CreateRestorePoint: HKLM\...\Run: [] => [X] GroupPolicyScripts: Group Policy detected <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:47574 HKU\S-1-5-21-2961099189-892354221-2781886693-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.mywebsearch.com/index.jhtml?n=77de8857&p2=^hj^xdm017^yy^us&ptb=753b0ac6-c38b-4456-a92b-999ac41eeb9f&si=pconverter HKU\S-1-5-21-2961099189-892354221-2781886693-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60180 SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKU\S-1-5-21-2961099189-892354221-2781886693-1003 -> {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = hxxp://www.crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=60180 SearchScopes: HKU\S-1-5-21-2961099189-892354221-2781886693-1003 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=360&chn=S1122&geo=US&ver=21&locale=en_US&gct=kwd&qsrc=2869 SearchScopes: HKU\S-1-5-21-2961099189-892354221-2781886693-1003 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80116&lng=en BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security Suite\Engine\21.7.0.11\coIEPlg.dll [2015-06-26] (Symantec Corporation) BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton Security Suite\Engine\21.7.0.11\IPS\IPSBHO.DLL [2015-03-04] (Symantec Corporation) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\21.7.0.11\coIEPlg.dll [2015-06-26] (Symantec Corporation) Toolbar: HKU\S-1-5-21-2961099189-892354221-2781886693-1003 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-2961099189-892354221-2781886693-1003 -> No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File Toolbar: HKU\S-1-5-21-2961099189-892354221-2781886693-1003 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\21.7.0.11\coIEPlg.dll [2015-06-26] (Symantec Corporation) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.) FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn FF Extension: No Name - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-08-07] FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found] CHR Extension: (SwagButton) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\gngocbkfmikdgphklgmmehbjjlfgdemm [2015-06-21] CHR Extension: (Pin It Button) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-06-21] CHR Extension: (Norton Identity Safe) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-06-21] CHR Extension: (No Name) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2015-06-21] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.goo...ice/update2/crx CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files\Norton Security Suite\Engine\21.7.0.11\Exts\Chrome.crx S2 CouponPrinterService; C:\Program Files\Coupons\CouponPrinterService.exe [1051632 2015-05-18] (Coupons.com Inc.) S2 N360; C:\Program Files\Norton Security Suite\Engine\21.7.0.11\N360.exe [265000 2015-03-26] (Symantec Corporation) S1 BHDrvx86; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\BASHDefs\20150728.001_2f0\BHDrvx86.sys [1181936 2015-07-28] (Symantec Corporation) S1 ccSet_N360; C:\Windows\system32\drivers\N360\1507000.00B\ccSetx86.sys [127064 2013-09-25] (Symantec Corporation) S1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [389456 2015-08-06] (Symantec Corporation) S1 IDSVix86; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\IPSDefs\20150807.001\IDSvix86.sys [523512 2015-08-06] (Symantec Corporation) S3 NAVENG; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20150807.017\NAVENG.SYS [104440 2015-08-06] (Symantec Corporation) S3 NAVEX15; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20150807.017\NAVEX15.SYS [1645432 2015-08-06] (Symantec Corporation) S1 SRTSP; C:\Windows\System32\Drivers\N360\1507000.00B\SRTSP.SYS [664792 2014-08-25] (Symantec Corporation) S1 SRTSPX; C:\Windows\system32\drivers\N360\1507000.00B\SRTSPX.SYS [32984 2014-08-25] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360\1507000.00B\SYMDS.SYS [367704 2013-09-09] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360\1507000.00B\SYMEFA.SYS [936152 2014-08-25] (Symantec Corporation) S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2015-06-21] (Symantec Corporation) S1 SymIRON; C:\Windows\system32\drivers\N360\1507000.00B\Ironx86.SYS [209624 2014-08-06] (Symantec Corporation) S1 SYMTDIv; C:\Windows\System32\Drivers\N360\1507000.00B\SYMTDIV.SYS [384728 2014-08-25] (Symantec Corporation) 2015-08-08 14:58 - 2015-08-08 14:58 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite(33) 2015-07-05 12:42 - 2015-07-05 12:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons 2015-07-05 12:42 - 2015-07-05 12:42 - 00000000 ____D C:\Program Files\Coupons 2015-07-01 19:26 - 2015-07-01 19:26 - 00000000 ____D C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB 2015-06-21 13:57 - 2015-08-09 18:14 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared 2015-06-21 13:57 - 2015-06-21 13:57 - 00142936 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT.SYS 2015-06-21 13:57 - 2015-06-21 13:57 - 00008194 _____ C:\Windows\system32\Drivers\SYMEVENT.CAT 2015-06-21 13:56 - 2015-06-22 14:48 - 00002182 _____ C:\Users\Public\Desktop\Norton Security Suite.lnk 2015-06-21 13:56 - 2015-06-21 13:56 - 00000000 ____D C:\Users\Joanna\Documents\Bluetooth Exchange Folder 2015-06-21 13:54 - 2015-08-09 18:14 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite 2015-06-21 13:54 - 2015-08-09 18:14 - 00000000 ____D C:\Windows\system32\Drivers\N360 2015-06-21 13:54 - 2015-08-09 18:14 - 00000000 ____D C:\Program Files\Norton Security Suite 2015-06-21 13:54 - 2015-08-09 17:01 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite(91) 2015-06-21 13:54 - 2015-08-09 04:57 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite(90) 2015-06-21 13:54 - 2015-08-09 04:46 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite(88) 2015-06-21 13:54 - 2015-08-09 03:05 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite(83) 2015-06-21 13:54 - 2015-08-08 21:47 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite(87) 2015-06-21 13:54 - 2015-08-08 21:21 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite(74) 2015-06-21 13:19 - 2015-06-21 13:19 - 00000000 ____D C:\Users\Joanna\Documents\Symantec 2015-06-21 12:57 - 2015-08-08 15:02 - 00000000 ____D C:\ProgramData\Norton 2015-06-21 12:57 - 2015-08-08 13:46 - 00000000 ____D C:\Users\Public\Downloads\Norton 2015-06-21 12:57 - 2015-06-21 14:20 - 00000000 ____D C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton CustomCLSID: HKU\S-1-5-21-2961099189-892354221-2781886693-1003_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2961099189-892354221-2781886693-1003_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2961099189-892354221-2781886693-1003_Classes\CLSID\{BB6410D8-F879-4184-9C5C-6A02D16AE0B3}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2961099189-892354221-2781886693-1003_Classes\CLSID\{CA1073A2-5F3F-4445-8E5E-7109BDCEDDBE}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2961099189-892354221-2781886693-1003_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-2961099189-892354221-2781886693-1003_Classes\CLSID\{D5A55D2D-C59D-42C3-A5BF-4C08EEE74339}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File Task: {0C4DA452-BFDF-4227-AC06-E967B2A455D9} - System32\Tasks\Norton Security Suite\Norton Error Processor => C:\Program Files\Norton Security Suite\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {3998DDB7-7828-47EB-A269-73FF886302B1} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Security Suite\Engine\21.7.0.11\WSCStub.exe [2015-03-07] (Symantec Corporation) Task: {FBDD453B-B8C4-4DC2-A1CD-9540AE9B884F} - System32\Tasks\Norton Security Suite\Norton Error Analyzer => C:\Program Files\Norton Security Suite\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation) AlternateDataStreams: C:\ProgramData\TEMP:4B1BA31B CMD: bitsadmin /reset /allusers CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state off RemoveProxy: Hosts: EmptyTemp: