systems Incorporated)
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\MountPoints2: {cdca7044-329d-11e1-840e-b870f47876ce} - E:\AutoLaunch.exe
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-18\…\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\Program Files (x86)\SupTab\SearchProtect64.dll [102512 2014-05-08] (Skytech Co., Ltd.)
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [91248 2014-05-08] (Skytech Co., Ltd.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2012-05-19]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Teresa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2014-05-19]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [S-1-5-21-504136971-1847211166-3120143677-1000] => Proxy is enabled.
ProxyServer: [S-1-5-21-504136971-1847211166-3120143677-1000] => http=127.0.0.1:14427;https=127.0.0.1:14427
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5B06BF4C-FFD7-4511-9771-B9D290391CC5}: [DhcpNameServer] 192.168.1.254 [removed]
Tcpip\..\Interfaces\{8BBE56C8-9777-40E5-ADEE-9E92F232A69F}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{BA035D19-38CF-4A21-8CB0-017F1CCBC26C}: [DhcpNameServer] [removed]
ManualProxies: 1http=127.0.0.1:14103;https=127.0.0.1:14103

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com/?type=hp&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com/?type=hp&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com/?type=hp&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
URLSearchHook: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 - (No Name) - {b54561db-0bbb-41b4-a814-df8301fe0a8e} - No File
URLSearchHook: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 - (No Name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll (MindSpark)
URLSearchHook: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 - (No Name) - {8040829d-1177-46e2-9157-8282438b79c7} - C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5aSrcAs.dll (Mindspark)
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://speedial.com/results.php?f=4&q;={searchTerms}&a;=spd_secureddownload_14_21_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzyBtDtN1L2XzutBtFtBtDtFtCtAtFtDtN1L1CzutCyEtDtAtDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2StC0A0EtAyEyDtByCtGtByCzyzztG0AtByCzztGtC0ByCtDtGyCtCtC0F0CyByE0B0C0Dzz0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=264653511&ir;=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM -> {31090377-0740-419E-BEFC-A56E50500D5B} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
SearchScopes: HKLM -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=107&systemid;=2&sr;=0&q;={searchTerms}
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=384&systemid;=406&sr;=0&q;={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=107&systemid;=2&sr;=0&q;={searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=384&systemid;=406&sr;=0&q;={searchTerms}
SearchScopes: HKLM-x32 -> {E627DC4B-8C04-4234-A2D4-1D634EE01C41} URL = hxxp://www.bigseekpro.com/search/toolbar/mp3rocket/{730F4B83-001C-80BE-0B4C-C3B978797925}?q={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://speedial.com/results.php?f=4&q;={searchTerms}&a;=spd_secureddownload_14_21_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzyBtDtN1L2XzutBtFtBtDtFtCtAtFtDtN1L1CzutCyEtDtAtDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2StC0A0EtAyEyDtByCtGtByCzyzztG0AtByCzztGtC0ByCtDtGyCtCtC0F0CyByE0B0C0Dzz0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=264653511&ir;=
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://speedial.com/results.php?f=4&q;={searchTerms}&a;=spd_secureddownload_14_21_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzyBtDtN1L2XzutBtFtBtDtFtCtAtFtDtN1L1CzutCyEtDtAtDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2StC0A0EtAyEyDtByCtGtByCzyzztG0AtByCzztGtC0ByCtDtGyCtCtC0F0CyByE0B0C0Dzz0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=264653511&ir;=
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID;=112060&tt;=010712_8&babsrc;=SP_ss&mntrId;=b4a493270000000000000aa3c4b8a45a
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3319611&octid;=EB_ORIGINAL_CTID&SearchSource;=58&CUI;=&UM;=5&UP;=SPD1FAFB5A-19BE-4978-B8F6-4E387A8BCC8C&q;={searchTerms}&SSPV;=
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://www.ask.com/web?l=dis&o;=41648007&gct;=sb&qsrc;=2869&apn;_dtid=^YYYYYY^YY^CA&apn;_ptnrs=^8M&apn;_uid=8439412123714045&p2;=^8M^YYYYYY^YY^CA&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {4BC552F8-FE4F-4BAB-BFF6-8D5C9183C7F0} URL = hxxp://websearch.ask.com/redirect?client=ie&tb;=ORJ&o;=100000027&src;=kw&q;={searchTerms}&locale;=&apn;_ptnrs=U3&apn;_dtid=YYYYYYYYCA&apn;_uid=F37AA36C-B573-4DFE-9D09-DFD39434B78E&apn;_sauid=B91E7160-B9C4-4DDE-8591-CECC082B5A1C
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {5BBA514E-D260-4565-B9CD-E792047B6F2D} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3268494&CUI;=UN73002158717166189&UM;=2
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {74E7751D-8DE8-42C7-A65D-555854303C6C} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3101810
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=107&systemid;=2&sr;=0&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=384&systemid;=406&sr;=0&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {A6CA5EA8-2AF9-42B8-8970-91DA32ACD4F5} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {DC72F286-063B-41E9-8DC2-1DD46D642351} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3071132
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {E627DC4B-8C04-4234-A2D4-1D634EE01C41} URL = hxxp://www.bigseekpro.com/search/toolbar/mp3rocket/{730F4B83-001C-80BE-0B4C-C3B978797925}?q={searchTerms}
BHO: Websaver -> {1470D9B2-6DB1-8015-3543-ED4858FFE508} -> C:\ProgramData\Websaver\R3.x64.dll [2014-08-03] ()
BHO: EXattraShopper -> {23BADEE4-2438-F09C-5FFE-EC5973CC1CF8} -> C:\ProgramData\EXattraShopper\jUuR3.x64.dll [2014-09-12] ()
BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL => No File
BHO: avast! Online Security -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll => No File
BHO: ExTraShoPPeR -> {31b76765-eac3-4e65-8a3e-764222fb09c4} -> C:\ProgramData\ExTraShoPPeR\9K0lnxXfNNUQ1H.x64.dll [2014-11-26] ()
BHO: saverneti -> {5F81FE2B-A7C6-4913-1FB0-8CD63FEC8C51} -> C:\ProgramData\saverneti\9y.x64.dll [2014-07-19] ()
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
BHO: LUckyCOUpoon -> {C089BF59-2120-84F6-00C3-D185F7DB4B45} -> C:\ProgramData\LUckyCOUpoon\5McC9VhD1M.x64.dll [2014-09-11] ()
BHO: PrOOShoepper -> {C0B2DEB7-D5C8-20BF-FC61-65D4267D6E9C} -> C:\ProgramData\PrOOShoepper\IvSjUoob21.x64.dll [2014-07-06] ()
BHO: PriceDoownlloader -> {D9F6F33C-DF70-07B9-3306-A835A4169C03} -> C:\ProgramData\PriceDoownlloader\Y.x64.dll [2014-07-03] ()
BHO-x32: Chatvibes Browser Helper -> {00cbb66b-1d3b-46d3-9577-323a336acb50} -> C:\Program Files (x86)\BrowserCompanion\jsloader.dll [2011-10-27] ( )
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO-x32: Search Assistant BHO -> {14d02517-c8be-4735-a344-3c8366c77aa0} -> C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5aSrcAs.dll [2014-02-12] (Mindspark)
BHO-x32: Toolbar BHO -> {1e91a655-bb4b-4693-a05e-2edebc4c9d89} -> C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39bar.dll [2012-01-29] (MindSpark)
BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\progra~1\mcafee\msk\mskapbho.dll => No File
BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\SupTab\SupTab.dll [2014-05-08] (Thinknice Co. Limited)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\coIEPlg.dll [2014-04-29] (Symantec Corporation)
BHO-x32: Re-markit -> {609467CB-A447-E4FA-5EEE-CEE0E56F306B} -> C:\Program Files (x86)\Re-markit-soft\175.dll [2014-07-19] ()
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\IPS\IPSBHO.DLL [2013-04-08] (Symantec Corporation)
BHO-x32: Search Assistant BHO -> {71c1d63a-c944-428a-a5bd-ba513190e5d2} -> C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll [2012-01-29] (MindSpark)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-05-04] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Chatvibes Browser Helper Verifier -> {963B125B-8B21-49A2-A3A8-E37092276531} -> C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll [2011-10-27] ( )
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO-x32: Toolbar BHO -> {b1df253a-9e7a-480d-b6a5-7a435b520dbb} -> C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5abar.dll [2014-02-12] (Mindspark)
BHO-x32: Wincore Mediabar -> {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} -> C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll => No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-05-04] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - !{364ea597-e728-4ce4-bb4a-ed846ef47970} -  No File
Toolbar: HKLM - No Name - !{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKLM - No Name - !{af94b35c-3ac5-4030-9f9c-15fb4e3dc339} -  No File
Toolbar: HKLM-x32 - Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll No File
Toolbar: HKLM-x32 - No Name - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM-x32 - No Name - !{364ea597-e728-4ce4-bb4a-ed846ef47970} -  No File
Toolbar: HKLM-x32 - No Name - !{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKLM-x32 - No Name - !{af94b35c-3ac5-4030-9f9c-15fb4e3dc339} -  No File
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\coIEPlg.dll [2014-04-29] (Symantec Corporation)
Handler-x32: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll [2011-10-27] (Blabbers Communications Ltd)
Handler-x32: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll [2011-10-27] (Blabbers Communications Ltd)
Handler-x32: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll [2011-10-27] (Blabbers Communications Ltd)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-04-08] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default [2016-12-27]
FF user.js: detected! => C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\user.js [2014-07-19]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\eq94y0o8.default -> v9
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\eq94y0o8.default -> hxxp://www.bigseekpro.com/search/toolbar/mp3rocket/{730F4B83-001C-80BE-0B4C-C3B978797925}?q={searchTerms}
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\eq94y0o8.default -> Search Results
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\eq94y0o8.default -> v9
FF Homepage: Mozilla\Firefox\Profiles\eq94y0o8.default -> hxxp://www.v9.com/?type=hppp&ts;=1402694841&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=344123f43
FF Session Restore: Mozilla\Firefox\Profiles\eq94y0o8.default -> is enabled.
FF Keyword.URL: Mozilla\Firefox\Profiles\eq94y0o8.default -> hxxp://trovi.com/ResultsExt.aspx?ctid=CT3268494&SearchSource;=2&CUI;=UN33218121551869822&UM;=2&q;=
FF Extension: (No Name) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\39ffxtbr@MapsGalaxy_39.com [2012-01-29] [not signed]
FF Extension: (FulAShhCouuPon) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-10-11] [not signed]
FF Extension: (No Name) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\5affxtbr@MyWebFace_5a.com [2014-02-12] [not signed]
FF Extension: (LUckyyShoPper) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-10-11] [not signed]
FF Extension: (Browser Companion Helper) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2012-07-07] [not signed]
FF Extension: (Tiger Savings) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-07-12] [not signed]
FF Extension: (ProuShopper) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-07-12] [not signed]
FF Extension: (Babylon) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2012-01-21] [not signed]
FF Extension: (ExTraShopPere) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-11-26] [not signed]
FF Extension: (savernneT) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-07-19] [not signed]
FF Extension: (websaver) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-10-11] [not signed]
FF Extension: (Quick Start) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-06-13] [not signed]
FF Extension: (easYatoshop) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-07-03] [not signed]
FF Extension: (VisualBee V.1 ) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\{7aeae561-714b-45f6-ace3-4a8aed6e227b} [2014-07-12] [not signed]
FF Extension: (Somoto ) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\{bb45ef8e-1e36-4535-a017-ec908fb1e335} [2014-07-14] [not signed]
FF Extension: (Speedial) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\{fa95f577-07cb-4470-ac90-e843f5f83c52} [2014-05-19] [not signed]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\askcom.xml [2012-07-07]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\conduit-search.xml [2014-03-16]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\Mysearchdial.xml [2014-06-13]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\search.xml [2012-07-17]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\Search_Results.xml [2012-09-02]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\Speedial.xml [2014-05-19]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\visualbee-v1-customized-web-search.xml [2014-05-19]
FF Extension: (Skype Click to Call) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [39ffxtbr@MapsGalaxy_39.com] - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin
FF Extension: (No Name) - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin [2012-01-29] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-05-19] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn
FF Extension: (Norton Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn [2016-12-27] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFF
FF Extension: (Norton Vulnerability Protection) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFF [2014-01-25] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\extensions\[removed]
FF HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Firefox\Extensions: [{D2B1635C-3660-A50D-0853-6CBFDB7D714E}] - C:\Program Files (x86)\Re-markit-soft\175.xpi
FF Extension: (Re-markit) - C:\Program Files (x86)\Re-markit-soft\175.xpi [2014-07-19] [not signed]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml [2012-07-07]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\searchresultstb.xml [2012-07-16]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml [2012-09-02]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\v9.xml [2016-12-27]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll [2014-09-11] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll [2014-09-11] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-08-08] ()
FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-05-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 -> C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll [2012-05-04] (Oracle Corporation)
FF Plugin-x32: @MapsGalaxy_39.com/Plugin -> C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\NP39Stub.dll [2012-01-29] (MindSpark)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @MyWebFace_5a.com/Plugin -> C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\NP5aStub.dll [2014-02-12] (Mindspark)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-06-23] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-06-23] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [2012-07-03] ()
FF Plugin HKU\S-1-5-21-504136971-1847211166-3120143677-1000: @lightspark.github.com/Lightspark;version=1 -> C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll [No File]
FF Plugin HKU\S-1-5-21-504136971-1847211166-3120143677-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Teresa\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome:
=======
CHR DefaultProfile: Default
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HKLM\…\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-504136971-1847211166-3120143677-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-504136971-1847211166-3120143677-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [nlndmljfcnlkbcbbneenigbpikmdfcdh] - C:\Users\Teresa\AppData\Local\CRE\nlndmljfcnlkbcbbneenigbpikmdfcdh.crx [2013-04-14]
CHR HKU\S-1-5-21-504136971-1847211166-3120143677-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\Exts\Chrome.crx [2014-05-02]
CHR HKLM-x32\…\Chrome\Extension: [clbfjfbnelcflpgpklppgplejolacbej] - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx [2011-12-22]
CHR HKLM-x32\…\Chrome\Extension: [jealjalmcelnenljclnadlblookmkmdc] - C:\Users\Teresa\AppData\Local\Temp\crx8DFB.tmp [2011-08-27]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM-x32\…\Chrome\Extension: [nlndmljfcnlkbcbbneenigbpikmdfcdh] - C:\Users\Teresa\AppData\Local\CRE\nlndmljfcnlkbcbbneenigbpikmdfcdh.crx [2013-04-14]
CHR HKLM-x32\…\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - chrome.exe

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 64af91bf; c:\ProgramData\Fast And Safe\FastAndSafeSvc.dll [186192 2014-07-03] () [File not signed]
R2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll [186496 2014-06-13] () [File not signed]
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36392 2014-03-14] (Just Develop It) [File not signed] <==== ATTENTION
S3 BellCanadaRcAppSvc; C:\Program Files (x86)\Bell\Mobile Connect\RcAppSvc.exe [120344 2011-05-31] (SmithMicro Inc.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 CABellCanada; C:\Program Files (x86)\Bell\Mobile Connect\ConAppsSvc.exe [124440 2011-05-31] (SmithMicro Inc.)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED)
R2 MapsGalaxy_39Service; C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39barsvc.exe [42504 2012-01-29] (COMPANYVERS_NAME)
R2 MyWebFace_5aService; C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5abarsvc.exe [88648 2014-02-12] (COMPANYVERS_NAME)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccSvcHst.exe [144368 2013-05-20] (Symantec Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe [132504 2013-03-11] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation)
R2 NvtlService; C:\Program Files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe [92504 2011-02-18] ()
R2 NWHelper; C:\Program Files (x86)\Novatel Wireless\Drivers\NWHelper.exe [270336 2010-10-07] (Novatel Wireless Inc.) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
S3 ProfileImpSvc; C:\Program Files (x86)\Bell\Mobile Connect\ProfileImpSvc.exe [169496 2011-05-31] (SmithMicro Inc.)
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1919256 2014-12-22] (IBM Corp.)
R2 Re-markit; C:\Program Files (x86)\Re-markit-soft\Re-markitBG175.exe [160768 2014-07-19] () [File not signed] <==== ATTENTION
R2 SupraSavingsService64; C:\Program Files (x86)\CDDCF87A-3EAD-40C4-8099-34C6869D3E9D\SupraSavingsService64.exe [172544 2014-06-25] () [File not signed]
R2 vxlsnyaiet64; C:\Program Files\003\vxlsnyaiet64.exe [706560 2014-06-13] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20140214.001\BHDrvx64.sys [1526488 2014-01-21] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1405000.01C\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2014-01-23] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2014-01-23] (Symantec Corporation) [File not signed]
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2011-05-24] (Huawei Technologies Co., Ltd.)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20140321.001\IDSvia64.sys [524504 2014-03-15] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20140322.002\ENG64.SYS [126040 2014-02-21] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20140322.002\EX64.SYS [2099288 2014-02-21] (Symantec Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-07-08] (NetFilterSDK.com)
S3 NWRmNet; C:\Windows\System32\DRIVERS\NWRmNet.sys [295424 2010-10-27] (Novatel Wireless Inc.)
S3 PCTINDIS5X64; C:\Windows\system32\PCTINDIS5X64.SYS [43032 2010-08-05] (Smith Micro Inc.)
S1 RapportCerberus_80120; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_80120.sys [845464 2016-12-27] (IBM Corp.)
S1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [445816 2014-12-22] (IBM Corp.)
S0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [535576 2014-12-22] (IBM Corp.)
S1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [558872 2014-12-22] (IBM Corp.)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1405000.01C\SRTSP64.SYS [796760 2013-05-15] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1405000.01C\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1405000.01C\SYMDS64.SYS [493656 2013-05-20] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1405000.01C\SYMEFA64.SYS [1139800 2013-05-22] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2014-01-26] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1405000.01C\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation)
S1 SymNetS; C:\Windows\System32\Drivers\NISx64\1405000.01C\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation)
R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}Gw64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}Gw64.sys [61112 2014-05-16] (StdLib)
R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys [61112 2014-06-05] (StdLib)
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
U3 aswMBR; \??\C:\Users\Teresa\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Teresa\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-12-27 16:57 - 2016-12-27 16:58 - 00000000 ____D C:\FRST
2016-12-27 09:36 - 2016-12-27 09:36 - 00000480 _____ C:\Users\Teresa\Desktop\aswMBR.txt
2016-12-26 23:41 - 2016-12-26 23:47 - 00000000 ____D C:\Users\Teresa\AppData\Local\{6D2F5B73-4987-37CB-241F-12230077EEBB}

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-12-27 17:03 - 2009-07-13 22:13 - 00783464 _____ C:\Windows\system32\PerfStringBackup.INI
2016-12-27 17:03 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\inf
2016-12-27 16:59 - 2014-07-19 22:18 - 00000408 _____ C:\Windows\Tasks\Re-markit Update.job
2016-12-27 16:56 - 2014-07-19 22:18 - 00000388 _____ C:\Windows\Tasks\Re-markit_wd.job
2016-12-27 16:56 - 2012-12-22 19:46 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-12-27 16:56 - 2011-11-18 12:06 - 00000910 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000Core.job
2016-12-27 16:56 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-12-27 16:54 - 2009-07-13 22:08 - 00032562 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-12-27 16:48 - 2014-06-13 14:17 - 00000296 _____ C:\Windows\Tasks\MySearchDial.job
2016-12-27 16:48 - 2014-05-19 15:41 - 00000296 _____ C:\Windows\Tasks\Speedial.job
2016-12-27 16:48 - 2012-12-22 19:47 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-12-27 16:48 - 2012-12-22 19:46 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-12-27 16:48 - 2011-11-18 12:06 - 00000932 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000UA.job
2016-12-27 16:48 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\tracing
2016-12-27 09:10 - 2014-06-27 00:09 - 00000000 ____D C:\Program Files\SupraSavings
2016-12-27 09:02 - 2014-01-23 16:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection
2016-12-27 09:01 - 2012-01-26 15:32 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2016-12-27 08:55 - 2014-01-02 12:32 - 00252842 _____ C:\Windows\ntbtlog.txt
2016-12-27 08:34 - 2011-08-23 12:32 - 00000000 ____D C:\Users\Teresa\AppData\Roaming\Skype
2016-12-26 23:41 - 2014-05-19 20:42 - 00000178 _____ C:\Users\Teresa\AppData\Roaming\WB.CFG
2016-12-26 23:40 - 2011-12-26 22:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-12-26 23:35 - 2009-07-13 21:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-12-26 23:35 - 2009-07-13 21:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-12-26 18:24 - 2011-12-26 21:27 - 00000000 ____D C:\Users\Teresa\AppData\Local\ElevatedDiagnostics
2016-12-26 18:24 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache

==================== Files in the root of some directories =======

2013-12-29 17:59 - 2013-12-29 17:59 - 49940480 _____ () C:\Program Files (x86)\GUT2C1F.tmp
2014-05-19 20:51 - 2014-05-19 20:52 - 0001186 _____ () C:\Users\Teresa\AppData\Roaming\aps.scan.quick.results
2014-05-19 20:51 - 2014-05-19 20:51 - 0000000 _____ () C:\Users\Teresa\AppData\Roaming\aps.scan.results
2014-05-19 20:51 - 2014-05-19 20:52 - 0000320 _____ () C:\Users\Teresa\AppData\Roaming\aps.uninstall.scan.results
2014-05-19 20:42 - 2016-12-26 23:41 - 0000178 _____ () C:\Users\Teresa\AppData\Roaming\WB.CFG
2014-05-19 20:46 - 2014-05-19 06:19 - 1705063 _____ (AnyProtect.com) C:\Users\Teresa\AppData\Local\AnyProtectScannerSetup.exe
2012-01-23 20:45 - 2012-12-08 17:31 - 0008192 _____ () C:\Users\Teresa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-02-04 18:42 - 2013-02-04 18:42 - 0000017 _____ () C:\Users\Teresa\AppData\Local\resmon.resmoncfg
2011-05-04 16:07 - 2011-05-04 16:10 - 0015211 _____ () C:\ProgramData\ArcadeDeluxe5.log
2012-05-19 11:00 - 2014-03-16 11:49 - 0009733 _____ () C:\ProgramData\hpzinstall.log
2014-01-18 15:22 - 2014-01-18 15:25 - 0000032 _____ () C:\ProgramData\PS.log

Some files in TEMP:
====================
C:\Users\Teresa\AppData\Local\Temp\BackupSetup.exe
C:\Users\Teresa\AppData\Local\Temp\BearShare_setup.exe
C:\Users\Teresa\AppData\Local\Temp\conduitinstaller.exe
C:\Users\Teresa\AppData\Local\Temp\DefaultAssets.exe
C:\Users\Teresa\AppData\Local\Temp\DefaultOfflineContent.exe
C:\Users\Teresa\AppData\Local\Temp\dlLogic.exe
C:\Users\Teresa\AppData\Local\Temp\eTypeSetup.exe
C:\Users\Teresa\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe
C:\Users\Teresa\AppData\Local\Temp\GCVerifier.dll
C:\Users\Teresa\AppData\Local\Temp\HitmanPro.exe
C:\Users\Teresa\AppData\Local\Temp\ICReinstall_MediaCodec.exe
C:\Users\Teresa\AppData\Local\Temp\iMesh_setup.exe
C:\Users\Teresa\AppData\Local\Temp\incredibar_installer.exe
C:\Users\Teresa\AppData\Local\Temp\Installhelper.dll
C:\Users\Teresa\AppData\Local\Temp\jre-7u11-windows-i586-iftw.exe
C:\Users\Teresa\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Teresa\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
C:\Users\Teresa\AppData\Local\Temp\mconduitinstaller.exe
C:\Users\Teresa\AppData\Local\Temp\MindsparkAssets.exe
C:\Users\Teresa\AppData\Local\Temp\minibar-master.exe
C:\Users\Teresa\AppData\Local\Temp\NLStubInstallerResources.dll
C:\Users\Teresa\AppData\Local\Temp\nsb27D7.exe
C:\Users\Teresa\AppData\Local\Temp\nsb6CC9.tmp.exe
C:\Users\Teresa\AppData\Local\Temp\nsb8C2D.exe
C:\Users\Teresa\AppData\Local\Temp\nsbF0A9.exe
C:\Users\Teresa\AppData\Local\Temp\nsc8C14.exe
C:\Users\Teresa\AppData\Local\Temp\nscA2A1.exe
C:\Users\Teresa\AppData\Local\Temp\nscACE6.exe
C:\Users\Teresa\AppData\Local\Temp\nsd1B91.exe
C:\Users\Teresa\AppData\Local\Temp\nsd89EB.exe
C:\Users\Teresa\AppData\Local\Temp\nse4790.exe
C:\Users\Teresa\AppData\Local\Temp\nse9DB.exe
C:\Users\Teresa\AppData\Local\Temp\nseF7F5.exe
C:\Users\Teresa\AppData\Local\Temp\nsgC7FA.exe
C:\Users\Teresa\AppData\Local\Temp\nsjF199.exe
C:\Users\Teresa\AppData\Local\Temp\nsk8FD7.exe
C:\Users\Teresa\AppData\Local\Temp\nskC92.exe
C:\Users\Teresa\AppData\Local\Temp\nslB4F2.exe
C:\Users\Teresa\AppData\Local\Temp\nso3F26.exe
C:\Users\Teresa\AppData\Local\Temp\nso5C19.exe
C:\Users\Teresa\AppData\Local\Temp\nsoBAAD.exe
C:\Users\Teresa\AppData\Local\Temp\nsr1C4D.exe
C:\Users\Teresa\AppData\Local\Temp\nsrB9D9.exe
C:\Users\Teresa\AppData\Local\Temp\nsrDDE7.exe
C:\Users\Teresa\AppData\Local\Temp\nsrF8FA.exe
C:\Users\Teresa\AppData\Local\Temp\nst7709.exe
C:\Users\Teresa\AppData\Local\Temp\nsuDAD.exe
C:\Users\Teresa\AppData\Local\Temp\nsw68B.exe
C:\Users\Teresa\AppData\Local\Temp\nsz21CF.exe
C:\Users\Teresa\AppData\Local\Temp\nsz36AA.exe
C:\Users\Teresa\AppData\Local\Temp\nsz5E36.exe
C:\Users\Teresa\AppData\Local\Temp\optprosetup.exe
C:\Users\Teresa\AppData\Local\Temp\PCCU_Installer.exe
C:\Users\Teresa\AppData\Local\Temp\SecondStepInstaller.exe
C:\Users\Teresa\AppData\Local\Temp\SendMsg.dll
C:\Users\Teresa\AppData\Local\Temp\setup.exe
C:\Users\Teresa\AppData\Local\Temp\SetupDataMngr_Searchqu.exe
C:\Users\Teresa\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Teresa\AppData\Local\Temp\SpOrder.dll
C:\Users\Teresa\AppData\Local\Temp\SPStub.exe
C:\Users\Teresa\AppData\Local\Temp\SRAssetsHelper.dll
C:\Users\Teresa\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\Teresa\AppData\Local\Temp\System.Data.SQLite64855.dll
C:\Users\Teresa\AppData\Local\Temp\tbRad0.dll
C:\Users\Teresa\AppData\Local\Temp\tbSom0.dll
C:\Users\Teresa\AppData\Local\Temp\tbuTor.dll
C:\Users\Teresa\AppData\Local\Temp\tbVisu.dll
C:\Users\Teresa\AppData\Local\Temp\Toolbar_Phpnuke.exe
C:\Users\Teresa\AppData\Local\Temp\vbmz12.exe
C:\Users\Teresa\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Teresa\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Teresa\AppData\Local\Temp\verifier.exe
C:\Users\Teresa\AppData\Local\Temp\_Re-markitV37.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-12-26 18:17

==================== End of FRST.txt ============================

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-12-2016
Ran by [removed] (27-12-2016 17:04:48)
Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VITUUM5Z
Windows 7 Home Premium Service Pack 1 (X64) (2011-08-17 05:46:08)
Boot Mode:
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-504136971-1847211166-3120143677-500 - Administrator - Disabled)
Guest (S-1-5-21-504136971-1847211166-3120143677-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-504136971-1847211166-3120143677-1002 - Limited - Enabled)
Teresa (S-1-5-21-504136971-1847211166-3120143677-1000 - Administrator - Enabled) => C:\Users\Teresa

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Internet Security (Disabled - Out of date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton Internet Security (Disabled - Out of date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton Internet Security (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
Acer Backup Manager (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.85 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1523 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.0.1523 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.2.4 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.03.3004 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.1.0301.2011 - Acer Incorporated)
Acer Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3005 - Acer Incorporated)
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Agatha Christie - 4:50 from Paddington (x32 Version: 2.2.0.95 - WildTangent) Hidden
AnyProtect (HKLM-x32\…\AnyProtect) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION
Apple Application Support (HKLM-x32\…\{63EC2120-1742-4625-AA47-C6A8AEC9C64C}) (Version: 2.2.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}) (Version: 6.0.0.59 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Backup Manager V3 (x32 Version: 3.0.0.85 - NTI Corporation) Hidden
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Gigabit NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.6.1.2 - Broadcom Corporation)
BrowserCompanion (HKLM-x32\…\BrowserCompanion) (Version:  - ) <==== ATTENTION
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Coupon Downloader (HKLM\…\Coupon Downloader) (Version:  - SupraSavings) <==== ATTENTION
D1600 (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
DJ_SF_06_D1600_SW_Min (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden
ExTraShoPPeR (HKLM-x32\…\{7BCAC0EB-3993-2416-0531-848C39DF8B65}) (Version:  - "") <==== ATTENTION
Facebook Video Calling 3.1.0.521 (HKLM-x32\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fast And Safe (HKLM-x32\…\{5F189DF5-2D05-472B-9091-84D9848AE48B}{64af91bf}) (Version:  - GTgroup) <==== ATTENTION
FATE - The Traitor Soul (x32 Version: 2.2.0.95 - WildTangent) Hidden
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Drive (HKLM-x32\…\{D9F75285-4864-461D-83DA-8D056BAC44D1}) (Version: 1.16.6866.4367 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HP Deskjet D1600 Printer Driver Software 13.0 Rel .6 (HKLM\…\{2CD0168D-FBBC-4667-8810-105CB6EC6348}) (Version: 13.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Print Projects 1.0 (HKLM\…\HP Print Projects) (Version: 1.0 - HP)
HP Smart Web Printing 4.5 (HKLM\…\HP Smart Web Printing) (Version: 4.5 - HP)
HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM-x32\…\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard)
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
hpPrintProjects (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
hpWLPGInstaller (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3006 - Acer Incorporated)
iLivid (HKLM-x32\…\iLivid) (Version: 1.92 - Bandoo Media Inc) <==== ATTENTION
iMesh (HKLM-x32\…\iMesh) (Version: 12.0.0.130408 - iMesh Inc.) <==== ATTENTION
iMesh (x32 Version: 12.0.0.130408 - iMesh Inc.) Hidden <==== ATTENTION
InstallVC90Support (x32 Version: 1.01.0000 - Novatel Wireless) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2182 - Intel Corporation)
iTunes (HKLM\…\{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}) (Version: 10.7.0.21 - Apple Inc.)
Java(TM) 7 Update 5 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217005FF}) (Version: 7.0.50 - Oracle)
JavaFX 2.1.1 (HKLM-x32\…\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jewel Quest Heritage (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.5 - Acer Inc.)
LUckyCOUpoon (HKLM-x32\…\{BA5D43C9-D633-D0EC-CFEA-2ABA974B333D}) (Version:  - LuckyCoupon) <==== ATTENTION
MapsGalaxy (HKLM-x32\…\MapsGalaxy_39bar Uninstall) (Version:  - MapsGalaxy)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\…\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5131.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mobile Broadband Generic Drivers (HKLM-x32\…\{333494BF-7B36-4681-896A-C7AB23D31E17}) (Version: 2.03.25.001.11 - Novatel Wireless)
Mobile Connect (HKLM\…\{B12E09C4-C55E-48BD-9732-C68AB92DE847}) (Version: 4.02.0031.0 - Smith Micro)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 9.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 9.0.1 (x86 en-US)) (Version: 9.0.1 - Mozilla)
MP3 Rocket (HKLM-x32\…\MP3 Rocket) (Version:  - )
MyPC Backup  (HKLM\…\MyPC Backup) (Version:  - JDi Backup Ltd) <==== ATTENTION
Mysearchdial (HKLM-x32\…\mysearchdial) (Version:  - Mysearchdial) <==== ATTENTION
Mystery P.I. - Stolen in San Francisco (x32 Version: 2.2.0.95 - WildTangent) Hidden
MyWebFace Internet Explorer Toolbar (HKLM-x32\…\MyWebFace_5abar Uninstall Internet Explorer) (Version:  - Mindspark Interactive Network) <==== ATTENTION
Namco All-Stars: PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden
Norton Internet Security (HKLM-x32\…\NIS) (Version: 20.5.0.28 - Symantec Corporation)
Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
Norton PC Checkup (HKLM-x32\…\Norton PC Checkup_is1) (Version: 3.0.5.71.0 - Symantec Corporation)
NTI Media Maker 9 (HKLM-x32\…\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8942 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.8942 - NTI Corporation) Hidden
Optimizer Pro v3.2 (HKLM-x32\…\Optimizer Pro_is1) (Version:  - ) <==== ATTENTION
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
PriceDoownlloader (HKLM-x32\…\{2D471A31-4FA7-95BA-1880-D441113ED736}) (Version:  - PRIceDownLoaaderr) <==== ATTENTION
PrOOShoepper (HKLM-x32\…\{8F213470-964F-4092-6B31-BC7570F31B5A}) (Version:  - PiroShoappperr) <==== ATTENTION
Rapport (x32 Version: 3.5.1404.61 - Trusteer) Hidden
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30124 - Realtek Semiconductor Corp.)
Re-markit (HKLM-x32\…\DBD5527E-9DDF-2BF0-9B71-93D32BDD7FDD) (Version:  - Re-markit-software) <==== ATTENTION
saverneti (HKLM-x32\…\{614925F9-841A-53FE-A28F-DC30FA07239B}) (Version:  - savieronnet) <==== ATTENTION
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 6.16 (HKLM-x32\…\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SuperManCoupon (HKLM-x32\…\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version:  - SuperManCoupon) <==== ATTENTION
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
Torchlight (x32 Version: 2.2.0.95 - WildTangent) Hidden
TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden
Trusteer Endpoint Protection (HKLM-x32\…\Rapport_msi) (Version: 3.5.1404.61 - Trusteer)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
v9 uninstaller (HKLM-x32\…\v9 uninstaller) (Version:  - v9)
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95 - WildTangent) Hidden
VisualBee for Microsoft PowerPoint (HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\VisualBee for Microsoft PowerPoint) (Version: V3.6 - VisualBee.com)
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Websaver (HKLM-x32\…\{5CDF2354-26AF-2DBC-1012-44FEDFCC75BB}) (Version:  - Websavver) <==== ATTENTION
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.02.3102 - Acer Incorporated)
WildTangent Games App (Acer Games) (x32 Version: 4.0.5.36 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Zuma's Revenge (x32 Version: 2.2.0.95 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0AC44FBC-E220-4E15-8B15-9D0B7EA42962} - System32\Tasks\Re-markit Update => C:\Program Files (x86)\Re-markit-soft\Re-markitj73.exe [2014-07-19] () <==== ATTENTION
Task: {1E652AFE-E14F-4238-91CF-F22848870A26} - System32\Tasks\Re-markit_wd => C:\Program Files (x86)\Re-markit-soft\Re-markitw.exe [2014-07-19] () <==== ATTENTION
Task: {35D64B9F-A9F4-41AB-94FA-4CA19622304A} - System32\Tasks\{0AD51ECA-09F6-43C2-BB66-40A5DA138F34} => C:\Program Files (x86)\MP3 Rocket\MP3Rocket.exe [2012-05-09] ()
Task: {6CD519A0-A5D2-4F64-8AB5-8BDD7473961A} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe [2014-03-14] (MyPCBackup.com) <==== ATTENTION
Task: {7066A1FB-068F-4CAE-9CFD-23B67F57A73E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-26] (Adobe Systems Incorporated)
Task: {7096EC12-5813-473C-B80D-2EF9397C94DA} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {77DE6872-4424-4406-83D5-11A8B305FC55} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000UA => C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11] (Facebook Inc.)
Task: {8265B201-9E57-4B5F-B330-9C1C8277E2D8} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\SymErr.exe [2013-06-03] (Symantec Corporation)
Task: {8D8BD5F9-FCB9-42B0-BAFE-5CB5905DB422} - System32\Tasks\Speedial => C:\Users\Teresa\AppData\Roaming\Speedial\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {8EAD082B-D456-4DE6-BB72-2E505B183147} - System32\Tasks\VisualBeeRecovery => C:\Users\Teresa\AppData\Local\VisualBeeExe\VisualBeeRecovery.exe [2012-03-14] () <==== ATTENTION
Task: {9BC3AF30-DCE7-4456-AAA0-C5CB21F75A0F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000Core => C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11] (Facebook Inc.)
Task: {A2D208A8-BAF0-4506-8E9D-0383014E7E1D} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\SymErr.exe [2013-06-03] (Symantec Corporation)
Task: {D3211F0A-FF58-4495-99DC-B6048B355F20} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-22] (Google Inc.)
Task: {D593745A-1AD4-4B47-A97B-EF68CAB6F3AB} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\WSCStub.exe [2014-04-29] (Symantec Corporation)
Task: {E9FD0CF4-8115-4F06-8426-694915405C59} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-22] (Google Inc.)
Task: {EF396D68-E8AB-452B-A20A-C7FFD5E56572} - System32\Tasks\MySearchDial => C:\Users\Teresa\AppData\Roaming\MySearchDial\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000Core.job => C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000UA.job => C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\Teresa\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\Re-markit Update.job => C:\Program Files (x86)\Re-markit-soft\Re-markitj73.exe <==== ATTENTION
Task: C:\Windows\Tasks\Re-markit_wd.job => C:\Program Files (x86)\Re-markit-soft\Re-markitw.exe <==== ATTENTION
Task: C:\Windows\Tasks\Speedial.job => C:\Users\Teresa\AppData\Roaming\Speedial\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9

==================== Loaded Modules (Whitelisted) ==============

2014-05-19 15:20 - 2014-07-19 22:16 - 00097792 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markitw.exe
2011-02-18 10:48 - 2011-02-18 10:48 - 00092504 _____ () C:\Program Files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
2014-07-19 22:16 - 2014-07-19 22:16 - 00160768 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markitBG175.exe
2014-06-25 10:58 - 2014-06-25 10:58 - 00172544 _____ () C:\Program Files (x86)\CDDCF87A-3EAD-40C4-8099-34C6869D3E9D\SupraSavingsService64.exe
2014-06-12 12:05 - 2014-06-12 12:05 - 00110080 _____ () C:\Program Files (x86)\CDDCF87A-3EAD-40C4-8099-34C6869D3E9D\nfapi.dll
2014-06-12 12:05 - 2014-06-12 12:05 - 00456192 _____ () C:\Program Files (x86)\CDDCF87A-3EAD-40C4-8099-34C6869D3E9D\ProtocolFilters.dll
2014-06-13 13:42 - 2014-06-13 13:42 - 00706560 _____ () C:\Program Files\003\vxlsnyaiet64.exe
2014-07-19 22:16 - 2014-07-19 22:16 - 00422400 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markitj73.exe
2014-07-03 23:18 - 2014-07-03 23:18 - 00186192 _____ () c:\ProgramData\Fast And Safe\FastAndSafeSvc.dll
2014-07-03 23:18 - 2014-07-03 23:18 - 04125696 _____ () c:\ProgramData\Fast And Safe\FastAndSafe.dll
2014-06-13 14:16 - 2014-06-13 14:16 - 00186496 _____ () c:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll
2014-06-13 14:16 - 2014-06-13 14:16 - 03000776 _____ () c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll
2011-11-01 23:26 - 2011-11-01 23:26 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-11-01 23:26 - 2011-11-01 23:26 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-02-15 11:37 - 2011-02-15 11:37 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2011-02-15 11:36 - 2011-02-15 11:36 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2011-02-15 11:37 - 2011-02-15 11:37 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2014-07-19 22:16 - 2014-07-19 22:16 - 00171520 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markitBG175.dll
2014-05-02 01:35 - 2012-05-29 23:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.5.0.28\wincfi39.dll
2014-03-23 16:04 - 2014-03-23 16:04 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:373E1720 [118]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="3"
e"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-504136971-1847211166-3120143677-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Teresa\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{2EA1B7D1-33A0-41CE-B717-85B54487E5C5}C:\program files (x86)\java\jre7\bin\javaw.exe] => C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{36CFCEED-2BC5-4BF9-8F09-94071B94F244}C:\program files (x86)\java\jre7\bin\javaw.exe] => C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{20485983-4894-4690-B68C-558A8C2C1ACF}] => C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe
FirewallRules: [{5E59B09D-A799-4BA1-B58B-69E65A770351}] => C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe
FirewallRules: [{4E7CB2FE-92C9-4BBF-A943-2391C7EED270}] => C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{E8B371CF-D704-4131-BFF1-FB82796669E7}C:\users\teresa\appdata\local\facebook\video\skype\facebookvideocalling.exe] => C:\users\teresa\appdata\local\facebook\video\skype\facebookvideocalling.exe
FirewallRules: [UDP Query User{02CC8718-A8BB-48FD-B9C7-BAA600B49B46}C:\users\teresa\appdata\local\facebook\video\skype\facebookvideocalling.exe] => C:\users\teresa\appdata\local\facebook\video\skype\facebookvideocalling.exe
FirewallRules: [{580697C3-3EA8-4D9F-9FB1-8879B212997C}] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{E90A528C-2DB6-4B73-A201-B9FA9D4F9381}] => C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{3B682BBB-19C8-4A01-9149-ED2E4A85C089}] => C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{FB5A0965-EB93-406E-83C6-3B837D8CCA57}] => C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{1E6849BF-0FE3-4594-ABE6-481485477CAF}] => LPort=2869
FirewallRules: [{1143AE03-1067-45B6-BFFB-32B641E5D226}] => LPort=1900
FirewallRules: [{6642BE79-FFAC-443B-8161-16FEE295D939}] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{D8B78F3C-20ED-4806-A8DD-ECB482895D77}] => C:\Users\Teresa\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe

==================== Restore Points =========================

02-07-2014 09:37:48 Scheduled Checkpoint
03-07-2014 16:18:18 Installed Rapport
12-07-2014 01:49:25 Windows Update
13-07-2014 05:12:12 Windows Update
02-08-2014 19:33:45 Windows Update
14-10-2014 13:07:31 Windows Update
26-11-2014 20:38:10 Windows Modules Installer
26-12-2016 18:24:21 Scheduled Checkpoint

==================== Faulty Device Manager Devices =============

Name: Link-Layer Topology Discovery Responder
Description: Link-Layer Topology Discovery Responder
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: rspndr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Link-Layer Topology Discovery Mapper I/O Driver
Description: Link-Layer Topology Discovery Mapper I/O Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: lltdio
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: avast! Firewall NDIS Filter Miniport
Description: avast! Firewall NDIS Filter Miniport
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: ALWIL Software
Service: aswNdis
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.

Name: avast! Firewall NDIS Filter Miniport
Description: avast! Firewall NDIS Filter Miniport
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: ALWIL Software
Service: aswNdis
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: RapportEI64
Description: RapportEI64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: RapportEI64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: RapportKE64
Description: RapportKE64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: RapportKE64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: RapportPG64
Description: RapportPG64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: RapportPG64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Symantec Network Security WFP Driver
Description: Symantec Network Security WFP Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SymNetS
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

==================== Event log errors: =========================

Application errors:
==================
Error: (12/27/2016 04:55:58 PM) (Source: Customer Experience Improvement Program) (EventID: 1006) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being consolidated into files that can be sent to Microsoft, (Error 80004005).

Error: (12/27/2016 04:55:45 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (12/27/2016 04:52:40 PM) (Source: Software Protection Platform Service) (EventID: 1001) (User: )
Description: The Software Protection service failed to start. 0x80070002
6.1.7601.17514

Error: (12/27/2016 04:49:53 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 25633367

Error: (12/27/2016 04:49:53 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 25633367

Error: (12/27/2016 04:49:53 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (12/27/2016 04:49:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 25617767

Error: (12/27/2016 04:49:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 25617767

Error: (12/27/2016 04:49:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (12/27/2016 04:49:21 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 25602167

System errors:
=============
Error: (12/27/2016 04:57:02 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error:
An instance of the service is already running.

Error: (12/27/2016 04:57:02 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Multimedia Class Scheduler service, but this action failed with the following error:
An instance of the service is already running.

Error: (12/27/2016 04:57:02 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Computer Browser service, but this action failed with the following error:
An instance of the service is already running.

Error: (12/27/2016 04:56:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.

Error: (12/27/2016 04:56:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.

Error: (12/27/2016 04:56:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.

Error: (12/27/2016 04:55:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.

Error: (12/27/2016 04:55:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.

Error: (12/27/2016 04:55:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.

Error: (12/27/2016 04:55:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.

==================== Memory info ===========================

Processor: Intel(R) Celeron(R) CPU P4600 @ 2.00GHz
Percentage of memory in use: 93%
Total physical RAM: 2806.7 MB
Available physical RAM: 185.94 MB
Total Virtual: 5611.59 MB
Available Virtual: 2209.2 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:281.99 GB) (Free:165.35 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: D65CE497)
Partition 1: (Not Active) - (Size=16 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=282 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

Hi and welcome

It's been a while since I've seen one this infected.

- Save ALL Tools to your Desktop-

All tools that I have you download should be placed on the desktop unless otherwise stated. If you are familiar with how to save files to the desktop then you can skip this step.

Since you are continuing with this step then I assume you are unfamiliar with saving files to your desktop. As a result it's easiest if you configure your browser(s) to download any tools to the desktop by default. Please use the appropriate instructions below depending on the browser you are using.
[external image: Chrome.JPG]Google Chrome - Click the "Customize and control Google Chrome" button in the upper right-corner of the browser.[external image: Settings.JPG] Choose Settings. at the bottom of the screen click the
"Show advanced settings…" link. Scroll down to find the Downloads section and click the Change… button. Select your desktop and click OK.
[external image: Firefox.JPG]Mozilla Firefox - Click the "Open Menu" button in the upper right-corner of the browser. [external image: Settings.JPG] Choose Options. In the downloads section, click the Browse button, click on the Desktop folder
Click OK to get out of the Options menu.

~~~
Please download the Malwarebytes Anti-Malware setup file to your Desktop.

OR from this location Here
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs, followed by the first Scan Log.
  • Click Export, followed by Copy to Clipboard. Paste the log in your next reply.

~~

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
    In order to use AdwCleaner, you have to agree the Eula:
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
  • – File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~

Please download Junkware Removal Tool
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
  • ~~
    please post
    Malwarebytes Anti-Malware.txt
    AdwCleaner[C1].txt
    JRT.txt
Minor problem. It doesn't matter how I try starting the laptop today (safe mode or regular), I get a popular called Startup Repair and it says "computer unable to start" and begins searching for problems. I have tried cancelling and the screen just freezes.
So where do we go from here?
wowssa, hope this turns out better then what I think can happen from this point.

Had you run any of the tools when this happened?

Its possible it could be a physical problem, can happen when there is some system file that gets corrupted and then Windows tries to repair it but can't and then you get the loop.

1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
2. Press a key when you are prompted.
3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
4. Click Repair your computer.
5. Click the operating system that you want to repair, and then click Next.
6. In the System Recovery Options dialog box, click Command Prompt.
7. Type Bootrec.exe, and then press ENTER. Refer this link for more information
https://support.microsoft.com/en-us/kb/927392
How to use the Bootrec.exe tool in the Windows Recovery Environment to troubleshoot and repair startup issues in Windows

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

This tutorial will show you how to use the System Recovery Options provided by Windows to recover your system to a working state so that you don't have to risk losing data by performing a clean install.

http://www.sevenforums.com/tutorials/139576-startup-repair-infinite-loop-recovery.html
I managed to get it started again and was given the option of repair, which I chose. Ran malwarebytes while at work but am unsure where the log is stored as the laptop did an update and restarted.
Tried the thing with the disc, but it didn't run.

Now I am getting C:\PROGRA~2\Suptab\SEARCH~1.DLL is either not designed to run on Windows or it contains an error. Try installing the program again using the original installation media or contact your system administrator or the software vendor for support.
The top of that window also says "Facebook update.exe - Bad Image.

I cannot close that window either.
One more thing to add. I cannot open IE, chrome, or FF in normal mode. I tried safe mode and even after connecting to wireless I cannot run a diagnostic to see WHY I cannot connect to Internet.
Is it possible to just wipe the laptop entirely and start over using the discs? Or even better without a disc? I noticed a little note in the bottom corner saying this was not a legitimate version of Windows.

YES!!! Was playing around looking in control panel and figured out how to do a factory restore!!!
Will let you know how it worked :D


Update me on this.

After this I think it best to run a couple of scans to ensure it's better.

One glitch I have noticed- laptop will shut off with no warning. Other than that it seems okay, if a bit slow. 

Here is the malwarebytes scan, should I do the others you posted above?

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 12/29/16
Scan Time: 2:51 AM
Logfile: mwb.txt
Administrator: Yes
 
-Software Information-
Version: 3.0.5.1299
Components Version: 1.0.43
Update Package Version: 1.0.884
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 322723
Time Elapsed: 21 min, 19 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)

 

One glitch I have noticed- laptop will shut off with no warning.

 

Can't say I know whats up with that.  Hope it's not the power supply having a bad day.

 

Yes, run the other tools and post the results.

# AdwCleaner v6.041 - Logfile created 29/12/2016 at 17:06:12
# Updated on 16/12/2016 by Malwarebytes
# Database : 2016-12-29.2 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Sherry - SHERRY-PC
# Running from : C:\Users\Sherry\Downloads\AdwCleaner.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
 
 
***** [ Files ] *****
 
[-] File deleted: C:\Users\Public\Desktop\eBay.lnk
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
 
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Sherry\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Deleted: hxxp://search.imesh.net
[-] [C:\Users\Sherry\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Deleted: hxxp://search.conduit.com/?ctid=CT3320218&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP2B72293F-D46A-4483-9E9F-D7BD6AA3C78D&SSPV=
[-] [C:\Users\Sherry\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Deleted: hxxp://search.conduit.com/?gd=&ctid=CT3320218&octid=EB_ORIGINAL_CTID&ISID=&SearchSource=55&CUI=&UM=5&UP=SP2B72293F-D46A-4483-9E9F-D7BD6AA3C78D&SSPV=
[-] [C:\Users\Sherry\AppData\Local\Google\Chrome\User Data\Default] [homepage] Deleted: hxxp://search.imesh.net
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [1640 Bytes] - [29/12/2016 17:06:12]
C:\AdwCleaner\AdwCleaner[S0].txt - [1910 Bytes] - [29/12/2016 17:01:45]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1786 Bytes] ##########
 
 
 
 
 
 
 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 7 Home Premium x64 
Ran by [removed] (Administrator) on 29/12/2016 at 17:12:54.59
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 18 
 
Successfully deleted: C:\Program Files (x86)\GUT7B96.tmp (File) 
Successfully deleted: C:\Program Files (x86)\GUTF6BA.tmp (File) 
Successfully deleted: C:\Users\Sherry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0I2HH804 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Sherry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Sherry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Sherry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FD4UZQF4 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Sherry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Sherry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JA3L5C79 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Sherry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Sherry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH0VVZ36 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0I2HH804 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FD4UZQF4 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JA3L5C79 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MH0VVZ36 (Temporary Internet Files Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29/12/2016 at 17:22:18.09
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
  • Download the Emsisoft Emergency Kit and execute it. From there, click on the Extract button to extract the program in the EEK folder;
  • Once the extraction is complete, Emsisoft Emergency Kit will open, and suggest you to run an online update before using the program. Click on Yes to launch it.
  • After the update, click on Malware Scan under 2. Scan and accept to let Emsisoft Emergency Kit detect PUPs (click on Yes).
  • Once the scan is complete, make sure that every item in the list is checked, and click on Quarantine selected;
  • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
  • After the restart, click on the Start Emsisoft Emergency Kit icon again on your desktop to open it;
  • This time, click on Logs;
  • From there, go under the Quarantine Log tab, and click on the Export button;
  • Save the log on your desktop, then open it, and copy/paste its content in your next reply;
After running this online scan give me an update on how the computer is now.
Emsisoft Emergency Kit - Version 12.0
Last update: 29/12/2016 9:44:52 PM
User account: Sherry-PC\Sherry
Computer name: SHERRY-PC
OS version: Windows 7x64 Service Pack 1
 
Scan settings:
 
Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files
 
Detect PUPs: Off
Scan archives: Off
ADS Scan: On
File extension filter: Off
Direct disk access: Off
 
Scan start: 29/12/2016 9:46:58 PM
 
Scanned 71051
Found 0
 
Scan end: 29/12/2016 9:51:25 PM
Scan time: 0:04:27

 

It doesn't appear to :) The shutting down appears to be from overheating quickly. Any suggestions on a link for cleaning the inside of a laptop?
It doesn't appear to :) The shutting down appears to be from overheating quickly. Any suggestions on a link for cleaning the inside of a laptop?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI