Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Script errors, invalid destination errors, adobe flash crashing even w


  • This topic is locked This topic is locked

#31
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts
Sorry, let's try with this set of instructions.
RogueKiller.png Scan with RogueKiller
 
Please download RogueKiller and save the file to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.
 
  • Right-click on RogueKiller.png icon and select RunAsAdmin.jpg Run as Administrator  (if asked) to start the tool.
  • Wait patiently until the pre-scan will be done. It shouldn't take more than 2-3 minutes.
  • Accept the Terms of use.
  • When the Scan button becomes available, please click it. RogueKiller will start a full scan.
  • Let this process run uninterrupted!.
  • When finished, a Report button will become available. Click it. You will be presented with a logfile.
Please include the content of this logfile in your next reply.

 


  • 0

Advertisements


#32
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

Okay, I went back and clicked report on the Roguekiller and got a log.  Is this what you need?

 

RogueKiller V10.0.9.0 [Dec  8 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.co...es/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Sheyenne Alvarez [Administrator]
Mode : Scan -- Date : 12/08/2014  07:26:44

¤¤¤ Processes : 1 ¤¤¤
[Suspicious.Path] AmazonCloudDriveW.exe -- C:\Users\Sheyenne Alvarez\AppData\Local\Apps\2.0\C52Q8JWR.CDD\6A344DJW.HND\amaz..tion_f2fa081ea2183235_0002.0004_9f25fd1982bf3008\LocalServiceJre\bin\AmazonCloudDriveW.exe[7] -> Killed [TermProc]

¤¤¤ Registry : 12 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\Sheyenne Alvarez\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart  -> Found
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\Sheyenne Alvarez\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main | Start Page : www.google.com  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main | Start Page : www.google.com  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1003\Software\Microsoft\Internet Explorer\Main | Start Page : -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1003\Software\Microsoft\Internet Explorer\Main | Start Page : -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1004\Software\Microsoft\Internet Explorer\Main | Start Page : -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1004\Software\Microsoft\Internet Explorer\Main | Start Page : -> Found
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main | Search Page :   -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main | Search Page :   -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found

¤¤¤ Tasks : 1 ¤¤¤
[Suspicious.Path] \\Registration -- "C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe" (Registration ShowMessageTask2D) -> Found

¤¤¤ Files : 1 ¤¤¤
[Suspicious.Path][File] Z Cinema.lnk -- C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Z Cinema.lnk [LNK@] C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Installer\{6E166235-49F3-4DFA-A102-1E86675ABD11}\StartupShortcut_6E16623549F34DFAA1021E86675ABD11.exe /Minimize -> Found

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST310005 28AS SATA Disk Device +++++
--- User ---
[MBR] cfdccb54c74193842f7dcdbdc907be05
[BSP] 98a99a3f4bd0f7d48015f2b91db27b45 : Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 940541 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1926434816 | Size: 13226 MB
User = LL1 ... OK
User != LL2 ... KO!
--- LL2 ---
[MBR] 477387d3b2f87f015bd2876fe0794de4
[BSP] 5ddc4d0c0a4b6109ca3f425c8581df28 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 264071168 | Size: 300 MB

+++++ PhysicalDrive1: SAMSUNG HD502HI USB Device +++++
--- User ---
[MBR] 061b9ca934e76359f0feca71eec209c3
[BSP] 338062d4c3007acf9b84affdbb95387d : Unknown MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 63 | Size: 476937 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive2: Generic- SD/MMC USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive3: Generic- Compact Flash USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive4: Generic- SM/xD-Picture USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive5: Generic- MS/MS-Pro USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive6: Generic USB Mass Storage USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )
 


  • 0

#33
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

RogueKiller.png Fix with RogueKiller
 
Please re-run RogueKiller.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.
 
  • Right-click on RogueKiller.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the pre-scan will be done. It shouldn't take more than 2-3 minutes.
  • Accept the Terms of use.
  • When the Scan button becomes available, please click it. RogueKiller will start a full scan.
  • Upon completion, the Delete button will become available. Click it.
  • Removal process may take some time. Also your machine may be restarted during this procedure. It's normal.
  • Let this process run uninterrupted!.
  • When finished, a Report button will become available. Click it. You will be presented with a logfile.
Please include the content of this logfile in your next reply.

 


  • 0

#34
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

RogueKiller V10.0.9.0 [Dec  8 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.co...es/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Sheyenne Alvarez [Administrator]
Mode : Delete -- Date : 12/08/2014  13:33:14

¤¤¤ Processes : 1 ¤¤¤
[Suspicious.Path] AmazonCloudDriveW.exe -- C:\Users\Sheyenne Alvarez\AppData\Local\Apps\2.0\C52Q8JWR.CDD\6A344DJW.HND\amaz..tion_f2fa081ea2183235_0002.0004_9f25fd1982bf3008\LocalServiceJre\bin\AmazonCloudDriveW.exe[7] -> Killed [TermThr]

¤¤¤ Registry : 12 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\Sheyenne Alvarez\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart [x][x] -> Deleted
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\Sheyenne Alvarez\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart  -> ERROR [2]
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main | Start Page : www.google.com  -> Not selected
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main | Start Page : www.google.com  -> Not selected
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1003\Software\Microsoft\Internet Explorer\Main | Start Page : -> Not selected
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1003\Software\Microsoft\Internet Explorer\Main | Start Page : -> Not selected
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1004\Software\Microsoft\Internet Explorer\Main | Start Page : -> Not selected
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1004\Software\Microsoft\Internet Explorer\Main | Start Page : -> Not selected
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main | Search Page :   -> Not selected
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main | Search Page :   -> Not selected
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Not selected
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Not selected

¤¤¤ Tasks : 1 ¤¤¤
[Suspicious.Path] \\Registration -- "C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe" (Registration ShowMessageTask2D) -> Deleted

¤¤¤ Files : 1 ¤¤¤
[Suspicious.Path][File] Z Cinema.lnk -- C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Z Cinema.lnk [LNK@] C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Installer\{6E166235-49F3-4DFA-A102-1E86675ABD11}\StartupShortcut_6E16623549F34DFAA1021E86675ABD11.exe /Minimize -> Deleted

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST310005 28AS SATA Disk Device +++++
--- User ---
[MBR] cfdccb54c74193842f7dcdbdc907be05
[BSP] 98a99a3f4bd0f7d48015f2b91db27b45 : Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 940541 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1926434816 | Size: 13226 MB
User = LL1 ... OK
User != LL2 ... KO!
--- LL2 ---
[MBR] 477387d3b2f87f015bd2876fe0794de4
[BSP] 5ddc4d0c0a4b6109ca3f425c8581df28 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 264071168 | Size: 300 MB

+++++ PhysicalDrive1: SAMSUNG HD502HI USB Device +++++
--- User ---
[MBR] 061b9ca934e76359f0feca71eec209c3
[BSP] 338062d4c3007acf9b84affdbb95387d : Unknown MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 63 | Size: 476937 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive2: Generic- SD/MMC USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive3: Generic- Compact Flash USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive4: Generic- SM/xD-Picture USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive5: Generic- MS/MS-Pro USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive6: Generic USB Mass Storage USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )


============================================
RKreport_SCN_12082014_072644.log - RKreport_SCN_12082014_133224.log


  • 0

#35
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

I'm still getting invalid destination popups and some script errors. I'm also getting a java updater popup that comes up all the time.

Have these issues been eliminated yet?

 

Also, please run FRST as you did previously and post the resulting log. :)


  • 0

#36
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

There were about 7 or 8 invalid destination popups that I had to click on when I woke up this morning.  The script errors I think are still happening.  I know they happened yesterday, but I'm not sure now if it was before or after the last scan you had me run.  I've been studying for finals and wasn't on the internet a ton yesterday.  Same with the java updater.  I will play around and watch for it.

 

Here is the log:

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-12-2014
Ran by Sheyenne Alvarez (administrator) on SHEYENNEALVAREZ on 09-12-2014 07:05:52
Running from C:\Users\Sheyenne Alvarez\Desktop
Loaded Profiles: Sheyenne Alvarez & Gabriella & Dario Jr & Roman (Available profiles: Sheyenne Alvarez & Gabriella & Dario Jr & Roman)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Nero AG) C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe
(Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint\LBTWiz.exe
() C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
() C:\Program Files (x86)\Dell\ErrorApp\dkab1err.exe
(Motorola Mobility Inc.) C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoCast.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe
() C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
() C:\Users\Sheyenne Alvarez\AppData\Local\Amazon Music\Amazon Music Helper.exe
(GoPro) C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(NTI Corporation) C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZtray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
(Dropbox, Inc.) C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Logitech©) C:\Program Files\Logitech\Z Cinema\Z Cinema.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.)
HKLM\...\Run: [Bluetooth Connection Assistant] => LBTWIZ.EXE -silent
HKLM\...\Run: [DKADGmon] => C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe [951656 2012-11-07] ()
HKLM\...\Run: [IntelliPoint] => C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BackupNowEZtray] => C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZtray.exe [581624 2013-02-05] (NTI Corporation)
HKLM-x32\...\Run: [DKADGmon] => C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe [951656 2012-11-07] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
HKLM-x32\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [3414560 2014-05-19] (Fitbit, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [MotoCast] => C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk [2013 2013-08-19] ()
HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [DKab1err] => C:\Program Files (x86)\Dell\ErrorApp\DKab1err.exe [644456 2012-11-07] ()
HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [DKADGmon] => C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe [951656 2012-11-07] ()
HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [3414560 2014-05-19] (Fitbit, Inc.)
HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [Amazon Music] => C:\Users\Sheyenne Alvarez\AppData\Local\Amazon Music\Amazon Music Helper.exe [6281024 2014-10-14] ()
HKU\S-1-5-21-3854915487-3061028145-266851286-1003\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3854915487-3061028145-266851286-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3854915487-3061028145-266851286-1005\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3854915487-3061028145-266851286-1005\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-18\...\RunOnce: [panda2_0dn] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda2_0dn" /f
HKU\S-1-5-18\...\RunOnce: [panda2_0dn_XP] => reg.exe delete "HKCU\Software\panda2_0dn" /f
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CineForm Status.lnk
ShortcutTarget: CineForm Status.lnk -> C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe (GoPro)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
Startup: C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Amazon Cloud Drive.appref-ms ()
Startup: C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
HKU\S-1-5-21-3854915487-3061028145-266851286-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
HKU\S-1-5-21-3854915487-3061028145-266851286-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
HKU\S-1-5-21-3854915487-3061028145-266851286-1004\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.miniclip.com/games/en/
HKU\S-1-5-21-3854915487-3061028145-266851286-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
HKU\S-1-5-21-3854915487-3061028145-266851286-1005\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
HKU\S-1-5-21-3854915487-3061028145-266851286-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
SearchScopes: HKLM -> DefaultScope value is missing.
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....h={searchTerms}
SearchScopes: HKLM -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = http://rover.ebay.co...s}&mfe=Desktops
SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....h={searchTerms}
SearchScopes: HKLM-x32 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = http://rover.ebay.co...s}&mfe=Desktops
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.co...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....h={searchTerms}
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = http://rover.ebay.co...s}&mfe=Desktops
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1003 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1003 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1003 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1004 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1004 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1004 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1005 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Dell Toolbar -> {09B71986-2AC5-482d-B6CB-42EA34F4F85B} -> C:\Program Files\Dell Printable Web\toolband.dll ()
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Dell Toolbar - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Printable Web\toolband.dll ()
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab
DPF: HKLM-x32 {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
DPF: HKLM-x32 {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin..../p3dactivex.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Users\Sheyenne Alvarez\AppData\Roaming\Mozilla\Firefox\Profiles\btxhxadl.default-1415987071767
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Bing
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=12.0.1.652 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=12.0.1.652 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3854915487-3061028145-266851286-1000: @yahoo.com/BrowserPlus,version=2.9.8 -> C:\Users\Sheyenne Alvarez\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF Plugin HKU\S-1-5-21-3854915487-3061028145-266851286-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101710.dll (Amazon.com, Inc.)
FF Plugin HKU\S-1-5-21-3854915487-3061028145-266851286-1003: @hulu.com/Hulu Desktop -> C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll (Hulu LLC)
FF Plugin HKU\S-1-5-21-3854915487-3061028145-266851286-1004: @hulu.com/Hulu Desktop -> C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll (Hulu LLC)
FF Plugin HKU\S-1-5-21-3854915487-3061028145-266851286-1004: @soe.sony.com/installer,version=1.0.3 -> C:\Users\Dario Jr\AppData\Local\Microsoft\Internet Explorer\Downloaded Program Files\npsoe.dll ()
FF Plugin HKU\S-1-5-21-3854915487-3061028145-266851286-1004: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Dario Jr\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3854915487-3061028145-266851286-1005: @hulu.com/Hulu Desktop -> C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll (Hulu LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-02-18]
FF HKU\S-1-5-21-3854915487-3061028145-266851286-1004\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF HKU\S-1-5-21-3854915487-3061028145-266851286-1005\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi

Chrome:
=======
CHR Profile: C:\Users\Sheyenne Alvarez\AppData\Local\Google\Chrome\User Data\Default

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2443960 2014-10-30] (Microsoft Corporation)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [File not signed]
S4 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [File not signed]
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [1436192 2014-05-19] (Fitbit, Inc.)
S4 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-11-22] (Hewlett-Packard Company) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [120728 2012-10-02] ()
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3377568 2014-05-25] (INCA Internet Co., Ltd.)
R2 NTI BackupNowEZSvr; C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe [46072 2013-02-05] (NTI Corporation)
S4 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-06] (PDF Complete Inc)
R2 PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) [File not signed]
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390672 2012-09-11] ()
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 A_USBETHMP; C:\Windows\System32\Drivers\usbethmp.sys [32280 2009-07-09] (Intellon Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-09] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2014-12-08] ()
S3 WLRAWMp50x64; C:\Windows\System32\Drivers\WLRAWMp50x64.sys [35352 2013-10-31] (Logitech, Inc.)
S3 WLRAWMp50x64; C:\Windows\SysWOW64\Drivers\WLRAWMp50x64.sys [35352 2013-10-31] (Logitech, Inc.)
S3 WLRAWSp50x64; C:\Windows\System32\Drivers\WLRAWSp50x64.sys [34328 2013-10-31] (Logitech, Inc.)
S3 WLRAWSp50x64; C:\Windows\SysWOW64\Drivers\WLRAWSp50x64.sys [34328 2013-10-31] (Logitech, Inc.)
R3 ZCinema_TSHD_x64; C:\Windows\System32\drivers\ZCinema_SRS_amd64.sys [21648 2007-08-22] (SRS Labs, Inc.)
S3 Andbus; system32\DRIVERS\lgandbus64.sys [X]
S3 AndDiag; system32\DRIVERS\lganddiag64.sys [X]
S3 AndGps; system32\DRIVERS\lgandgps64.sys [X]
S3 ANDModem; system32\DRIVERS\lgandmodem64.sys [X]
S3 androidusb; System32\Drivers\lgandadb.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-09 07:05 - 2014-12-09 07:05 - 00000000 ____D () C:\Users\Sheyenne Alvarez\Desktop\FRST-OlderVersion
2014-12-08 07:29 - 2014-12-08 07:29 - 00852487 _____ () C:\Users\Sheyenne Alvarez\Desktop\SecurityCheck (2).exe
2014-12-08 07:11 - 2014-12-08 13:19 - 00035064 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-12-08 07:11 - 2014-12-08 07:11 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-12-08 07:10 - 2014-12-08 07:11 - 15201368 _____ () C:\Users\Sheyenne Alvarez\Desktop\RogueKiller.exe
2014-12-06 15:39 - 2014-12-06 16:48 - 00057965 _____ () C:\Users\Sheyenne Alvarez\Documents\My Assistant presentation.pptx
2014-12-05 09:57 - 2014-12-05 09:57 - 00052612 _____ () C:\Users\Sheyenne Alvarez\Desktop\Addition.txt
2014-12-05 09:55 - 2014-12-09 07:05 - 02119680 _____ (Farbar) C:\Users\Sheyenne Alvarez\Desktop\FRST64.exe
2014-12-05 09:55 - 2014-12-09 07:05 - 00027436 _____ () C:\Users\Sheyenne Alvarez\Desktop\FRST.txt
2014-12-05 09:55 - 2014-12-09 07:05 - 00000000 ____D () C:\FRST
2014-12-05 09:52 - 2014-12-05 09:52 - 00002326 _____ () C:\Users\Sheyenne Alvarez\Desktop\JRT.txt
2014-12-05 09:48 - 2014-12-05 09:48 - 00000000 ____D () C:\Windows\ERUNT
2014-12-05 09:47 - 2014-12-05 09:47 - 01707646 _____ (Thisisu) C:\Users\Sheyenne Alvarez\Desktop\JRT.exe
2014-12-05 09:26 - 2014-12-05 09:37 - 00000000 ____D () C:\AdwCleaner
2014-12-05 09:26 - 2014-12-05 09:36 - 00000165 _____ () C:\AdwCleanerDebug.txt
2014-12-05 09:25 - 2014-12-05 09:25 - 02153472 _____ () C:\Users\Sheyenne Alvarez\Desktop\AdwCleaner(1).exe
2014-12-05 09:17 - 2014-12-05 09:18 - 00002362 _____ () C:\Users\Sheyenne Alvarez\Desktop\FixExec.txt
2014-12-05 09:10 - 2014-12-05 09:10 - 00457632 _____ (Bleeping Computer, LLC) C:\Users\Sheyenne Alvarez\Downloads\FixExec.exe
2014-12-05 07:15 - 2014-12-05 07:15 - 00000000 __SHD () C:\Users\Dario Jr\AppData\Local\EmieBrowserModeList
2014-12-04 15:51 - 2014-12-04 15:45 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-12-04 15:48 - 2014-12-04 10:56 - 00091099 _____ () C:\zoek-results2014-12-04-165605.log
2014-12-04 14:41 - 2014-12-04 14:41 - 00186431 _____ () C:\Users\Sheyenne Alvarez\Documents\bookmarks.html
2014-12-04 13:07 - 2014-12-04 13:08 - 00244104 _____ () C:\Users\Sheyenne Alvarez\Downloads\Firefox Setup Stub 34.0.5.exe
2014-12-04 12:42 - 2014-12-09 06:56 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-04 12:42 - 2014-12-04 12:42 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-04 12:42 - 2014-12-04 12:42 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-04 12:42 - 2014-12-04 12:42 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-04 10:18 - 2014-12-04 15:53 - 00090828 _____ () C:\zoek-results.log
2014-12-04 10:13 - 2014-12-04 10:46 - 00000000 ____D () C:\zoek_backup
2014-12-04 10:09 - 2014-12-04 10:09 - 01295360 _____ () C:\Users\Sheyenne Alvarez\Desktop\zoek.exe
2014-12-04 09:39 - 2014-12-04 09:39 - 00000000 ____D () C:\_OTL
2014-12-02 13:09 - 2014-12-02 13:09 - 00102176 _____ () C:\Users\Sheyenne Alvarez\Downloads\Extras.Txt
2014-12-02 13:08 - 2014-12-02 13:08 - 00145552 _____ () C:\Users\Sheyenne Alvarez\Downloads\OTL.Txt
2014-12-02 12:47 - 2014-12-02 12:47 - 00602112 _____ (OldTimer Tools) C:\Users\Sheyenne Alvarez\Downloads\OTL.exe
2014-12-02 09:23 - 2014-12-02 09:23 - 00011484 _____ () C:\Users\Sheyenne Alvarez\Documents\My Assistant Start-Up Costs.xlsx
2014-12-01 21:52 - 2014-12-01 21:52 - 00137540 _____ () C:\Users\Sheyenne Alvarez\Documents\Sheyenne Resume for Bus. Plan class.dotx
2014-11-29 16:28 - 2014-11-29 16:41 - 00054376 _____ () C:\Users\Sheyenne Alvarez\Downloads\Result.txt
2014-11-29 16:26 - 2014-11-29 16:26 - 00401920 _____ (Farbar) C:\Users\Sheyenne Alvarez\Downloads\MiniToolBox.exe
2014-11-25 14:25 - 2014-11-25 14:27 - 13087456 _____ (Microsoft Corporation) C:\Users\Sheyenne Alvarez\Downloads\Silverlight_x64(3).exe
2014-11-23 17:31 - 2014-11-23 19:48 - 00170563 _____ () C:\Users\Sheyenne Alvarez\Documents\OB PRESENTATION-1-1 edits by Sheyenne.pptx
2014-11-23 17:26 - 2014-11-23 17:26 - 00178464 _____ () C:\Users\Sheyenne Alvarez\Downloads\OB PRESENTATION-1-1.pptx
2014-11-21 14:55 - 2014-11-21 14:55 - 01120240 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Sheyenne_Alvarez.ics
2014-11-20 16:24 - 2014-11-20 16:25 - 01174891 _____ () C:\Users\Sheyenne Alvarez\Downloads\finalized presentation.pptx
2014-11-20 13:27 - 2014-11-20 13:27 - 00077536 _____ () C:\Users\Sheyenne Alvarez\Downloads\yahoo_contacts.csv
2014-11-20 10:06 - 2014-11-20 10:06 - 00039066 _____ () C:\Users\Sheyenne Alvarez\Documents\My Assistant Financials - Income and Balance.xlsx
2014-11-20 10:04 - 2014-11-20 10:04 - 00037767 _____ () C:\Users\Sheyenne Alvarez\Downloads\Financials - Income and Balance.xlsx
2014-11-20 10:04 - 2014-11-20 10:04 - 00032615 _____ () C:\Users\Sheyenne Alvarez\Downloads\Financials - Cash Flow.xlsx
2014-11-19 10:27 - 2014-11-10 21:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 10:27 - 2014-11-10 21:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 10:27 - 2014-11-10 20:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 10:27 - 2014-11-10 20:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-18 14:20 - 2014-11-18 14:20 - 00029187 _____ () C:\Users\Sheyenne Alvarez\Documents\My Assistant Financials.xlsx
2014-11-18 12:51 - 2014-11-18 14:13 - 00029172 _____ () C:\Users\Sheyenne Alvarez\Downloads\Financials.xlsx
2014-11-17 11:22 - 2014-11-17 11:22 - 01173439 _____ () C:\Users\Sheyenne Alvarez\Documents\finalized presentation - suggestions from Sheyenne.pptx
2014-11-17 10:52 - 2014-11-17 10:52 - 00126043 _____ () C:\Users\Sheyenne Alvarez\Documents\OB PRESENTATION - suggestions by Sheyenne.pptx
2014-11-17 09:26 - 2014-11-17 09:26 - 00123651 _____ () C:\Users\Sheyenne Alvarez\Documents\OB PRESENTATION.pptx
2014-11-17 09:21 - 2014-11-17 09:21 - 00126234 _____ () C:\Users\Sheyenne Alvarez\Downloads\OB PRESENTATION.pptx
2014-11-16 15:46 - 2014-11-16 15:52 - 00035328 _____ () C:\Users\Sheyenne Alvarez\Documents\My Assistant SimplyMap by Sheyenne.xls
2014-11-16 15:41 - 2014-11-16 15:41 - 00010752 _____ () C:\Users\Sheyenne Alvarez\Downloads\standard_report.xls
2014-11-14 21:06 - 2014-11-14 21:06 - 13087456 _____ (Microsoft Corporation) C:\Users\Sheyenne Alvarez\Downloads\Silverlight_x64(2).exe
2014-11-14 21:05 - 2014-11-14 21:05 - 13087456 _____ (Microsoft Corporation) C:\Users\Sheyenne Alvarez\Downloads\Silverlight_x64(1).exe
2014-11-14 11:55 - 2014-11-14 11:55 - 01080496 _____ (Unity Technologies ApS) C:\Users\Sheyenne Alvarez\Downloads\UnityWebPlayer.exe
2014-11-14 11:44 - 2014-11-14 11:44 - 00000000 ____D () C:\Users\Sheyenne Alvarez\Desktop\Old Firefox Data
2014-11-12 05:41 - 2014-11-07 13:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-12 05:41 - 2014-11-07 13:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-11-12 05:41 - 2014-11-05 22:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-12 05:41 - 2014-11-05 22:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-12 05:41 - 2014-11-05 22:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-12 05:41 - 2014-11-05 21:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-12 05:41 - 2014-11-05 21:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-12 05:41 - 2014-11-05 21:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-12 05:41 - 2014-11-05 21:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-12 05:41 - 2014-11-05 21:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-12 05:41 - 2014-11-05 21:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-12 05:41 - 2014-11-05 21:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-12 05:41 - 2014-11-05 21:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-12 05:41 - 2014-11-05 21:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-12 05:41 - 2014-11-05 21:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-12 05:41 - 2014-11-05 21:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-12 05:41 - 2014-11-05 21:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-11-12 05:41 - 2014-11-05 21:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-12 05:41 - 2014-11-05 21:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-12 05:41 - 2014-11-05 21:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-12 05:41 - 2014-11-05 21:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-11-12 05:41 - 2014-11-05 21:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-11-12 05:41 - 2014-11-05 21:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-11-12 05:41 - 2014-11-05 21:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-11-12 05:41 - 2014-11-05 21:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-11-12 05:41 - 2014-11-05 21:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-12 05:41 - 2014-11-05 21:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-11-12 05:41 - 2014-11-05 21:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-11-12 05:41 - 2014-11-05 21:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-11-12 05:41 - 2014-11-05 21:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-12 05:41 - 2014-11-05 21:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-11-12 05:41 - 2014-11-05 21:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-12 05:41 - 2014-11-05 20:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-11-12 05:41 - 2014-11-05 20:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-11-12 05:41 - 2014-11-05 20:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-12 05:41 - 2014-11-05 20:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-11-12 05:41 - 2014-11-05 20:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-12 05:41 - 2014-11-05 20:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-12 05:41 - 2014-11-05 20:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-12 05:41 - 2014-11-05 20:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-12 05:41 - 2014-11-05 20:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-12 05:41 - 2014-11-05 20:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-11-12 05:41 - 2014-11-05 20:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-11-12 05:41 - 2014-11-05 20:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-11-12 05:41 - 2014-11-05 20:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-12 05:41 - 2014-11-05 20:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-11-12 05:41 - 2014-11-05 20:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-11-12 05:41 - 2014-11-05 20:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-11-12 05:41 - 2014-11-05 20:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-11-12 05:41 - 2014-11-05 20:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-12 05:41 - 2014-11-05 20:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-12 05:41 - 2014-11-05 20:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-11-12 05:41 - 2014-11-05 19:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-12 05:41 - 2014-11-05 19:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-11-12 05:41 - 2014-11-05 19:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-11-12 05:41 - 2014-11-05 19:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-11-12 05:41 - 2014-11-05 11:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-12 05:41 - 2014-11-05 11:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-12 05:41 - 2014-11-05 11:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-12 05:41 - 2014-10-13 20:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-12 05:41 - 2014-10-13 20:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-12 05:41 - 2014-10-13 20:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-12 05:41 - 2014-10-13 20:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-12 05:41 - 2014-10-13 20:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-12 05:41 - 2014-10-13 19:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-11-12 05:41 - 2014-10-13 19:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-11-12 05:41 - 2014-10-13 19:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-12 05:41 - 2014-10-13 19:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-12 05:40 - 2014-10-24 19:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-12 05:40 - 2014-10-24 19:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-12 05:40 - 2014-10-13 20:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-12 05:40 - 2014-10-13 19:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-12 05:40 - 2014-10-09 18:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-12 05:40 - 2014-10-02 20:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-12 05:40 - 2014-10-02 20:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-12 05:40 - 2014-10-02 20:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-12 05:40 - 2014-10-02 20:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-12 05:40 - 2014-10-02 20:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-12 05:40 - 2014-10-02 19:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 05:40 - 2014-10-02 19:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 05:40 - 2014-10-02 19:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 05:40 - 2014-09-19 03:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-12 05:40 - 2014-09-19 03:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-12 05:40 - 2014-09-19 03:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-12 05:40 - 2014-09-19 03:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-12 05:40 - 2014-09-19 03:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-12 05:40 - 2014-09-19 03:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-12 05:40 - 2014-09-19 03:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 05:40 - 2014-09-19 03:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-12 05:40 - 2014-09-19 03:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 05:40 - 2014-09-19 03:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-11-12 05:40 - 2014-09-19 03:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 05:40 - 2014-09-19 03:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-11-12 05:40 - 2014-08-21 00:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-12 05:40 - 2014-08-21 00:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-12 05:40 - 2014-08-21 00:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-12 05:40 - 2014-08-21 00:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 05:40 - 2014-08-11 20:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-12 05:40 - 2014-08-11 19:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-12 05:39 - 2014-10-17 20:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-12 05:39 - 2014-10-17 19:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-11 13:05 - 2014-11-11 13:05 - 00162901 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Gabby.ics
2014-11-11 13:05 - 2014-11-11 13:05 - 00107158 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Dario_Jr..ics
2014-11-11 13:05 - 2014-11-11 13:05 - 00081923 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Roman.ics
2014-11-11 13:05 - 2014-11-11 13:05 - 00018271 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Out_of_town.ics
2014-11-11 12:50 - 2014-11-11 12:50 - 00147247 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_classes.ics
2014-11-11 12:48 - 2014-11-11 12:49 - 00071237 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Birthdays.ics
2014-11-11 12:45 - 2014-11-11 12:45 - 00196799 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Action_item.ics
2014-11-10 08:38 - 2014-12-04 13:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-09 06:46 - 2014-03-29 19:12 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-09 05:48 - 2014-09-02 18:34 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-09 05:15 - 2014-09-29 16:29 - 00000376 _____ () C:\Windows\Tasks\HPCeeScheduleForSheyenne Alvarez.job
2014-12-09 03:00 - 2011-02-18 21:54 - 01779203 _____ () C:\Windows\WindowsUpdate.log
2014-12-08 13:12 - 2011-08-05 12:42 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Local\Deployment
2014-12-08 12:46 - 2014-03-29 19:12 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-07 14:53 - 2011-02-18 22:24 - 00157858 _____ () C:\Windows\DirectX.log
2014-12-07 14:48 - 2012-02-23 08:31 - 00000000 ____D () C:\Users\Sheyenne Alvarez\Documents\Gabby's stuff
2014-12-06 14:38 - 2009-07-13 22:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-06 14:38 - 2009-07-13 22:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-06 08:13 - 2013-08-19 19:08 - 00000000 ____D () C:\Users\Sheyenne Alvarez\.gstreamer-0.10
2014-12-06 08:13 - 2013-08-19 19:04 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Roaming\MotoCast
2014-12-06 08:12 - 2013-12-16 19:02 - 00000000 ___RD () C:\Users\Sheyenne Alvarez\Dropbox
2014-12-06 08:12 - 2013-12-16 18:55 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox
2014-12-06 08:11 - 2012-01-17 14:15 - 00000000 ____D () C:\TEMP
2014-12-06 08:10 - 2012-08-18 09:35 - 00123950 _____ () C:\Windows\setupact.log
2014-12-06 08:10 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-05 14:44 - 2011-02-19 01:01 - 01198024 _____ () C:\Windows\PFRO.log
2014-12-05 07:14 - 2012-03-14 08:22 - 00156656 _____ () C:\Users\Dario Jr\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-05 07:14 - 2012-03-14 08:22 - 00000008 __RSH () C:\Users\Dario Jr\ntuser.pol
2014-12-05 07:14 - 2012-03-14 08:22 - 00000000 ____D () C:\Users\Dario Jr
2014-12-04 13:12 - 2012-07-18 19:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-04 13:09 - 2012-07-18 19:14 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-12-04 13:09 - 2012-07-18 19:14 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-12-04 12:42 - 2014-08-21 21:28 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Local\Adobe
2014-12-04 10:54 - 2012-03-10 00:18 - 00000008 __RSH () C:\Users\Sheyenne Alvarez\ntuser.pol
2014-12-04 10:54 - 2011-03-05 23:03 - 00000000 ____D () C:\Users\Sheyenne Alvarez
2014-12-04 10:39 - 2009-07-13 21:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-12-04 10:39 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-12-04 10:02 - 2012-05-08 13:55 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Roaming\Mozilla
2014-12-04 09:33 - 2013-01-04 16:58 - 00000000 ____D () C:\Program Files (x86)\FileHippo.com
2014-12-04 09:30 - 2011-03-20 13:02 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-12-04 09:28 - 2011-03-06 16:38 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Local\Google
2014-12-04 09:24 - 2014-01-14 16:08 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
2014-12-02 12:50 - 2014-09-02 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-02 12:50 - 2014-09-02 18:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-02 12:50 - 2012-12-24 08:55 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-01 17:15 - 2014-09-29 16:29 - 00003252 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForSheyenne Alvarez
2014-11-30 21:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\L2Schemas
2014-11-29 12:32 - 2011-02-18 22:02 - 00000000 ____D () C:\ProgramData\Temp
2014-11-29 01:27 - 2011-03-06 20:06 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Local\Microsoft Help
2014-11-29 01:27 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\registration
2014-11-28 14:18 - 2009-07-13 23:13 - 02223910 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-24 16:54 - 2011-03-24 17:29 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Local\CrashDumps
2014-11-23 19:48 - 2012-02-01 08:24 - 00511488 ___SH () C:\Users\Sheyenne Alvarez\Documents\Thumbs.db
2014-11-23 19:47 - 2012-01-25 17:24 - 01224704 ___SH () C:\Users\Sheyenne Alvarez\Downloads\Thumbs.db
2014-11-21 06:14 - 2014-09-02 18:33 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-21 06:14 - 2014-09-02 18:33 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-21 06:14 - 2012-12-24 08:55 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-16 05:02 - 2011-03-06 20:06 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-16 04:58 - 2014-05-24 19:46 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-11-14 18:37 - 2011-05-25 08:06 - 00003232 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForSHEYENNEALVAREZ$
2014-11-14 18:37 - 2011-05-25 08:06 - 00000356 _____ () C:\Windows\Tasks\HPCeeScheduleForSHEYENNEALVAREZ$.job
2014-11-14 12:41 - 2014-03-29 19:12 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-14 12:41 - 2014-03-29 19:12 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-14 11:30 - 2013-12-16 19:02 - 00001061 _____ () C:\Users\Sheyenne Alvarez\Desktop\Dropbox.lnk
2014-11-14 11:30 - 2013-12-16 18:57 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-11-13 07:19 - 2011-03-05 23:06 - 00156656 _____ () C:\Users\Sheyenne Alvarez\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-13 04:24 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\rescache
2014-11-13 03:34 - 2009-07-13 22:45 - 00525504 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-13 03:32 - 2014-04-30 02:01 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-13 03:10 - 2013-08-14 00:28 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-13 03:02 - 2011-08-03 14:15 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-11 14:35 - 2009-07-13 23:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD

Files to move or delete:
====================
C:\Users\Sheyenne Alvarez\jobq.dat


Some content of TEMP:
====================
C:\Users\Sheyenne Alvarez\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Sheyenne Alvarez\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwfr_fr.dll
C:\Users\Sheyenne Alvarez\AppData\Local\Temp\jna1452598040496632230.dll
C:\Users\Sheyenne Alvarez\AppData\Local\Temp\jna2913011790614662125.dll
C:\Users\Sheyenne Alvarez\AppData\Local\Temp\jna7895520593767980963.dll
C:\Users\Sheyenne Alvarez\AppData\Local\Temp\sqlite-3.6.20-sqlitejdbc.dll
C:\Users\Sheyenne Alvarez\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-05 10:38

==================== End Of Log ============================


  • 0

#37
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts
FRST.gif Fix with Farbar Recovery Scan Tool


 

icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif
icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

Press the WindowsKey.png + R on your keyboard at the same time. Type Notepad and click OK.
Copy the entire content of the codebox below and paste into the Notepad document:
 
start
CloseProcesses:
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page =
SearchScopes: HKLM -> DefaultScope value is missing.
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = [url=http://en.wikipedia....h={searchTerms]http://en.wikipedia....h={searchTerms[/url]}
SearchScopes: HKLM -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = [url=http://rover.ebay.co...s}&mfe=Desktops]http://rover.ebay.co...s}&mfe=Desktops[/url]
SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = [url=http://www.bing.com/...rc=IE-SearchBox]http://www.bing.com/...rc=IE-SearchBox[/url]
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1003 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1003 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1003 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1004 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1004 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1004 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1005 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
DeleteJunctionsIndirectory: C:\Windows\system64
EmptyTemp:
end
  • Click File, Save As and type fixlist.txt as the File Name.
Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!
  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please post it to your reply.
 
Let's do a Check Disk first and see if doesn't straighten out some of the Disk Errors. Then do a Start Up Repair per the instructions.
 
If the CHKDSK has trouble or problems, don't move on to the Startup Repair until we discuss the errors.(It's expected that it will find problems on the disk and fix them. Unusual things would be, Blue Screen, not finishing, sudden termination of the program, etc.
 
First
Click Start, All Programs, Accessories
 
Then, if you look down the list you should see Command Prompt. Right click Command Prompt and then select Run as Administrator.
 
In the box that opens, type chkdsk /f
 
Startup Repair

Run this three times in a row and even if it reports that nothing was repaired, it can at time still improve matters.
  • Click on Start(Windows 7 Orb).
  • Click on All Programs >> Accessories
  • Right click on Command Prompt and select Run as Administrator.
  • Click on Continue in the UAC prompt.
  • At the Command Prompt C:\Windows\System32> type in the following exactly:
  • cd c:\
  • Then depress the Enter/Return key, then type in the following exactly:
  • sfc /scannow
  • Then depress the Enter/Return key.
Note: This may take awhile to finish. When completed close the Administrator Command Prompt window, via typing Exit then depress the Enter/Return key.
  • 0

#38
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

Okay, I got the java updater popup and a script error when the computer restarted after doing the fix.  I was able to copy the popup.  "A script on this page may be busy, or it may have stopped responding. You can stop the script now, open the script in the debugger, or let the script continue.

Script: http://cdn.viglink.c...pi/vglnk.js:27"

 

Here is the fixlog:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-12-2014
Ran by Sheyenne Alvarez at 2014-12-09 11:31:41 Run:2
Running from C:\Users\Sheyenne Alvarez\Desktop
Loaded Profiles: Sheyenne Alvarez & Gabriella & Dario Jr & Roman (Available profiles: Sheyenne Alvarez & Gabriella & Dario Jr & Roman)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CloseProcesses:
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page =
SearchScopes: HKLM -> DefaultScope value is missing.
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....h={searchTerms}
SearchScopes: HKLM -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = http://rover.ebay.co...s}&mfe=Desktops
SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1003 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1003 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1003 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1004 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1004 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1004 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL =
SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1005 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
DeleteJunctionsIndirectory: C:\Windows\system64
EmptyTemp:
end
*****************

Processes closed successfully.
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Local Page => Value was restored successfully.
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Local Page => Value was restored successfully.
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Local Page => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => Key deleted successfully.
"HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}" => Key deleted successfully.
"HKCR\CLSID\{d944bb61-2e34-4dbf-a683-47e505c587dc}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}" => Key deleted successfully.
"HKCR\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}" => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
HKU\S-1-5-21-3854915487-3061028145-266851286-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\ToolbarSearchProviderProgress => value deleted successfully.
HKU\S-1-5-21-3854915487-3061028145-266851286-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-3854915487-3061028145-266851286-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => Key deleted successfully.
"HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => Key not found.
"HKU\S-1-5-21-3854915487-3061028145-266851286-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}" => Key deleted successfully.
"HKCR\CLSID\{d944bb61-2e34-4dbf-a683-47e505c587dc}" => Key not found.
HKU\S-1-5-21-3854915487-3061028145-266851286-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-3854915487-3061028145-266851286-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => Key deleted successfully.
"HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => Key not found.
"HKU\S-1-5-21-3854915487-3061028145-266851286-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}" => Key deleted successfully.
"HKCR\CLSID\{d944bb61-2e34-4dbf-a683-47e505c587dc}" => Key not found.
HKU\S-1-5-21-3854915487-3061028145-266851286-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10" => Key not found.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key not found.
"C:\Windows\system64" => Deleting reparse point and unlocking started.
"C:\Windows\system64" => Deleting reparse point and unlocking completed.
EmptyTemp: => Removed 378 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====


  • 0

#39
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

Okay, I really messed up here.  I was trying to read your instructions and it was partially blocked by the start menu, and I typed in the commands for the second step instead of the first.  When I realized my mistake I clicked the "x" to close the box.  Then I tried to do the chkdsk part, but it said the volume was in use by another process.  Can I fix this?


  • 0

#40
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts
The chkdsk error was not caused by you. It's an odditiy caused by the Operating System. Often, if you try the CHkDSK and it gives that messeage, an immediate reboot will start the CHKDSK process after the Boot is complete. Give it a try. If that doesn't work, then try this.

Try this:
Highlight and copy the following four lines:



sfc /scannow
chkntfs /d
echo y|chkdsk /r
shutdown /r /t 0 /f



Click Start and type in cmd and press [Enter].


Right-click anywhere in the cmd window, select Paste, and then press [Enter] once.

Before your computer boots back up into Windows, you should see CHKDSK doing it's thing, which might take a few minutes. Once it's done Windows will load up normally.

1.The "sfc /scannow" command will run, (which might take a few minutes). This command scans the integrity of all protected system files and repairs files with problems when possible and/or replaces incorrect versions with correct Microsoft versions.

2.The "chkntfs /d" command will run next which restores the machine to the default behavior; all drives are checked at boot time and chkdsk is run on those that are dirty.

3.The "chkdsk /r" command will run next which will attempt to fix any errors found on the disk, locate any bad sectors and recover readable information, and create a status report.

4.And the "shutdown /r /t 0 /f" command will reboot your computer.
  • 0

Advertisements


#41
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

Okay, the chkdsk ran when I restarted.  Then I did the startup repair.  It said it didn't find any integrity violations.


  • 0

#42
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

With Startup Repair, you did run it 3 times in a row, correct?


  • 0

#43
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

I hadn't, but I just did and it said no integrity violations every time.  Sorry for the delayed response.  Yesterday was a full day of testing and presentations for me.  But now I'm done.


  • 0

#44
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

I'm still getting invalid destination, script errors, and the java updater.


  • 0

#45
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

Hmmm....no doubt that there is still something significant that I'm missing something. Very sorry that this is so protracted.

 

Let's have a look with a different tool.

 

51a5bf3d99e8a-ComboFixlogo16.png Scan with ComboFix

This is a very powerful tool that should be used only if advised by Malware Analyst.
Do not run ComboFix on your own!


Referring to this instruction, please download ComboFix by sUBs and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on 51a5bf3d99e8a-ComboFixlogo16.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Accept the disclaimer and agree if prompted to install Recovery Console.
  • Do not take any actions while ComboFix goes through your System - it may cause it to stall!
  • This scan may take some time!
  • When finished - it will display a logfile (located also on your main drive, usually C:\ComboFix.txt).


Include that log in your next reply.
icon_idea.gif If you'll encounter any issues with internet connection after running ComboFix, please visit this link.
icon_idea.gif If an error about operation on the key marked for deletion will appear after running the tool, please reboot your machine.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP