Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

I Think I've Picked up Malware .....Adobe Flash Crashes Constantly


  • This topic is locked This topic is locked

#31
star_stitcher5

star_stitcher5

    Member

  • Topic Starter
  • Member
  • PipPip
  • 53 posts

They both saved to Documents.....I don't know why they won't save to the Desktop but they're in the same place so hoping it worked.

x result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Linda at 2015-03-15 15:52:41 Run:2
Running from C:\Users\Linda\Downloads
Loaded Profiles: Linda (Available profiles: Linda)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\SmartPCFixer.lnk -> C:\Program Files (x86)\SmartPCFixer\SmartPCFixer.exe (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\Uninstall SmartPCFixer.lnk -> C:\Program Files (x86)\SmartPCFixer\unins000.exe (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\update.lnk -> C:\Program Files (x86)\SmartPCFixer\update\update.EXE (No File)
Shortcut: C:\Users\Public\Desktop\SmartPCFixer.lnk -> C:\Program Files (x86)\SmartPCFixer\SmartPCFixer.exe (No File)
C:\Program Files (x86)\SmartPCFixer


*****************

Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\SmartPCFixer.lnk -> C:\Program Files (x86)\SmartPCFixer\SmartPCFixer.exe (No File) => Error: No automatic fix found for this entry.
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\Uninstall SmartPCFixer.lnk -> C:\Program Files (x86)\SmartPCFixer\unins000.exe (No File) => Error: No automatic fix found for this entry.
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\update.lnk -> C:\Program Files (x86)\SmartPCFixer\update\update.EXE (No File) => Error: No automatic fix found for this entry.
Shortcut: C:\Users\Public\Desktop\SmartPCFixer.lnk -> C:\Program Files (x86)\SmartPCFixer\SmartPCFixer.exe (No File) => Error: No automatic fix found for this entry.
"C:\Program Files (x86)\SmartPCFixer" => File/Directory not found.

==== End of Fixlog 15:52:41 ====


  • 0

Advertisements


#32
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

Hmm... you did everything right but the fix didn't do the job. :)

 

Try this one:

 

Download the attached fixlist.txt file and save it to the Desktop.

NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST/FRST64 and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.


  • 0

#33
star_stitcher5

star_stitcher5

    Member

  • Topic Starter
  • Member
  • PipPip
  • 53 posts

OK I've done them again, they are saving to Documents and not the desktop;

 

The FRST Scan:

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Linda (administrator) on LINDALAPTOP on 15-03-2015 17:36:19
Running from C:\Users\Linda\Downloads
Loaded Profiles: Linda (Available profiles: Linda)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
() C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Toshiba Corporation) C:\Program Files\Toshiba\Teco\TecoService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
() C:\Windows\SysWOW64\UMonit64.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Teco\TecoResident.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Hotkey\TCrdMain_Win8.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(AppEx Networks Corporation) C:\Program Files\AMD Quick Stream\AMDQuickStream.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [356776 2012-07-11] (TOSHIBA Corporation)
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [178016 2013-08-21] (TOSHIBA Corporation)
HKLM\...\Run: [TSSSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe [296520 2013-09-11] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768 2013-08-17] (TOSHIBA Corporation)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [894048 2013-01-11] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516512 2013-07-23] (TOSHIBA)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software)
HKU\S-1-5-21-2293777963-1639995663-2975564211-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7780120 2015-01-28] (SUPERAntiSpyware)
HKU\S-1-5-21-2293777963-1639995663-2975564211-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd)
HKU\S-1-5-21-2293777963-1639995663-2975564211-1001\...\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [429792 2013-04-11] (AppEx Networks Corporation)
HKU\S-1-5-21-2293777963-1639995663-2975564211-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft...=5.5&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft...=5.5&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft...=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\S-1-5-21-2293777963-1639995663-2975564211-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\S-1-5-21-2293777963-1639995663-2975564211-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft...=5.5&ar=msnhome
HKU\S-1-5-21-2293777963-1639995663-2975564211-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.toshiba.ca/welcome/?w=23
HKU\S-1-5-21-2293777963-1639995663-2975564211-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.toshiba.ca/welcome/?w=23
HKU\S-1-5-21-2293777963-1639995663-2975564211-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft...=ie&ar=iesearch
HKU\S-1-5-21-2293777963-1639995663-2975564211-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/en-ca/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-12-05] (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-10-27] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-12-05] (AVAST Software)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-10-27] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 75.153.176.1

FireFox:
========
FF ProfilePath: C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\1v38mi9i.default-1425365656615
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-03-07] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-03-07] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-10-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-10-27] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-03] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-07-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2293777963-1639995663-2975564211-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Linda\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-09-05] (Unity Technologies ApS)
FF Extension: Linkificator - C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\1v38mi9i.default-1425365656615\Extensions\[email protected] [2015-03-02]
FF Extension: Video WithOut Flash - C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\1v38mi9i.default-1425365656615\Extensions\[email protected] [2015-03-03]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-12]

Chrome:
=======
CHR DefaultSearchKeyword: Default -> ask.com
CHR Profile: C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-02-28]
CHR Extension: (Quick Extension Reload) - C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Extensions\goeiakeofnlpkioeadcbocfifmgkidpb [2014-09-07]
CHR Extension: (Avast Online Security) - C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-28]
CHR Extension: (Google Wallet) - C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-28]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-05]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-08-15] (SUPERAntiSpyware.com)
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [99328 2013-08-30] () [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-05] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-12-05] (Avast Software)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S4 THAccelSvc; C:\Program Files\TOSHIBA\HDD Accelerator\THAccelSvc.exe [216976 2013-10-17] (TOSHIBA CORPORATION)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 83855696; C:\Windows\system32\DRIVERS\83855696.sys [458336 2014-12-06] (Kaspersky Lab ZAO)
R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17504 2013-02-07] (Advanced Micro Devices, INC.)
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [219360 2013-04-18] (AppEx Networks Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-05] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-05] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-05] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-05] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-05] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-05] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-12-05] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-22] (Advanced Micro Devices)
U5 GeneStor; C:\Windows\System32\Drivers\GeneStor.sys [105704 2013-08-16] (GenesysLogic)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-14] (Malwarebytes Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1544704 2013-03-12] (Realtek Semiconductor Corporation                           )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 THAccel; C:\Windows\System32\DRIVERS\THAccel.sys [111488 2013-10-15] (TOSHIBA Corporation)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [32624 2013-08-19] (Windows ® Win 7 DDK provider)
U4 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-12-05] (Avast Software)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-15 17:35 - 2015-03-15 17:35 - 00000297 _____ () C:\Users\Linda\Downloads\fixlist.txt
2015-03-15 14:02 - 2015-03-15 14:02 - 00094644 _____ () C:\Users\Linda\Downloads\Shortcut.txt
2015-03-15 10:08 - 2015-03-15 10:10 - 00000442 _____ () C:\Users\Linda\Downloads\Search.txt
2015-03-14 14:33 - 2015-03-14 14:33 - 00000000 ____D () C:\Program Files (x86)\ESET
2015-03-14 14:32 - 2015-03-14 14:32 - 02347384 _____ (ESET) C:\Users\Linda\Downloads\esetsmartinstaller_enu.exe
2015-03-14 14:03 - 2015-03-14 14:04 - 02095616 _____ (Farbar) C:\Users\Linda\Downloads\FRST64(1).exe
2015-03-14 11:02 - 2015-03-14 11:02 - 00000328 _____ () C:\Windows\PFRO.log
2015-03-14 11:02 - 2015-03-14 11:02 - 00000116 _____ () C:\Windows\setupact.log
2015-03-14 11:02 - 2015-03-14 11:02 - 00000000 _____ () C:\Windows\setuperr.log
2015-03-14 10:55 - 2015-03-14 10:55 - 02171392 _____ () C:\Users\Linda\Downloads\AdwCleaner.exe
2015-03-13 10:20 - 2015-03-13 10:20 - 00001077 _____ () C:\Users\Linda\Desktop\JRT.txt
2015-03-13 10:11 - 2015-03-13 10:11 - 01388333 _____ (Thisisu) C:\Users\Linda\Downloads\JRT(3).exe
2015-03-12 15:33 - 2015-03-04 14:24 - 00792032 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-12 15:33 - 2015-03-04 14:24 - 00178144 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-11 11:15 - 2015-03-14 14:08 - 00020037 _____ () C:\Users\Linda\Downloads\Addition.txt
2015-03-11 11:15 - 2015-03-12 15:21 - 00001452 _____ () C:\Users\Linda\Downloads\FRST64 - Shortcut.lnk
2015-03-11 11:13 - 2015-03-15 17:36 - 00015909 _____ () C:\Users\Linda\Downloads\FRST.txt
2015-03-11 11:12 - 2015-03-15 17:36 - 00000000 ____D () C:\FRST
2015-03-11 11:11 - 2015-03-11 11:11 - 02095616 _____ (Farbar) C:\Users\Linda\Downloads\FRST64.exe
2015-03-11 10:14 - 2015-03-05 19:53 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 10:14 - 2015-03-05 19:33 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-03-11 10:14 - 2015-02-25 16:26 - 04178944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 10:14 - 2015-02-19 20:03 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 10:14 - 2015-02-19 19:58 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 10:14 - 2015-02-19 19:20 - 00301056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-03-11 10:14 - 2015-02-19 19:15 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-03-11 10:14 - 2015-01-30 16:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-03-11 10:14 - 2015-01-30 16:29 - 02484224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-03-11 10:14 - 2015-01-28 18:58 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll
2015-03-11 10:14 - 2015-01-28 18:29 - 00290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\photowiz.dll
2015-03-11 10:14 - 2015-01-26 20:44 - 00933888 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
2015-03-11 10:14 - 2015-01-23 18:51 - 00816128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe
2015-03-11 10:14 - 2015-01-23 00:17 - 00723072 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2015-03-11 10:14 - 2015-01-22 22:02 - 00560392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2015-03-11 10:14 - 2014-10-28 19:49 - 00003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 10:14 - 2014-10-28 19:44 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 10:14 - 2014-10-28 19:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 10:14 - 2014-10-28 19:04 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-03-11 10:14 - 2014-10-28 19:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-03-11 10:14 - 2014-10-28 19:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-03-11 10:13 - 2015-02-20 18:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 10:13 - 2015-02-20 17:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-03-11 10:13 - 2015-02-06 16:09 - 00396419 _____ () C:\Windows\system32\ApnDatabase.xml
2015-03-11 10:13 - 2015-02-03 16:58 - 00264000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2015-03-11 10:13 - 2015-02-03 16:58 - 00114496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys
2015-03-11 10:13 - 2015-02-03 16:58 - 00044024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2015-03-11 10:13 - 2015-02-02 16:53 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\winshfhc.dll
2015-03-11 10:13 - 2015-02-02 16:53 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winshfhc.dll
2015-03-11 10:12 - 2015-02-20 17:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-03-11 10:12 - 2015-02-20 17:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-03-11 10:12 - 2015-02-20 17:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-03-11 10:12 - 2015-02-20 16:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 10:12 - 2015-02-20 16:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-03-11 10:12 - 2015-02-19 19:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 10:12 - 2015-02-19 19:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 10:12 - 2015-02-19 19:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 10:12 - 2015-02-19 19:35 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-03-11 10:12 - 2015-02-19 19:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 10:12 - 2015-02-19 19:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 10:12 - 2015-02-19 19:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-03-11 10:12 - 2015-02-19 19:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-03-11 10:12 - 2015-02-19 19:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-03-11 10:12 - 2015-02-19 19:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 10:12 - 2015-02-19 19:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-03-11 10:12 - 2015-02-19 18:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-03-11 10:12 - 2015-02-19 18:56 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-03-11 10:12 - 2015-02-19 18:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-03-11 10:12 - 2015-02-19 18:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 10:12 - 2015-02-19 18:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 10:12 - 2015-02-19 18:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 10:12 - 2015-02-19 18:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 10:12 - 2015-02-19 18:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-03-11 10:12 - 2015-02-19 18:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-03-11 10:12 - 2015-02-19 18:29 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-03-11 10:12 - 2015-02-19 18:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 10:12 - 2015-02-19 18:26 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-03-11 10:12 - 2015-02-19 18:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-03-11 10:12 - 2015-02-19 18:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-03-11 10:12 - 2015-02-19 18:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 10:12 - 2015-02-19 18:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 10:12 - 2015-02-19 18:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-03-11 10:12 - 2015-02-19 17:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-03-11 10:12 - 2015-02-19 17:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-03-11 10:11 - 2015-02-12 10:40 - 22291584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 10:11 - 2015-02-12 10:34 - 19731824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-03-11 10:11 - 2015-01-30 16:20 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 10:11 - 2015-01-29 11:45 - 01763352 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 10:11 - 2015-01-29 11:34 - 01488040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-11 10:11 - 2015-01-28 18:04 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-03-11 10:11 - 2015-01-28 18:04 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2015-03-11 10:11 - 2015-01-28 17:59 - 02773504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-03-11 10:11 - 2015-01-28 17:49 - 02459136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-03-11 10:11 - 2015-01-28 08:41 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 10:11 - 2015-01-28 08:41 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-03-11 10:11 - 2015-01-28 08:41 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-03-11 10:11 - 2015-01-27 19:24 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\StorageContextHandler.dll
2015-03-11 10:11 - 2015-01-27 18:47 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StorageContextHandler.dll
2015-03-11 10:11 - 2015-01-27 18:31 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 10:11 - 2015-01-27 18:11 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2015-03-11 10:11 - 2015-01-27 16:47 - 02501368 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-03-11 10:11 - 2015-01-27 16:41 - 02207488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2015-03-11 10:11 - 2015-01-26 21:22 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-11 10:11 - 2015-01-26 19:11 - 03547648 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-11 10:11 - 2014-10-28 20:56 - 00027456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-03-11 10:11 - 2014-10-28 19:43 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\printui.exe
2015-03-11 10:11 - 2014-10-28 19:37 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\rfxvmt.dll
2015-03-11 10:11 - 2014-10-28 19:34 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\compstui.dll
2015-03-11 10:11 - 2014-10-28 19:04 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\findnetprinters.dll
2015-03-11 10:11 - 2014-10-28 18:58 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\printui.exe
2015-03-11 10:11 - 2014-10-28 18:52 - 00289280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\compstui.dll
2015-03-11 10:11 - 2014-10-28 18:51 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2015-03-11 10:11 - 2014-10-28 18:45 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\prnntfy.dll
2015-03-11 10:11 - 2014-10-28 18:28 - 00055808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\findnetprinters.dll
2015-03-11 10:11 - 2014-10-28 18:20 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2015-03-11 10:11 - 2014-10-28 18:15 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prnntfy.dll
2015-03-11 10:11 - 2014-10-28 17:55 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll
2015-03-11 10:11 - 2014-10-28 17:44 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiapi.dll
2015-03-11 10:11 - 2014-10-28 17:41 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\DafPrintProvider.dll
2015-03-11 10:11 - 2014-10-28 17:35 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DafPrintProvider.dll
2015-03-11 10:10 - 2015-02-07 16:57 - 01090048 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2015-03-11 10:10 - 2015-02-07 16:49 - 00791040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2015-03-11 10:10 - 2015-02-05 18:28 - 02257408 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-03-11 10:10 - 2015-02-05 18:08 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-03-11 10:10 - 2015-02-05 13:24 - 01113920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-03-11 10:10 - 2015-02-02 17:03 - 03551744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2015-03-11 10:10 - 2015-02-02 17:02 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2015-03-11 10:10 - 2015-01-29 20:01 - 00097792 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys
2015-03-11 10:10 - 2015-01-29 19:03 - 01488896 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2015-03-11 10:10 - 2015-01-29 19:03 - 01464832 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2015-03-11 10:10 - 2015-01-29 19:02 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2015-03-11 10:10 - 2015-01-29 18:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2015-03-11 10:10 - 2015-01-29 18:42 - 01204224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2015-03-11 10:10 - 2015-01-29 18:40 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll
2015-03-11 10:10 - 2015-01-29 18:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2015-03-11 10:10 - 2015-01-29 18:29 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atlthunk.dll
2015-03-11 10:10 - 2015-01-29 18:24 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2015-03-11 10:10 - 2015-01-29 18:24 - 00250880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll
2015-03-11 10:10 - 2015-01-29 18:16 - 00266752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll
2015-03-11 10:10 - 2015-01-29 18:08 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll
2015-03-11 10:10 - 2015-01-29 18:06 - 00278016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll
2015-03-11 10:10 - 2015-01-28 18:11 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 10:10 - 2015-01-28 18:00 - 00210944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 10:10 - 2015-01-28 17:55 - 00971776 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2015-03-11 10:10 - 2015-01-28 17:50 - 00811008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2015-03-11 10:10 - 2015-01-20 22:54 - 01384712 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 10:10 - 2015-01-20 22:15 - 01123848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-03-11 10:10 - 2014-12-10 22:36 - 00046456 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentServer.exe
2015-03-11 10:10 - 2014-10-28 19:34 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WSCollect.exe
2015-03-11 10:10 - 2014-10-28 19:34 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\WSReset.exe
2015-03-11 10:10 - 2014-10-28 18:28 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\atlthunk.dll
2015-03-11 10:10 - 2014-10-28 18:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\eappprxy.dll
2015-03-11 10:10 - 2014-10-28 18:13 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-03-11 10:10 - 2014-10-28 17:59 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappprxy.dll
2015-03-11 10:10 - 2014-10-28 17:55 - 00223744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2015-03-09 11:13 - 2015-03-09 11:13 - 02171392 _____ () C:\Users\Linda\Downloads\adwcleaner_4.112.exe
2015-03-07 11:28 - 2015-03-07 11:28 - 05325696 _____ (Piriform Ltd) C:\Users\Linda\Downloads\ccsetup503.exe
2015-03-05 15:54 - 2015-03-05 15:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-01 18:48 - 2015-03-15 17:22 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-01 18:48 - 2015-03-07 12:55 - 00003718 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-03-01 18:43 - 2015-03-01 18:43 - 00003176 _____ () C:\Windows\System32\Tasks\{A94C431E-77B1-4B8A-807D-5B77451B19F8}
2015-03-01 18:31 - 2015-03-01 18:31 - 00072959 _____ () C:\468d6e04-9c3a-4082-917d-e101b2501656.dmp
2015-02-28 20:09 - 2015-02-28 20:09 - 18129584 _____ (Adobe Systems Incorporated) C:\Users\Linda\Downloads\install_flash_player.exe
2015-02-28 12:18 - 2015-02-28 12:18 - 00001080 _____ () C:\Users\Linda\Desktop\Eusing Free Registry Cleaner.lnk
2015-02-28 12:17 - 2015-02-28 12:17 - 00983613 _____ () C:\Users\Linda\Downloads\EFRCSetup(2).exe
2015-02-28 11:06 - 2015-02-28 11:06 - 41008512 _____ () C:\Users\Linda\Downloads\Firefox Setup 36.0.exe
2015-02-28 11:02 - 2014-12-13 14:28 - 00513488 _____ () C:\Windows\SysWOW64\locale.nls
2015-02-28 11:02 - 2014-12-13 14:28 - 00513488 _____ () C:\Windows\system32\locale.nls
2015-02-28 11:02 - 2014-10-28 18:27 - 01200128 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2015-02-28 11:02 - 2014-10-28 18:27 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\GlobCollationHost.dll
2015-02-28 11:02 - 2014-10-28 18:04 - 00868352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2015-02-28 11:02 - 2014-10-28 18:04 - 00200704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GlobCollationHost.dll
2015-02-28 10:51 - 2015-02-28 10:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-02-28 10:50 - 2014-12-05 12:28 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-02-26 16:38 - 2015-03-15 16:23 - 01681171 _____ () C:\Windows\WindowsUpdate.log
2015-02-26 11:40 - 2015-02-26 11:40 - 00000000 ____D () C:\Users\Linda\AppData\Roaming\LavasoftStatistics
2015-02-26 11:34 - 2015-02-26 13:56 - 00000000 ____D () C:\ProgramData\Lavasoft
2015-02-25 11:26 - 2015-02-25 11:26 - 00000000 ____D () C:\Users\Public\Documents\sun
2015-02-22 16:27 - 2015-02-22 16:31 - 133616624 _____ () C:\Users\Linda\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_en-GB(1).exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-15 17:33 - 2014-05-12 14:02 - 00000930 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-15 17:00 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\system32\sru
2015-03-15 16:35 - 2014-05-12 13:54 - 00003938 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7F98E464-546B-493E-8A66-68F21CF9D6A0}
2015-03-15 15:11 - 2014-03-26 01:01 - 00065536 _____ () C:\Windows\system32\spu_storage.bin
2015-03-15 10:39 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\rescache
2015-03-15 10:04 - 2014-05-16 22:07 - 05786112 ___SH () C:\Users\Linda\Downloads\Thumbs.db
2015-03-14 16:13 - 2014-10-27 17:15 - 00000000 ____D () C:\AdwCleaner
2015-03-14 15:33 - 2014-05-12 14:02 - 00000926 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-14 12:50 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-03-14 12:35 - 2014-05-16 13:35 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-14 11:07 - 2013-09-13 18:58 - 00863592 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-14 11:03 - 2014-05-17 18:42 - 00000000 ___DO () C:\Users\Linda\OneDrive
2015-03-14 11:02 - 2013-08-22 07:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-14 11:01 - 2013-08-22 06:25 - 00262144 _____ () C:\Windows\system32\config\BBI
2015-03-14 11:00 - 2014-03-26 01:25 - 16813968 _____ () C:\Users\Public\CAFADEBUG.log
2015-03-14 10:34 - 2014-05-16 13:26 - 00001988 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-03-14 02:23 - 2014-03-26 01:31 - 00000000 ____D () C:\ProgramData\Norton
2015-03-13 23:46 - 2014-05-12 13:54 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2293777963-1639995663-2975564211-1001
2015-03-13 10:26 - 2014-12-05 12:29 - 00002197 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-03-13 10:03 - 2014-05-17 09:37 - 00000000 ____D () C:\Users\Linda\AppData\Local\CrashDumps
2015-03-13 10:00 - 2014-05-12 14:02 - 00000000 ____D () C:\Program Files (x86)\Google
2015-03-12 15:32 - 2013-08-22 07:44 - 00362544 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-12 15:28 - 2013-08-22 08:36 - 00000000 ___RD () C:\Windows\ToastData
2015-03-12 15:28 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-12 15:28 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-12 15:28 - 2013-08-22 08:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-12 15:28 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\WinStore
2015-03-12 15:28 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\Windows Defender
2015-03-12 15:28 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-03-12 11:00 - 2013-08-22 08:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-03-11 11:46 - 2014-05-15 02:23 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-11 11:40 - 2014-05-15 02:23 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-09 13:51 - 2014-03-26 01:19 - 00000000 ____D () C:\Windows\System32\Tasks\TOSHIBA
2015-03-09 13:39 - 2013-09-13 19:18 - 00000000 ____D () C:\Program Files (x86)\TOSHIBA
2015-03-09 13:39 - 2013-09-13 19:17 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-03-09 11:38 - 2014-05-12 14:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-09 10:53 - 2014-05-16 13:26 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-03-08 10:34 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\system32\NDF
2015-03-07 12:56 - 2014-07-23 13:31 - 00000000 ____D () C:\Users\Linda\AppData\Local\Adobe
2015-03-07 11:29 - 2014-07-07 19:14 - 00000805 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-03-07 11:29 - 2014-07-07 19:14 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-02 23:54 - 2014-05-12 23:40 - 00000000 ____D () C:\Users\Linda\Desktop\Old Firefox Data
2015-02-28 11:16 - 2014-05-12 14:18 - 00001186 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-28 11:16 - 2014-05-12 14:18 - 00001174 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-28 10:51 - 2014-05-12 14:03 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-02-28 10:49 - 2014-05-12 13:46 - 00000000 ____D () C:\Users\Linda
2015-02-28 10:47 - 2014-12-10 21:00 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-28 10:47 - 2014-07-09 22:08 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-28 10:47 - 2013-08-22 08:36 - 00000000 __RSD () C:\Windows\Media
2015-02-28 10:47 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-02-28 10:46 - 2014-07-10 13:53 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2015-02-28 10:46 - 2014-07-07 19:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-02-28 10:46 - 2013-08-22 06:36 - 00000000 ____D () C:\Windows\system32\Sysprep
2015-02-28 10:39 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\registration
2015-02-28 10:34 - 2014-10-27 11:00 - 00000000 ____D () C:\Program Files\AMD
2015-02-28 10:34 - 2014-07-10 13:52 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2015-02-19 16:21 - 2013-08-22 06:25 - 00262144 _____ () C:\Windows\system32\config\BBI(134)

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-09 12:09

==================== End Of Log ============================

 

And the Fixlog scan:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Linda at 2015-03-15 17:38:10 Run:3
Running from C:\Users\Linda\Downloads
Loaded Profiles: Linda (Available profiles: Linda)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\SmartPCFixer.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\Uninstall SmartPCFixer.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\update.lnk
C:\Users\Public\Desktop\SmartPCFixer.lnk
*****************

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\SmartPCFixer.lnk => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\Uninstall SmartPCFixer.lnk => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer\update.lnk => Moved successfully.
"C:\Users\Public\Desktop\SmartPCFixer.lnk" => File/Directory not found.

==== End of Fixlog 17:38:10 ====


  • 0

#34
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

Looks very good. :)

 

I see you didn't uninstall Google Chrome. If you did ever decide to use Chrome then, if it were me, I would remove Ask as the search engine. As you don't use it, it doesn't matter really.

 

How is your machine now?


  • 0

#35
star_stitcher5

star_stitcher5

    Member

  • Topic Starter
  • Member
  • PipPip
  • 53 posts

Hi,

 

I did uninstall Chrome, went into add/remove programs to do it.......how odd.......

 

Anyway, my machine seems fine, don't see anything that seems to be wrong anymore.

 

I have a question, should I continue to use the free AVAST or would it be better to switch to the Microsoft Security Suite?

 

Thanks so much!! ☺


  • 0

#36
star_stitcher5

star_stitcher5

    Member

  • Topic Starter
  • Member
  • PipPip
  • 53 posts

I double checked for the Chrome Browser and Ask toolbar, can't find either one, doesn't show in add/remove programs, nothing has Ask in it either ..........I know Ask is considered a hijack browser and I certainly don't want it on the pc


  • 0

#37
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

I did uninstall Chrome, went into add/remove programs to do it.......how odd.......


I double checked for the Chrome Browser and Ask toolbar, can't find either one, doesn't show in add/remove programs, nothing has Ask in it either ..........I know Ask is considered a hijack browser and I certainly don't want it on the pc


Hmm... don't know what is going on there. It is showing in your logs. Maybe it's just a leftover.

Let's run another small fix.

 

After that I will talk about the Anti-Virus programs and then, all going well we will clear away the tools we have been using. :)

 

Now

Download the attached fixlist.txt file and save it.

NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST/FRST64 and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.


  • 0

#38
star_stitcher5

star_stitcher5

    Member

  • Topic Starter
  • Member
  • PipPip
  • 53 posts

OK, I've run it again, here's the log:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Linda at 2015-03-16 13:56:12 Run:4
Running from C:\Users\Linda\Downloads
Loaded Profiles: Linda (Available profiles: Linda)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Users\Linda\AppData\Local\Google\Chrome
C:\Program Files\AVAST Software\Avast\WebRep\Chrome
*****************

C:\Users\Linda\AppData\Local\Google\Chrome => Moved successfully.

"C:\Program Files\AVAST Software\Avast\WebRep\Chrome" directory move:

Could not move "C:\Program Files\AVAST Software\Avast\WebRep\Chrome" directory. => Scheduled to move on reboot.


=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-03-16 13:59:50)<=

"C:\Program Files\AVAST Software\Avast\WebRep\Chrome" => Directory could not move.

==== End of Fixlog 13:59:51 ====


  • 0

#39
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

That looks good. :thumbsup:

 

I think we can go to clearing away the tools we have been using.

 

We have a couple of last steps to perform and then you're all set. :)

To clear away the tools we have been using download Delfix from here.

Put a check (tick) in the following boxes:

 

  • Remove disinfection tools
  • Purge System Restore
  • Then click Run

The tool will run for a short time. When completed a notepad window will open with a log. Please copy and paste the log back here.

Any remaining tools may be deleted.
-------------------------------------------------------------------------------------------------------------------

A reminder:  Remember to (re-install if uninstalled during cleaning) update and turn back on any anti-malware programs you may have turned off during the cleaning process.
-------------------------------------------------------------------------------------------------------------------

Here are some things that I think are worth having a look at if you don't already know about them:

----------------------------------------------------------------------------------------------------------------------

So many of us use Facebook nowadays. Go here for a guide to Facebook security.

-----------------------------------------------------------------------------------------------------------------------

It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article Strong passwords: How to create and use them.

----------------------------------------------------------------------------------------------------------------------

Java warning

Java is a popular point of entry to your computer for malicous programs. The United States Department of Homeland Security recommends that computer users disable Java, see here. Unless you need it to run an important software the safest approach is to completely uninstall Java. Where you do require it, then the next safest option is to disable it in your browsers until you need it, then enable it.

How to disable Java in your web browser and How to unplug Java from the browser

If you do still need Java then regularly check that it is up to date. Older versions are the most vulnerable to malicious attack.

You also need to unininstall older versions of Java.

  • Open Control Panel by swiping in from the right edge of the screen, tapping Search (or if you're using a mouse, pointing to the upper-right corner of the screen, moving the mouse pointer down, and then clicking Search)
  • Enter Control Panel in the search box and then tap or click Control Panel.
  • Control Panel > Uninstall a Program
      
  • Remove all Java updates except the latest one you have just installed.

--------------------------------------------------------------------------------------------------------------------

To help protect your computer in the future:

If you do not already have automatic updates set then it is recommended that you do set Windows to check, download and install your updates automatically.

  • Open Control Panel by swiping in from the right edge of the screen, tapping Search (or if you're using a mouse, pointing to the upper-right corner of the screen, moving the mouse pointer down, and then clicking Search)
  • Enter Control Panel in the search box, and then tap or click Control Panel.
  • Click/tap System and Security > Windows Update
  • Under Windows Update click on Turn automatic updating on or off
  • Check items shown to ensure you receive updates automatically. Click OK.

Be aware of what emails you open and websites you visit.

Go here for some good advice about how to prevent infection.

For some common sense advice about protecting your computer read URL=http://www.microsoft...protect-pc.aspx]How to boost your malware defense and protect your PC[/URL]

A fun way to check your online safety literacy.

Quiz - getsafeonline

Have a safe and happy computing day!

 


  • 0

#40
star_stitcher5

star_stitcher5

    Member

  • Topic Starter
  • Member
  • PipPip
  • 53 posts

I downloaded Defix and got a warning saying Windows Smart Screen was unavailable and wouldn't be available to help if something goes wrong, should I allow Defix anyway?


  • 0

Advertisements


#41
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

Yes run it but make sure only these ones have a tick against them:

 

  • Remove disinfection tools
  • Purge System Restore

  • 0

#42
star_stitcher5

star_stitcher5

    Member

  • Topic Starter
  • Member
  • PipPip
  • 53 posts

OK I've run it, here's the log:

 

DelFix v10.9 - Logfile created 16/03/2015 at 18:25:42

# Updated 27/02/2015 by Xplode
# Username : Linda - LINDALAPTOP
# Operating System : Windows 8.1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\AdwCleanerDebug.txt
Deleted : C:\Users\Linda\Desktop\JRT.txt
Deleted : C:\Users\Linda\Downloads\Addition.txt
Deleted : C:\Users\Linda\Downloads\AdwCleaner.exe
Deleted : C:\Users\Linda\Downloads\adwcleaner_4.112.exe
Deleted : C:\Users\Linda\Downloads\esetsmartinstaller_enu.exe
Deleted : C:\Users\Linda\Downloads\Fixlog.txt
Deleted : C:\Users\Linda\Downloads\FRST.txt
Deleted : C:\Users\Linda\Downloads\FRST64 - Shortcut.lnk
Deleted : C:\Users\Linda\Downloads\FRST64(1).exe
Deleted : C:\Users\Linda\Downloads\FRST64.exe
Deleted : C:\Users\Linda\Downloads\JRT(1).exe
Deleted : C:\Users\Linda\Downloads\JRT(2).exe
Deleted : C:\Users\Linda\Downloads\JRT(3).exe
Deleted : C:\Users\Linda\Downloads\JRT.exe
Deleted : C:\Users\Linda\Downloads\Search.txt
Deleted : C:\Users\Linda\Downloads\Shortcut.txt
Deleted : HKLM\SOFTWARE\AdwCleaner

~ Cleaning system restore ...

Deleted : RP #55 [Restore Operation | 02/28/2015 17:29:26]
Deleted : RP #56 [avast! antivirus system restore point | 03/02/2015 03:43:04]
Deleted : RP #57 [Scheduled Checkpoint | 03/09/2015 20:32:00]

New restore point created !

########## - EOF - ##########


  • 0

#43
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

All looks good. :thumbsup:

 

I will keep this topic open for a day or two in case any issues arise. :)


  • 0

#44
star_stitcher5

star_stitcher5

    Member

  • Topic Starter
  • Member
  • PipPip
  • 53 posts

OK then! Machine seems to be running just fine and dandy......if any other issues come up in the next day or two I'll post them here.

 

THANK YOU SO VERY, VERY MUCH FOR ALL YOUR HELP, IT'S APPRECIATED GREATLY!! ☺

 

Linda ☺


  • 0

#45
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

You are very welcome. :happy:


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP