Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Popups taking over screen - Malware/Spyware


  • This topic is locked This topic is locked

#1
heyage13

heyage13

    Member

  • Member
  • PipPipPip
  • 132 posts

Hello I believe my computer is infected with malware and or spyware. Popups are constantly populating on mys screen at all corners. 

 

The popups have the label "Ads by Deal Keeper"

 

Help is needed and much appreciated as always :)

 

FRST Log:

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-05-2015
Ran by Amy (administrator) on AMY_LAPTOP on 04-05-2015 20:32:15
Running from C:\Users\Amy\Downloads
Loaded Profiles: Amy (Available profiles: Amy & amyca_000)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files (x86)\Deal Keeper\updateDealKeeper.exe
() C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe
(DELL Inc.) C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.PurBrowse64.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(RCP) C:\Program Files (x86)\RCP\RegCleanPro.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BrowserAdapter64.exe
() C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BrowserAdapter.exe
() C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BOASHelper.exe
() C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.expext.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Pay By Ads LTD) C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BOASPRT.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BOAS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\ByteCodeGenerator.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5762408 2013-06-03] (Dell Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3457434629-2911053778-409059968-1001\...\Run: [Yahoo! Search] => C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe [644816 2015-03-22] (Pay By Ads LTD)
Startup: C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2014-07-21]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (No File)
ShellIconOverlayIdentifiers: [DBARFileBackuped] -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\Windows\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DBARFileNotBackuped] -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\Windows\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3457434629-2911053778-409059968-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.search.yah...c_dsssyc_bd_com
HKU\S-1-5-21-3457434629-2911053778-409059968-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com/?pc=DCJB
SearchScopes: HKLM -> DefaultScope {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = http://rocket-find.c...r=609539609&ir=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = http://rocket-find.c...r=609539609&ir=
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> DefaultScope {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = http://q.search-simp...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> OldSearch URL = http://rocket-find.c...r=609539609&ir=
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = http://q.search-simp...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> {237FDB45-B214-48E0-BBED-D888F86CC633} URL = http://q.search-simp...rchTerms}&r=726
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
Tcpip\Parameters: [DhcpNameServer] 64.71.255.204 64.71.255.198
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-28] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-28] (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-01] (Google Inc.)
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR RestoreOnStartup: Default -> "hxxp://ca.search.yahoo.com/?fr=hp-ddc-bd&type=124_pr__alt__ddc_dsssyc_bd_com"
CHR StartupUrls: Default -> "hxxp://ca.search.yahoo.com/?fr=hp-ddc-bd&type=124_pr__alt__ddc_dsssyc_bd_com"
CHR DefaultSearchKeyword: Default -> yahoo.com
CHR DefaultNewTabURL: Default -> http://ca.search.yah...sssyctab_bd_com
CHR DefaultSuggestURL: Default -> 
CHR Profile: C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-25]
CHR Extension: (Google Docs) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-31]
CHR Extension: (Google Drive) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-31]
CHR Extension: (YouTube) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-31]
CHR Extension: (Google Search) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-31]
CHR Extension: (Deal Keeper) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eencbeelgfacnhekfiklkobllfleohce [2014-10-19]
CHR Extension: (Google Sheets) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-25]
CHR Extension: (Bookmark Manager) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-04]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-22]
CHR Extension: (Google Wallet) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-31]
CHR Extension: (Gmail) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-31]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [53320 2014-11-13] (Just Develop It) <==== ATTENTION
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 Intel® Wireless Bluetooth® 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-10-15] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-28] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-10-11] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor)
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1915920 2013-11-21] (SoftThinks SAS)
R2 Update Deal Keeper; C:\Program Files (x86)\Deal Keeper\updateDealKeeper.exe [651504 2015-05-04] ()
R2 Util Deal Keeper; C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe [651504 2015-05-04] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
R2 WysePocketCloud; C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe [16176 2013-08-22] ()
R2 WyseRemoteAccess; C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe [1785344 2013-08-19] (DELL Inc.) [File not signed]
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3671792 2013-10-11] (Intel® Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-24] (OSR Open Systems Resources, Inc.)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [119240 2013-10-15] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverx64.sys [99288 2013-08-28] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3607520 2013-10-14] (Intel Corporation)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-09-06] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-09-06] (Synaptics Incorporated)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
R1 {55dce8ba-9dec-4013-937e-adbf9317d990}Gw64; C:\Windows\System32\drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}Gw64.sys [61120 2014-07-21] (StdLib)
R1 {55dce8ba-9dec-4013-937e-adbf9317d990}w64; C:\Windows\System32\drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}w64.sys [61072 2014-07-30] (StdLib)
R1 {7e4355b8-96cd-43eb-b59a-82af29f01b16}w64; C:\Windows\System32\drivers\{7e4355b8-96cd-43eb-b59a-82af29f01b16}w64.sys [48784 2014-11-23] (StdLib)
R1 {af7618ea-6d4f-47e5-9e06-5f808487ae22}w64; C:\Windows\System32\drivers\{af7618ea-6d4f-47e5-9e06-5f808487ae22}w64.sys [48784 2014-10-19] (StdLib)
R1 {eb8709c5-52a2-49ef-9341-2b49aaf413b8}w64; C:\Windows\System32\drivers\{eb8709c5-52a2-49ef-9341-2b49aaf413b8}w64.sys [48784 2015-03-01] (StdLib)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-05-04 20:32 - 2015-05-04 20:32 - 00017720 _____ () C:\Users\Amy\Downloads\FRST.txt
2015-05-04 20:31 - 2015-05-04 20:32 - 00000000 ____D () C:\FRST
2015-05-04 20:31 - 2015-05-04 20:31 - 02101248 _____ (Farbar) C:\Users\Amy\Downloads\FRST64.exe
2015-05-04 20:29 - 2015-05-04 20:29 - 00000000 ____D () C:\63fa85a6a133d2e221a723a8
2015-05-04 19:42 - 2015-05-04 19:43 - 00288240 _____ () C:\Windows\Minidump\050415-31156-01.dmp
2015-05-04 18:29 - 2015-05-04 18:29 - 00291224 _____ () C:\Windows\Minidump\050415-33265-01.dmp
2015-04-25 16:34 - 2015-04-25 16:34 - 00000000 ____D () C:\Users\amyca_000\AppData\Local\Pay-By-Ads
2015-04-25 15:30 - 2015-04-25 15:37 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3457434629-2911053778-409059968-1004
2015-04-25 15:29 - 2015-04-25 15:30 - 00000000 __RDO () C:\Users\amyca_000\SkyDrive
2015-04-25 15:26 - 2015-04-25 15:26 - 00000000 ____D () C:\Users\amyca_000\AppData\Roaming\Intel Corporation
2015-04-25 15:25 - 2015-04-25 15:25 - 00000000 ____D () C:\Users\amyca_000\AppData\Roaming\Apple Computer
2015-04-25 15:24 - 2015-04-25 15:28 - 00000000 ____D () C:\Users\amyca_000\AppData\Local\Packages
2015-04-25 15:24 - 2015-04-25 15:24 - 00001444 _____ () C:\Users\amyca_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-25 15:24 - 2015-04-25 15:24 - 00000000 ____D () C:\Users\amyca_000\AppData\Roaming\Adobe
2015-04-25 15:23 - 2015-04-25 15:23 - 00000000 ____D () C:\Users\amyca_000\AppData\Roaming\Intel
2015-04-25 15:23 - 2015-04-25 15:23 - 00000000 ____D () C:\Users\amyca_000\AppData\Local\VirtualStore
2015-04-25 15:23 - 2015-04-25 15:23 - 00000000 ____D () C:\Users\amyca_000\AppData\Local\Google
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-05-04 20:31 - 2014-03-08 20:40 - 01122109 _____ () C:\Windows\WindowsUpdate.log
2015-05-04 20:31 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-05-04 20:29 - 2014-05-30 20:33 - 00000000 ____D () C:\Users\Amy\AppData\Local\Packages
2015-05-04 20:25 - 2014-05-31 22:16 - 00002205 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-04 20:24 - 2014-05-31 22:14 - 00000928 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-04 20:24 - 2014-05-31 22:14 - 00000924 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-04 20:23 - 2014-05-30 20:39 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3457434629-2911053778-409059968-1001
2015-05-04 20:22 - 2014-07-21 22:26 - 00003090 _____ () C:\Windows\System32\Tasks\RegClean Pro
2015-05-04 20:20 - 2014-10-03 18:28 - 00001332 _____ () C:\Users\Amy\Desktop\Clean Registry for Free!.lnk
2015-05-04 20:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\sru
2015-05-04 19:47 - 2014-03-08 20:24 - 00005640 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-04 19:47 - 2013-08-29 08:05 - 01480786 _____ () C:\Windows\system32\perfh00C.dat
2015-05-04 19:47 - 2013-08-29 08:05 - 00479816 _____ () C:\Windows\system32\perfc00C.dat
2015-05-04 19:46 - 2014-03-08 20:55 - 00000000 ____D () C:\Program Files (x86)\Dell Backup and Recovery
2015-05-04 19:45 - 2014-05-30 20:30 - 00000000 ____D () C:\Users\Amy
2015-05-04 19:44 - 2014-07-21 22:27 - 00000000 ____D () C:\Program Files (x86)\Deal Keeper
2015-05-04 19:44 - 2013-08-22 08:25 - 00000226 _____ () C:\Windows\win.ini
2015-05-04 19:43 - 2013-08-22 09:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-04 19:42 - 2014-06-01 11:06 - 691903280 _____ () C:\Windows\MEMORY.DMP
2015-05-04 19:42 - 2014-06-01 11:06 - 00000000 ____D () C:\Windows\Minidump
2015-05-04 18:27 - 2014-11-25 16:34 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-30 00:20 - 2013-08-22 09:46 - 00017299 _____ () C:\Windows\setupact.log
2015-04-30 00:12 - 2014-03-08 20:52 - 00000000 ____D () C:\ProgramData\McAfee
2015-04-30 00:12 - 2014-03-08 20:52 - 00000000 ____D () C:\Program Files (x86)\McAfee
2015-04-30 00:11 - 2013-08-22 08:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2015-04-25 15:29 - 2014-08-04 00:27 - 00000000 ____D () C:\Users\amyca_000
2015-04-25 15:25 - 2014-05-30 20:35 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
 
==================== Files in the root of some directories =======
 
2014-03-08 20:10 - 2014-03-08 20:10 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-03-10 18:19 - 2015-03-10 18:19 - 0000032 _____ () C:\ProgramData\Temp.log
2014-03-08 20:48 - 2014-03-08 20:49 - 0000121 _____ () C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log
2014-03-08 20:44 - 2014-03-08 20:46 - 0000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log
2014-03-08 20:46 - 2014-03-08 20:47 - 0000111 _____ () C:\ProgramData\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}.log
2014-03-08 20:47 - 2014-03-08 20:48 - 0000108 _____ () C:\ProgramData\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}.log
2014-03-08 20:44 - 2014-03-08 20:44 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
 
Some content of TEMP:
====================
C:\Users\Amy\AppData\Local\Temp\CloudBackup7066.exe
C:\Users\Amy\AppData\Local\Temp\RocketUpdate.exe
C:\Users\Amy\AppData\Local\Temp\vcredist_x64.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-05-04 20:29
 
==================== End Of Log ============================
 
ADDITION Log:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-05-2015
Ran by Amy at 2015-05-04 20:33:13
Running from C:\Users\Amy\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3457434629-2911053778-409059968-500 - Administrator - Disabled)
Amy (S-1-5-21-3457434629-2911053778-409059968-1001 - Administrator - Enabled) => C:\Users\Amy
amyca_000 (S-1-5-21-3457434629-2911053778-409059968-1004 - Limited - Enabled) => C:\Users\amyca_000
Guest (S-1-5-21-3457434629-2911053778-409059968-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3457434629-2911053778-409059968-1003 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Amazon 1Button App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.4 - Amazon)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Buzzdock (HKLM\...\{ac225167-00fc-452d-94c5-bb93600e7d9a}) (Version:  - Alactro LLC) <==== ATTENTION
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deal Keeper (HKLM\...\Deal Keeper) (Version: 2014.07.22.013919 - Deal Keeper) <==== ATTENTION
Dell Backup and Recovery - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 1.6.2.0 - Dell Inc.)
Dell Backup and Recovery (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.6.2.0 - Dell Inc.)
Dell Product Registration (HKLM-x32\...\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.16.1 - Dell Inc.)
Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 17.0.13.0 - Synaptics Incorporated)
DSC/AA Factory Installer (Version: 3.4.6299.48 - PC-Doctor, Inc.) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.135 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3316 - Intel Corporation)
Intel® PROSet/Wireless Software for Bluetooth® Technology(patch version 3.0.1342.1) (HKLM\...\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{6882ac6d-e97d-4e25-b3ea-5f3f21055dfe}) (Version: 16.6.0 - Intel Corporation)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
My Dell (HKLM\...\PC-Doctor for Windows) (Version: 3.4.6299.48 - PC-Doctor, Inc.)
MyPC Backup  (HKLM\...\MyPC Backup) (Version:  - JDi Backup Ltd) <==== ATTENTION
PocketCloud (HKLM-x32\...\{D9752C7D-A595-4687-A0D5-362E9C311C55}) (Version: 2.7.14 - Wyse Technology)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.15.021 - Dell Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7023 - Realtek Semiconductor Corp.)
RegClean-Pro (HKLM-x32\...\RegClean-Pro_is1) (Version: 6.21 - Systweak Inc) <==== ATTENTION
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Yahoo! Search (HKU\S-1-5-21-3457434629-2911053778-409059968-1001\...\Yahoo! Search) (Version:  - Pay-By-Ads) <==== ATTENTION
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
 
==================== Restore Points  =========================
 
24-11-2014 23:14:47 Installed iTunes
10-03-2015 18:09:41 Windows Update
22-03-2015 19:11:45 Windows Update
25-04-2015 15:22:51 Windows Update
30-04-2015 00:03:54 Windows Update
04-05-2015 19:38:11 Windows Update
04-05-2015 20:12:07 RCP Mon, May 04, 15  20:12
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {14D00A86-E52B-4F56-A122-4F691D74FB75} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-16] (RCP) <==== ATTENTION
Task: {17A5B96C-F541-4DBE-A2EE-01AB16673841} - System32\Tasks\PocketCloudUpdater => C:\Program
Task: {342F72EE-D159-4AEC-A4B3-025759C5228F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-04-01] (Microsoft Corporation)
Task: {6123547C-3345-41F2-8B24-55D221208CB3} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2013-08-21] (PC-Doctor, Inc.)
Task: {6C9C3AE3-8FF6-48E0-A081-D5C6A28E7F4A} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {74866D04-85E5-41AB-95FE-FD2404066C0B} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-16] (RCP) <==== ATTENTION
Task: {79D47F2C-9682-4FFC-93CB-2724844721EB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-31] (Google Inc.)
Task: {8227E9C7-974C-4996-9CF3-843C0332A411} - System32\Tasks\ASP => C:\Program Files (x86)\RegClean Pro\SystweakASP.exe <==== ATTENTION
Task: {88F2864D-D744-407E-B40C-2EBFF9FB9A40} - System32\Tasks\PocketCloud => C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe [2013-08-22] ()
Task: {9BA2146E-B36F-4353-A9AA-D38F939B2C3E} - System32\Tasks\Dell\Dell System Registration => C:\Program Files (x86)\System Registration\prodreg.exe [2012-07-09] (Dell, Inc.)
Task: {9F09FE05-26C7-454F-BB3D-8A513DD33FA3} - System32\Tasks\Yahoo! Search => C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe [2015-03-22] (Pay By Ads LTD) <==== ATTENTION
Task: {AB0EE9FA-436D-47B5-9E5E-AC805F504299} - System32\Tasks\PocketCloudVirtualChannel => C:\Program Files (x86)\Wyse\PocketCloud\WPCRDPVirtualChannelServer.exe [2013-08-22] ()
Task: {AB3ED129-70F5-49C3-94E9-C6FD329361A3} - System32\Tasks\Yahoo! Search Updater => C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrsetup.exe [2015-03-22] (Pay By Ads LTD) <==== ATTENTION
Task: {B5FADBA0-1908-4E53-B0CB-35711B8FD336} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {BA993297-4C85-4F2E-AE85-4C8F631F736B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-31] (Google Inc.)
Task: {D1586CD3-62B1-41BD-9327-F07E279D881A} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-09-06] (Synaptics Incorporated)
Task: {D51B86B3-023B-45C0-A765-8DDD7AF7CDF3} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2013-08-21] (PC-Doctor, Inc.)
Task: {F055F4CB-042B-4468-8EA0-5F394B54E555} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-16] (RCP) <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
 
==================== Loaded Modules (whitelisted) ==============
 
2014-07-21 20:39 - 2015-05-04 20:03 - 00651504 _____ () C:\Program Files (x86)\Deal Keeper\updateDealKeeper.exe
2014-07-21 23:28 - 2015-05-04 20:02 - 00651504 _____ () C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe
2013-08-22 14:40 - 2013-08-22 14:40 - 00016176 _____ () C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe
2013-08-22 14:40 - 2013-08-22 14:40 - 00040240 _____ () C:\Program Files (x86)\Wyse\PocketCloud\AetherServiceLib.dll
2013-08-22 14:40 - 2013-08-22 14:40 - 00046384 _____ () C:\Program Files (x86)\Wyse\PocketCloud\AetherHelperLib.dll
2015-03-22 19:35 - 2015-05-04 05:55 - 00353520 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.PurBrowse64.exe
2014-03-08 20:56 - 2013-08-19 12:21 - 00020256 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIcon.dll
2014-03-08 20:56 - 2013-08-19 12:21 - 00019232 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayNotBackuped.dll
2014-03-08 20:56 - 2013-08-19 12:21 - 00035104 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRShellExtension.dll
2015-03-22 19:35 - 2015-05-04 06:59 - 00126192 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BrowserAdapter64.exe
2015-03-22 19:35 - 2015-05-04 06:59 - 00108272 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BrowserAdapter.exe
2015-03-22 19:35 - 2015-05-04 02:08 - 01649904 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BOASHelper.exe
2015-03-22 19:35 - 2015-05-04 16:55 - 00101616 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.expext.exe
2015-03-22 19:35 - 2015-05-04 02:08 - 01786608 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BOASPRT.exe
2015-03-22 19:35 - 2015-05-04 02:08 - 01791216 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BOAS.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-03-08 20:39 - 2013-08-28 05:02 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2015-03-22 19:35 - 2015-05-04 16:56 - 00081648 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.expextdll.dll
2015-03-22 19:35 - 2015-03-22 19:35 - 00306688 _____ () C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\aBcafkoU.dll
2015-05-04 20:25 - 2015-04-27 21:07 - 01252680 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libglesv2.dll
2015-05-04 20:25 - 2015-04-27 21:07 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libegl.dll
2015-05-04 20:25 - 2015-04-27 21:07 - 14980424 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\Users\Amy\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\amyca_000\SkyDrive:ms-properties
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3457434629-2911053778-409059968-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\dell\BlueLava_1112000xx_inspiron_wallpaper58095_16x9_72dpi_RGB.jpg
DNS Servers: 64.71.255.204 - 64.71.255.198
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{0894B932-D8EC-4138-9B7C-F1BCCFEF78A6}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{F6F5C8B5-79B2-4214-8C8E-68FE171A9431}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe
FirewallRules: [{C832C1F8-EF32-48A8-8B6E-62CB6C2F3E83}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\AetherWindowsService.exe
FirewallRules: [{9CDA5007-AAE0-442F-8D6A-8D65ED28BFF3}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe
FirewallRules: [{4CD1EFE0-BB60-40AC-934D-D57F36FA2788}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{A4188666-C929-460A-9A1E-590B45943D10}] => (Allow) LPort=2869
FirewallRules: [{D47FCBC8-78C7-4362-8C6B-9514FD24551B}] => (Allow) LPort=1900
FirewallRules: [{51633A0B-FE0B-4E7D-A46B-343C9B1C6C7D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{B22066F5-BE4D-4AD7-8217-074D415954D9}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{86716175-A31A-4B23-870E-5676DD3F67CA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1F3E48E9-2B47-44C2-9EC5-DBD944434D00}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B8E2A9EB-1A0A-44E7-BF0A-A1DE74BEC3EE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{5CEE3C91-DE7F-4A4C-AD9E-42F0800F671B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4C1A3792-41CD-4E59-9451-D4B7D65FD626}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{AA38818E-9D1C-48BF-BB49-227DA8383A2C}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{97BFB331-FD37-4C2E-8C7B-E6DC5A9F997D}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{61D212CD-ECC0-453C-A057-C9B54669D553}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/04/2015 07:47:43 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (05/04/2015 07:47:43 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (05/04/2015 07:47:42 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (05/04/2015 07:44:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ZeroConfigService.exe, version: 16.6.0.0, time stamp: 0x52585e22
Faulting module name: MurocApi.dll, version: 16.6.0.0, time stamp: 0x52585cf1
Exception code: 0xc0000005
Fault offset: 0x000000000002bcd8
Faulting process id: 0x928
Faulting application start time: 0xZeroConfigService.exe0
Faulting application path: ZeroConfigService.exe1
Faulting module path: ZeroConfigService.exe2
Report Id: ZeroConfigService.exe3
Faulting package full name: ZeroConfigService.exe4
Faulting package-relative application ID: ZeroConfigService.exe5
 
Error: (05/04/2015 07:30:06 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (05/04/2015 07:30:06 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (05/04/2015 07:30:06 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (05/04/2015 06:30:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ZeroConfigService.exe, version: 16.6.0.0, time stamp: 0x52585e22
Faulting module name: MurocApi.dll, version: 16.6.0.0, time stamp: 0x52585cf1
Exception code: 0xc0000005
Fault offset: 0x000000000003e09e
Faulting process id: 0x8b8
Faulting application start time: 0xZeroConfigService.exe0
Faulting application path: ZeroConfigService.exe1
Faulting module path: ZeroConfigService.exe2
Report Id: ZeroConfigService.exe3
Faulting package full name: ZeroConfigService.exe4
Faulting package-relative application ID: ZeroConfigService.exe5
 
Error: (04/30/2015 03:29:49 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10807234
 
Error: (04/30/2015 03:29:49 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 10807234
 
 
System errors:
=============
Error: (05/04/2015 08:31:24 PM) (Source: DCOM) (EventID: 10016) (User: AMY_LAPTOP)
Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Amy_laptopAmyS-1-5-21-3457434629-2911053778-409059968-1001LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (05/04/2015 08:31:11 PM) (Source: DCOM) (EventID: 10016) (User: AMY_LAPTOP)
Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Amy_laptopAmyS-1-5-21-3457434629-2911053778-409059968-1001LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (05/04/2015 08:30:54 PM) (Source: DCOM) (EventID: 10016) (User: AMY_LAPTOP)
Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Amy_laptopAmyS-1-5-21-3457434629-2911053778-409059968-1001LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (05/04/2015 08:26:27 PM) (Source: DCOM) (EventID: 10016) (User: AMY_LAPTOP)
Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Amy_laptopAmyS-1-5-21-3457434629-2911053778-409059968-1001LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (05/04/2015 08:19:21 PM) (Source: DCOM) (EventID: 10016) (User: AMY_LAPTOP)
Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Amy_laptopAmyS-1-5-21-3457434629-2911053778-409059968-1001LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (05/04/2015 07:46:14 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Computer Backup (MyPC Backup) service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (05/04/2015 07:44:12 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® PROSet/Wireless Zero Configuration Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (05/04/2015 07:43:28 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x0000001a (0x0000000000005002, 0xfffff58010804000, 0x0000000000060bf0, 0x004060bf1ffffffe)C:\Windows\MEMORY.DMP050415-31156-01
 
Error: (05/04/2015 07:42:54 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 6:29:36 PM on ‎2015-‎05-‎04 was unexpected.
 
Error: (05/04/2015 07:28:29 PM) (Source: DCOM) (EventID: 10010) (User: AMY_LAPTOP)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
 
 
Microsoft Office Sessions:
=========================
Error: (05/04/2015 07:47:43 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: WmiApRplWmiApRpl8F2030000E5050000
 
Error: (05/04/2015 07:47:43 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Performance163707000000000000000000008F020000
 
Error: (05/04/2015 07:47:42 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Performance163707000000000000000000008F020000
 
Error: (05/04/2015 07:44:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ZeroConfigService.exe16.6.0.052585e22MurocApi.dll16.6.0.052585cf1c0000005000000000002bcd892801d086cc8c132359C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exeC:\Program Files\Intel\WiFi\bin\MurocApi.dlld45aa2a3-f2bf-11e4-82ca-ac7ba11b386f
 
Error: (05/04/2015 07:30:06 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: WmiApRplWmiApRpl8F2030000E5050000
 
Error: (05/04/2015 07:30:06 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Performance163707000000000000000000008F020000
 
Error: (05/04/2015 07:30:06 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Performance163707000000000000000000008F020000
 
Error: (05/04/2015 06:30:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ZeroConfigService.exe16.6.0.052585e22MurocApi.dll16.6.0.052585cf1c0000005000000000003e09e8b801d086c249234656C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exeC:\Program Files\Intel\WiFi\bin\MurocApi.dll9550bd26-f2b5-11e4-82c9-ac7ba11b386f
 
Error: (04/30/2015 03:29:49 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10807234
 
Error: (04/30/2015 03:29:49 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 10807234
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-4200U CPU @ 1.60GHz
Percentage of memory in use: 35%
Total physical RAM: 8072.96 MB
Available physical RAM: 5188.73 MB
Total Pagefile: 16264.96 MB
Available Pagefile: 13216.73 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:920.6 GB) (Free:783.12 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 3E436CEC)
 
Partition: GPT Partition Type.
 
==================== End Of Log ============================

 


  • 0

Advertisements


#2
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)

I'll be with you shortly with instructions
  • 0

#3
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
First do this:
Farber Recovery Scanner(FRST) needs to be running from the desktop. You have it in the downloads folder. Please move to desktop.
To do that:
  • Navagate to your downloads folder--> C:\Users\Amy\Downloads
  • In the downloads folder find FRST (Farber recovery scan tool)
  • Right click on it,Choose cut.
  • Go back to the desktop.
  • On an empty space right click, choose paste.
  • Farber will now have been successfully moved to desktop.
No need to do another scan after doing that.

Second do this.
Please remove these programs from your programs an features list, Start > Control panel > Programs an features. In the list find the program listed below and uninstall it.
  • Buzzdock
  • Deal Keeper
  • MyPC Backup
  • RegClean-Pro
  • Yahoo! Search
If a program will not remove skip it and keep following instructions please. It's also possible you may not see a program that is listed.

Next
A few items to fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
start
CloseProcesses:
CreateRestorePoint:
Startup: C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2014-07-21]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (No File)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> DefaultScope {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = http://rocket-find.c...r=609539609&ir=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = http://rocket-find.c...r=609539609&ir=
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> OldSearch URL = http://rocket-find.c...r=609539609&ir=
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = http://q.search-simp...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> {237FDB45-B214-48E0-BBED-D888F86CC633} URL = http://q.search-simp...rchTerms}&r=726
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
CHR RestoreOnStartup: Default -> "hxxp://ca.search.yahoo.com/?fr=hp-ddc-bd&type=124_pr__alt__ddc_dsssyc_bd_com"
CHR StartupUrls: Default -> "hxxp://ca.search.yahoo.com/?fr=hp-ddc-bd&type=124_pr__alt__ddc_dsssyc_bd_com"
CHR DefaultNewTabURL: Default -> http://ca.search.yah...sssyctab_bd_com
CHR DefaultSuggestURL: Default -> 
CHR Extension: (Deal Keeper) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eencbeelgfacnhekfiklkobllfleohce [2014-10-19]
R2 Util Deal Keeper; C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe [651504 2015-05-04] ()
C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe 
2015-04-25 16:34 - 2015-04-25 16:34 - 00000000 ____D () C:\Users\amyca_000\AppData\Local\Pay-By-Ads
2015-05-04 20:22 - 2014-07-21 22:26 - 00003090 _____ () C:\Windows\System32\Tasks\RegClean Pro
2015-05-04 20:20 - 2014-10-03 18:28 - 00001332 _____ () C:\Users\Amy\Desktop\Clean Registry for Free!.lnk
2015-05-04 19:44 - 2014-07-21 22:27 - 00000000 ____D () C:\Program Files (x86)\Deal Keeper
Task: {14D00A86-E52B-4F56-A122-4F691D74FB75} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-16] (RCP) <==== ATTENTION
C:\Program Files (x86)\RCP\RegCleanPro.exe
Task: {74866D04-85E5-41AB-95FE-FD2404066C0B} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-16] (RCP) <==== ATTENTION
Task: {8227E9C7-974C-4996-9CF3-843C0332A411} - System32\Tasks\ASP => C:\Program Files (x86)\RegClean Pro\SystweakASP.exe <==== ATTENTION
C:\Program Files (x86)\RegClean Pro\SystweakASP.exe
Task: {9F09FE05-26C7-454F-BB3D-8A513DD33FA3} - System32\Tasks\Yahoo! Search => C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe [2015-03-22] (Pay By Ads LTD) <==== ATTENTION
C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search
Task: {AB3ED129-70F5-49C3-94E9-C6FD329361A3} - System32\Tasks\Yahoo! Search Updater => C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrsetup.exe [2015-03-22] (Pay By Ads LTD) <==== ATTENTION
Task: {F055F4CB-042B-4468-8EA0-5F394B54E555} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-16] (RCP) <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
AlternateDataStreams: C:\Users\Amy\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\amyca_000\SkyDrive:ms-properties
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
hosts:
Emptytemp:
Click Format and ensure Wordwrap is unchecked.
Save as Fixlist.txt to your Desktop (Must be in this location)
Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

In your next reply please post;
Fixlog.txt That log will be found on your desktop after fix has run.

Thanks
Joe :)
  • 0

#4
heyage13

heyage13

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts

Thanks for the help so far!

 

Here is the log:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-05-2015
Ran by Amy at 2015-05-05 20:41:54 Run:1
Running from C:\Users\Amy\Desktop
Loaded Profiles: Amy (Available profiles: Amy & amyca_000)
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
start
CloseProcesses:
CreateRestorePoint:
Startup: C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2014-07-21]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (No File)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> DefaultScope {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = http://rocket-find.c...r=609539609&ir=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = http://rocket-find.c...r=609539609&ir=
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> OldSearch URL = http://rocket-find.c...r=609539609&ir=
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> {15E4F387-107B-4B48-99F9-AFF505E9AC1F} URL = http://q.search-simp...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> {237FDB45-B214-48E0-BBED-D888F86CC633} URL = http://q.search-simp...rchTerms}&r=726
SearchScopes: HKU\S-1-5-21-3457434629-2911053778-409059968-1001 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
CHR RestoreOnStartup: Default -> "hxxp://ca.search.yahoo.com/?fr=hp-ddc-bd&type=124_pr__alt__ddc_dsssyc_bd_com"
CHR StartupUrls: Default -> "hxxp://ca.search.yahoo.com/?fr=hp-ddc-bd&type=124_pr__alt__ddc_dsssyc_bd_com"
CHR DefaultNewTabURL: Default -> http://ca.search.yah...sssyctab_bd_com
CHR DefaultSuggestURL: Default -> 
CHR Extension: (Deal Keeper) - C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eencbeelgfacnhekfiklkobllfleohce [2014-10-19]
R2 Util Deal Keeper; C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe [651504 2015-05-04] ()
C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe 
2015-04-25 16:34 - 2015-04-25 16:34 - 00000000 ____D () C:\Users\amyca_000\AppData\Local\Pay-By-Ads
2015-05-04 20:22 - 2014-07-21 22:26 - 00003090 _____ () C:\Windows\System32\Tasks\RegClean Pro
2015-05-04 20:20 - 2014-10-03 18:28 - 00001332 _____ () C:\Users\Amy\Desktop\Clean Registry for Free!.lnk
2015-05-04 19:44 - 2014-07-21 22:27 - 00000000 ____D () C:\Program Files (x86)\Deal Keeper
Task: {14D00A86-E52B-4F56-A122-4F691D74FB75} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-16] (RCP) <==== ATTENTION
C:\Program Files (x86)\RCP\RegCleanPro.exe
Task: {74866D04-85E5-41AB-95FE-FD2404066C0B} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-16] (RCP) <==== ATTENTION
Task: {8227E9C7-974C-4996-9CF3-843C0332A411} - System32\Tasks\ASP => C:\Program Files (x86)\RegClean Pro\SystweakASP.exe <==== ATTENTION
C:\Program Files (x86)\RegClean Pro\SystweakASP.exe
Task: {9F09FE05-26C7-454F-BB3D-8A513DD33FA3} - System32\Tasks\Yahoo! Search => C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe [2015-03-22] (Pay By Ads LTD) <==== ATTENTION
C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search
Task: {AB3ED129-70F5-49C3-94E9-C6FD329361A3} - System32\Tasks\Yahoo! Search Updater => C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrsetup.exe [2015-03-22] (Pay By Ads LTD) <==== ATTENTION
Task: {F055F4CB-042B-4468-8EA0-5F394B54E555} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-16] (RCP) <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
AlternateDataStreams: C:\Users\Amy\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\amyca_000\SkyDrive:ms-properties
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
hosts:
Emptytemp:
*****************
 
Processes closed successfully.
Restore point was successfully created.
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk not found.
C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe not found.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{15E4F387-107B-4B48-99F9-AFF505E9AC1F}" => Key deleted successfully.
HKCR\CLSID\{15E4F387-107B-4B48-99F9-AFF505E9AC1F} => Key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. 
"HKU\S-1-5-21-3457434629-2911053778-409059968-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch" => Key deleted successfully.
HKCR\CLSID\OldSearch => Key not found. 
"HKU\S-1-5-21-3457434629-2911053778-409059968-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{15E4F387-107B-4B48-99F9-AFF505E9AC1F}" => Key deleted successfully.
HKCR\CLSID\{15E4F387-107B-4B48-99F9-AFF505E9AC1F} => Key not found. 
"HKU\S-1-5-21-3457434629-2911053778-409059968-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{237FDB45-B214-48E0-BBED-D888F86CC633}" => Key deleted successfully.
HKCR\CLSID\{237FDB45-B214-48E0-BBED-D888F86CC633} => Key not found. 
"HKU\S-1-5-21-3457434629-2911053778-409059968-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}" => Key deleted successfully.
HKCR\CLSID\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} => Key not found. 
RestoreOnStartup not detected.
Chrome StartupUrls not detected.
CHR DefaultNewTabURL: Default -> http://ca.search.yah...sssyctab_bd_com=> Error: No automatic fix found for this entry.
Chrome DefaultSuggestURL not detected.
C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eencbeelgfacnhekfiklkobllfleohce directory not found.
Util Deal Keeper => Service not found.
"C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe" => File/Directory not found.
C:\Users\amyca_000\AppData\Local\Pay-By-Ads => Moved successfully.
"C:\Windows\System32\Tasks\RegClean Pro" => File/Directory not found.
"C:\Users\Amy\Desktop\Clean Registry for Free!.lnk" => File/Directory not found.
"C:\Program Files (x86)\Deal Keeper" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{14D00A86-E52B-4F56-A122-4F691D74FB75} => Key could not be deleted. Access denied.
C:\Windows\System32\Tasks\RegClean Pro not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro => Key could not be deleted. Access denied.
"C:\Program Files (x86)\RCP\RegCleanPro.exe" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{74866D04-85E5-41AB-95FE-FD2404066C0B} => Key could not be deleted. Access denied.
C:\Windows\System32\Tasks\RegClean Pro_DEFAULT not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_DEFAULT => Key could not be deleted. Access denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8227E9C7-974C-4996-9CF3-843C0332A411} => Key could not be deleted. Access denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8227E9C7-974C-4996-9CF3-843C0332A411} => Key could not be deleted. Access denied.
C:\Windows\System32\Tasks\ASP => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASP => Key could not be deleted. Access denied.
"C:\Program Files (x86)\RegClean Pro\SystweakASP.exe" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F09FE05-26C7-454F-BB3D-8A513DD33FA3} => Key could not be deleted. Access denied.
C:\Windows\System32\Tasks\Yahoo! Search not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yahoo! Search => Key could not be deleted. Access denied.
C:\Users\Amy\AppData\Local\Pay-By-Ads\Yahoo! Search => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB3ED129-70F5-49C3-94E9-C6FD329361A3} => Key could not be deleted. Access denied.
C:\Windows\System32\Tasks\Yahoo! Search Updater not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yahoo! Search Updater => Key could not be deleted. Access denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F055F4CB-042B-4468-8EA0-5F394B54E555} => Key could not be deleted. Access denied.
C:\Windows\System32\Tasks\RegClean Pro_UPDATES not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_UPDATES => Key could not be deleted. Access denied.
C:\Windows\Tasks\RegClean Pro_DEFAULT.job not found.
C:\Windows\Tasks\RegClean Pro_UPDATES.job not found.
"C:\Users\Amy\SkyDrive" => ":ms-properties" ADS not found.
"C:\Users\amyca_000\SkyDrive" => ":ms-properties" ADS not found.
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.7.9600 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
0 out of 0 jobs canceled.
 
========= End of CMD: =========
 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1 GB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 20:42:26 ====

  • 0

#5
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
You're welcome for the help so far :)

Next

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the logfile button and the log will open in Notepad.
  • NOTE: If you get an error message, it means that nothing was found. Exit from AdwCleaner.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished and the PC has rebooted.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner
Next

thisisujrt.gif Please download Junkware Removal Tool to your Desktop.

Please close your security software to avoid potential conflicts. See Here how to disable you security protection (Anti Virus)
Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete, depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
Please post the contents of JRT.txt into your reply.

In your next reply post;
  • The AdwCleaner [SO].txt Log
  • The JRT.txt Log
Thanks
Joe :)
  • 0

#6
heyage13

heyage13

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts

|ADWCleaner Log:

 

# AdwCleaner v4.203 - Logfile created 05/05/2015 at 21:25:00
# Updated 30/04/2015 by Xplode
# Database : 2015-04-30.2 [Local]
# Operating system : Windows 8.1  (x64)
# Username : Amy - AMY_LAPTOP
# Running from : C:\Users\Amy\Desktop\adwcleaner_4.203.exe
# Option : Scan
 
***** [ Services ] *****
 
Service Found : {55dce8ba-9dec-4013-937e-adbf9317d990}Gw64
Service Found : {55dce8ba-9dec-4013-937e-adbf9317d990}w64
Service Found : {7e4355b8-96cd-43eb-b59a-82af29f01b16}w64
Service Found : {af7618ea-6d4f-47e5-9e06-5f808487ae22}w64
Service Found : {eb8709c5-52a2-49ef-9341-2b49aaf413b8}w64
 
***** [ Files / Folders ] *****
 
File Found : C:\Windows\System32\drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}Gw64.sys
File Found : C:\Windows\System32\drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}w64.sys
File Found : C:\Windows\System32\drivers\{7e4355b8-96cd-43eb-b59a-82af29f01b16}w64.sys
File Found : C:\Windows\System32\drivers\{af7618ea-6d4f-47e5-9e06-5f808487ae22}w64.sys
File Found : C:\Windows\System32\drivers\{eb8709c5-52a2-49ef-9341-2b49aaf413b8}w64.sys
File Found : C:\Windows\System32\roboot64.exe
Folder Found : C:\Program Files (x86)\WSE Rocket
Folder Found : C:\ProgramData\Systweak
Folder Found : C:\Users\Amy\AppData\Local\pay-by-ads
Folder Found : C:\Users\Amy\AppData\Roaming\Systweak
 
***** [ Scheduled tasks ] *****
 
Task Found : ASP
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\Rocket Browser
Key Found : HKCU\Software\systweak
Key Found : HKCU\Software\WSE Rocket
Key Found : [x64] HKCU\Software\InstallCore
Key Found : [x64] HKCU\Software\Rocket Browser
Key Found : [x64] HKCU\Software\systweak
Key Found : [x64] HKCU\Software\WSE Rocket
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\EFEE0228DC83E77358593193D847A0EC
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\EFEE0228DC83E77358593193D847A0EC
Key Found : HKLM\SOFTWARE\InstallCore
Key Found : HKLM\SOFTWARE\systweak
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EFEE0228DC83E77358593193D847A0EC
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.16518
 
 
-\\ Google Chrome v42.0.2311.135
 
 
*************************
 
AdwCleaner[R0].txt - [2741 bytes] - [05/05/2015 21:25:00]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2800 bytes] ##########
 
 
JRT Log:
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.7 (04.30.2015:1)
OS: Windows 8.1 x64
Ran by Amy on 2015-05-05 at 21:35:08.11
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-3457434629-2911053778-409059968-1001
Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-3457434629-2911053778-409059968-1004
Successfully deleted: [Task] C:\Windows\system32\tasks\PCDEventLauncherTask
Successfully deleted: [Task] C:\Windows\system32\tasks\PCDoctorBackgroundMonitorTask
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] C:\ProgramData\pcdr
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2015-05-05 at 21:37:00.67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

  • 0

#7
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hello,

Run the clean option on adwcleaner so it removes the files, your log just shows a scan

Click the Scan button and wait for the process to complete.
Click the logfile button and the log will open in Notepad.
Then
Click on the Clean button follow the prompts.

Next
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
  • Enable free trial of Malwarebytes Anti-Malware Premium
  • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that that all Threats are selected, and click Remove Selected.
  • Reboot your computer if prompted.
Posting the Malwarebytes log.
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the Scan Log which shows the Date and time of the scan just performed.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • post that saved log to your next reply.
1-Post the Malwarebytes log
2-Post the adwClean log
  • 0

#8
heyage13

heyage13

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts

Unfortunately every time I runt he scan feature on Malware Bytes my computer receives an error message and it restarts without completing the scan process. 

 

Here is the Adw Log:

 

# AdwCleaner v4.203 - Logfile created 05/05/2015 at 22:27:00
# Updated 30/04/2015 by Xplode
# Database : 2015-05-05.1 [Server]
# Operating system : Windows 8.1  (x64)
# Username : Amy - AMY_LAPTOP
# Running from : C:\Users\Amy\Desktop\adwcleaner_4.203.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.16518
 
 
-\\ Google Chrome v42.0.2311.135
 
 
*************************
 
AdwCleaner[R0].txt - [2903 bytes] - [05/05/2015 21:25:00]
AdwCleaner[R1].txt - [648 bytes] - [05/05/2015 22:27:00]
AdwCleaner[S0].txt - [2848 bytes] - [05/05/2015 21:31:00]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [765 bytes] ##########

  • 0

#9
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Can you uninstall Malwarebytes and reinstall it and see if that helps.

Let me know...

Thanks
Joe :)
  • 0

#10
heyage13

heyage13

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts

same issue..

 

I get the following error message: KERNEL_DATA_INPAGE_ERROR


  • 0

Advertisements


#11
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hello,

You get that message when trying to uninstall Malwarebytes free ?

If so, lets run a special tool called Malwarebytes clean to remove the free version of Malwarebytes..

Malwarebytes clean tool
  • Please download mbam-clean.exe from here to your desktop and save it.
  • Please close all open applications and temporarily shutdown your antivirus to avoid any conflicts when running the tool.
  • Locate the file mbam-clean.exe and double-click to run it and follow the onscreen prompts.
  • It will ask to restart your computer, please allow it to do so very important
  • Make sure you have re-enabled your Anti-Virus/Internet-Security applications after the restart
Let me know.

Thanks
Joe :)
  • 0

#12
heyage13

heyage13

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts

I receive that message when trying to complete a system scan... unfortunately it doesn't let me complete it...that's when the error message appears. 


  • 0

#13
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Don't try any more scans. Please uninstall Malwarebytes and reinstall it.
  • 0

#14
heyage13

heyage13

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts

I have uninstalled then re-installed and the same error populates. 


  • 0

#15
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hello there,

Other then Malwarebytes problem how is the computer ?

Also please;

Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Make sure you checkmark Addition.txt box.
  • Press Scan button.
  • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP