This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop drained for resourses

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am trying to help my niece with her laptop. It is not the newest and fastest, it is 7years old, 2Gb ram, 2.3 GHz AMD processer, so it will of course never be ligthning fast, but it is running remarkably slow as it is. It litterally took me more tyhan 2 hours to boot, and write this message.

 

I can't find anything suspicious in the taskmanager. There don't seem to be any processes that uses unusually big amounts of CPU or memmory, so I Wonder if some kind of malware could be to blame? - I have executed aswMBR and FRST as instructed, and I would be grateful if someone here could take a look at the logs and see if anything looks bad.

 

Thanks in advance. :-)

 

Here comes my logs:

 

 

aswMBR.log:

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-01-11 18:17:36
—————————–
18:17:36.844    OS Version: Windows x64 6.1.7601 Service Pack 1
18:17:36.844    Number of processors: 1 586 0x603
18:17:36.844    ComputerName: NANNA-PC  UserName: kim
18:17:39.621    Initialize success
18:17:39.823    VM: initialized successfully
18:17:39.823    VM: Amd CPU supported
18:22:55.388    AVAST engine defs: 17010903
18:26:04.585    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
18:26:04.585    Disk 0 Vendor: WDC_WD3200BPVT-22ZEST0 01.01A01 Size: 305245MB BusType: 11
18:26:04.741    Disk 0 MBR read successfully
18:26:04.741    Disk 0 MBR scan
18:26:04.913    Disk 0 Windows 7 default MBR code
18:26:04.913    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        14336 MB offset 2048
18:26:04.975    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 29362176
18:26:05.037    Disk 0 Boot: NTFS     code=1
18:26:05.069    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       290807 MB offset 29566976
18:26:05.271    Disk 0 scanning C:\Windows\system32\drivers
18:26:18.516    Service scanning
18:26:49.310    Modules scanning
18:26:49.326    Disk 0 trace - called modules:
18:26:49.357    ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
18:26:49.357    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8002453410]
18:26:49.373    3 CLASSPNP.SYS[fffff880018cd43f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80023fd060]
18:26:50.901    AVAST engine scan C:\Windows
18:26:53.273    AVAST engine scan C:\Windows\system32
18:30:19.567    AVAST engine scan C:\Windows\system32\drivers
18:30:34.013    AVAST engine scan C:\Users\kim
18:30:56.757    AVAST engine scan C:\ProgramData
18:31:51.343    Disk 0 statistics 3115093/0/0 @ 8,09 MB/s
18:31:51.358    Scan finished successfully
18:32:34.040    Disk 0 MBR has been saved successfully to "C:\Users\kim\Desktop\MBR.dat"
18:32:34.040    The log file has been saved successfully to "C:\Users\kim\Desktop\aswMBR.txt"

 

=======================================================================================

 

FRST.txt:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-01-2017
Ran by [removed] (administrator) on NANNA-PC (11-01-2017 18:34:40)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Dansk (Danmark)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Acer Group) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_11_5_502_146_ActiveX.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11444840 2010-09-21] (Realtek Semiconductor)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated)
HKLM\…\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [206208 2010-06-09] ()
HKLM\…\Run: [Acer ePower Management] => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe [263936 2010-06-28] (NewTech Infosystems, Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-10-28] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\…\Run: [Camera Assistant Software] => c:\program files (x86)\video web camera\traybar.exe [600688 2010-07-06] (Chicony)
HKLM-x32\…\Run: [Browser companion helper] => c:\program files (x86)\browsercompanion\bchelper.exe [182576 2011-11-29] (Blabbers Communications LTD)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\…\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
Startup: C:\Users\Nanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Screen Clipper and Launcher til OneNote 2007.lnk [2012-02-08]
ShortcutTarget: Screen Clipper and Launcher til OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.127.127.11 [removed] [removed]
Tcpip\..\Interfaces\{7669D56C-823A-4037-AC39-2D33B1373031}: [DhcpNameServer] 10.127.127.11 [removed] [removed]
Tcpip\..\Interfaces\{E78EF6AF-F479-4726-AE4C-B73851565F14}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{EF83CEBC-E005-4A94-B194-B3C18B6EBAAC}: [DhcpNameServer] [removed] [removed]

Internet Explorer:
==================
HKU\S-1-5-21-139978781-2723255831-1225844396-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/da-dk/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid;=InternetTurboYB&co;=DK&userid;=4230dde0-841b-494b-add4-53db15c814be&searchtype;=ds&q;={searchTerms}&installDate;=22/02/2013
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid;=InternetTurboYB&co;=DK&userid;=4230dde0-841b-494b-add4-53db15c814be&searchtype;=ds&q;={searchTerms}&installDate;=22/02/2013
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll => No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-20] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-20] (Oracle Corporation)
BHO: DVDVideoSoft WebPageAdjuster Class -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll [2013-01-30] (DVDVideoSoft Ltd.)
BHO-x32: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssie.dll => No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-03-13] (Sun Microsystems, Inc.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-03-13] (Sun Microsystems, Inc.)
BHO-x32: DVDVideoSoft WebPageAdjuster Class -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll [2013-01-30] (DVDVideoSoft Ltd.)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll [2013-01-20] ()
FF Plugin: @java.com/DTPlugin,version=10.11.2 -> C:\Windows\system32\npDeployJava1.dll [2013-01-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.11.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-01-20] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-02-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll [2013-01-20] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-04-08] ()
FF Plugin-x32: @java.com/DTPlugin -> C:\Program Files (x86)\Java\jre6\bin\npDeployJava1.dll [2012-03-13] (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2012-03-13] (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-02-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-16] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-09-26] (Adobe Systems Inc.)

Chrome:
=======
CHR HKLM-x32\…\Chrome\Extension: [ibgfbdggapddbjjbopabhlhianklajie] - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx [2011-11-29]
CHR HKLM-x32\…\Chrome\Extension: [plmlpkfpkijnlijgalnjaacllnjmoamo] - C:\Users\Nanna\AppData\Local\CRE\plmlpkfpkijnlijgalnjaacllnjmoamo.crx [2012-12-01]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [971160 2016-12-15] (AVG Technologies CZ, s.r.o.)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5337600 2016-12-15] (AVG Technologies CZ, s.r.o.)
S2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [725976 2016-12-15] (AVG Technologies CZ, s.r.o.)
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [868896 2010-06-11] (Acer Incorporated)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [255744 2010-06-28] (NewTech Infosystems, Inc.)
R2 Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [312576 2016-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [298240 2016-11-30] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [254208 2016-09-26] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [299264 2016-07-27] (AVG Technologies CZ, s.r.o.)
R0 avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.)
U5 GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [33240 2012-08-21] (GEAR Software Inc.)
R4 AVGIDSFilter; system32\DRIVERS\avgidsfiltera.sys [X]
S3 k57nd60a; system32\DRIVERS\k57nd60a.sys [X]
U3 aswMBR; \??\C:\Users\kim\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\kim\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-11 18:34 - 2017-01-11 18:35 - 00014701 _____ C:\Users\kim\Desktop\FRST.txt
2017-01-11 18:33 - 2017-01-11 18:34 - 00000000 ____D C:\FRST
2017-01-11 18:32 - 2017-01-11 18:32 - 00002132 _____ C:\Users\kim\Desktop\aswMBR.txt
2017-01-11 18:32 - 2017-01-11 18:32 - 00000512 _____ C:\Users\kim\Desktop\MBR.dat
2017-01-11 18:16 - 2017-01-11 18:16 - 02419200 _____ (Farbar) C:\Users\kim\Desktop\FRST64.exe
2017-01-11 18:14 - 2017-01-11 18:14 - 05198336 _____ (AVAST Software) C:\Users\kim\Desktop\aswMBR.exe
2017-01-11 18:09 - 2017-01-11 18:09 - 00000000 ____D C:\Program Files\Common Files\AV
2017-01-11 17:32 - 2017-01-11 17:32 - 00000000 __SHD C:\Users\kim\AppData\LocalLow\EmieUserList
2017-01-11 17:29 - 2017-01-11 17:29 - 00000000 __SHD C:\Users\kim\AppData\Local\EmieUserList
2017-01-11 17:29 - 2017-01-11 17:29 - 00000000 __SHD C:\Users\kim\AppData\Local\EmieSiteList
2017-01-11 17:27 - 2017-01-11 17:32 - 00000000 __SHD C:\Users\kim\AppData\LocalLow\EmieSiteList
2017-01-11 17:13 - 2017-01-11 17:13 - 00000000 ____D C:\Users\kim\AppData\Roaming\AVG2012
2017-01-11 17:13 - 2017-01-11 17:13 - 00000000 ____D C:\Users\kim\AppData\Local\CEF
2017-01-11 17:12 - 2017-01-11 17:12 - 00110376 _____ C:\Users\kim\AppData\Local\GDIPFONTCACHEV1.DAT
2017-01-11 17:12 - 2017-01-11 17:12 - 00000000 ____D C:\Users\kim\AppData\Local\Avg
2017-01-11 17:11 - 2017-01-11 17:11 - 00000984 _____ C:\Users\Public\Desktop\AVG.lnk
2017-01-11 17:11 - 2017-01-11 17:11 - 00000000 ____D C:\Users\kim\AppData\Roaming\Apple Computer
2017-01-11 17:10 - 2017-01-11 17:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2017-01-11 17:01 - 2017-01-11 17:01 - 00001429 _____ C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-01-11 17:01 - 2017-01-11 17:01 - 00000000 ____D C:\Users\kim\AppData\Roaming\Adobe
2017-01-11 16:55 - 2017-01-11 16:55 - 00000000 ____D C:\Users\kim\AppData\Local\VirtualStore
2017-01-11 16:53 - 2017-01-11 17:00 - 00000000 ____D C:\Users\kim
2017-01-11 16:53 - 2017-01-11 16:53 - 00000020 ___SH C:\Users\kim\ntuser.ini
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Skabeloner
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Printere
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Menuen Start
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Lokale indstillinger
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Dokumenter
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Documents\Videoer
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Documents\Musik
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Documents\Billeder
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programmer
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\AppData\Local\Oversigt
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Andre computere
2017-01-11 16:53 - 2013-01-31 00:57 - 00000000 ____D C:\Users\kim\AppData\Roaming\TuneUp Software
2017-01-11 16:53 - 2012-02-09 13:02 - 00000000 ____D C:\Users\kim\AppData\Local\Microsoft Help
2017-01-11 16:53 - 2009-07-14 08:44 - 00000000 ____D C:\Users\kim\AppData\Roaming\Media Center Programs
2017-01-11 16:46 - 2017-01-11 16:46 - 00003600 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
2017-01-11 16:37 - 2017-01-11 17:37 - 00000000 ____D C:\ProgramData\Avg

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-11 18:12 - 2012-08-02 11:31 - 00000000 ___HD C:\$AVG
2017-01-11 18:12 - 2012-02-06 11:00 - 00000000 ____D C:\ProgramData\AVG2012
2017-01-11 18:12 - 2012-02-06 10:58 - 00000000 ____D C:\Program Files (x86)\AVG
2017-01-11 18:12 - 2012-02-06 10:42 - 00000000 ____D C:\ProgramData\MFAData
2017-01-11 18:11 - 2014-05-25 14:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-01-11 18:08 - 2013-01-20 14:34 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-01-11 17:50 - 2008-12-31 23:17 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-01-11 16:54 - 2013-01-26 16:56 - 00000354 _____ C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job
2017-01-11 16:38 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-11 16:38 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

Files to move or delete:
====================
C:\Users\Nanna\temp.dat

Some files in TEMP:
====================
C:\Users\Michael\AppData\Local\Temp\1249DF99.dll
C:\Users\Michael\AppData\Local\Temp\3FE192CE.dll
C:\Users\Michael\AppData\Local\Temp\3FE4B813.dll
C:\Users\Michael\AppData\Local\Temp\3FE5CADB.dll
C:\Users\Michael\AppData\Local\Temp\42E29267.dll
C:\Users\Michael\AppData\Local\Temp\42E75679.dll
C:\Users\Michael\AppData\Local\Temp\4EA186D8.dll
C:\Users\Michael\AppData\Local\Temp\4EA4B6AF.dll
C:\Users\Michael\AppData\Local\Temp\7DB3C97C.dll
C:\Users\Michael\AppData\Local\Temp\90CAF1B7.dll
C:\Users\Nanna\AppData\Local\Temp\04F76823.dll
C:\Users\Nanna\AppData\Local\Temp\12ED7C46.dll
C:\Users\Nanna\AppData\Local\Temp\12ED7E1A.dll
C:\Users\Nanna\AppData\Local\Temp\1444B246.dll
C:\Users\Nanna\AppData\Local\Temp\32D4FFBF.dll
C:\Users\Nanna\AppData\Local\Temp\32DFDFA4.dll
C:\Users\Nanna\AppData\Local\Temp\33E8E5A1.dll
C:\Users\Nanna\AppData\Local\Temp\46BAACDD.dll
C:\Users\Nanna\AppData\Local\Temp\47A8F8F3.dll
C:\Users\Nanna\AppData\Local\Temp\47B3617E.dll
C:\Users\Nanna\AppData\Local\Temp\8DE221F7.dll
C:\Users\Nanna\AppData\Local\Temp\8DE7710F.dll
C:\Users\Nanna\AppData\Local\Temp\8DEC051B.dll
C:\Users\Nanna\AppData\Local\Temp\9DD13E8D.dll
C:\Users\Nanna\AppData\Local\Temp\9DD560B6.dll
C:\Users\Nanna\AppData\Local\Temp\9DD77CF2.dll
C:\Users\Nanna\AppData\Local\Temp\9DD7E0D6.dll
C:\Users\Nanna\AppData\Local\Temp\EBEEE7EE.dll
C:\Users\Nanna\AppData\Local\Temp\F3891244.dll
C:\Users\Nanna\AppData\Local\Temp\Installer.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2013-04-30 18:44

==================== End of FRST.txt ============================

 

 

Addition.txt:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-01-2017
Ran by [removed] (11-01-2017 18:35:46)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-01-30 19:02:06)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-139978781-2723255831-1225844396-500 - Administrator - Disabled)
Gæst (S-1-5-21-139978781-2723255831-1225844396-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-139978781-2723255831-1225844396-1002 - Limited - Enabled)
kim (S-1-5-21-139978781-2723255831-1225844396-1004 - Administrator - Enabled) => C:\Users\kim
Nanna (S-1-5-21-139978781-2723255831-1225844396-1001 - Administrator - Enabled) => C:\Users\Nanna

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG Anti-Virus Free Edition 2012 (Enabled - Up to date) {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: AVG AntiVirus Free Edition (Disabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: AVG Anti-Virus Free Edition 2012 (Enabled - Up to date) {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition (Disabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Flash Player 11 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 11.5.502.146 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 11.5.502.146 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.05) - Dansk (HKLM-x32\…\{AC76BA86-7AD7-1030-7B44-AB0000000001}) (Version: 11.0.05 - Adobe Systems Incorporated)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Apple Mobile Device Support (HKLM\…\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Apple-programunderstøttelse (HKLM-x32\…\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
ATI Catalyst Install Manager (HKLM\…\{2023DAEC-90C2-E042-909F-BFAD8AC9B60C}) (Version: 3.0.795.0 - ATI Technologies, Inc.)
AVG (HKLM\…\AvgZen) (Version: 1.113.2.50020 - AVG Technologies)
AVG (Version: 16.141.7996 - AVG Technologies) Hidden
AVG 2012 (Version: 12.0.3222 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4749 - AVG Technologies) Hidden
AVG Protection (HKLM\…\AVG) (Version: 2016.141.7996 - AVG Technologies)
AVG Zen (Version: 1.113.1 - AVG Technologies) Hidden
Backup Manager Basic (x32 Version: 2.0.0.68 - NewTech Infosystems) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon MP490 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series) (Version:  - )
ccc-core-static (x32 Version: 2010.1028.1114.18274 - Dit firmanavn) Hidden
FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden
Free YouTube Download version 3.2.0.128 (HKLM-x32\…\Free YouTube Download_is1) (Version: 3.2.0.128 - DVDVideoSoft Ltd.)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3003 - Packard Bell)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
iTunes (HKLM\…\{76FF0F03-B707-4332-B5D1-A56C8303514E}) (Version: 11.0.4.4 - Apple Inc.)
Java 7 Update 11 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417011FF}) (Version: 7.0.110 - Oracle)
Java 7 Update 45 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle)
Java(TM) 6 Update 31 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle)
Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 4.0.14 - Packard Bell)
Microsoft .NET Framework 4.5.1 (dansk) (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1030) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\…\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Klik og kør 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - dansk (HKLM-x32\…\{90140011-0066-0406-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\…\{95140000-00AF-0406-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyTomTom 3.2.0.1055 (HKLM-x32\…\MyTomTom) (Version: 3.2.0.1055 - TomTom)
Nero 9 Essentials (HKLM-x32\…\{a97f0ac6-e34b-400a-8ce4-c4a5ab45344e}) (Version:  - Nero AG)
Opdatering til Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\…\{90120000-0016-0406-0000-0000000FF1CE}_ENTERPRISE_{7304A9DD-2F95-4147-8CD4-E135168C61E6}) (Version:  - Microsoft)
Opdatering til Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\…\{90120000-0018-0406-0000-0000000FF1CE}_ENTERPRISE_{0C315122-B0FA-428D-A3BB-6F6510F866FF}) (Version:  - Microsoft)
Opdatering til Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\…\{90120000-001B-0406-0000-0000000FF1CE}_ENTERPRISE_{EA60117C-C535-4A3F-AED1-C888F5114210}) (Version:  - Microsoft)
Overførselsværktøj til Windows Live (HKLM-x32\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Packard Bell MyBackup (HKLM-x32\…\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.68 - NewTech Infosystems)
Packard Bell Power Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 5.00.3005 - Packard Bell)
Packard Bell Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Packard Bell)
Packard Bell Social Networks (HKLM-x32\…\InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}) (Version: 1.0.1901 - CyberLink Corp.)
Packard Bell Social Networks (x32 Version: 1.0.1901 - CyberLink Corp.) Hidden
Packard Bell Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3001 - Packard Bell)
Realtek HDMI Audio Driver for ATI (HKLM-x32\…\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6034 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6206 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30122 - Realtek Semiconductor Corp.)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 14.0.19.0 - Synaptics Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Video Web Camera (HKLM-x32\…\{12A1B519-5934-4508-ADBD-335347B0DC87}) (Version: 1.7.137.706 - Chicony Electronics Co.,Ltd.)
Visual Studio 2008 x64 Redistributables (HKLM-x32\…\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Visual Studio C++ 10.0 Runtime (HKLM-x32\…\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{02B8DBC1-7312-43AF-8BA7-9F29CDD6B348}) (Version: 14.0.8117.416 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {2920AE8A-E72D-4EBA-9DAD-AE00CD10462A} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {429F750E-E424-45C8-8111-D5FB15349F9D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-20] (Adobe Systems Incorporated)
Task: {9600B749-2A15-48D3-8CFE-840073931790} - System32\Tasks\ROC_JAN2013_TB_rmv => C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe
Task: {CA648314-17B8-4937-A075-A31D6AFC81D0} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job => C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2011-11-01 23:26 - 2011-11-01 23:26 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-11-01 23:26 - 2011-11-01 23:26 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2010-06-28 23:20 - 2010-06-28 23:20 - 00465576 _____ () C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
2010-06-28 23:12 - 2010-06-28 23:12 - 01081600 _____ () C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\ACE.dll
2010-09-16 11:55 - 2009-05-20 07:02 - 00072200 _____ () C:\Program Files (x86)\Launch Manager\CdDirIo.dll
2017-01-11 16:46 - 2017-01-11 16:43 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-139978781-2723255831-1225844396-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\kim\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.127.127.11 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{BCBB3E32-8A4F-4C9D-87AD-85113628492E}] => C:\Program Files (x86)\Adobe\Elements Organizer 8.0\AdobePhotoshopElementsMediaServer.exe
FirewallRules: [{527B415A-27C4-4ADB-B950-CDBE0381B93B}] => C:\Program Files (x86)\Adobe\Elements Organizer 8.0\AdobePhotoshopElementsMediaServer.exe
FirewallRules: [{26C2BCCA-4635-4F92-9D64-50FC3EEAF567}] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{C81A9253-C70B-43EC-8079-F45E33B09434}] => svchost.exe
FirewallRules: [{8149B6A7-322F-4D7E-A04D-7BB5AB381D5B}] => C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{D7832EB0-A552-4AED-956E-C1FBDDEB0AF0}] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{A07AE41F-B8CA-452C-893D-BF343EF0F8ED}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{21940ECF-7B93-4E19-999B-AB5F9684F2AD}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{35041BCB-9238-4632-947C-AB79063999A1}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{12307BD3-B4C1-4372-A808-A5EF13025A9A}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{D28254BF-B9FA-4DD7-AE11-4F5F62C4F8E5}C:\program files (x86)\java\jre6\bin\java.exe] => C:\program files (x86)\java\jre6\bin\java.exe
FirewallRules: [UDP Query User{A11C4438-88A8-4516-9846-811F601BFE0D}C:\program files (x86)\java\jre6\bin\java.exe] => C:\program files (x86)\java\jre6\bin\java.exe
FirewallRules: [{82519764-9E61-4217-A9C1-52A87A1A073B}] => C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{CB885D71-8C2E-40FD-A68A-9A707B772756}] => C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{222521B9-0F4B-4F02-ADFE-91FE875C7850}] => C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{C75E0D39-0CA3-45B8-87A0-65B7EB8A919C}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{299A961A-D598-4808-ADB4-367148342122}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{691331BF-2AA2-4A67-9AA2-71300EA16A46}] => C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{949A55D3-7ABC-445C-A20A-BCDF28BAFAD1}] => C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{D65CE8C4-D29B-4AA5-A214-2ECCDC59A084}] => C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{CFDB7880-5B88-4A8C-B910-29DD3FE13B28}] => C:\Program Files (x86)\AVG\Av\avgemca.exe

==================== Restore Points =========================

31-12-2008 23:31:32 Windows Update
18-01-2014 23:30:44 Windows Update
20-04-2014 19:54:32 Windows Update
20-04-2014 20:22:16 Windows Update
25-05-2014 14:47:38 Windows Update
25-05-2014 16:13:12 Windows Update
06-07-2014 18:23:05 Windows Update
11-01-2017 17:25:02 Installed AVG 2016
11-01-2017 17:40:03 Installed AVG

==================== Faulty Device Manager Devices =============

Name: TSSTcorp CDDVDW TS-L633F ATA Device
Description: cd-rom-drev
Class Guid: {4d36e965-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard cd-rom-drev)
Service: cdrom
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.

Name: Ethernet-controller
Description: Ethernet-controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

==================== Event log errors: =========================

Application errors:
==================
Error: (01/11/2017 06:07:43 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: Sikkerhedskopieringen blev ikke fuldført, da der ikke kunne skrives til sikkerhedskopiplaceringen D:\. Fejlen er: Sikkerhedskopiplaceringen blev ikke fundet, eller den er ikke gyldig. Gennemgå indstillingerne for sikkerhedskopiering, og kontrollér sikkerhedskopiplaceringen. (0x81000006).

Error: (01/11/2017 04:52:58 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Aktiveringskontekstgenereringen mislykkedes for "C:\Windows\Temp\AvgSetup\1b29118f-ce2e-47cf-8e9c-35bbaea1640d\install\fmw\avgrdsttestx.exe".
Afhængig samling AVG.VC140.CRT,processorArchitecture="x86",publicKeyToken="f92d94485545da78",type="win32",version="14.0.23918.0" blev ikke fundet.
Anvend sxstrace.exe til detaljeret diagnose.

Error: (01/11/2017 04:51:12 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Aktiveringskontekstgenereringen mislykkedes for "C:\Windows\Temp\AvgSetup\1b29118f-ce2e-47cf-8e9c-35bbaea1640d\install\fmw\avgrdsttesta.exe".
Afhængig samling AVG.VC140.CRT,processorArchitecture="amd64",publicKeyToken="f92d94485545da78",type="win32",version="14.0.23918.0" blev ikke fundet.
Anvend sxstrace.exe til detaljeret diagnose.

Error: (01/11/2017 04:45:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programmet Explorer.EXE version 6.1.7601.17567 afbrød kommunikationen med Windows og blev afsluttet. Hvis du vil se, om der findes flere oplysninger om problemet, kan du læse om problemets historik via Løsningscenter.

Proces-id: dbc

Starttidspunkt: 01c96ba61d45d445

Afslutningstidspunkt: 18159

Programsti: C:\Windows\Explorer.EXE

Rapport-id: c768a8c0-d814-11e6-ad26-e4f2e8458dfe

Error: (01/01/2009 12:54:22 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Fjernelse af ydelsestællerstrenge for tjenesten WmiApRpl (WmiApRpl) mislykkedes. Det første DWORD i dataafsnittet indeholder fejlkoden.

Error: (01/01/2009 12:54:22 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Ydelsestællerstrengene i registreringsdatabaseværdien for ydelse blev beskadiget under behandling af udvidelsestællerudbyderen Performance. Værdien BaseIndex fra registreringsdatabasen for ydelse er det første DWORD i dataafsnittet, værdien LastCounter er det andet DWORD i dataafsnittet, og værdien LastHelp er det tredje DWORD i dataafsnittet.

Error: (01/01/2009 12:54:21 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Ydelsestællerstrengene i registreringsdatabaseværdien for ydelse blev beskadiget under behandling af udvidelsestællerudbyderen Performance. Værdien BaseIndex fra registreringsdatabasen for ydelse er det første DWORD i dataafsnittet, værdien LastCounter er det andet DWORD i dataafsnittet, og værdien LastHelp er det tredje DWORD i dataafsnittet.

Error: (12/31/2008 11:11:43 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Kun oplysninger.
(Patch task for {90140011-0066-0406-0000-0000000FF1CE}): DownloadLatest Failed: Der er ingen aktiv netværksforbindelse i øjeblikket. BITS (Background Intelligent Transfer Service) prøver igen, når der er tilsluttet et netværkskort.

Error: (12/31/2008 11:06:33 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Fjernelse af ydelsestællerstrenge for tjenesten WmiApRpl (WmiApRpl) mislykkedes. Det første DWORD i dataafsnittet indeholder fejlkoden.

Error: (12/31/2008 11:06:33 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Ydelsestællerstrengene i registreringsdatabaseværdien for ydelse blev beskadiget under behandling af udvidelsestællerudbyderen Performance. Værdien BaseIndex fra registreringsdatabasen for ydelse er det første DWORD i dataafsnittet, værdien LastCounter er det andet DWORD i dataafsnittet, og værdien LastHelp er det tredje DWORD i dataafsnittet.

System errors:
=============
Error: (01/11/2017 06:09:08 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Tjenesten AVGIDSAgent blev afbrudt med den tjenestespecifikke fejl %%-536753635.

Error: (01/11/2017 06:03:29 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Der opstod en timeout (30000 millisekunder), mens der ventedes på et transaktionssvar fra tjenesten avgwd.

Error: (01/11/2017 05:54:08 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Der opstod en timeout (30000 millisekunder), mens der ventedes på et transaktionssvar fra tjenesten Browser.

Error: (01/11/2017 05:53:38 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Der opstod en timeout (30000 millisekunder), mens der ventedes på et transaktionssvar fra tjenesten Browser.

Error: (01/11/2017 05:53:08 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Der opstod en timeout (30000 millisekunder), mens der ventedes på et transaktionssvar fra tjenesten Browser.

Error: (01/11/2017 05:24:36 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: Fejlen "1053" opstod på DCOM under forsøg på at starte tjenesten VSS med argumenterne "" for at køre serveren:
{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}

Error: (01/11/2017 05:24:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Tjenesten Øjebliksbillede af diskenhed kunne ikke starte pga. følgende fejl:
Tjenesten svarede ikke på en start- eller kontrolanmodning inden for det forventede tidsinterval.

Error: (01/11/2017 05:24:36 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Der opstod timeout (30000 millisekunder), mens systemet ventede på, at der blev oprettet forbindelse til tjenesten Øjebliksbillede af diskenhed.

Error: (01/11/2017 05:00:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Tjenesten AVG Service kunne ikke starte pga. følgende fejl:
Tjenesten svarede ikke på en start- eller kontrolanmodning inden for det forventede tidsinterval.

Error: (01/11/2017 05:00:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Der opstod timeout (30000 millisekunder), mens systemet ventede på, at der blev oprettet forbindelse til tjenesten AVG Service.

==================== Memory info ===========================

Processor: AMD V140 Processor
Percentage of memory in use: 63%
Total physical RAM: 1786.9 MB
Available physical RAM: 650.87 MB
Total Virtual: 4021.8 MB
Available Virtual: 2389.91 MB

==================== Drives ================================

Drive c: (Packard Bell) (Fixed) (Total:283.99 GB) (Free:217.56 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 9DBC78D8)
Partition 1: (Not Active) - (Size=14 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=284 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

These versions of Java need to be uninstalled. The most current version can be downloaded later.

Java 7 Update 11 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417011FF}) (Version: 7.0.110 - Oracle)
Java 7 Update 45 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle)
Java 6 Update 31 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle)

~~~~~~~~~~~~~~~~~``

Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
HKLM-x32\…\Run: [Browser companion helper] => c:\program files (x86)\browsercompanion\bchelper.exe [182576 2011-11-29] (Blabbers Communications LTD)
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DK&userid=4230dde0-841b-494b-add4-53db15c814be&searchtype=ds&q={searchTerms}&installDate=22/02/2013
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DK&userid=4230dde0-841b-494b-add4-53db15c814be&searchtype=ds&q={searchTerms}&installDate=22/02/2013
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll => No File
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-20] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-20] (Oracle Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-03-13] (Sun Microsystems, Inc.)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-03-13] (Sun Microsystems, Inc.)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
FF Plugin: @java.com/JavaPlugin,version=10.11.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-01-20] (Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin -> C:\Program Files (x86)\Java\jre6\bin\npDeployJava1.dll [2012-03-13] (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2012-03-13] (Sun Microsystems, Inc.)
CHR HKLM-x32\…\Chrome\Extension: [ibgfbdggapddbjjbopabhlhianklajie] - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx [2011-11-29]
CHR HKLM-x32\…\Chrome\Extension: [plmlpkfpkijnlijgalnjaacllnjmoamo] - C:\Users\Nanna\AppData\Local\CRE\plmlpkfpkijnlijgalnjaacllnjmoamo.crx [2012-12-01]
U3 aswMBR; \??\C:\Users\kim\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\kim\AppData\Local\Temp\aswVmm.sys [X]
C:\Users\Nanna\temp.dat
C:\Users\Michael\AppData\Local\Temp\1249DF99.dll
C:\Users\Michael\AppData\Local\Temp\3FE192CE.dll
C:\Users\Michael\AppData\Local\Temp\3FE4B813.dll
C:\Users\Michael\AppData\Local\Temp\3FE5CADB.dll
C:\Users\Michael\AppData\Local\Temp\42E29267.dll
C:\Users\Michael\AppData\Local\Temp\42E75679.dll
C:\Users\Michael\AppData\Local\Temp\4EA186D8.dll
C:\Users\Michael\AppData\Local\Temp\4EA4B6AF.dll
C:\Users\Michael\AppData\Local\Temp\7DB3C97C.dll
C:\Users\Michael\AppData\Local\Temp\90CAF1B7.dll
C:\Users\Nanna\AppData\Local\Temp\04F76823.dll
C:\Users\Nanna\AppData\Local\Temp\12ED7C46.dll
C:\Users\Nanna\AppData\Local\Temp\12ED7E1A.dll
C:\Users\Nanna\AppData\Local\Temp\1444B246.dll
C:\Users\Nanna\AppData\Local\Temp\32D4FFBF.dll
C:\Users\Nanna\AppData\Local\Temp\32DFDFA4.dll
C:\Users\Nanna\AppData\Local\Temp\33E8E5A1.dll
C:\Users\Nanna\AppData\Local\Temp\46BAACDD.dll
C:\Users\Nanna\AppData\Local\Temp\47A8F8F3.dll
C:\Users\Nanna\AppData\Local\Temp\47B3617E.dll
C:\Users\Nanna\AppData\Local\Temp\8DE221F7.dll
C:\Users\Nanna\AppData\Local\Temp\8DE7710F.dll
C:\Users\Nanna\AppData\Local\Temp\8DEC051B.dll
C:\Users\Nanna\AppData\Local\Temp\9DD13E8D.dll
C:\Users\Nanna\AppData\Local\Temp\9DD560B6.dll
C:\Users\Nanna\AppData\Local\Temp\9DD77CF2.dll
C:\Users\Nanna\AppData\Local\Temp\9DD7E0D6.dll
C:\Users\Nanna\AppData\Local\Temp\EBEEE7EE.dll
C:\Users\Nanna\AppData\Local\Temp\F3891244.dll
C:\Users\Nanna\AppData\Local\Temp\Installer.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
EmptyTemp:
Hosts:
End


Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~~~``

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
    In order to use AdwCleaner, you have to agree the Eula:
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
– File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please download Junkware Removal Tool
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
please post

~~~
Fixlog.txt
AdwCleaner[C1].txt
JRT.txt

Hi Juliet,

 

Thanks for your fast reply! :-) - I am Kim by the way (it a males name i Denmark, just to clarify)

 

I have followed your instructions and deleted the tree Java versions. Then I ran FRST, AdwCleaner, and JTR as described. The only deviation is that I chose to run the AdwCleanwer as administrator, even though you didn't specifically demanded it, but I thought that it couldn't harm to give it the privilegies in case the program had to delete some stuff etc. Hope that it is in order.

 

Bellow follows the logfiles, and thanks a lot for your help! :-)

 

 

Fixlog.txt:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 11-01-2017
Ran by [removed] (12-01-2017 13:13:01) Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKLM-x32\…\Run: [Browser companion helper] => c:\program files (x86)\browsercompanion\bchelper.exe [182576 2011-11-29] (Blabbers Communications LTD)
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DK&userid=4230dde0-841b-494b-add4-53db15c814be&searchtype=ds&q={searchTerms}&installDate=22/02/2013
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DK&userid=4230dde0-841b-494b-add4-53db15c814be&searchtype=ds&q={searchTerms}&installDate=22/02/2013
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll => No File
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-20] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-20] (Oracle Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-03-13] (Sun Microsystems, Inc.)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-03-13] (Sun Microsystems, Inc.)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
FF Plugin: @java.com/JavaPlugin,version=10.11.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-01-20] (Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin -> C:\Program Files (x86)\Java\jre6\bin\npDeployJava1.dll [2012-03-13] (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2012-03-13] (Sun Microsystems, Inc.)
CHR HKLM-x32\…\Chrome\Extension: [ibgfbdggapddbjjbopabhlhianklajie] - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx [2011-11-29]
CHR HKLM-x32\…\Chrome\Extension: [plmlpkfpkijnlijgalnjaacllnjmoamo] - C:\Users\Nanna\AppData\Local\CRE\plmlpkfpkijnlijgalnjaacllnjmoamo.crx [2012-12-01]
U3 aswMBR; \??\C:\Users\kim\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\kim\AppData\Local\Temp\aswVmm.sys [X]
C:\Users\Nanna\temp.dat
C:\Users\Michael\AppData\Local\Temp\1249DF99.dll
C:\Users\Michael\AppData\Local\Temp\3FE192CE.dll
C:\Users\Michael\AppData\Local\Temp\3FE4B813.dll
C:\Users\Michael\AppData\Local\Temp\3FE5CADB.dll
C:\Users\Michael\AppData\Local\Temp\42E29267.dll
C:\Users\Michael\AppData\Local\Temp\42E75679.dll
C:\Users\Michael\AppData\Local\Temp\4EA186D8.dll
C:\Users\Michael\AppData\Local\Temp\4EA4B6AF.dll
C:\Users\Michael\AppData\Local\Temp\7DB3C97C.dll
C:\Users\Michael\AppData\Local\Temp\90CAF1B7.dll
C:\Users\Nanna\AppData\Local\Temp\04F76823.dll
C:\Users\Nanna\AppData\Local\Temp\12ED7C46.dll
C:\Users\Nanna\AppData\Local\Temp\12ED7E1A.dll
C:\Users\Nanna\AppData\Local\Temp\1444B246.dll
C:\Users\Nanna\AppData\Local\Temp\32D4FFBF.dll
C:\Users\Nanna\AppData\Local\Temp\32DFDFA4.dll
C:\Users\Nanna\AppData\Local\Temp\33E8E5A1.dll
C:\Users\Nanna\AppData\Local\Temp\46BAACDD.dll
C:\Users\Nanna\AppData\Local\Temp\47A8F8F3.dll
C:\Users\Nanna\AppData\Local\Temp\47B3617E.dll
C:\Users\Nanna\AppData\Local\Temp\8DE221F7.dll
C:\Users\Nanna\AppData\Local\Temp\8DE7710F.dll
C:\Users\Nanna\AppData\Local\Temp\8DEC051B.dll
C:\Users\Nanna\AppData\Local\Temp\9DD13E8D.dll
C:\Users\Nanna\AppData\Local\Temp\9DD560B6.dll
C:\Users\Nanna\AppData\Local\Temp\9DD77CF2.dll
C:\Users\Nanna\AppData\Local\Temp\9DD7E0D6.dll
C:\Users\Nanna\AppData\Local\Temp\EBEEE7EE.dll
C:\Users\Nanna\AppData\Local\Temp\F3891244.dll
C:\Users\Nanna\AppData\Local\Temp\Installer.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
EmptyTemp:
Hosts:
End

*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Browser companion helper => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => key removed successfully
HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} => key removed successfully
HKCR\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} => key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found.
HKCR\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key not found.
HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key removed successfully
HKCR\Wow6432Node\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key removed successfully
HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value removed successfully
HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value removed successfully
HKCR\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} => key not found.
HKCR\PROTOCOLS\Handler\linkscanner => key not found.
HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => key not found.
HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2 => key not found.
"C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll" => not found.
HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin => key removed successfully
C:\Program Files (x86)\Java\jre6\bin\npDeployJava1.dll => not found.
HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin => key not found.
C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll => not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ibgfbdggapddbjjbopabhlhianklajie => key removed successfully
C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx => moved successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\plmlpkfpkijnlijgalnjaacllnjmoamo => key removed successfully
C:\Users\Nanna\AppData\Local\CRE\plmlpkfpkijnlijgalnjaacllnjmoamo.crx => moved successfully
aswMBR => service not found.
aswVmm => service not found.
C:\Users\Nanna\temp.dat => moved successfully
C:\Users\Michael\AppData\Local\Temp\1249DF99.dll => moved successfully
C:\Users\Michael\AppData\Local\Temp\3FE192CE.dll => moved successfully
C:\Users\Michael\AppData\Local\Temp\3FE4B813.dll => moved successfully
C:\Users\Michael\AppData\Local\Temp\3FE5CADB.dll => moved successfully
C:\Users\Michael\AppData\Local\Temp\42E29267.dll => moved successfully
C:\Users\Michael\AppData\Local\Temp\42E75679.dll => moved successfully
C:\Users\Michael\AppData\Local\Temp\4EA186D8.dll => moved successfully
C:\Users\Michael\AppData\Local\Temp\4EA4B6AF.dll => moved successfully
C:\Users\Michael\AppData\Local\Temp\7DB3C97C.dll => moved successfully
C:\Users\Michael\AppData\Local\Temp\90CAF1B7.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\04F76823.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\12ED7C46.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\12ED7E1A.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\1444B246.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\32D4FFBF.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\32DFDFA4.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\33E8E5A1.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\46BAACDD.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\47A8F8F3.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\47B3617E.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\8DE221F7.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\8DE7710F.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\8DEC051B.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\9DD13E8D.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\9DD560B6.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\9DD77CF2.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\9DD7E0D6.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\EBEEE7EE.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\F3891244.dll => moved successfully
C:\Users\Nanna\AppData\Local\Temp\Installer.exe => moved successfully
C:\Users\Nanna\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe => moved successfully
C:\Users\Nanna\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe => moved successfully
C:\Users\Nanna\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 2379351 B
Java, Flash, Steam htmlcache => 492 B
Windows/system/drivers => 309217736 B
Edge => 0 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 66228 B
Public => 0 B
ProgramData => 0 B
systemprofile => 98610641 B
systemprofile32 => 95627 B
LocalService => 132244 B
NetworkService => 66228 B
Nanna => 352981759 B
Michael => 45305917 B
kim => 408225431 B

RecycleBin => 0 B
EmptyTemp: => 1.1 GB temporary data Removed.

================================

The system needed a reboot.

==== End of Fixlog 13:15:30 ====

 

 

 

AdwCleaner[C0].txt:

 

# AdwCleaner v6.042 - Logfile created 12/01/2017 at 14:01:55
# Updated on 06/01/2017 by Malwarebytes
# Database : 2017-01-11.1 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : kim - NANNA-PC
# Running from : C:\Users\kim\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support

 

***** [ Services ] *****

 

***** [ Folders ] *****

[-] Folder deleted: C:\Users\Nanna\AppData\Local\Babylon
[-] Folder deleted: C:\Users\Nanna\AppData\Local\Conduit
[-] Folder deleted: C:\Users\Nanna\AppData\LocalLow\BabylonToolbar
[-] Folder deleted: C:\Users\Nanna\AppData\LocalLow\Conduit
[-] Folder deleted: C:\Users\Nanna\AppData\Roaming\Babylon
[-] Folder deleted: C:\Users\Nanna\AppData\Roaming\dvdvideosoftiehelpers
[#] Folder deleted on reboot: C:\Users\Nanna\AppData\Roaming\OpenCandy
[-] Folder deleted: C:\ProgramData\Ask
[-] Folder deleted: C:\ProgramData\Babylon
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Ask
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Babylon
[-] Folder deleted: C:\Program Files (x86)\BrowserCompanion
[-] Folder deleted: C:\Program Files (x86)\Conduit
[-] Folder deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\AVG Secure Search

***** [ Files ] *****

[-] File deleted: C:\END
[-] File deleted: C:\user.js

***** [ DLL ] *****

 

***** [ WMI ] *****

 

***** [ Shortcuts ] *****

 

***** [ Scheduled Tasks ] *****

 

***** [ Registry ] *****

[-] Key deleted: HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
[-] Key deleted: HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
[-] Key deleted: HKLM\SOFTWARE\Classes\driverscanner
[-] Key deleted: HKLM\SOFTWARE\Classes\Prod.cap
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\driverscanner
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Prod.cap
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
[-] Key deleted: HKU\.DEFAULT\Software\Auslogics
[#] Key deleted on reboot: HKU\S-1-5-18\Software\Auslogics
[-] Key deleted: HKLM\SOFTWARE\Babylon
[-] Key deleted: HKLM\SOFTWARE\Conduit
[-] Key deleted: HKLM\SOFTWARE\Uniblue
[#] Key deleted on reboot: HKLM\SOFTWARE\Uniblue\DriverScanner
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\escort.DLL
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}

***** [ Web browsers ] *****

 

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [5239 Bytes] - [12/01/2017 14:01:55]
C:\AdwCleaner\AdwCleaner[S0].txt - [5179 Bytes] - [12/01/2017 13:59:05]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5385 Bytes] ##########

 

================================================================================

 

 

JRT.txt:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 7 Home Premium x64
Ran by [removed] (Administrator) on 12-01-2017 at 14:43:04,75
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

File System: 11

Successfully deleted: C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KJ6GQAAC (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QDHQGY4O (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RV0J5CT2 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UGW0RFKM (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KJ6GQAAC (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QDHQGY4O (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RV0J5CT2 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UGW0RFKM (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\SysWOW64\sho3606.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho8E99.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoAE6B.tmp (File)

 

Registry: 3

Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl\\Default (Registry Value)

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12-01-2017 at 14:46:01,59
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Nice to meet you Kim.

Please download the Malwarebytes Anti-Malware setup file to your Desktop.

OR from this location Here
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
    [external image: MBAM3_zpsw0f8rn9n.jpg]
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
After running the above scan/tool, please tell me how the computer is now.

Hi Juliet,

 

I am sorry for the late reply, but I have been strugling to run Mbam. It actually executes ok, but only for a while until it all of a suden hangs at a random file. I have been wondering what could be the reason, and I have been speculating if hardware is to blame. I have executed the windows build-in tools for testing the disk and the memmory, but none of them pointed out any issues. Then I booted the laptop in safe mode to make sure that only a minimum of drivers was loaded when I executed Mbam, but unfortunately the result was the same; it was still hanging at ramdom places.

 

I can tell that mbam actually finds arround 16 "potentional unwanted programs", but I have the feeling that those not really are the reason that Mbam hangs. I don't have any ideas by now, so I wonder if you might have some experience what to do when Mbam is hanging like that?

 

Best regards

 

Kim.

My first thought is to turn off or temporarily disable AVG antivirus, possibly interfering.
https://support.avg.com/SupportArticleView?l=en&urlName=How-to-disable-AVG

If it is hardware, ouch!

If trying that doesn't work, we'll try a different one.
  • Download Emsisoft Emergency Kit and save it to your desktop.
  • Double-click icon then click Install
  • A Window should open highlighting Start Emergency Kit Scanner
  • Right click on the icon and select Run as administrator
  • Click 1. Update now!
  • Once the update is completed select Settings under Scan
  • Uncheck Join the Emsisoft Anti-Malware Network
  • Click Scan at the top
  • Click On scan completion
  • Click Quarantine detected objects, then click OK
  • Click Malware Scan
  • Once completed click View Report
  • Save the file to your Desktop using the default file name
  • Copy and paste the report in your reply
===============

Hi Again!

 

Well, I was a bit ahead of you here; I allready tried to disable AVG to make sure that it wasn't interferring with MBAM, but the result was the same. I just forgot to mention it in my former answer. One ting though; I clearly felt that turning of AVG freed up some resourses, so it might be worth to switch to another antivirus program.

 

I installed EEK aka your instructions, and it executed with no problems at all! - it is also worth to mention that I hasn't seen any other programs that is hanging, so it might be some bug in MBAM that gets triggered on this computer.

 

Here follows the report:

 

 

Emsisoft Emergency Kit - Version 12.0
Last update: 16-01-2017 21:20:06
User account: Nanna-Pc\kim
Computer name: NANNA-PC
OS version: Windows 7x64 Service Pack 1

Scan settings:

Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files

Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Direct disk access: Off

Scan start: 16-01-2017 21:23:43
C:\Users\Nanna\AppData\Roaming\OpenCandy  detected: Application.AppInstall (A) []
C:\Users\Nanna\AppData\Local\cre  detected: Application.AppInstall (A) []
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\APPDATALOW\SOFTWARE\CONDUIT  detected: Application.Toolbar (A) []
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{963B125B-8B21-49A2-A3A8-E37092276531}  detected: Application.Win32.Toolbar (A) []
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\CONDUIT  detected: Application.InstallAd (A) []
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}  detected: Application.Win32.WSearch (A) []
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\SMARTBAR  detected: Application.InstallAd (A) []
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}  detected: Application.AdReg (A) []
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\BROWSERCOMPANION  detected: Application.InstallAd (A) []
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1003\SOFTWARE\BROWSERCOMPANION  detected: Application.InstallAd (A) []
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\PLMLPKFPKIJNLIJGALNJAACLLNJMOAMO  detected: Application.WebExt (A) []

Scanned 77991
Found 11

Scan end: 16-01-2017 21:44:52
Scan time: 0:21:09

Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}  Application.AdReg (A)
C:\Users\Nanna\AppData\Local\cre  Application.AppInstall (A)
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\BROWSERCOMPANION  Application.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1003\SOFTWARE\BROWSERCOMPANION  Application.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\CONDUIT  Application.InstallAd (A)
C:\Users\Nanna\AppData\Roaming\OpenCandy  Application.AppInstall (A)
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\APPDATALOW\SOFTWARE\CONDUIT  Application.Toolbar (A)
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}  Application.Win32.WSearch (A)
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{963B125B-8B21-49A2-A3A8-E37092276531}  Application.Win32.Toolbar (A)
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\SMARTBAR  Application.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-139978781-2723255831-1225844396-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\PLMLPKFPKIJNLIJGALNJAACLLNJMOAMO  Application.WebExt (A)

Quarantined 11

Sometimes we never know why some tools fight each other and play well with others.

If I remember correctly, AVG is a good antivirus but heavy on the resources.

You could experiment and uninstall then try to reinstall MBAM to see if that helps?

I'll post a list of different antivirusAs for which free versus paid for Antivirus I have to leave this up to you but, I've always stayed with a free version, that use less resources and consumes less time in updating. This is my personal opinion and also with free versions of Antivirus, firewall is not included.

~~~~~~~~~~~~~~~~

What problems remain?

Hi Again,

 

I have now deinstalled AVG and installed avast instead, and it is clearly less demanding on the resources, so that is deffenitly preferable on this small old computer.

 

To further optimize a bit I have also executed Ccleaner, and I allowed it to delete what it surgested, and likewise I did also let it remove what bad entries it could find in the registry. I don't know how much it helps, but I can't think thak it will do any harm.

 

I have also been experimenting a lot to get MBAM to finish, but I must realize that it is just not possible, so I deinstalled it again.

 

It is clearly my impression that the computer is a least a little better, so unless you have any ideas what further could be done, I think that I will hand it over to my niece again and let her try it out…

 

Regards Kim.

Ccleaner - I did also let it remove what bad entries it could find in the registry. I don't know how much it helps, but I can't think thak it will do any harm.

Actually, this can cause a problem. We don't recommend people use registry cleaners…..down the road big issues could come in and that would most likely be un-repairable.

I think your good to go
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
*************
  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP
  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: 6YRrgUC.png]Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: jv4nhMJ.png]NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png]Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: j1OLIec.png]SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • [external image: sHjS79L.png]Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.

Hi Juliet,

 

I am aware of the fact that deleting registries can corrupt the system, but I backed up the registry first, and I also checked what it wanted to delete before I accpeted the deletion, and my judgement was that the surgested entries were safe enough to delete, so I felt relatively safe to do it.

 

I have executed DelFix as you instructed, and here is its log:

 

# DelFix v1.010 - Logfile created 23/01/2017 at 13:57:10
# Updated 26/04/2015 by Xplode
# Username : kim - NANNA-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Activating UAC … OK

~ Removing disinfection tools …

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\kim\Desktop\Addition.txt
Deleted : C:\Users\kim\Desktop\AdwCleaner.exe
Deleted : C:\Users\kim\Desktop\AdwCleaner[C0].txt
Deleted : C:\Users\kim\Desktop\aswMBR.exe
Deleted : C:\Users\kim\Desktop\aswMBR.txt
Deleted : C:\Users\kim\Desktop\Fixlog.txt
Deleted : C:\Users\kim\Desktop\FRST.txt
Deleted : C:\Users\kim\Desktop\FRST64.exe
Deleted : C:\Users\kim\Desktop\JRT.exe
Deleted : C:\Users\kim\Desktop\JRT.txt
Deleted : C:\Users\kim\Desktop\MBR.dat
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

########## - EOF - ##########

 

I noticed that EmisisoftEmergencyKit were not removed, so I just deleted it myself.

 

Thanks a lot for your help! - it is really fantastic that your guys are volunteering to do this for people you don't even know! :-) :-)

 

 

Best Regards

 

- Kim.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI