Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-02-2015 Ran by sheryl29 (administrator) on SHERYL29-NERD on 22-02-2015 18:21:38 Running from C:\Users\sheryl29\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z8G9N5KN Loaded Profiles: sheryl29 (Available profiles: sheryl29 & Administrator & Guest) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 11 (Default browser: Opera) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Apache Software Foundation) C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Apache Software Foundation) C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe (LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro PDF\Reader\1.0\NitroPDFReaderDriverServicex64.exe (Sony Corporation) C:\Program Files (x86)\SONY\PMB\PMBDeviceInfoProvider.exe (TMRG, Inc.) C:\Program Files (x86)\RelevantKnowledge\rlservice.exe () C:\Users\sheryl29\AppData\Roaming\VOPackage\VOsrv.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe () C:\Program Files (x86)\grassmow\updategrassmow.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe (Sony Corporation) C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) C:\Program Files\SONY\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) C:\Program Files\SONY\VAIO Smart Network\VSNService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe (AMD) C:\Windows\System32\atieclxx.exe (Sony Corporation) C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (SlimWare Utilities, Inc.) C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe (Sony Corporation) C:\Program Files\SONY\VAIO Smart Network\VSNClient.exe (Sony Corporation) C:\Program Files\SONY\VAIO Gate\VAIO Gate.exe (Sony Corporation) C:\Program Files\SONY\VAIO Power Management\SPMgr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Sony Corporation) C:\Program Files\SONY\VAIO Power Management\SPMService.exe (Intel Corporation) C:\Program Files\SONY\VAIO Care\ESRV\esrv_svc.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe (LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe (Sony Corporation) C:\Program Files\SONY\VAIO Care\VCAdmin.exe (Sony Corporation) C:\Program Files\SONY\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\SONY\VAIO Update\VUAgent.exe (Sony Corporation) C:\Program Files\SONY\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\SONY\VAIO Care\VCAgent.exe (BitTorrent, Inc.) C:\Users\sheryl29\Desktop\utorrent.exe (Sony Corporation) C:\Program Files\SONY\VAIO Care\VCSystemTray.exe (Sony Corporation) C:\Program Files\SONY\VCM Manager Settings\VcmMgrNotification64.exe () C:\Program Files (x86)\SweepTools PC Cleaner\PC Cleaner.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe (Avanquest Software) C:\Program Files (x86)\SONY\Sony PC Companion\PCCService.exe (Sony) C:\Program Files (x86)\SONY\Sony PC Companion\PCCompanion.exe () C:\Program Files (x86)\SONY\Sony PC Companion\PCCompanionInfo.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Eyeo GmbH) C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_14_0_0_145_ActiveX.exe (TMRG, Inc.) C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation) HKLM-x32\...\Run: [fst_au_214] => [X] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [118272 2014-07-11] (LeapFrog Enterprises, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X] HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\Run: [uTorrent] => C:\Users\sheryl29\Desktop\utorrent.exe [399736 2011-05-02] (BitTorrent, Inc.) HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\Run: [Driver Support] => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe /applicationMode:systemTray /showWelcome:false HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\Run: [SpeedItupFree] => "C:\Program Files (x86)\SpeedItup Free\speeditupfree.exe" HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\Run: [AVG-Secure-Search-Update_1214avt] => C:\Users\sheryl29\AppData\Roaming\Avg_Update_1214avt\AVG-Secure-Search-Update_1214avt.exe /PROMPT /mid=2ddac6bead6347cdb3b021328d0cb64c-eda72383ce33b8c02cbe9c1b1aef95043567e879 /CMPID=1214avt HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\Policies\system: [NoDispCPL] 0 HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\Policies\Explorer: [NoInstrumentation] 1 HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\MountPoints2: {115774c3-b48e-11df-bd54-f07bcbe85fbf} - G:\AutoRun.exe HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\MountPoints2: {115774cf-b48e-11df-bd54-f07bcbe85fbf} - H:\AutoRun.exe HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\MountPoints2: {12e2f86d-52a0-11e3-96da-544249609db6} - H:\Startme.exe HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\MountPoints2: {73c9a46c-a203-11e2-9224-f07bcbe85fbf} - H:\Startme.exe HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\MountPoints2: {a9e79584-c221-11df-813d-f07bcbe85fbf} - G:\AutoRun.exe HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\MountPoints2: {a9e79588-c221-11df-813d-f07bcbe85fbf} - G:\AutoRun.exe HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\MountPoints2: {e5df9549-b8ab-11e0-9b40-f07bcbe85fbf} - G:\LaunchU3.exe -a HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\...\MountPoints2: {efcb0e1a-bf5e-11e2-ae9f-f07bcbe85fbf} - G:\Startme.exe HKU\S-1-5-18\...\Run: [RegistryBooster] => "C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe" delay 20000 AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll File Not Found AppInit_DLLs: C:\Users\sheryl29\AppData\Local\Smartbar\Application\Resources\crdlil64.dll => C:\Users\sheryl29\AppData\Local\Smartbar\Application\Resources\crdlil64.dll File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => "C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" File Not Found Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk ShortcutTarget: LimeWire On Startup.lnk -> C:\Program Files (x86)\LimeWire\LimeWire.exe (No File) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:54653;https=127.0.0.1:54653 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.SearchAssist.net/?p=h&m=639&c=d&s=sp HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.SearchAssist.net/?p=h&m=639&c=d&s=sp HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1409721153&from=tugs&uid=TOSHIBAXMK5065GSX_50S5S6EQSXX50S5S6EQS&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1409721153&from=tugs&uid=TOSHIBAXMK5065GSX_50S5S6EQSXX50S5S6EQS&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.SearchAssist.net/?p=h&m=639&c=d&s=sp HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1409721153&from=tugs&uid=TOSHIBAXMK5065GSX_50S5S6EQSXX50S5S6EQS HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1409721153&from=tugs&uid=TOSHIBAXMK5065GSX_50S5S6EQSXX50S5S6EQS&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1409721153&from=tugs&uid=TOSHIBAXMK5065GSX_50S5S6EQSXX50S5S6EQS&q={searchTerms} HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1409721153&from=tugs&uid=TOSHIBAXMK5065GSX_50S5S6EQSXX50S5S6EQS&q={searchTerms} HKU\S-1-5-21-1155007634-2346187462-1659951187-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.SearchAssist.net/?p=h&m=639&c=d&s=sp SearchScopes: HKLM -> DefaultScope {BA1BE292-1D15-488B-934D-008742212380} URL = http://www.SearchAssist.net/search?q={searchTerms}&p=s&m=639&c=d&s=sp SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.searchassist.net/search?q={searchTerms}&p=sm=639&c=d&s=sp SearchScopes: HKLM -> {BA1BE292-1D15-488B-934D-008742212380} URL = http://www.SearchAssist.net/search?q={searchTerms}&p=s&m=639&c=d&s=sp SearchScopes: HKU\S-1-5-21-1155007634-2346187462-1659951187-1001 -> DefaultScope {BA1BE292-1D15-488B-934D-008742212380} URL = http://www.SearchAssist.net/search?q={searchTerms}&p=s&m=639&c=d&s=sp SearchScopes: HKU\S-1-5-21-1155007634-2346187462-1659951187-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=M83F71A24-DEC6-42B2-9C4A-51E7C710E0C6&SearchSource=58&CUI=&UM=6&UP=SP4C5486DF-0792-4800-9BF9-654724F45CD4&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-1155007634-2346187462-1659951187-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.searchassist.net/search?q={searchTerms}&p=sm=639&c=d&s=sp SearchScopes: HKU\S-1-5-21-1155007634-2346187462-1659951187-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1409721153&from=tugs&uid=TOSHIBAXMK5065GSX_50S5S6EQSXX50S5S6EQS&q={searchTerms} SearchScopes: HKU\S-1-5-21-1155007634-2346187462-1659951187-1001 -> {7E4BF3FD-0038-469C-94A7-EDF285CE18C1} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-1155007634-2346187462-1659951187-1001 -> {BA1BE292-1D15-488B-934D-008742212380} URL = http://www.SearchAssist.net/search?q={searchTerms}&p=s&m=639&c=d&s=sp BHO: No Name -> {11111111-1111-1111-1111-110611171187} -> No File BHO: No Name -> {283E6CFC-946C-A505-85D0-F04CADB49E66} -> No File BHO: SearchAssist -> {8DDAC7C3-2592-4D84-A7A7-AA7865E53875} -> C:\Program Files\SearchAssist\ie\adxloader64.dll () BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO: BlockAndSurf -> {F9785F77-9BA1-A18F-2700-08002077A974} -> C:\Program Files (x86)\ver8BlockAndSurf\183_x64.dll () BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll (Adblock Plus) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: grassmow -> {12ef4f7f-6c80-4ac9-976b-a4ee342815c5} -> C:\Program Files (x86)\grassmow\grassmowbho.dll No File BHO-x32: DivX Plus Web Player HTML5