I have them in a folder in my downloads. Here is the Fixlog:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Laurie at 2015-03-24 20:17:36 Run:1
Running from C:\Users\Laurie\Downloads\New folder
Loaded Profiles: Laurie (Available profiles: scott & Laurie & Morgan)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKLM Group Policy restriction on software: C:\Program Files\SUPERAntiSpyware <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\Microsoft Security Client <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Malwarebytes <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] fastprox.dll ATTENTION! ====> ZeroAccess?
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <===== ATTENTION
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=CPNTDF
SearchScopes: HKLM-x32 -> DefaultScope {82D49C3D-6CEC-495A-B675-572AC32446DF} URL =
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=CPNTDF
SearchScopes: HKLM-x32 -> {38bc6857-67fa-4358-afae-28e0f9ad2128} URL = http://search.mywebs...or={searchTerms}
SearchScopes: HKU\S-1-5-21-3102672133-3772107906-1656686465-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL =
SearchScopes: HKU\S-1-5-21-3102672133-3772107906-1656686465-1001 -> {38bc6857-67fa-4358-afae-28e0f9ad2128} URL = http://search.mywebs...or={searchTerms}
SearchScopes: HKU\S-1-5-21-3102672133-3772107906-1656686465-1001 -> {82D49C3D-6CEC-495A-B675-572AC32446DF} URL = http://search.condui...0934701126&UM=2
Toolbar: HKU\S-1-5-21-3102672133-3772107906-1656686465-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
CMD: netsh winsock reset
FF SearchEngineOrder.1: Ask Search
FF user.js: detected! => C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rl45r5i0.default\user.js [2014-10-18]
FF SearchPlugin: C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rl45r5i0.default\searchplugins\ask-search.xml [2014-07-16]
FF Extension: {{EXT_NAME}} - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rl45r5i0.default\Extensions\jid0-GjwrPchS3Ugt7xydvqVK4DQk8Ls@jetpack [2014-10-02]
FF Extension: No Name - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rl45r5i0.default\extensions\[email protected] [Not Found]
FF Extension: No Name - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rl45r5i0.default\extensions\[email protected] [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
CHR DefaultSearchKeyword: Default -> blekko
CHR DefaultSearchURL: Default -> http://blekko.com/ws...&q={searchTerms}
CHR DefaultSuggestURL: Default ->
S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S3 cpuz134; \??\C:\Users\Laurie\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
R3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
2015-03-23 12:54 - 2015-03-23 12:54 - 00004276 _____ () C:\Windows\System32\Tasks\ReimageUpdater
2015-03-23 12:34 - 2015-03-23 21:02 - 00000000 ____D () C:\Program Files\Reimage
2015-03-23 12:26 - 2015-03-23 12:54 - 00000165 _____ () C:\Windows\Reimage.ini
2015-03-23 12:13 - 2015-03-23 12:26 - 00768512 _____ (Reimage®) C:\Users\Laurie\Downloads\ReimageRepair.exe
2014-09-18 01:55 - 2014-09-18 01:55 - 0000112 _____ () C:\ProgramData\1r7bsq3n5.dat
2014-10-07 08:36 - 2015-03-23 11:18 - 0000112 _____ () C:\ProgramData\75uRt613w.dat
C:\$Recycle.Bin\S-1-5-21-3102672133-3772107906-1656686465-1000\$ec33501a4ccc5055382d11e4e0c8280d
C:\$Recycle.Bin\S-1-5-18\$ec33501a4ccc5055382d11e4e0c8280d
C:\Users\scott\AppData\Roaming\skype.ini
DeleteJunctionsIndirectory: C:\Windows\system64
Task: {0247A51F-F7C5-42D2-AC41-5239203CB7B2} - \DealPly No Task File <==== ATTENTION
Task: {23F98067-6D1D-4601-A13B-14967C2FFECD} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
C:\Program Files (x86)\MyPC Backup
Task: {9253D290-3608-4F18-8351-F7734AD1258E} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATTENTION
C:\Program Files\Reimage
Task: {931349CB-D3FB-4529-93CD-9809078B60AC} - System32\Tasks\FoxTab => C:\Users\Laurie\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
C:\Users\Laurie\AppData\Roaming\FoxTab
Task: {966217BD-8D66-45CB-8DA5-5387AB12BAF5} - System32\Tasks\{AF171429-BE6F-437B-9EBC-D16DF71513D7} => pcalua.exe -a E:\SETUP.EXE -d E:\
Task: {D19295C4-7D49-448D-9003-6759116C7D22} - System32\Tasks\UpdaterEX => C:\Users\Laurie\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
C:\Users\Laurie\AppData\Roaming\UPDATE~1
Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Laurie\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\Laurie\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:B4273EB5
CMD: bitsadmin /reset /allusers
Reboot:
end
*****************
Error: (0) Failed to create a restore point.
Processes closed successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => Value was restored successfully.
"HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore" => Key deleted successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully.
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{38bc6857-67fa-4358-afae-28e0f9ad2128}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{38bc6857-67fa-4358-afae-28e0f9ad2128} => Key not found.
"HKU\S-1-5-21-3102672133-3772107906-1656686465-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found.
"HKU\S-1-5-21-3102672133-3772107906-1656686465-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{38bc6857-67fa-4358-afae-28e0f9ad2128}" => Key deleted successfully.
HKCR\CLSID\{38bc6857-67fa-4358-afae-28e0f9ad2128} => Key not found.
"HKU\S-1-5-21-3102672133-3772107906-1656686465-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{82D49C3D-6CEC-495A-B675-572AC32446DF}" => Key deleted successfully.
HKCR\CLSID\{82D49C3D-6CEC-495A-B675-572AC32446DF} => Key not found.
HKU\S-1-5-21-3102672133-3772107906-1656686465-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value deleted successfully.
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found.
Winsock: Catalog5 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll
Winsock: Catalog5 entry 000000000005\\LibraryPath was set successfully to %SystemRoot%\System32\mswsock.dll
Winsock: Catalog5-x64 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll
Winsock: Catalog5-x64 entry 000000000005\\LibraryPath was set successfully to %SystemRoot%\System32\mswsock.dll
========= netsh winsock reset =========
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
========= End of CMD: =========
Firefox SearchEngineOrder.1 deleted successfully.
C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rl45r5i0.default\user.js => Moved successfully.
C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rl45r5i0.default\searchplugins\ask-search.xml => Moved successfully.
C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rl45r5i0.default\Extensions\jid0-GjwrPchS3Ugt7xydvqVK4DQk8Ls@jetpack => Moved successfully.
C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rl45r5i0.default\extensions\[email protected] not found.
C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rl45r5i0.default\extensions\[email protected] not found.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} not found.
Chrome DefaultSearchKeyword deleted successfully.
Chrome DefaultSearchURL deleted successfully.
Chrome DefaultSuggestURL deleted successfully.
ReimageRealTimeProtector => Service deleted successfully.
clwvd => Service deleted successfully.
cpuz134 => Service deleted successfully.
MBAMSwissArmy => Service stopped successfully.
MBAMSwissArmy => Service deleted successfully.
C:\Windows\System32\Tasks\ReimageUpdater => Moved successfully.
C:\Program Files\Reimage => Moved successfully.
C:\Windows\Reimage.ini => Moved successfully.
C:\Users\Laurie\Downloads\ReimageRepair.exe => Moved successfully.
C:\ProgramData\1r7bsq3n5.dat => Moved successfully.
C:\ProgramData\75uRt613w.dat => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-3102672133-3772107906-1656686465-1000\$ec33501a4ccc5055382d11e4e0c8280d => Moved successfully.
C:\$Recycle.Bin\S-1-5-18\$ec33501a4ccc5055382d11e4e0c8280d => Moved successfully.
C:\Users\scott\AppData\Roaming\skype.ini => Moved successfully.
"C:\Windows\system64" => Deleting reparse point and unlocking started.
"C:\Windows\system64" => Deleting reparse point and unlocking done.
"C:\Windows\system64" => Deleting reparse point and unlocking completed.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0247A51F-F7C5-42D2-AC41-5239203CB7B2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0247A51F-F7C5-42D2-AC41-5239203CB7B2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{23F98067-6D1D-4601-A13B-14967C2FFECD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{23F98067-6D1D-4601-A13B-14967C2FFECD}" => Key deleted successfully.
C:\Windows\System32\Tasks\LaunchSignup => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchSignup" => Key deleted successfully.
"C:\Program Files (x86)\MyPC Backup" => File/Directory not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9253D290-3608-4F18-8351-F7734AD1258E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9253D290-3608-4F18-8351-F7734AD1258E}" => Key deleted successfully.
C:\Windows\System32\Tasks\ReimageUpdater not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ReimageUpdater" => Key deleted successfully.
"C:\Program Files\Reimage" => File/Directory not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{931349CB-D3FB-4529-93CD-9809078B60AC}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{931349CB-D3FB-4529-93CD-9809078B60AC}" => Key deleted successfully.
C:\Windows\System32\Tasks\FoxTab => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FoxTab" => Key deleted successfully.
C:\Users\Laurie\AppData\Roaming\FoxTab => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{966217BD-8D66-45CB-8DA5-5387AB12BAF5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{966217BD-8D66-45CB-8DA5-5387AB12BAF5}" => Key deleted successfully.
C:\Windows\System32\Tasks\{AF171429-BE6F-437B-9EBC-D16DF71513D7} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AF171429-BE6F-437B-9EBC-D16DF71513D7}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D19295C4-7D49-448D-9003-6759116C7D22}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D19295C4-7D49-448D-9003-6759116C7D22}" => Key deleted successfully.
C:\Windows\System32\Tasks\UpdaterEX => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UpdaterEX" => Key deleted successfully.
C:\Users\Laurie\AppData\Roaming\UPDATE~1 => Moved successfully.
C:\Windows\Tasks\FoxTab.job => Moved successfully.
C:\Windows\Tasks\UpdaterEX.job => Moved successfully.
C:\ProgramData\Temp => ":B4273EB5" ADS removed successfully.
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
{CED6CEB4-1C23-4B2C-B75E-86AA9326622F} canceled.
{1C7AF89D-5892-4559-872E-23993AD6C87A} canceled.
{2298DA79-24F5-4471-A37D-3F792358872D} canceled.
{C67A7EDF-224B-45F6-947B-66AB61CEF3BA} canceled.
{39E8B062-8352-4C25-9DB5-10A9A479E87B} canceled.
{CAF840EE-081B-42F8-BA43-EC6C8C96D6A4} canceled.
{AE5D6BFE-9763-4932-B212-4AC4EBD9479F} canceled.
{09173B40-7DCC-4407-B00C-60BCC56CA5AB} canceled.
{BC752562-0439-4709-972D-2C47CF1EF98D} canceled.
{8AD9C597-B2B2-4FDD-A15A-9618FF3A7509} canceled.
{C4B620B3-970B-4039-B204-3CB5CDFA9348} canceled.
{18ED8FD2-1B59-423D-867A-B79EE3D9740A} canceled.
{A15AE026-A912-4F7E-A2C9-4236B5DDFA7F} canceled.
{07583C6A-C344-4C7F-A8BD-C67E8DFF54BB} canceled.
{3946FC65-C024-4A73-A110-263D0A7AF135} canceled.
{192B1E5B-A6B7-48C8-A249-FAC828CCC73D} canceled.
{E905686E-F1AA-4841-96FC-E14D7D4EA92E} canceled.
{77D78C6B-54E0-4C68-A291-24DD0B8C7F04} canceled.
{78BABA40-D3F0-47FD-9E38-47790DEF9459} canceled.
{3BB88287-63EA-4D13-B03B-CC8BBE2BDC60} canceled.
{FFDA418D-4B80-40C4-B0C2-F8AC87FC67BD} canceled.
{65A936FB-5EB7-458E-85D3-F1D53F11AA1B} canceled.
{56E8A26D-A060-4B21-A44F-FD74184847F3} canceled.
{0E18FC5D-3D48-4FC4-9D5B-AC9A088F3DFF} canceled.
{05F8CF88-360C-4183-852C-175ABF0E6492} canceled.
{049DDEEC-9183-4E7E-8578-0147104947A8} canceled.
{75DDCE89-37F5-4F98-80D6-6304CD62D5EF} canceled.
{1AE694FB-A165-47DB-B262-70FDED17986B} canceled.
{8A55CA9A-1222-41DD-8BFF-1B1CFC83B8D6} canceled.
{461D698E-81DB-47B1-9691-F1168D8B01FA} canceled.
{D1549EFB-A88E-41A8-A251-8521357185B4} canceled.
{742EC158-3BFB-4F79-AD36-3295635011AC} canceled.
{AD4B04B0-A35D-406A-9F0B-CCD0E3BC1B2C} canceled.
{A756DE32-EE80-4D48-AA93-9387DE9A2D81} canceled.
{8022546C-7497-402C-9777-E04499413FE4} canceled.
{C00E803F-AE24-4745-B0B7-834106F61055} canceled.
{DFCF623E-AD3F-4218-933C-6E326840B91E} canceled.
{1DC4E036-D051-48CA-B540-771B9EE64902} canceled.
{5CF9F40C-0B14-449B-B19C-8FD66A1A869B} canceled.
{E2B7A90F-D8DE-47D7-939F-FEE164694467} canceled.
{AEA0516A-C972-4ABA-A8FC-0CEEB6B2A466} canceled.
{88831312-96A6-4C52-B1DC-1F61B398BDE6} canceled.
{A3D97FBE-1220-475E-B88D-4A290E54B622} canceled.
{6FA00DC4-716D-4087-A256-C43952ED4A61} canceled.
{193A5CA8-CD7C-47BF-BAC4-E2A859145B7B} canceled.
{8B7FD342-1756-448E-A79D-29D9976D577C} canceled.
{8FE460F7-D56F-4A6A-9A85-6A944521FC48} canceled.
{F9D05601-3277-419B-BD3C-D9733922CE54} canceled.
{093B8001-ABBE-4242-A802-457A58F2EB0A} canceled.
{97989E8A-6F5B-4A10-9713-5085D172D96E} canceled.
{8018E028-B479-4688-8263-7E782334B910} canceled.
{F96E2FB0-D95F-4C03-A941-006982288223} canceled.
{F14580B9-9E2E-4A0E-8E8A-35F9B4D36661} canceled.
{6A300684-F251-48F4-A783-E482875C2AE0} canceled.
{9009818D-B237-405D-8FD3-151FB95A456D} canceled.
{2AEFB6A4-3B10-4500-82F8-B8DD4232DFF1} canceled.
{16036C38-3F02-4EFB-948D-2743376F7BD4} canceled.
{ADF6C3B4-9E3F-45E0-8844-30C8B2DAE110} canceled.
58 out of 58 jobs canceled.
========= End of CMD: =========
The system needed a reboot.
==== End of Fixlog 20:17:51 ====