Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Popups taking over screen - Malware/Spyware


  • This topic is locked This topic is locked

#16
heyage13

heyage13

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts

It's running much better...no more pop ups.

 

Here are my logs:

 

FRST:

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2015
Ran by Amy (administrator) on AMY_LAPTOP on 10-05-2015 18:36:03
Running from C:\Users\Amy\Desktop
Loaded Profiles: Amy &  (Available profiles: Amy & amyca_000)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe
(DELL Inc.) C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Toaster.exe
() C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\BackgroundTransferHost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5762408 2013-06-03] (Dell Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Yahoo! Search] => C:\Users\amyca_000\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.25.0\dsrlte.exe
ShellIconOverlayIdentifiers: [DBARFileBackuped] -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\Windows\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DBARFileNotBackuped] -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\Windows\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3457434629-2911053778-409059968-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.search.yah...c_dsssyc_bd_com
HKU\S-1-5-21-3457434629-2911053778-409059968-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com/?pc=DCJB
HKU\S-1-5-21-3457434629-2911053778-409059968-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.search.yah...c_dsssyc_bd_com
HKU\S-1-5-21-3457434629-2911053778-409059968-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com/?pc=DCJB
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=na
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com/?pc=DCJB
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = 
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {A7DDB849-0C96-4F34-B268-2308D81C8BFC} URL = http://q.search-simp...rchTerms}&r=607
Tcpip\Parameters: [DhcpNameServer] 64.71.255.204 64.71.255.198
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-28] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-28] (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-01] (Google Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-25]
CHR Extension: (Google Docs) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-31]
CHR Extension: (Google Drive) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-31]
CHR Extension: (YouTube) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-31]
CHR Extension: (Google Search) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-31]
CHR Extension: (Google Sheets) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-25]
CHR Extension: (Bookmark Manager) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-04]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-22]
CHR Extension: (Google Wallet) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-31]
CHR Extension: (Gmail) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-31]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 Intel® Wireless Bluetooth® 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-10-15] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-28] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-10-11] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor)
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1915920 2013-11-21] (SoftThinks SAS)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
R2 WysePocketCloud; C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe [16176 2013-08-22] ()
R2 WyseRemoteAccess; C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe [1785344 2013-08-19] (DELL Inc.) [File not signed]
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3671792 2013-10-11] (Intel® Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-24] (OSR Open Systems Resources, Inc.)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [119240 2013-10-15] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-06] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverx64.sys [99288 2013-08-28] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3607520 2013-10-14] (Intel Corporation)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-09-06] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-09-06] (Synaptics Incorporated)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-05-10 18:36 - 2015-05-10 18:36 - 00014941 _____ () C:\Users\Amy\Desktop\FRST.txt
2015-05-10 18:35 - 2015-05-10 18:35 - 00000000 ____D () C:\Users\Amy\Desktop\FRST-OlderVersion
2015-05-06 20:31 - 2015-05-06 20:32 - 00289624 _____ () C:\Windows\Minidump\050615-19375-01.dmp
2015-05-06 20:24 - 2015-05-06 20:33 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-06 20:24 - 2015-05-06 20:24 - 00001116 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-06 20:24 - 2015-05-06 20:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-06 20:24 - 2015-05-06 20:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-06 20:24 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-06 20:24 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-06 20:24 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-06 18:24 - 2015-05-06 18:24 - 00289312 _____ () C:\Windows\Minidump\050615-23031-01.dmp
2015-05-05 22:50 - 2015-05-05 22:51 - 00289232 _____ () C:\Windows\Minidump\050515-24578-01.dmp
2015-05-05 22:40 - 2015-05-05 22:40 - 00289432 _____ () C:\Windows\Minidump\050515-25296-01.dmp
2015-05-05 22:32 - 2015-05-05 22:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-05 22:31 - 2015-05-05 22:31 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Amy\Desktop\mbam-setup-2.1.6.1022.exe
2015-05-05 22:27 - 2015-05-05 22:27 - 00000843 _____ () C:\Users\Amy\Desktop\AdwCleaner[R1].txt
2015-05-05 21:38 - 2015-05-06 20:29 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3457434629-2911053778-409059968-1001
2015-05-05 21:37 - 2015-05-05 21:37 - 00001074 _____ () C:\Users\Amy\Desktop\JRT.txt
2015-05-05 21:35 - 2015-05-05 21:35 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-AMY_LAPTOP-Windows-8.1-(64-bit).dat
2015-05-05 21:35 - 2015-05-05 21:35 - 00000000 ____D () C:\RegBackup
2015-05-05 21:34 - 2015-05-05 21:34 - 02716306 _____ (Thisisu) C:\Users\Amy\Desktop\JRT.exe
2015-05-05 21:30 - 2015-05-05 21:30 - 00002903 _____ () C:\Users\Amy\Desktop\AdwCleaner[R0].txt
2015-05-05 21:24 - 2015-05-05 22:28 - 00000000 ____D () C:\AdwCleaner
2015-05-05 21:23 - 2015-05-05 21:24 - 02204160 _____ () C:\Users\Amy\Desktop\adwcleaner_4.203.exe
2015-05-04 20:33 - 2015-05-04 20:33 - 00026588 _____ () C:\Users\Amy\Downloads\Addition.txt
2015-05-04 20:32 - 2015-05-04 20:33 - 00024246 _____ () C:\Users\Amy\Downloads\FRST.txt
2015-05-04 20:31 - 2015-05-10 18:36 - 00000000 ____D () C:\FRST
2015-05-04 20:31 - 2015-05-10 18:35 - 02102784 _____ (Farbar) C:\Users\Amy\Desktop\FRST64.exe
2015-05-04 20:29 - 2015-05-04 20:29 - 00000000 ____D () C:\63fa85a6a133d2e221a723a8
2015-05-04 19:42 - 2015-05-04 19:43 - 00288240 _____ () C:\Windows\Minidump\050415-31156-01.dmp
2015-05-04 18:29 - 2015-05-04 18:29 - 00291224 _____ () C:\Windows\Minidump\050415-33265-01.dmp
2015-04-25 15:29 - 2015-04-25 15:30 - 00000000 __RDO () C:\Users\amyca_000\SkyDrive
2015-04-25 15:26 - 2015-04-25 15:26 - 00000000 ____D () C:\Users\amyca_000\AppData\Roaming\Intel Corporation
2015-04-25 15:25 - 2015-04-25 15:25 - 00000000 ____D () C:\Users\amyca_000\AppData\Roaming\Apple Computer
2015-04-25 15:24 - 2015-04-25 15:28 - 00000000 ____D () C:\Users\amyca_000\AppData\Local\Packages
2015-04-25 15:24 - 2015-04-25 15:24 - 00001444 _____ () C:\Users\amyca_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-25 15:24 - 2015-04-25 15:24 - 00000000 ____D () C:\Users\amyca_000\AppData\Roaming\Adobe
2015-04-25 15:23 - 2015-04-25 15:23 - 00000000 ____D () C:\Users\amyca_000\AppData\Roaming\Intel
2015-04-25 15:23 - 2015-04-25 15:23 - 00000000 ____D () C:\Users\amyca_000\AppData\Local\VirtualStore
2015-04-25 15:23 - 2015-04-25 15:23 - 00000000 ____D () C:\Users\amyca_000\AppData\Local\Google
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-05-10 18:36 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\sru
2015-05-06 20:40 - 2014-03-08 20:55 - 00000000 ____D () C:\Program Files (x86)\Dell Backup and Recovery
2015-05-06 20:32 - 2013-08-22 09:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-06 20:31 - 2014-06-01 11:06 - 595173054 _____ () C:\Windows\MEMORY.DMP
2015-05-06 20:31 - 2014-06-01 11:06 - 00000000 ____D () C:\Windows\Minidump
2015-05-06 20:31 - 2014-03-08 20:06 - 00022896 _____ () C:\Windows\PFRO.log
2015-05-05 22:41 - 2014-05-30 20:30 - 00000000 ____D () C:\Users\Amy
2015-05-05 22:28 - 2014-03-08 20:40 - 02035198 _____ () C:\Windows\WindowsUpdate.log
2015-05-05 21:37 - 2014-03-08 20:24 - 00005640 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-05 21:37 - 2013-08-29 08:05 - 01516982 _____ () C:\Windows\system32\perfh00C.dat
2015-05-05 21:37 - 2013-08-29 08:05 - 00497164 _____ () C:\Windows\system32\perfc00C.dat
2015-05-05 21:31 - 2013-08-22 08:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2015-05-05 20:43 - 2014-10-19 15:16 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-05-05 20:41 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2015-05-05 20:41 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-05-05 20:40 - 2013-08-22 09:46 - 00018142 _____ () C:\Windows\setupact.log
2015-05-04 21:12 - 2013-08-22 08:25 - 00000226 _____ () C:\Windows\win.ini
2015-05-04 20:29 - 2014-05-30 20:33 - 00000000 ____D () C:\Users\Amy\AppData\Local\Packages
2015-05-04 20:25 - 2014-05-31 22:16 - 00002205 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-04 20:24 - 2014-05-31 22:14 - 00000928 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-04 20:24 - 2014-05-31 22:14 - 00000924 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-04 18:27 - 2014-11-25 16:34 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-30 00:12 - 2014-03-08 20:52 - 00000000 ____D () C:\ProgramData\McAfee
2015-04-30 00:12 - 2014-03-08 20:52 - 00000000 ____D () C:\Program Files (x86)\McAfee
2015-04-25 15:29 - 2014-08-04 00:27 - 00000000 ____D () C:\Users\amyca_000
2015-04-25 15:25 - 2014-05-30 20:35 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
 
==================== Files in the root of some directories =======
 
2014-03-08 20:10 - 2014-03-08 20:10 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-03-10 18:19 - 2015-03-10 18:19 - 0000032 _____ () C:\ProgramData\Temp.log
2014-03-08 20:48 - 2014-03-08 20:49 - 0000121 _____ () C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log
2014-03-08 20:44 - 2014-03-08 20:46 - 0000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log
2014-03-08 20:46 - 2014-03-08 20:47 - 0000111 _____ () C:\ProgramData\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}.log
2014-03-08 20:47 - 2014-03-08 20:48 - 0000108 _____ () C:\ProgramData\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}.log
2014-03-08 20:44 - 2014-03-08 20:44 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
 
Some content of TEMP:
====================
C:\Users\Amy\AppData\Local\Temp\Quarantine.exe
C:\Users\Amy\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-05-04 20:29
 
==================== End Of Log ============================
 
ADDITION Log:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-05-2015
Ran by Amy at 2015-05-10 18:36:58
Running from C:\Users\Amy\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3457434629-2911053778-409059968-500 - Administrator - Disabled)
Amy (S-1-5-21-3457434629-2911053778-409059968-1001 - Administrator - Enabled) => C:\Users\Amy
amyca_000 (S-1-5-21-3457434629-2911053778-409059968-1004 - Limited - Enabled) => C:\Users\amyca_000
Guest (S-1-5-21-3457434629-2911053778-409059968-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3457434629-2911053778-409059968-1003 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Amazon 1Button App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.4 - Amazon)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Backup and Recovery - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 1.6.2.0 - Dell Inc.)
Dell Backup and Recovery (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.6.2.0 - Dell Inc.)
Dell Product Registration (HKLM-x32\...\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.16.1 - Dell Inc.)
Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 17.0.13.0 - Synaptics Incorporated)
DSC/AA Factory Installer (Version: 3.4.6299.48 - PC-Doctor, Inc.) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.135 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3316 - Intel Corporation)
Intel® PROSet/Wireless Software for Bluetooth® Technology(patch version 3.0.1342.1) (HKLM\...\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{6882ac6d-e97d-4e25-b3ea-5f3f21055dfe}) (Version: 16.6.0 - Intel Corporation)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
My Dell (HKLM\...\PC-Doctor for Windows) (Version: 3.4.6299.48 - PC-Doctor, Inc.)
PocketCloud (HKLM-x32\...\{D9752C7D-A595-4687-A0D5-362E9C311C55}) (Version: 2.7.14 - Wyse Technology)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.15.021 - Dell Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7023 - Realtek Semiconductor Corp.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Yahoo! Search (HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Yahoo! Search) (Version:  - Pay-By-Ads) <==== ATTENTION
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
 
==================== Restore Points  =========================
 
22-03-2015 19:11:45 Windows Update
25-04-2015 15:22:51 Windows Update
30-04-2015 00:03:54 Windows Update
04-05-2015 19:38:11 Windows Update
04-05-2015 20:12:07 RCP Mon, May 04, 15  20:12
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 08:25 - 2015-05-05 20:42 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {17A5B96C-F541-4DBE-A2EE-01AB16673841} - System32\Tasks\PocketCloudUpdater => C:\Program
Task: {342F72EE-D159-4AEC-A4B3-025759C5228F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-04-01] (Microsoft Corporation)
Task: {6123547C-3345-41F2-8B24-55D221208CB3} - \PCDEventLauncherTask No Task File <==== ATTENTION
Task: {6C9C3AE3-8FF6-48E0-A081-D5C6A28E7F4A} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {79D47F2C-9682-4FFC-93CB-2724844721EB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-31] (Google Inc.)
Task: {88F2864D-D744-407E-B40C-2EBFF9FB9A40} - System32\Tasks\PocketCloud => C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe [2013-08-22] ()
Task: {9BA2146E-B36F-4353-A9AA-D38F939B2C3E} - System32\Tasks\Dell\Dell System Registration => C:\Program Files (x86)\System Registration\prodreg.exe [2012-07-09] (Dell, Inc.)
Task: {AB0EE9FA-436D-47B5-9E5E-AC805F504299} - System32\Tasks\PocketCloudVirtualChannel => C:\Program Files (x86)\Wyse\PocketCloud\WPCRDPVirtualChannelServer.exe [2013-08-22] ()
Task: {B5FADBA0-1908-4E53-B0CB-35711B8FD336} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {BA993297-4C85-4F2E-AE85-4C8F631F736B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-31] (Google Inc.)
Task: {C6E0A303-0F06-4C26-9435-AE518F633CC5} - \Optimize Start Menu Cache Files-S-1-5-21-3457434629-2911053778-409059968-1004 No Task File <==== ATTENTION
Locked "{CFFB31DB-A07D-4569-B954-E2169057BBE6}" task was unlocked successfully. <===== ATTENTION
Task: {D1586CD3-62B1-41BD-9327-F07E279D881A} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-09-06] (Synaptics Incorporated)
Task: {D51B86B3-023B-45C0-A765-8DDD7AF7CDF3} - \PCDoctorBackgroundMonitorTask No Task File <==== ATTENTION
Locked "{F9656F1E-91A0-45AC-94C9-FB3ED31E915D}" task was unlocked successfully. <===== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) ==============
 
2013-08-22 14:40 - 2013-08-22 14:40 - 00016176 _____ () C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe
2013-08-22 14:40 - 2013-08-22 14:40 - 00040240 _____ () C:\Program Files (x86)\Wyse\PocketCloud\AetherServiceLib.dll
2013-08-22 14:40 - 2013-08-22 14:40 - 00046384 _____ () C:\Program Files (x86)\Wyse\PocketCloud\AetherHelperLib.dll
2014-03-08 20:56 - 2013-08-19 12:21 - 00020256 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIcon.dll
2014-03-08 20:56 - 2013-08-19 12:21 - 00019232 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayNotBackuped.dll
2014-03-08 20:56 - 2013-11-21 20:22 - 00484880 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-05-04 20:25 - 2015-04-27 21:07 - 01252680 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libglesv2.dll
2015-05-04 20:25 - 2015-04-27 21:07 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libegl.dll
2014-03-08 20:39 - 2013-08-28 05:02 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2014-03-08 20:56 - 2013-11-21 18:00 - 01904928 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\STRestoreAPI.dll
2014-03-08 20:56 - 2012-11-26 01:20 - 01153384 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\libxml2.dll
2014-03-08 20:56 - 2012-11-26 01:20 - 00117608 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\zlib1.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\Users\Amy\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\amyca_000\SkyDrive:ms-properties
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3457434629-2911053778-409059968-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\dell\BlueLava_1112000xx_inspiron_wallpaper58095_16x9_72dpi_RGB.jpg
HKU\S-1-5-21-3457434629-2911053778-409059968-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\dell\BlueLava_1112000xx_inspiron_wallpaper58095_16x9_72dpi_RGB.jpg
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\dell\BlueLava_1112000xx_inspiron_wallpaper58095_16x9_72dpi_RGB.jpg
DNS Servers: 64.71.255.204 - 64.71.255.198
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{0894B932-D8EC-4138-9B7C-F1BCCFEF78A6}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{F6F5C8B5-79B2-4214-8C8E-68FE171A9431}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe
FirewallRules: [{C832C1F8-EF32-48A8-8B6E-62CB6C2F3E83}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\AetherWindowsService.exe
FirewallRules: [{9CDA5007-AAE0-442F-8D6A-8D65ED28BFF3}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe
FirewallRules: [{4CD1EFE0-BB60-40AC-934D-D57F36FA2788}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{A4188666-C929-460A-9A1E-590B45943D10}] => (Allow) LPort=2869
FirewallRules: [{D47FCBC8-78C7-4362-8C6B-9514FD24551B}] => (Allow) LPort=1900
FirewallRules: [{51633A0B-FE0B-4E7D-A46B-343C9B1C6C7D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{B22066F5-BE4D-4AD7-8217-074D415954D9}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{86716175-A31A-4B23-870E-5676DD3F67CA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1F3E48E9-2B47-44C2-9EC5-DBD944434D00}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B8E2A9EB-1A0A-44E7-BF0A-A1DE74BEC3EE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{5CEE3C91-DE7F-4A4C-AD9E-42F0800F671B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4C1A3792-41CD-4E59-9451-D4B7D65FD626}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{AA38818E-9D1C-48BF-BB49-227DA8383A2C}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{97BFB331-FD37-4C2E-8C7B-E6DC5A9F997D}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{61D212CD-ECC0-453C-A057-C9B54669D553}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/06/2015 08:33:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ZeroConfigService.exe, version: 16.6.0.0, time stamp: 0x52585e22
Faulting module name: MurocApi.dll, version: 16.6.0.0, time stamp: 0x52585cf1
Exception code: 0xc0000005
Fault offset: 0x000000000002bcd8
Faulting process id: 0x888
Faulting application start time: 0xZeroConfigService.exe0
Faulting application path: ZeroConfigService.exe1
Faulting module path: ZeroConfigService.exe2
Report Id: ZeroConfigService.exe3
Faulting package full name: ZeroConfigService.exe4
Faulting package-relative application ID: ZeroConfigService.exe5
 
Error: (05/05/2015 10:51:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ZeroConfigService.exe, version: 16.6.0.0, time stamp: 0x52585e22
Faulting module name: MurocApi.dll, version: 16.6.0.0, time stamp: 0x52585cf1
Exception code: 0xc0000005
Fault offset: 0x000000000002bcd8
Faulting process id: 0x88c
Faulting application start time: 0xZeroConfigService.exe0
Faulting application path: ZeroConfigService.exe1
Faulting module path: ZeroConfigService.exe2
Report Id: ZeroConfigService.exe3
Faulting package full name: ZeroConfigService.exe4
Faulting package-relative application ID: ZeroConfigService.exe5
 
Error: (05/05/2015 10:28:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: AMY_LAPTOP)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (05/05/2015 09:37:23 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (05/05/2015 09:37:23 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (05/05/2015 09:37:23 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (05/05/2015 08:48:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (05/05/2015 08:48:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (05/05/2015 08:48:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (05/05/2015 03:16:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9500
 
 
System errors:
=============
Error: (05/06/2015 08:33:05 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® PROSet/Wireless Zero Configuration Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (05/06/2015 08:32:27 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x0000007a (0x0000000000000001, 0xffffffffc0000005, 0xffffe00008c25080, 0xfffff6fac003c000)C:\Windows\MEMORY.DMP050615-19375-01
 
Error: (05/06/2015 08:32:18 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942405.
 
Error: (05/06/2015 08:32:18 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942405.
 
Error: (05/06/2015 08:32:00 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 6:24:21 PM on ‎2015-‎05-‎06 was unexpected.
 
Error: (05/06/2015 08:21:16 PM) (Source: DCOM) (EventID: 10010) (User: AMY_LAPTOP)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
 
Error: (05/06/2015 06:24:37 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x0000001a (0x0000000000041792, 0xfffff6800008b1e0, 0x0040000000000000, 0x0000000000000000)C:\Windows\MEMORY.DMP050615-23031-01
 
Error: (05/06/2015 06:24:34 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942405.
 
Error: (05/06/2015 06:24:34 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942405.
 
Error: (05/06/2015 06:24:20 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:50:46 PM on ‎2015-‎05-‎05 was unexpected.
 
 
Microsoft Office Sessions:
=========================
Error: (05/06/2015 08:33:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ZeroConfigService.exe16.6.0.052585e22MurocApi.dll16.6.0.052585cf1c0000005000000000002bcd888801d08865b4a173abC:\Program Files\Intel\WiFi\bin\ZeroConfigService.exeC:\Program Files\Intel\WiFi\bin\MurocApi.dll00137ebc-f459-11e4-82d1-ac7ba11b386f
 
Error: (05/05/2015 10:51:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ZeroConfigService.exe16.6.0.052585e22MurocApi.dll16.6.0.052585cf1c0000005000000000002bcd888c01d087afe9d07093C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exeC:\Program Files\Intel\WiFi\bin\MurocApi.dll36ca69d2-f3a3-11e4-82cf-ac7ba11b386f
 
Error: (05/05/2015 10:28:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: AMY_LAPTOP)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141
 
Error: (05/05/2015 09:37:23 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: WmiApRplWmiApRpl8F2030000E5050000
 
Error: (05/05/2015 09:37:23 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Performance163707000000000000000000008F020000
 
Error: (05/05/2015 09:37:23 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Performance163707000000000000000000008F020000
 
Error: (05/05/2015 08:48:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: WmiApRplWmiApRpl8F2030000E5050000
 
Error: (05/05/2015 08:48:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Performance163707000000000000000000008F020000
 
Error: (05/05/2015 08:48:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Performance163707000000000000000000008F020000
 
Error: (05/05/2015 03:16:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9500
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-05-05 21:25:07.705
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-05-05 21:25:07.596
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-4200U CPU @ 1.60GHz
Percentage of memory in use: 26%
Total physical RAM: 8072.96 MB
Available physical RAM: 5894.39 MB
Total Pagefile: 16264.96 MB
Available Pagefile: 13678.64 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:920.6 GB) (Free:785.5 GB) NTFS
Drive x: (WINRETOOLS) (Fixed) (Total:2 GB) (Free:1.69 GB) NTFS
Drive y: (PBR Image) (Fixed) (Total:8.26 GB) (Free:0.73 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 3E436CEC)
 
Partition: GPT Partition Type.
 
==================== End Of Log ============================

  • 0

Advertisements


#17
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
A few items to fix

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.

CreateRestorePoint:
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Yahoo! Search] => C:\Users\amyca_000\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.25.0\dsrlte.exe
HKU\S-1-5-21-3457434629-2911053778-409059968-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.search.yah...c_dsssyc_bd_com
HKU\S-1-5-21-3457434629-2911053778-409059968-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.search.yah...c_dsssyc_bd_com
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=na
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = 
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {A7DDB849-0C96-4F34-B268-2308D81C8BFC} URL = http://q.search-simp...rchTerms}&r=607
C:\Users\Amy\AppData\Local\Temp\Quarantine.exe
C:\Users\Amy\AppData\Local\Temp\sqlite3.dll
Yahoo! Search (HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Yahoo! Search) (Version:  - Pay-By-Ads) <==== ATTENTION
Task: {6123547C-3345-41F2-8B24-55D221208CB3} - \PCDEventLauncherTask No Task File <==== ATTENTION
Task: {C6E0A303-0F06-4C26-9435-AE518F633CC5} - \Optimize Start Menu Cache Files-S-1-5-21-3457434629-2911053778-409059968-1004 No Task File <==== ATTENTION
Locked "{CFFB31DB-A07D-4569-B954-E2169057BBE6}" task was unlocked successfully. <===== ATTENTION
Task: {D51B86B3-023B-45C0-A765-8DDD7AF7CDF3} - \PCDoctorBackgroundMonitorTask No Task File <==== ATTENTION
Locked "{F9656F1E-91A0-45AC-94C9-FB3ED31E915D}" task was unlocked successfully. <===== ATTENTION
AlternateDataStreams: C:\Users\Amy\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\amyca_000\SkyDrive:ms-properties
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
Emptytemp:
Click Format and ensure Wordwrap is unchecked.
Save as Fixlist.txt to your Desktop (Must be in this location)
Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.


Post the fixlog.txt in you next reply. That log will be found on the desktop after fix has run.

Thanks
Joe :)
  • 0

#18
heyage13

heyage13

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-05-2015
Ran by Amy at 2015-05-12 19:18:49 Run:2
Running from C:\Users\Amy\Desktop
Loaded Profiles: Amy &  (Available profiles: Amy & amyca_000)
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
CreateRestorePoint:
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Yahoo! Search] => C:\Users\amyca_000\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.25.0\dsrlte.exe
HKU\S-1-5-21-3457434629-2911053778-409059968-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.search.yah...c_dsssyc_bd_com
HKU\S-1-5-21-3457434629-2911053778-409059968-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.search.yah...c_dsssyc_bd_com
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=na
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = 
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {A7DDB849-0C96-4F34-B268-2308D81C8BFC} URL = http://q.search-simp...rchTerms}&r=607
C:\Users\Amy\AppData\Local\Temp\Quarantine.exe
C:\Users\Amy\AppData\Local\Temp\sqlite3.dll
Yahoo! Search (HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Yahoo! Search) (Version:  - Pay-By-Ads) <==== ATTENTION
Task: {6123547C-3345-41F2-8B24-55D221208CB3} - \PCDEventLauncherTask No Task File <==== ATTENTION
Task: {C6E0A303-0F06-4C26-9435-AE518F633CC5} - \Optimize Start Menu Cache Files-S-1-5-21-3457434629-2911053778-409059968-1004 No Task File <==== ATTENTION
Locked "{CFFB31DB-A07D-4569-B954-E2169057BBE6}" task was unlocked successfully. <===== ATTENTION
Task: {D51B86B3-023B-45C0-A765-8DDD7AF7CDF3} - \PCDoctorBackgroundMonitorTask No Task File <==== ATTENTION
Locked "{F9656F1E-91A0-45AC-94C9-FB3ED31E915D}" task was unlocked successfully. <===== ATTENTION
AlternateDataStreams: C:\Users\Amy\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\amyca_000\SkyDrive:ms-properties
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
Emptytemp:
*****************
 
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully.
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Run\\Yahoo! Search => value deleted successfully.
HKU\S-1-5-21-3457434629-2911053778-409059968-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKU\S-1-5-21-3457434629-2911053778-409059968-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A7DDB849-0C96-4F34-B268-2308D81C8BFC}" => Key deleted successfully.
HKCR\CLSID\{A7DDB849-0C96-4F34-B268-2308D81C8BFC} => Key not found. 
C:\Users\Amy\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Amy\AppData\Local\Temp\sqlite3.dll => Moved successfully.
Yahoo! Search (HKU\S-1-5-21-3457434629-2911053778-409059968-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Yahoo! Search) (Version:  - Pay-By-Ads) <==== ATTENTION => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6123547C-3345-41F2-8B24-55D221208CB3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6123547C-3345-41F2-8B24-55D221208CB3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCDEventLauncherTask" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C6E0A303-0F06-4C26-9435-AE518F633CC5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6E0A303-0F06-4C26-9435-AE518F633CC5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimize Start Menu Cache Files-S-1-5-21-3457434629-2911053778-409059968-1004" => Key deleted successfully.
Locked "{CFFB31DB-A07D-4569-B954-E2169057BBE6}" task was unlocked successfully. <===== ATTENTION => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D51B86B3-023B-45C0-A765-8DDD7AF7CDF3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D51B86B3-023B-45C0-A765-8DDD7AF7CDF3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCDoctorBackgroundMonitorTask" => Key deleted successfully.
Locked "{F9656F1E-91A0-45AC-94C9-FB3ED31E915D}" task was unlocked successfully. <===== ATTENTION => Error: No automatic fix found for this entry.
"C:\Users\Amy\SkyDrive" => ":ms-properties" ADS not found.
"C:\Users\amyca_000\SkyDrive" => ":ms-properties" ADS not found.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc" => Key deleted successfully.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc" => Key deleted successfully.
EmptyTemp: => Removed 82.8 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 19:19:52 ====

  • 0

#19
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hello, we're getting near the end :)

ESET Online Scanner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.
  • Please go >>HERE<< then click on: ESET1st.jpg

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on the ESETexe.jpg icon to install.

    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: ESETsave.jpg
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: EOLS3.gif
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed make sure you first copy the logfile located at C:\Program Files (x86)\ESET\Esetonlinescanner\log.txt).
  • Copy and paste that log as a reply to this topic.
  • Now click on: EOLS4.gif
    (Selecting Uninstall application on close if you so wish)
Next

Download Security Check by screen317 from Here or Here
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE: If SecurityCheck aborts and you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED! try rebooting the system and then run SecurityCheck again.

In your next reply;
Post the ESET scan results
Post checkup.txt

Thanks
Joe :)
  • 0

#20
heyage13

heyage13

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts

Very strange but i tried completing the scan 3 times and each time I received the same error as before when trying to complete the Malware Bytes scan...


  • 0

#21
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
That is strange, this error you're getting ?

KERNEL_DATA_INPAGE_ERROR
  • 0

#22
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP