Quantcast
Channel: Tech Support Guy - Virus & Other Malware Removal
Viewing all 4746 articles
Browse latest View live

Malware/hijacks in Chrome

$
0
0
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-02-2015
Ran by Sean (administrator) on SEAN-PC on 10-02-2015 19:27:52
Running from D:\BitComet Downloads
Loaded Profiles: Sean (Available profiles: Sean)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
( ) C:\Windows\System32\lxducoms.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.2.0\ToolbarUpdater.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.2.0\loggingserver.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(www.BitComet.com) C:\Program Files (x86)\BitComet\BitComet.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Dropbox, Inc.) C:\Users\Sean\AppData\Roaming\Dropbox\bin\Dropbox.exe
(www.BitComet.com) C:\Program Files (x86)\BitComet\tools\BitCometService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
(AVG Secure Search) C:\Program Files (x86)\AVG Web TuneUp\avgcefrend.exe
(Qwerty) C:\Program Files (x86)\TornPlusTV_version1.11\TornPlusTV_version1.11-codedownloader.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(AVG Secure Search) C:\Program Files (x86)\AVG Web TuneUp\avgcefrend.exe
(Qwerty) C:\Program Files (x86)\TornPlusTV_version1.11\TornPlusTV_version1.11-bg.exe
(Google) C:\Users\Sean\AppData\Local\Google\Chromecast\ChromecastApp.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe

==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10144288 2010-04-06] (Realtek Semiconductor)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [2703752 2010-03-25] (ELAN Microelectronics Corp.)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3089688 2013-06-27] (Logitech, Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [3081752 2014-12-13] ()
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\...\Run: [BitComet] => C:\Program Files (x86)\BitComet\BitComet.exe [12805888 2013-05-01] (www.BitComet.com)
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-05-27] (Google Inc.)
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\...\Run: [Windows Remote Service] => C:\Program Files (x86)\Banamalon\Windows Remote Service\WindowsRemoteService.exe [173568 2013-05-24] (Banamalon)
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7780120 2015-01-20] (SUPERAntiSpyware)
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-09-14] (Apple Inc.)
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\...\Run: [Google Update] => C:\Users\Sean\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-02-10] (Google Inc.)
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\...\Run: [Google+ Auto Backup] => "C:\Users\Sean\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\...\Run: [GoogleChromeAutoLaunch_4C759CBE76051A54F37D4E70F0F48AE0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-02-04] (Google Inc.)
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\...\MountPoints2: {202d88f5-0a10-11e3-91cf-e811328de355} - F:\LaunchU3.exe -a
AppInit_DLLs-x32: c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll => "c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll" File Not Found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Sean\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://samsung.msn.com
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKU\S-1-5-21-2942724973-3254444484-952029406-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
SearchScopes: HKLM -> DefaultScope value is missing.
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={search...c=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2942724973-3254444484-952029406-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2942724973-3254444484-952029406-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid=...r&d=2014-12-13 19:48:46&v=4.0.5.7&pid=wtu&sg=&sap=dsp&q={searchTerms}
BHO: TornPlusTV_version1.11 -> {11111111-1111-1111-1111-110611881155} -> C:\Program Files (x86)\TornPlusTV_version1.11\TornPlusTV_version1.11-bho64.dll (Qwerty)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: TornPlusTV_version1.11 -> {11111111-1111-1111-1111-110611881155} -> C:\Program Files (x86)\TornPlusTV_version1.11\TornPlusTV_version1.11-bho.dll (Qwerty)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: BitComet Helper -> {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} -> C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.0.5.7\AVG Web TuneUp.dll (AVG)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-2942724973-3254444484-952029406-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.2.0\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.2.0\\npsitesafety.dll No File
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2942724973-3254444484-952029406-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Sean\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-2942724973-3254444484-952029406-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Sean\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-07-21]
Chrome:
=======
CHR HomePage: Default -> hxxp://search.babylon.com/?affID=119351&tt=300513_new&babsrc=HP_ss_din2g&mntrId=100CE0CA9467E177
CHR StartupUrls: Default -> "hxxp://www.google.com/", "hxxp://www.kickass.so/"
CHR DefaultSuggestURL: Default -> http://toolbar.avg.com/acp?q={searchTerms}&o=1
CHR Profile: C:\Users\Sean\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Sean\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-22]
CHR Extension: (Google Docs) - C:\Users\Sean\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-22]
CHR Extension: (Google Drive) - C:\Users\Sean\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-04]
CHR Extension: (YouTube) - C:\Users\Sean\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-04]
CHR Extension: (caplfhpahpkhhckglldpmdmjclabckhc) - C:\Users\Sean\AppData\Local\Google\Chrome\User Data\Default\Extensions\caplfhpahpkhhckglldpmdmjclabckhc [2015-01-07]
CHR Extension: (AVG Secure Search) - C:\Users\Sean\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2014-12-16]
CHR Extension: (Google Sheets) - C:\Users\Sean\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-22]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2015-01-20] (SUPERAntiSpyware.com)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.)
R3 BITCOMET_HELPER_SERVICE; C:\Program Files (x86)\BitComet\tools\BitCometService.exe [1296728 2010-12-28] (www.BitComet.com)
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-01-02] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-01-02] (globalUpdate) [File not signed]
R2 lxdu_device; C:\windows\system32\lxducoms.exe [1039360 2009-10-16] ( )
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 vToolbarUpdater18.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.2.0\ToolbarUpdater.exe [1850392 2014-12-13] (AVG Secure Search)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 vToolbarUpdater15.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [260888 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [203544 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-10-10] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [52000 2014-12-13] (AVG Technologies)
S3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-18] (Siliten)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-10 19:27 - 2015-02-10 19:27 - 00000000 ____D () C:\FRST
2015-02-10 19:08 - 2015-02-10 19:08 - 00001165 _____ () C:\Users\Sean\Desktop\Chromecast.lnk
2015-02-10 19:08 - 2015-02-10 19:08 - 00000000 ____D () C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromecast
2015-02-10 19:05 - 2015-02-10 19:05 - 00880208 _____ (Google Inc.) C:\Users\Sean\Downloads\chromecastinstaller.exe
2015-01-27 20:46 - 2015-01-27 20:46 - 00003293 _____ () C:\Users\Sean\Downloads\[kickass.so]paper.love.sarah.wildman.epub.torrent
2015-01-27 20:44 - 2015-01-27 20:44 - 00001420 _____ () C:\Users\Sean\Downloads\[kickass.so]all.the.light.we.cannot.see.epub.torrent
2015-01-27 20:43 - 2015-01-27 20:43 - 00002767 _____ () C:\Users\Sean\Downloads\[kickass.so]the.rosie.project.2013.graeme.simsion.torrent
2015-01-25 22:57 - 2015-01-25 22:57 - 00000000 __SHD () C:\found.001
2015-01-25 20:58 - 2015-01-25 20:58 - 00278904 _____ () C:\windows\Minidump\012515-29983-01.dmp
2015-01-21 18:40 - 2015-01-21 18:40 - 00000000 ____D () C:\Users\Sean\AppData\Roaming\AVG2015
2015-01-21 18:36 - 2015-01-21 18:36 - 00000965 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2015-01-21 18:34 - 2015-01-21 18:39 - 00000000 ____D () C:\ProgramData\AVG2015
2015-01-21 18:32 - 2015-01-21 18:32 - 00000000 __SHD () C:\Users\Sean\AppData\Local\EmieBrowserModeList
2015-01-21 18:28 - 2015-01-21 18:40 - 00000000 ____D () C:\Users\Sean\AppData\Local\Avg2015
2015-01-21 18:27 - 2015-01-21 18:27 - 00000000 ____D () C:\Users\Sean\AppData\Local\MFAData
2015-01-13 16:13 - 2014-12-18 21:06 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-01-13 16:13 - 2014-12-18 19:46 - 00141312 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2015-01-13 16:13 - 2014-12-11 23:35 - 05553592 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-01-13 16:13 - 2014-12-11 23:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-01-13 16:13 - 2014-12-11 23:31 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-01-13 16:13 - 2014-12-11 23:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-01-13 16:13 - 2014-12-11 23:11 - 03971512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-01-13 16:13 - 2014-12-11 23:11 - 03916728 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-01-13 16:13 - 2014-12-11 23:07 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-01-13 16:13 - 2014-12-11 11:47 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2015-01-13 16:13 - 2014-12-05 22:17 - 00303616 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2015-01-13 16:13 - 2014-12-05 21:50 - 00156672 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncsi.dll
2015-01-13 16:13 - 2014-12-05 21:50 - 00052224 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlaapi.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-10 19:30 - 2014-12-13 19:49 - 00009606 _____ () C:\windows\SysWOW64\debug.log
2015-02-10 19:29 - 2011-04-28 20:05 - 01858104 _____ () C:\windows\WindowsUpdate.log
2015-02-10 19:27 - 2014-09-20 00:27 - 00000153 _____ () C:\windows\wininit.ini
2015-02-10 19:26 - 2014-09-19 23:11 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-02-10 19:26 - 2013-05-31 08:42 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-02-10 19:26 - 2013-05-28 18:12 - 00000000 ____D () C:\Users\Sean\AppData\Roaming\BitComet
2015-02-10 19:25 - 2014-08-10 15:27 - 00000852 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2942724973-3254444484-952029406-1000Core.job
2015-02-10 19:12 - 2015-01-02 16:11 - 00005518 _____ () C:\windows\Tasks\66f6670a-a75f-4186-8918-ebb3b414d5ba-6.job
2015-02-10 19:12 - 2014-08-10 15:27 - 00000904 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2942724973-3254444484-952029406-1000UA.job
2015-02-10 19:08 - 2013-05-27 17:09 - 00000000 ____D () C:\Users\Sean\AppData\Local\Google
2015-02-10 19:07 - 2014-08-10 15:27 - 00003876 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2942724973-3254444484-952029406-1000UA
2015-02-10 19:07 - 2014-08-10 15:27 - 00003480 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2942724973-3254444484-952029406-1000Core
2015-02-10 19:02 - 2013-06-12 22:31 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-02-10 18:53 - 2009-07-13 22:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-10 18:53 - 2009-07-13 22:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-10 18:52 - 2013-05-01 20:57 - 00000000 ___RD () C:\Users\Sean\Dropbox
2015-02-10 18:51 - 2013-05-01 20:53 - 00000000 ____D () C:\Users\Sean\AppData\Roaming\Dropbox
2015-02-10 18:50 - 2013-06-13 12:45 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-02-10 18:49 - 2015-01-02 16:11 - 00005182 _____ () C:\windows\Tasks\66f6670a-a75f-4186-8918-ebb3b414d5ba-7.job
2015-02-10 18:49 - 2015-01-02 16:11 - 00003468 _____ () C:\windows\Tasks\66f6670a-a75f-4186-8918-ebb3b414d5ba-1.job
2015-02-10 18:49 - 2015-01-02 16:11 - 00002446 _____ () C:\windows\Tasks\66f6670a-a75f-4186-8918-ebb3b414d5ba-5_user.job
2015-02-10 18:49 - 2015-01-02 16:11 - 00002446 _____ () C:\windows\Tasks\66f6670a-a75f-4186-8918-ebb3b414d5ba-5.job
2015-02-10 18:49 - 2015-01-02 16:11 - 00002110 _____ () C:\windows\Tasks\66f6670a-a75f-4186-8918-ebb3b414d5ba-2.job
2015-02-10 18:49 - 2015-01-02 16:11 - 00000902 _____ () C:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-02-10 18:49 - 2013-05-27 17:09 - 00000894 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-10 18:49 - 2013-04-21 09:16 - 00000000 ____D () C:\ProgramData\MFAData
2015-02-10 18:46 - 2009-07-13 23:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-02-10 18:46 - 2009-07-13 22:51 - 00086388 _____ () C:\windows\setupact.log
2015-02-07 19:34 - 2013-05-27 17:09 - 00000898 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-07 17:17 - 2015-01-02 16:11 - 00000906 _____ () C:\windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-02-05 00:02 - 2013-06-12 22:31 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-02-05 00:02 - 2013-06-12 22:31 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-05 00:02 - 2013-06-12 22:31 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-02-04 09:29 - 2013-05-27 17:09 - 00003894 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-04 09:29 - 2013-05-27 17:09 - 00003642 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-01-25 20:58 - 2014-05-16 20:07 - 00000000 ____D () C:\windows\Minidump
2015-01-25 20:58 - 2014-05-16 20:06 - 552865119 _____ () C:\windows\MEMORY.DMP
2015-01-22 18:55 - 2013-04-21 09:18 - 00000000 ____D () C:\ProgramData\AVG2013
2015-01-22 18:55 - 2010-11-20 21:47 - 00928402 _____ () C:\windows\PFRO.log
2015-01-21 18:40 - 2014-11-22 11:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-01-21 18:40 - 2013-04-21 09:18 - 00000000 ___HD () C:\$AVG
2015-01-21 18:40 - 2013-04-21 09:18 - 00000000 ____D () C:\Program Files (x86)\AVG
2015-01-21 18:32 - 2014-11-22 11:51 - 00000000 __SHD () C:\Users\Sean\AppData\Local\EmieUserList
2015-01-21 18:32 - 2014-11-22 11:51 - 00000000 __SHD () C:\Users\Sean\AppData\Local\EmieSiteList
2015-01-14 17:58 - 2015-01-02 15:58 - 00000000 ____D () C:\Program Files (x86)\TornPlusTV_version1.11
2015-01-14 05:48 - 2014-05-28 20:49 - 00000000 ____D () C:\windows\system32\MRT
2015-01-14 03:38 - 2014-05-28 20:49 - 113365784 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
==================== Files in the root of some directories =======
2015-01-02 15:58 - 2015-01-02 17:12 - 2022376 _____ (Qwerty) C:\Users\Sean\AppData\Roaming\QJAFTAMZ.exe
2013-04-21 08:41 - 2010-01-16 06:18 - 0131368 _____ () C:\ProgramData\FullRemove.exe
Some content of TEMP:
====================
C:\Users\Sean\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpftvx4q.dll

==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-02-03 00:41
==================== End Of Log ============================

Crypto locker encrypted file recovery

$
0
0
Hello honored to join you all.
Does any one have a solution to the Crypto locker encrypted file recovery. a friend was hit by this virus and all data locked up. he has no current backups. need help.

Isaac

AVG blocked by group policy program

$
0
0
I don't see anything serious wrong with the machine.
MSSE is updating nicely, but you can get that message if the machine is busy, or if it has already updated itself.
Not to worry.
You can always check the last update by opening the program.
Click on the system tray in the lower right (shows speaker, USB, etc.) and right click on the "schoolhouse" icon
Click open and see when the last update was.
.

Network renamed a day after phishing email

$
0
0
Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft® Windows Vista™ Home Premium, Service Pack 2, 64 bit
Processor: Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz, Intel64 Family 6 Model 15 Stepping 13
Processor Count: 2
RAM: 3963 Mb
Graphics Card: Mobile Intel(R) 4 Series Express Chipset Family, 1853 Mb
Hard Drives: C: Total - 142858 MB, Free - 78511 MB;
Motherboard: TOSHIBA, Portable PC
Antivirus: Microsoft Security Essentials, Updated and Enabled

Why does the following matter? I received an email yesterday with an attachment. It was meant to seem to be from the government so I would open it. It seemed a like a new and ingenious form of phishing. It took me 30 minutes or more to find an authority that would let me forward it to them.
After forwarding it I deleted it from my email client (Win. Mail) inbox and deleted items folder then went to the server and deleted it there. Afterwards I noticed I forgot to remove the sent items and deleted them as well. Nothing seemed different from then til I shutdown.
So this morning, this happens and it has me wondering if that email was still able to download something onto my machine.
After booting up and plugging in my network cable and a window opened offering to help me set up “the” network which was numbered 3. I ignored it and closed it as my network has been setup for years.
Only afterwards did it occur to me this was odd and I opened network and sharing center. The network I am connected with is “Network 3” and the only other one is the wireless connection which is disabled. I searched for other networks with no luck. I’m sure my network was never called “Network 3”.

My computer has malware that interrupts my keyboard

$
0
0
Thanks it seems that adwCleaner solved the issue. you can mark this thread as resolved

PC Clean Maestro Malware

$
0
0
go to add/remove programs and uninstall
Driver Manager
PC Clean Maestro
PC TuneUp Maestro
PC Ultra Speed v2.0

System is Loaded

$
0
0
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 2/11/2015
Scan Time: 10:53:49 AM
Logfile: Malwarebytes Anti.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2014.11.20.06
Rootkit Database: v2015.02.03.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Camilla

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 341571
Time Elapsed: 31 min, 35 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 1
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\PureLeads.Service.exe, 3932, Delete-on-Reboot, [0cfa112d5a222b0bf9a8cf637f8420e0]

Modules: 0
(No malicious items detected)

Registry Keys: 2
PUP.Optional.PureLeads.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PlsvcV2, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PureLe ads, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],

Registry Values: 1
PUP.Optional.FreeMakeConverter.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|fmconverter@gmail.com, C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\, Quarantined, [9472c876255716200c7376c43dc67a86]

Registry Data: 0
(No malicious items detected)

Folders: 2
PUP.Optional.PureLeads.A, C:\ProgramData\PureLeads, Quarantined, [8a7cb08efd7fe155940c50e2b54e8e72],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads, Delete-on-Reboot, [0cfa112d5a222b0bf9a8cf637f8420e0],

Files: 30
PUP.Optional.PureLeads.A, C:\ProgramData\PureLeads\config.pureleads, Quarantined, [8a7cb08efd7fe155940c50e2b54e8e72],
PUP.Optional.PureLeads.A, C:\ProgramData\PureLeads\Logo.ico, Quarantined, [8a7cb08efd7fe155940c50e2b54e8e72],
PUP.Optional.PureLeads.A, C:\ProgramData\PureLeads\pureleads.log, Quarantined, [8a7cb08efd7fe155940c50e2b54e8e72],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\DynLib.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\freebl3.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\Interop.PCProxyLib.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\libnspr4.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\libplc4.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\libplds4.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\nss3.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\nssckbi.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\nssdbm3.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\nssutil3.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\PAD_FILE.xml, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\plsapp.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\plsapp64.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\plsappDLL.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\plsappLSP.exe, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\plsappLSP.ini, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\plsappLSP64.exe, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\pureleads-win-upgrader.exe, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\PureLeads.Library.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\PureLeads.Service.exe, Delete-on-Reboot, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\PureLeadsControl.exe, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\PureLeadsUp.exe, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\smime3.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\softokn3.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\sqlite3.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\ssl3.dll, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],
PUP.Optional.PureLeads.A, C:\Program Files (x86)\PureLeads\Uninstall.exe, Quarantined, [0cfa112d5a222b0bf9a8cf637f8420e0],

Physical Sectors: 0
(No malicious items detected)


(end)

Need help recovering media files!

$
0
0
So I'm on windows 8 and I got a virus a while back which prevents me from accessing the internet and playing online games. Windows defender detects it but won't remove it and when I tried to reset my pc it said I am missing some files, your recovery device will provide these files or something along those lines. After some research, I found out a few people have this issue and I found a solution that was to go to a website and download the missing files, but I can't do that as the virus prevents me from visiting any websites or accessing the internet. Please help!

Should I delete Strong signal c723a437-2eaf-466d-a95b-3fa0966bf88c.dll?

$
0
0
I have done the auto runs and some stuff has come up in red, strong signal is one of them, I just cleared out a nasty almost-takeover by binkiland, but thank goodness a scanner on autorun started up even though everything else was down. It gave me an option to go online to register, so I went online and downloaded malwayrebytes, kaspersky scan and one other and half way through the scans it opened up my computer to me again. Had that not been on autorun, i would have been screwed. I am going to back everything up, but as my computer has just come back from repair a month ago I don't have too much...so... I need to Change programs from auto updating as this was why this all happened. So should I delete anything in red on auto runs?





My info:
Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 8.1, 64 bit
Processor: AMD A6-4455M APU with Radeon(tm) HD Graphics, AMD64 Family 21 Model 16 Stepping 1
Processor Count: 2
RAM: 5602 Mb
Graphics Card: AMD Radeon HD 7500G, 512 Mb
Hard Drives: C: Total - 689979 MB, Free - 636982 MB; D: Total - 24184 MB, Free - 2914 MB;
Motherboard: Hewlett-Packard, 193B
Antivirus: Windows Defender, Disabled

Need confirmation for adwcleaner cleaning

$
0
0
Hello,

im on a friends laptop fixing some cpu and memory issues but am not very familiar with HP and Win Vista. So here is a AdwCleaner log and would like to have confirmation for the removal. I wasn't sure about the hpservice thing...

here is the log:

# AdwCleaner v4.110 - Logfile created 12/02/2015 at 09:38:08
# Updated 05/02/2015 by Xplode
# Database : 2015-02-05.2 [Local]
# Operating system : Windows Vista (TM) Business Service Pack 2 (x86)
# Username : vero - PC_VAN_VERO
# Running from : C:\Users\vero.PC_van_vero\Documents\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : hpsrv

***** [ Files / Folders ] *****

File Found : C:\Windows\system32\hpservice.exe
Folder Found : C:\ProgramData\epifpapdjplgoeplljjndobdnmmhlape

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}

***** [ Web browsers ] *****

-\\ Internet Explorer v7.0.6002.18005


-\\ Mozilla Firefox v7.0.1 (nl)


-\\ Google Chrome v39.0.2171.95

*************************

AdwCleaner[R0].txt - [20603 bytes] - [22/08/2014 23:52:49]
AdwCleaner[R1].txt - [20664 bytes] - [22/08/2014 23:55:32]
AdwCleaner[R2].txt - [6105 bytes] - [09/01/2015 21:53:31]
AdwCleaner[R3].txt - [1282 bytes] - [12/02/2015 09:38:08]
AdwCleaner[S0].txt - [21027 bytes] - [22/08/2014 23:58:48]
AdwCleaner[S1].txt - [6071 bytes] - [09/01/2015 22:07:32]

########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [1460 bytes] ##########


thanks for the help,

Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft® Windows Vista™ Business, Service Pack 2, 32 bit
Processor: Intel(R) Core(TM)2 Duo CPU T7300 @ 2.00GHz, x64 Family 6 Model 15 Stepping 10
Processor Count: 2
RAM: 2038 Mb
Graphics Card: Mobile Intel(R) 965 Express Chipset Family, 448 Mb
Hard Drives: C: Total - 144626 MB, Free - 27626 MB; E: Total - 7996 MB, Free - 768 MB;
Motherboard: Hewlett-Packard, 30C0
Antivirus: Norton Internet Security, Updated and Enabled

Problem with my Windows 7

$
0
0
Hello and welcome to TSG,

Use the instructions in the following link to show hidden files:

http://www.bleepingcomputer.com/tuto...es-in-windows/

Next,

Backup the Registry:

Modifying the Registry can create unforeseen problems, so it's always wise to create a backup before doing so.
  • Please download ERUNT from one of the following links: Link1 | Link2 | Link3
  • ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.
  • Double click on erunt-setup.exe to Install ERUNT by following the prompts.
  • NOTE: Do not choose to allow ERUNT to add an Entry to the Startup folder. Click NO.
  • Start ERUNT either by double clicking on the desktop icon or choosing to start the program at the end of the setup process.
  • Choose a location for the backup.
  • Note: the default location is C:\Windows\ERDNT which is acceptable.
  • Make sure that at least the first two check boxes are selected.


  • Click on OK
  • Then click on YES to create the folder.
  • Note: if it is necessary to restore the registry, open the backup folder and start ERDNT.exe

Next,

Run the following scans and post the produced logs:

Step 1

Download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Step 2

Please download RogueKiller and save it to your desktop from the following link: http://www.bleepingcomputer.com/download/roguekiller/
  • Quit all running programs.
  • For Windows XP, double-click to start.
  • For Vista,Windows 7/8, Right-click on the program and select Run as Administrator to start and when prompted allow it to run.
  • Read and accept the EULA (End User Licene Agreement)
  • Click Scan to scan the system.
  • When the scan completes select "Report", log will open. Close the program > Don't Fix anything!
  • Post back the report which should also be located here:

C:\Programdata\RogueKiller\Logs <-------- W7/8
C:\Documents and Settings\All Users\Application Data\RogueKiller\Logs <------XP

Thank you,

Kevin...

Signs of a Nasty Virus?

$
0
0
Hi,
I run AVG (free) and it doesn't show anything.
I run Malware Bytes... cleans up everything. Next day, it finds a virus again.
I run SuperAntispyware... always finds something.. cleans up. Next day, finds something again.
Now my text in emails and on internet is looking "slightly pixilated"...

Can somebody please help?
(Thank you in advance!)

Omega plus and pro pc cleaner

$
0
0
I have had absolutely no more problems. So I'm marking this as solved, and thanks again.

Help removing brower re-direct

$
0
0
Here are the scan results

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-02-2015
Ran by Brian (administrator) on BRIAN-PC on 13-02-2015 11:21:03
Running from C:\Users\Brian\Downloads
Loaded Profiles: Brian (Available profiles: Brian)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Lexar Media, Inc.) C:\Windows\System32\LxrSII1s.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1045800 2008-03-28] (Synaptics, Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [978520 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM\...\Run: [DelaypluginInstall] => [X]
HKU\S-1-5-21-1511418393-2390573130-3487323023-1000\...\Run: [uTorrent] => C:\Users\Brian\AppData\Roaming\uTorrent\uTorrent.exe [1374032 2015-01-21] (BitTorrent Inc.)
HKU\S-1-5-21-1511418393-2390573130-3487323023-1000\...\Run: [SoftonicAssistant] => "C:\Users\Brian\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe"
AppInit_DLLs: c:/progra~2/{2307c~1/191~1.1/tafa.dll => c:/progra~2/{2307c~1/191~1.1/tafa.dll [964608 2015-02-04] ()
BootExecute: autocheck autochk * SBBD.exe /d \Device\HarddiskVolume2\Program Files\Ad-Aware Antivirus\Definitions
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKU\S-1-5-21-1511418393-2390573130-3487323023-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://mytoba.ca/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1511418393-2390573130-3487323023-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = https://www.google.com/search?q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll No File
BHO: Wondershare Video Converter Ultimate 7.1.0 -> {451C804F-C205-4F03-B48E-537EC94937BF} -> C:\PROGRA~2\WONDER~1\VIDEOC~1\WSBROW~1.DLL No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll (Adblock Plus)
Toolbar: HKU\S-1-5-21-1511418393-2390573130-3487323023-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 192.168.100.254
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\mypqylgd.default-1423835577387
FF DefaultSearchEngine: Google
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1511418393-2390573130-3487323023-1000: sony.com/MediaGoDetector -> C:\Program Files\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome:
=======
CHR Profile: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-27]
CHR Extension: (Google Drive) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-27]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-07-01]
CHR Extension: (YouTube) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-27]
CHR Extension: (Google Search) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-27]
CHR Extension: (Google Wallet) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-27]
CHR Extension: (Gmail) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-27]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 LxrSII1s; C:\Windows\system32\LxrSII1s.exe [65536 2009-12-30] (Lexar Media, Inc.) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)
S2 Update EnterDigital; "C:\Program Files\EnterDigital\updateEnterDigital.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-08-30] (GFI Software)
R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [14848 2010-06-19] (Siliten)
R2 LxrSII1d; C:\Windows\System32\Drivers\LxrSII1d.sys [63448 2009-12-30] (Lexar Media, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
R3 RLDesignVirtualAudioCableWdm; C:\Windows\System32\DRIVERS\livecamv.sys [31616 2007-01-15] ()
R3 VC0130Afx; C:\Windows\System32\Drivers\C0130Afx.sys [142656 2007-06-10] (Creative Technology Ltd.)
R3 VC0130Aud; C:\Windows\System32\Drivers\C0130Aud.sys [94976 2007-03-27] (Creative Technology Ltd.)
R3 VC0130Dev; C:\Windows\System32\DRIVERS\C0130Vid.sys [690656 2007-04-17] (Creative Technology Ltd.)
R3 VC0130Vfx; C:\Windows\System32\DRIVERS\C0130VFx.sys [6912 2006-06-19] (EyePower Games Pte. Ltd.)
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
S1 SBRE; \SystemRoot\system32\drivers\SBREDrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-13 11:16 - 2015-02-13 11:16 - 00019179 _____ () C:\Users\Brian\Downloads\Addition.txt
2015-02-13 11:15 - 2015-02-13 11:21 - 00011590 _____ () C:\Users\Brian\Downloads\FRST.txt
2015-02-13 11:14 - 2015-02-13 11:21 - 00000000 ____D () C:\FRST
2015-02-13 11:14 - 2015-02-13 11:14 - 01125376 _____ (Farbar) C:\Users\Brian\Downloads\FRST.exe
2015-02-13 09:18 - 2015-02-13 09:19 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-13 09:18 - 2015-02-13 09:18 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-13 09:18 - 2015-02-13 09:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-13 09:18 - 2015-02-13 09:18 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-02-13 09:18 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-13 09:18 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-13 09:18 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-13 09:17 - 2015-02-13 09:17 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Brian\Downloads\mbam-setup-2.0.4.1028(1).exe
2015-02-13 09:03 - 2015-02-13 09:03 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Brian\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-12 15:32 - 2015-02-12 15:32 - 00000000 ____D () C:\Program Files\ESET
2015-02-12 15:11 - 2015-02-12 15:18 - 00000000 ____D () C:\AdwCleaner
2015-02-12 15:10 - 2015-02-12 15:10 - 02112512 _____ () C:\Users\Brian\Downloads\adwcleaner_4.110.exe
2015-02-12 15:05 - 2015-02-12 15:06 - 38804664 _____ (Microsoft Corporation) C:\Users\Brian\Downloads\Windows-KB890830-V5.21.exe
2015-02-12 13:54 - 2015-02-12 13:54 - 00509440 _____ (Tech Support Guy System) C:\Users\Brian\Downloads\SysInfo.exe
2015-02-12 13:47 - 2015-02-12 13:47 - 00388608 _____ (Trend Micro Inc.) C:\Users\Brian\Downloads\HijackThis.exe
2015-02-12 13:47 - 2015-02-12 13:47 - 00005688 _____ () C:\Users\Brian\Downloads\hijackthis.log
2015-02-11 09:27 - 2015-01-15 01:46 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-11 09:27 - 2015-01-15 01:46 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-11 09:27 - 2015-01-15 01:43 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-11 09:27 - 2015-01-15 01:43 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-11 09:27 - 2015-01-15 01:42 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-11 09:27 - 2015-01-15 01:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-11 09:27 - 2015-01-15 01:42 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-11 09:27 - 2015-01-15 01:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-11 09:27 - 2015-01-15 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-11 09:27 - 2015-01-15 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-11 09:27 - 2015-01-15 01:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-11 09:27 - 2015-01-14 22:21 - 00369968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-11 09:27 - 2015-01-08 20:48 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-02-11 09:27 - 2015-01-08 20:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-02-11 09:27 - 2015-01-08 20:48 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-02-11 09:27 - 2015-01-08 19:45 - 02380288 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-11 09:26 - 2015-02-03 20:54 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 09:26 - 2015-02-03 20:53 - 00767488 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-11 09:26 - 2015-02-03 20:53 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-11 09:26 - 2015-02-03 20:53 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-11 09:26 - 2015-02-03 20:53 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-11 09:26 - 2015-02-03 20:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-02-11 09:26 - 2015-02-03 20:49 - 00886784 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-11 09:26 - 2015-01-27 17:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-02-11 09:26 - 2015-01-13 23:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-02-11 09:26 - 2015-01-13 23:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-11 09:26 - 2014-11-25 21:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-11 09:25 - 2015-01-13 23:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-11 09:25 - 2015-01-11 20:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-11 09:25 - 2015-01-11 20:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-11 09:25 - 2015-01-11 20:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 09:25 - 2015-01-11 20:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-11 09:25 - 2015-01-11 20:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-11 09:25 - 2015-01-11 20:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-11 09:25 - 2015-01-11 20:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-11 09:25 - 2015-01-11 20:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-11 09:25 - 2015-01-11 20:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-11 09:25 - 2015-01-11 19:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-11 09:25 - 2015-01-11 19:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-11 09:25 - 2015-01-11 19:55 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-11 09:25 - 2015-01-11 19:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-11 09:25 - 2015-01-11 19:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-11 09:25 - 2015-01-11 19:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 09:25 - 2015-01-11 19:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-11 09:25 - 2015-01-11 19:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 09:25 - 2015-01-11 19:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-11 09:25 - 2015-01-11 19:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-11 09:25 - 2015-01-11 19:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-11 09:25 - 2015-01-11 19:29 - 04300800 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-11 09:25 - 2015-01-11 19:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-11 09:25 - 2015-01-11 19:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-11 09:25 - 2015-01-11 19:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-11 09:25 - 2015-01-11 19:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-11 09:25 - 2015-01-11 19:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-11 09:25 - 2015-01-11 19:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-11 09:25 - 2015-01-11 18:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-11 09:25 - 2015-01-11 18:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-11 09:25 - 2015-01-10 00:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-11 09:25 - 2015-01-10 00:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-11 09:25 - 2015-01-10 00:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-11 09:25 - 2015-01-10 00:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-11 09:25 - 2015-01-10 00:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-11 09:25 - 2015-01-10 00:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-11 09:25 - 2015-01-10 00:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-11 09:24 - 2015-01-12 20:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-11 09:24 - 2014-12-11 23:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-02-11 09:24 - 2014-12-07 20:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-04 11:59 - 2015-02-13 07:45 - 00000000 ____D () C:\Users\Brian\AppData\Roaming\NCH Software
2015-02-04 11:59 - 2015-02-04 11:59 - 00962608 _____ (NCH Software) C:\Users\Brian\Downloads\wpsetup.exe
2015-02-04 11:59 - 2015-02-04 11:59 - 00000000 ____D () C:\ProgramData\NCH Software
2015-02-04 11:49 - 2015-02-04 11:54 - 00000000 ____D () C:\Users\Brian\AppData\Roaming\Audacity
2015-02-04 11:48 - 2015-02-04 11:48 - 22892794 _____ (Audacity Team ) C:\Users\Brian\Downloads\audacity-win-2.0.6.exe
2015-02-04 11:44 - 2015-02-04 11:44 - 00000000 ____D () C:\ProgramData\85e17b600005157
2015-02-04 11:41 - 2015-02-04 11:41 - 00000000 ____D () C:\Users\Brian\AppData\Local\GGEmpire
2015-02-04 11:40 - 2015-02-04 11:40 - 00000000 ____D () C:\ProgramData\{2307CBC4-7385-1A42-C203-6AC01281B94E}
2015-02-04 09:24 - 2015-02-04 09:24 - 00000000 ____D () C:\Users\Brian\VideoPlayer Picture
2015-02-01 17:33 - 2015-02-01 18:45 - 00000000 ____D () C:\Users\Brian\Desktop\pics
2015-01-26 20:31 - 2015-01-26 20:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-01-14 11:18 - 2015-01-14 11:18 - 00243416 _____ () C:\Users\Brian\Downloads\Firefox Setup Stub 35.0.exe
2015-01-14 07:03 - 2014-12-18 20:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 07:03 - 2014-12-11 11:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 07:03 - 2014-12-05 21:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 07:02 - 2014-12-18 19:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-13 11:18 - 2013-10-12 15:01 - 00000000 ____D () C:\Users\Brian\Documents\New folder
2015-02-13 11:12 - 2014-06-24 07:34 - 00201060 _____ () C:\Windows\setupact.log
2015-02-13 11:12 - 2013-07-15 21:00 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-13 10:20 - 2013-07-14 18:59 - 01228225 _____ () C:\Windows\WindowsUpdate.log
2015-02-13 08:56 - 2009-07-13 22:34 - 00026368 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-13 08:56 - 2009-07-13 22:34 - 00026368 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-13 07:53 - 2014-01-21 08:25 - 00000000 ____D () C:\Users\Brian\Desktop\Old Firefox Data
2015-02-13 07:43 - 2013-07-19 12:50 - 00000000 ____D () C:\Users\Brian\AppData\Roaming\uTorrent
2015-02-13 07:13 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-02-13 06:56 - 2009-07-13 22:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-12 19:10 - 2014-08-19 17:50 - 00000000 ____D () C:\Program Files\Adware-Removal-Tool
2015-02-12 13:47 - 2013-07-14 20:08 - 00000000 ____D () C:\Users\Brian\AppData\Local\VirtualStore
2015-02-12 13:45 - 2009-07-13 20:37 - 00000000 ___RD () C:\Users\Public
2015-02-12 09:33 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\rescache
2015-02-12 08:34 - 2009-07-13 22:33 - 00335440 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-12 08:33 - 2014-11-02 08:53 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-02-12 08:33 - 2010-11-20 15:48 - 00207852 _____ () C:\Windows\PFRO.log
2015-02-12 08:30 - 2014-12-12 06:35 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-12 08:30 - 2014-05-07 07:20 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-12 08:30 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\tracing
2015-02-12 08:11 - 2013-07-15 17:53 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-12 07:41 - 2013-09-01 12:55 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-12 07:22 - 2013-07-15 21:08 - 00001945 _____ () C:\Windows\epplauncher.mif
2015-02-12 07:22 - 2013-07-15 21:07 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-02-12 07:21 - 2013-07-15 21:07 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-02-05 08:30 - 2013-07-15 21:00 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-02-05 08:30 - 2013-07-15 21:00 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-02-05 00:54 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-02-04 11:40 - 2014-11-02 08:53 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-04 11:40 - 2014-02-02 08:17 - 00000000 ____D () C:\Users\Brian\AppData\Local\CrashDumps
2015-02-04 09:24 - 2013-07-14 19:08 - 00000000 ____D () C:\Users\Brian
2015-02-04 09:22 - 2010-11-20 15:01 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-02 05:55 - 2013-07-19 12:56 - 00000000 ____D () C:\Users\Brian\AppData\Roaming\Skype
2015-01-29 17:49 - 2013-07-15 16:51 - 113756392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-19 18:14 - 2013-08-27 09:05 - 00000000 ____D () C:\Users\Brian\Documents\Recipes
2015-01-16 10:30 - 2013-07-15 21:00 - 00000000 ____D () C:\Users\Brian\AppData\Local\Adobe
2015-01-14 11:21 - 2014-11-02 08:53 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk

==================== Files in the root of some directories =======

2014-01-18 19:25 - 2014-01-18 19:25 - 0087608 _____ () C:\Users\Brian\AppData\Roaming\inst.exe
2014-01-18 19:25 - 2014-01-18 19:25 - 0007887 _____ () C:\Users\Brian\AppData\Roaming\pcouffin.cat
2014-01-18 19:25 - 2014-01-18 19:25 - 0001144 _____ () C:\Users\Brian\AppData\Roaming\pcouffin.inf
2014-01-18 19:26 - 2014-01-18 19:26 - 0000034 _____ () C:\Users\Brian\AppData\Roaming\pcouffin.log
2014-01-18 19:25 - 2014-01-18 19:25 - 0047360 _____ (VSO Software) C:\Users\Brian\AppData\Roaming\pcouffin.sys
2014-01-18 19:27 - 2014-08-16 14:28 - 0001041 _____ () C:\Users\Brian\AppData\Roaming\vso_ts_preview.xml
2013-12-27 19:45 - 2014-01-22 04:52 - 0000081 _____ () C:\Users\Brian\AppData\Roaming\WB.CFG
2014-08-28 22:06 - 2014-08-28 22:06 - 0007618 _____ () C:\Users\Brian\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
C:\Users\Brian\AppData\Local\Temp\2A345860-FDE6-BEF1-4732-CE11E23923C4.dll
C:\Users\Brian\AppData\Local\Temp\2A345860-FDE6-BEF1-4732-CE11E23923C4.exe
C:\Users\Brian\AppData\Local\Temp\36446uninstall.exe
C:\Users\Brian\AppData\Local\Temp\CTPBSEQ.EXE
C:\Users\Brian\AppData\Local\Temp\Quarantine.exe
C:\Users\Brian\AppData\Local\Temp\SAS6_Update.exe
C:\Users\Brian\AppData\Local\Temp\SoftonicAssistant_v0-1-6.exe
C:\Users\Brian\AppData\Local\Temp\Sqlite3.dll
C:\Users\Brian\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\Brian\AppData\Local\Temp\System.Data.SQLite51870.dll
C:\Users\Brian\AppData\Local\Temp\System.Data.SQLite94447.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-13 08:36

==================== End Of Log ============================



Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-02-2015
Ran by Brian at 2015-02-13 11:16:01
Running from C:\Users\Brian\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1511418393-2390573130-3487323023-1000\...\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
Adblock Plus for IE (32-bit) (HKLM\...\{DF0E7912-4A45-4B24-B472-E521C4D2C663}) (Version: 99.9 - Eyeo GmbH)
Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.3.153 - Adobe Systems, Inc.)
Advanced Audio FX Engine (HKLM\...\Advanced Audio FX Engine) (Version: - )
Advanced Video FX Engine (HKLM\...\Advanced Video FX Engine) (Version: - )
Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon iP4700 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4700_series) (Version: - )
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.58.1.0 - Conexant)
ConvertXtoDVD 4.0.3.313 (HKLM\...\{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1) (Version: 4.0.3.313 - )
CopyTrans Suite Remove Only (HKU\S-1-5-21-1511418393-2390573130-3487323023-1000\...\CopyTrans Suite) (Version: 2.37 - WindSolutions)
Creative Live! Cam Center (HKLM\...\Creative Live! Cam Center) (Version: - )
Creative Live! Cam Doodling (HKLM\...\Creative Live! Cam Doodling) (Version: - )
Creative Live! Cam FX Creator (HKLM\...\Creative Live! Cam FX Creator) (Version: - )
Creative Live! Cam Manager (HKLM\...\Creative Live! Cam Manager) (Version: - )
Creative Live! Cam Notebook Ultra Driver (1.02.01.00) (HKLM\...\Creative VC0130) (Version: - )
Creative Live! Cam Notebook Ultra User's Guide (English) (HKLM\...\Creative Live! Cam Notebook Ultra User's Guide English) (Version: - )
Creative Photo Calendar (HKLM\...\Creative Photo Calendar) (Version: - )
Creative Photo Manager (HKLM\...\Creative Photo Manager) (Version: - )
Creative System Information (HKLM\...\SysInfo) (Version: - )
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDA_HSF) (Version: 7.80.4.50 - Conexant Systems)
iRip (HKLM\...\{39A3321A-BA57-4983-903C-7A24A4EA94D0}) (Version: 1.0.1.24 - The Little App Factory, LLC.)
iTunes (HKLM\...\{C197BC08-3D82-4651-8886-E68C21578A38}) (Version: 11.1.3.8 - Apple Inc.)
Java 7 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle)
Live! Cam Avatar Creator (HKLM\...\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.5.3104.1 - Creative)
Live! Cam Avatar v1.0 (HKLM\...\{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}) (Version: 1.0 - Creative)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Media Go (HKLM\...\{F66C4A41-C3A8-4523-AB6C-BAA1DB38305C}) (Version: 2.7.357 - Sony)
Media Go Network Downloader (HKLM\...\{5562F05F-908C-4F15-9B3C-98D5FD32DCAB}) (Version: 1.5.19.0 - Sony)
Media Go Video Playback Engine 2.4.104.12040 (HKLM\...\{7C5AEEE1-6D7C-8922-4548-7BF9096077EC}) (Version: 2.4.104.12040 - Sony)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 35.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 35.0 - Mozilla)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NWZ-E380 WALKMAN Guide (HKLM\...\{D98ED583-338D-4425-B2EF-A4C7FB93CE88}) (Version: 2.2.0.05230 - Sony Corporation)
PlayStation(R)Store (HKLM\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.18.0.15698 - Sony Computer Entertainment Inc.)
Revo Uninstaller Pro 3.1.1 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.1 - VS Revo Group, Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 6.21 (HKLM\...\{1845470B-EB14-4ABC-835B-E36C693DC07D}) (Version: 6.21.104 - Skype Technologies S.A.)
StudioTax 2013 (HKLM\...\{A02B37F4-26DA-454A-9997-B006D3587102}) (Version: 9.1.9.2 - BHOK IT Consulting)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 11.0.7.0 - Synaptics)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points =========================

01-02-2015 22:18:44 Windows Update
04-02-2015 09:21:41 Installed Lorex Player 11
04-02-2015 09:28:29 Removed Lorex Player 11
04-02-2015 09:29:52 Installed Lorex Player 11
04-02-2015 09:32:29 Removed Lorex Player 11
05-02-2015 09:39:18 Windows Update
08-02-2015 11:26:33 Windows Update
11-02-2015 16:40:38 Windows Update
12-02-2015 07:15:16 Windows Update
13-02-2015 06:51:27 Windows Update

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1A0CE612-64A9-4F93-A6FE-DC22D216F7AF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {250C00C7-A064-41BF-898B-E3EF02991B6A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
Task: {72D0DCA0-5F6D-4318-93E3-B4C6054287B4} - System32\Tasks\{632865A6-7C91-4E86-B845-2C31D0802344} => Firefox.exe http://ui.skype.com/ui/0/6.6.0.106/e...LastError=1603
Task: {7E6F23FB-8459-47F6-9959-78AEC59B5EC2} - System32\Tasks\Binkiland tafa => C:\ProgramData\{2307CBC4-7385-1A42-C203-6AC01281B94E}\1.9.1.1\f
Task: {8BB8AA7A-5F79-48B0-8F47-73DFB3F0BCF3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A83BDD52-CEA1-4C13-A373-9C2A9E7FC7DB} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) ==============

2013-07-15 17:03 - 2014-07-02 13:42 - 00107992 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 14:45 - 2010-10-20 14:45 - 08801120 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-09-13 19:51 - 2013-09-13 19:51 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-09-13 19:51 - 2013-09-13 19:51 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-26 20:31 - 2015-01-26 20:31 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1511418393-2390573130-3487323023-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Brian\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper .jpg
DNS Servers: 192.168.100.254 - 192.168.0.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Ad-Aware Antivirus => "C:\Program Files\Ad-Aware Antivirus\AdAwareLauncher" --windows-run
MSCONFIG\startupreg: Ad-Aware Browsing Protection => "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
MSCONFIG\startupreg: Creative Live! Cam Manager => "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSCONFIG\startupreg: uTorrent => "C:\Users\Brian\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED

==================== Accounts: =============================

Administrator (S-1-5-21-1511418393-2390573130-3487323023-500 - Administrator - Disabled)
Brian (S-1-5-21-1511418393-2390573130-3487323023-1000 - Administrator - Enabled) => C:\Users\Brian
Guest (S-1-5-21-1511418393-2390573130-3487323023-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1511418393-2390573130-3487323023-1003 - Limited - Enabled)

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/13/2015 11:12:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3104077

Error: (02/13/2015 11:12:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3104077

Error: (02/13/2015 11:12:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/13/2015 11:12:42 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3103063

Error: (02/13/2015 11:12:42 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3103063

Error: (02/13/2015 11:12:42 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/13/2015 11:12:41 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3102033

Error: (02/13/2015 11:12:41 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3102033

Error: (02/13/2015 11:12:41 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/13/2015 11:12:39 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3100598


System errors:
=============
Error: (02/13/2015 11:12:46 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (02/13/2015 09:01:03 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (02/13/2015 06:56:54 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SBRE

Error: (02/13/2015 06:56:54 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (02/13/2015 06:56:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Update EnterDigital service failed to start due to the following error:
%%2

Error: (02/13/2015 06:56:53 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (02/13/2015 06:56:53 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (02/13/2015 06:56:53 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (02/13/2015 06:51:18 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (02/13/2015 06:51:16 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.


Microsoft Office Sessions:
=========================
Error: (02/13/2015 11:12:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3104077

Error: (02/13/2015 11:12:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3104077

Error: (02/13/2015 11:12:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/13/2015 11:12:42 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3103063

Error: (02/13/2015 11:12:42 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3103063

Error: (02/13/2015 11:12:42 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/13/2015 11:12:41 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3102033

Error: (02/13/2015 11:12:41 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3102033

Error: (02/13/2015 11:12:41 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/13/2015 11:12:39 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3100598


==================== Memory info ===========================

Processor: AMD Athlon Dual-Core QL-62
Percentage of memory in use: 58%
Total physical RAM: 1790.43 MB
Available physical RAM: 736.64 MB
Total Pagefile: 3580.85 MB
Available Pagefile: 2180.92 MB
Total Virtual: 2047.88 MB
Available Virtual: 1895.65 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:138.61 GB) (Free:70.88 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:10.33 GB) (Free:1.77 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 8FB11AD3)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=138.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=10.3 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Go Daddy cert not valid.

$
0
0
Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM) i7 CPU Q 740 @ 1.73GHz, Intel64 Family 6 Model 30 Stepping 5
Processor Count: 8
RAM: 4084 Mb
Graphics Card: NVIDIA GeForce GTX 460M, 1536 Mb
Hard Drives: C: Total - 463819 MB, Free - 373230 MB;
Motherboard: TOSHIBA, Qosmio X505-Q894
Antivirus: avast! Antivirus, Updated and Enabled

I keep getting a popup message about redirecting to a website that does not have a valid certificate, do i still want to proceed. This happens even when there is nothing else open on my computer. My computer had blue screened twice, done a check disk for errors spontaneously and can't successfully restore a previous windows restore point... although i think the windows restore issue is not related. I've had that issue since I bought the computer and even when it was put in for warranty for the issue it still couldn't update windows when they gave it back to me >.< I've backed up all my data. Thanks in advance for the assistance!

mrtstub file on external hard drive

$
0
0
I found a folder with a randomly generated name (35ad7f9d92...) on my portable hard drive and it asked me for permission to view, which I allowed so I could see what files were in it. In it were $shtdwn$.req, an mrt exe file, and mrtstub. I immediately googled what they could be in case they were malware and most google results said that they were most likely just microsoft malware removal files. I recently took my laptop to the geek squad to get cleaned up, which is possibly where the file coud have come from, but I very rarely plug my external hard drive into the computer. Yesterday was maybe the second time since I took my laptop to the geek squad. The file didn't show up until today.

The reason I'm posting rather than just deleting the files, like other posts suggested, is because when I reopened the hard drive's file so i could delete the files, a new randomly named folder (4a1a9f3...) that wasn't there before was right above the first, also asking me for permission. Also the original folder no longer contains the mrt files, it only contains the $shtdwn$.req file now. I'm scared to give the new folder permission in case it is an actual virus.

Windows 8 error on sign in.

$
0
0
I have a windows 8 computer, hp, its not even a week old and it has this message in it. I actually saved this image from a thread that was posted here before. In that thread you helped the person fix this. My problem is that it boots up, you get the screen where you put in your password and after you click enter the error message appears.

If I can NOT get to any screen in windows how can I fix this.

Does windows 8.1 have a key you can click on startup to just refresh the computer to day one?

Any help would be appreciated.

Attached Images
File Type: jpg Error message.JPG (48.4 KB)

IBM Thinkpad (older laptop) clean up help requested

$
0
0
I have experienced some issues such as loss of sensitive documents attached to emails, slow functioning of the PC. I would like to remove a movie download that may have a Trojan. I am interested in cleaning up this PC extensively so as to regain confidence that it is not infected. I recently changed passwords on a safe PC as instructed; I would like to start a VPN service and a Suite for email, document, and file protection and security. Before continuing to utilize this pc, I would like to make sure it is cleansed of any virus or malware/spyware, etc., and that it is all up-to-date. Thank You in advance!


Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows XP Professional, Service Pack 3, 32 bit
Processor: Intel(R) Pentium(R) M processor 1.70GHz, x86 Family 6 Model 13 Stepping 6
Processor Count: 1
RAM: 1014 Mb
Graphics Card:
Hard Drives: C: Total - 76316 MB, Free - 45161 MB;
Motherboard: IBM, 2888GSU
Antivirus: Kaspersky Internet Security, Updated: Yes, On-Demand Scanner: Enabled

virus kicking my butt

$
0
0
Hello, annieskid25. My nickname is Nevan and I will be helping you getting your system back on its electronic feet.

Before we get started, please keep these things in mind:
  • Always read every part of my post carefully. If you don't, you may do something wrong and there could be more problems to solve.
  • If your security programs give you any warnings when using tools I asked you to, don't be afraid. Every tool I provide to you is 100% safe.
  • Only run tools that I ask you to. Some of them can be dangerous to your system as they have much power.
  • You should save or print my instructions. It is possible that we will be using Safe mode, which will cut you off from your internet connection and without access to them, you might be stuck.
  • Malware removal is a complicated process that takes multiple steps to be completed. Don't give up, be patient.
  • The tools we are going to use and your software may cause unwanted interactions. Because of that, I recommend you to make backups of any important files from your machine before proceeding as they might be lost.
  • I recommend you to stay with me until I tell you that we are done. It is important because when your system does not show any bad symptoms anymore it does not mean that it is 100% clean.
  • Every program I ask you to download should be saved to and run from desktop. If you don't know how to choose the direction of where a download is saved, check this site. You can also just copy these programs to your desktop manually and then run them from there.
  • Remember that the fixes I give you are only for your machine. Using it on other systems may (and probably will) cause problems.
  • Finally, if you have any questions or are unsure about something, just ask. I will not blame you for it. It is better to ask rather than regret it later.

Also, please note that I'm currently in training, so my answers to you will have to be checked first by an experienced helper before I can post them. This can lengthen the time between my answers to you, but in return you will have an extra person reviewing your log.

Let's get started :)



First, I'd like to have a look at your system. Please, do the following:

FRST Scan

Download Farbar Recovery Scan Tool and save it to your Desktop. There are two different versions:
  • Click here to download the 32-bit version.
  • Click here to download the 64-bit version.

If you don't know which version you should use, download one of them and check if it's working or not. If it doesn't, download the second one. Once you have the right one, perform the instructions below.
  1. Right click FRST.exe (or FRST64.exe) and click Run as administrator. When the tool opens click Yes to disclaimer.
  2. Make sure that Addition.txt is checked and press the Scan button.
  3. It will produce two logs - one called FRST.txt and another one called Addition.txt in the same directory the tool is run from.
  4. Select all (CTRL+A) the content of the logs, copy them (CTRL+C) and paste (CTRL+V) them into your next reply.



Things that should appear in your next post:
  • FRST.txt log content
  • Addition.txt log content

Hidden Rootkit/Malware crippling computer / Freezing click/mouse points on programs

$
0
0
If you're unable to run or complete the scan as shown below please see the following:

MBAM Clean Removal Process 2x

Follow the relevant steps and ensure to run mbam-clean tool after UNinstalling Malwarebytes.

When reinstalling the program please try the latest version from here:

http://www.malwarebytes.org/mwb-download/

Right click and choose "Run as administrator" to open Malwarebytes Anti-Malware and from the Dashboard please Check for Updates by clicking the Update Now... link
Open up Malwarebytes > Settings > Detection and Protection > Enable Scan for rootkit and Under Non Malware Protection set both PUP and PUM to Treat detections as malware.
Click on the SCAN button and run a Threat Scan with Malwarebytes Anti-Malware by clicking the Scan Now>> button.
Once completed please click on the History > Application Logs and find your scan log and open it and then click on the "copy to clipboard" button and post back the results on your next reply.

Thanks,

Kevin
Viewing all 4746 articles
Browse latest View live




Latest Images