Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Old Compacq Win 7 running like a snail [Closed]


  • This topic is locked This topic is locked

#1
Don Stewart

Don Stewart

    Member

  • Member
  • PipPipPip
  • 239 posts

When your typing, especially yahoo.....letters, etc.in at their own place....delayed!

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-05-2015 01
Ran by Don (administrator) on DON-PC on 22-05-2015 22:56:18
Running from H:\Users\Don\Desktop
Loaded Profiles: Don (Available Profiles: Don & Merry)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(SUPERAntiSpyware.com) H:\Program Files\SASCore.exe
(Microsoft Corporation) H:\Windows\System32\msiexec.exe
(Symantec Corporation) H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\nav.exe
(Nuance Communications, Inc.) H:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
(Microsoft Corporation) H:\Windows\System32\PrintIsolationHost.exe
(Google Inc.) H:\Program Files\Google\Chrome\Application\chrome.exe
(Symantec Corporation) H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\nav.exe
(Google Inc.) H:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) H:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) H:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\...\Run: [GoogleChromeAutoLaunch_ABD3ADD719CEC27F075C120D03994BF7] => H:\Program Files\Google\Chrome\Application\chrome.exe [813896 2015-05-13] (Google Inc.)
HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\...\Run: [Web Companion] => H:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\...\Run: [083B39FB7B958A0F78E959FDA72E539905C51D18._service_run] => H:\Program Files\Google\Chrome\Application\chrome.exe [813896 2015-05-13] (Google Inc.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => H:\Windows\System32\SPReview\SPReview.exe [280576 2014-04-17] (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?...OIE8MSE&PC=UP09
HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/...nlogo=CT3331981
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKU\S-1-5-21-3964834215-2275053063-3108885826-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3964834215-2275053063-3108885826-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...q={searchTerms}
BHO: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> H:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\IPS\IPSBHO.DLL [2015-03-04] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> H:\Program Files\Java\jre7\bin\ssv.dll [2014-09-26] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> H:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-26] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.2.25
 
FireFox:
========
FF ProfilePath: H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833
FF DefaultSearchEngine: Bing
FF DefaultSearchEngine.US: Bing
FF Plugin: @adobe.com/FlashPlayer -> H:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-18] ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> H:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> H:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @tools.google.com/Google Update;version=3 -> H:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-14] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> H:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-14] (Google Inc.)
FF Plugin: Adobe Reader -> H:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF user.js: detected! => H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\user.js [2015-05-21]
FF Extension: Flashblock - H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2014-12-10]
FF Extension: NoScript - H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-10-23]
FF Extension: Adblock Plus - H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-23]
 
Chrome: 
=======
CHR Profile: H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bookmark Manager) - H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-16]
CHR Extension: (Chrome Hotword Shared Module) - H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-16]
CHR Extension: (Google Wallet) - H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-19]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; H:\Program Files\SASCORE.EXE [142648 2014-07-22] (SUPERAntiSpyware.com)
S3 BrYNSvc; H:\Program Files\Browny02\BrYNSvc.exe [282112 2012-10-26] (Brother Industries, Ltd.) []
R2 DiagTrack; H:\Windows\system32\diagtrack.dll [851456 2015-04-27] (Microsoft Corporation)
S2 MBAMService; H:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 NAV; H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\NAV.exe [262928 2015-03-06] (Symantec Corporation)
R2 PDFProFiltSrvPP; H:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [145256 2011-08-02] (Nuance Communications, Inc.)
S3 WinDefend; H:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)
S2 Update Triple Pose; "H:\Program Files\Triple Pose\updateTriplePose.exe" [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 ALCXWDM; H:\Windows\System32\drivers\ALCXWDM.SYS [3844032 2006-01-11] (Realtek Semiconductor Corp.)
R1 BHDrvx86; H:\Program Files\Norton AntiVirus\NortonData\21.1.0.18\Definitions\BASHDefs\20150519.001\BHDrvx86.sys [1172184 2015-05-01] (Symantec Corporation)
R1 ccSet_NAV; H:\Windows\system32\drivers\NAV\1507000.00B\ccSetx86.sys [127064 2013-09-25] (Symantec Corporation)
R1 eeCtrl; H:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2015-03-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; H:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [111408 2015-03-15] (Symantec Corporation)
S3 GKUPRO2D; H:\Windows\System32\DRIVERS\GKUPRO2D.sys [90240 2012-11-05] (Gemalto)
R1 IDSVix86; H:\Program Files\Norton AntiVirus\NortonData\21.1.0.18\Definitions\IPSDefs\20150521.003\IDSvix86.sys [505048 2015-03-30] (Symantec Corporation)
R3 MBAMProtector; H:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMSwissArmy; H:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-05-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; H:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R3 NAVENG; H:\Program Files\Norton AntiVirus\NortonData\21.1.0.18\Definitions\VirusDefs\20150522.003\NAVENG.SYS [95704 2015-03-15] (Symantec Corporation)
R3 NAVEX15; H:\Program Files\Norton AntiVirus\NortonData\21.1.0.18\Definitions\VirusDefs\20150522.003\NAVEX15.SYS [1636696 2015-03-15] (Symantec Corporation)
R1 SASDIFSV; H:\Program Files\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; H:\Program Files\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SISNIC; H:\Windows\System32\DRIVERS\sisnic.sys [40840 2006-07-13] (SiS Corporation)
S3 SISNICXP; H:\Windows\System32\DRIVERS\sisnicxp.sys [32768 2006-02-14] (SiS Corporation)
R3 SRTSP; H:\Windows\System32\Drivers\NAV\1507000.00B\SRTSP.SYS [664792 2014-08-25] (Symantec Corporation)
R1 SRTSPX; H:\Windows\system32\drivers\NAV\1507000.00B\SRTSPX.SYS [32984 2014-08-25] (Symantec Corporation)
S3 SrvHsfPCI; H:\Windows\System32\DRIVERS\VSTBS23.SYS [266752 2009-07-13] (Conexant Systems, Inc.)
R0 SymDS; H:\Windows\System32\drivers\NAV\1507000.00B\SYMDS.SYS [367704 2013-09-09] (Symantec Corporation)
R0 SymEFA; H:\Windows\System32\drivers\NAV\1507000.00B\SYMEFA.SYS [936152 2014-03-03] (Symantec Corporation)
R3 SymEvent; H:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2014-04-16] (Symantec Corporation)
R1 SymIRON; H:\Windows\system32\drivers\NAV\1507000.00B\Ironx86.SYS [209624 2014-08-06] (Symantec Corporation)
R1 SymNetS; H:\Windows\System32\Drivers\NAV\1507000.00B\SYMNETS.SYS [447704 2014-02-17] (Symantec Corporation)
R1 {ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw; H:\Windows\System32\drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys [43152 2015-05-20] (StdLib)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-05-22 22:56 - 2015-05-22 22:56 - 00010898 _____ () H:\Users\Don\Desktop\FRST.txt
2015-05-22 22:54 - 2015-05-22 22:56 - 00000000 ____D () H:\FRST
2015-05-22 22:54 - 2015-05-22 22:54 - 00000000 ____D () H:\Users\Don\Desktop\FRST-OlderVersion
2015-05-22 22:53 - 2015-05-22 22:54 - 01147392 _____ (Farbar) H:\Users\Don\Desktop\FRST.exe
2015-05-22 15:30 - 2015-05-22 15:30 - 00000000 ____D () H:\Users\Public\Documents\Sewer
2015-05-21 22:06 - 2015-05-21 22:06 - 00000000 ____D () H:\Users\Don\Desktop\DVDIRECT_DISC_00100002052
2015-05-21 21:46 - 2015-05-21 21:46 - 03060320 ____N (Symantec Corporation) H:\Users\Don\Downloads\NPE.exe
2015-05-21 14:13 - 2015-05-21 14:13 - 00000000 _____ () H:\Users\Don\Documents\Nuance Image Printer Writer Port
2015-05-21 13:41 - 2015-05-21 13:43 - 00000000 _____ () H:\Users\Merry\Documents\Nuance Image Printer Writer Port
2015-05-21 13:33 - 2015-05-21 13:33 - 00000000 ____D () H:\Users\Merry\AppData\Roaming\Zeon
2015-05-20 14:18 - 2015-04-27 12:11 - 03989440 _____ (Microsoft Corporation) H:\Windows\system32\ntkrnlpa.exe
2015-05-20 14:18 - 2015-04-27 12:11 - 03934144 _____ (Microsoft Corporation) H:\Windows\system32\ntoskrnl.exe
2015-05-20 14:18 - 2015-04-27 12:11 - 00137664 _____ (Microsoft Corporation) H:\Windows\system32\Drivers\ksecpkg.sys
2015-05-20 14:18 - 2015-04-27 12:11 - 00067520 _____ (Microsoft Corporation) H:\Windows\system32\Drivers\ksecdd.sys
2015-05-20 14:18 - 2015-04-27 12:08 - 01307648 _____ (Microsoft Corporation) H:\Windows\system32\ntdll.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00851456 _____ (Microsoft Corporation) H:\Windows\system32\diagtrack.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00635392 _____ (Microsoft Corporation) H:\Windows\system32\tdh.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00400896 _____ (Microsoft Corporation) H:\Windows\system32\srcore.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00259584 _____ (Microsoft Corporation) H:\Windows\system32\msv1_0.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00221184 _____ (Microsoft Corporation) H:\Windows\system32\ncrypt.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00172032 _____ (Microsoft Corporation) H:\Windows\system32\wdigest.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00100352 _____ (Microsoft Corporation) H:\Windows\system32\sspicli.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00092160 _____ (Microsoft Corporation) H:\Windows\system32\sechost.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00065536 _____ (Microsoft Corporation) H:\Windows\system32\TSpkg.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00043008 _____ (Microsoft Corporation) H:\Windows\system32\srclient.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00022016 _____ (Microsoft Corporation) H:\Windows\system32\secur32.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00015872 _____ (Microsoft Corporation) H:\Windows\system32\sspisrv.dll
2015-05-20 14:18 - 2015-04-27 12:04 - 01061376 _____ (Microsoft Corporation) H:\Windows\system32\lsasrv.dll
2015-05-20 14:18 - 2015-04-27 12:04 - 00641536 _____ (Microsoft Corporation) H:\Windows\system32\advapi32.dll
2015-05-20 14:18 - 2015-04-27 12:04 - 00550912 _____ (Microsoft Corporation) H:\Windows\system32\kerberos.dll
2015-05-20 14:18 - 2015-04-27 12:04 - 00364544 _____ (Microsoft Corporation) H:\Windows\system32\tracerpt.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00262656 _____ (Microsoft Corporation) H:\Windows\system32\rstrui.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00082944 _____ (Microsoft Corporation) H:\Windows\system32\logman.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00069632 _____ (Microsoft Corporation) H:\Windows\system32\smss.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00040448 _____ (Microsoft Corporation) H:\Windows\system32\typeperf.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00038912 _____ (Microsoft Corporation) H:\Windows\system32\csrsrv.dll
2015-05-20 14:18 - 2015-04-27 12:04 - 00037888 _____ (Microsoft Corporation) H:\Windows\system32\relog.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00022528 _____ (Microsoft Corporation) H:\Windows\system32\lsass.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00017408 _____ (Microsoft Corporation) H:\Windows\system32\credssp.dll
2015-05-20 14:18 - 2015-04-27 12:03 - 00050176 _____ (Microsoft Corporation) H:\Windows\system32\auditpol.exe
2015-05-20 14:18 - 2015-04-27 12:03 - 00017408 _____ (Microsoft Corporation) H:\Windows\system32\diskperf.exe
2015-05-20 14:18 - 2015-04-27 12:01 - 00146432 _____ (Microsoft Corporation) H:\Windows\system32\msaudite.dll
2015-05-20 14:18 - 2015-04-27 12:01 - 00060416 _____ (Microsoft Corporation) H:\Windows\system32\msobjs.dll
2015-05-20 14:18 - 2015-04-27 11:59 - 00686080 _____ (Microsoft Corporation) H:\Windows\system32\adtschema.dll
2015-05-20 14:18 - 2015-04-27 11:59 - 00006656 _____ (Microsoft Corporation) H:\Windows\system32\apisetschema.dll
2015-05-20 14:18 - 2015-04-27 11:00 - 00036864 _____ (Microsoft Corporation) H:\Windows\system32\UtcResources.dll
2015-05-20 14:18 - 2015-01-28 20:02 - 02311168 _____ (Microsoft Corporation) H:\Windows\system32\wpdshext.dll
2015-05-20 14:16 - 2015-04-10 20:07 - 00054656 _____ (Microsoft Corporation) H:\Windows\system32\Drivers\stream.sys
2015-05-20 14:16 - 2015-03-13 20:04 - 01372160 _____ (Microsoft Corporation) H:\Windows\system32\dwmcore.dll
2015-05-20 14:16 - 2015-03-13 20:04 - 00067584 _____ (Microsoft Corporation) H:\Windows\system32\dwmapi.dll
2015-05-20 14:16 - 2015-03-03 21:11 - 00005120 _____ (Microsoft Corporation) H:\Windows\system32\shimeng.dll
2015-05-20 14:16 - 2015-03-03 21:10 - 00295936 _____ (Microsoft Corporation) H:\Windows\system32\apphelp.dll
2015-05-20 14:16 - 2015-03-03 21:10 - 00062464 _____ (Microsoft Corporation) H:\Windows\system32\aelupsvc.dll
2015-05-20 14:16 - 2015-03-03 21:10 - 00020992 _____ (Microsoft Corporation) H:\Windows\system32\sdbinst.exe
2015-05-20 13:53 - 2015-05-20 13:53 - 00000000 ____D () H:\Users\Don\AppData\Local\WebDiscoverBrowser
2015-05-20 13:48 - 2015-05-20 13:48 - 00000000 ____D () H:\Users\Don\Documents\ProPCCleaner
2015-05-20 13:25 - 2015-05-20 07:43 - 00043152 _____ (StdLib) H:\Windows\system32\Drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys
2015-05-20 13:24 - 2015-05-21 22:47 - 00000000 ____D () H:\Program Files\WebDiscoverBrowser
2015-05-20 13:22 - 2015-05-21 22:57 - 00000000 ____D () H:\Program Files\Triple Pose
2015-05-20 13:22 - 2015-05-20 13:22 - 00000000 ____D () H:\ProgramData\CouponAlert
2015-05-20 13:21 - 2015-05-20 13:21 - 00002848 _____ () H:\Windows\system32\LavasoftTcpServiceOff.ini
2015-05-20 13:21 - 2015-04-30 10:50 - 00347976 _____ (Lavasoft Limited) H:\Windows\system32\LavasoftTcpService.dll
2015-05-20 13:19 - 2015-05-20 13:19 - 00001117 _____ () H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-05-20 13:19 - 2015-05-20 13:19 - 00001105 _____ () H:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-05-20 13:19 - 2015-05-20 13:19 - 00000000 ____D () H:\Program Files\Mozilla Maintenance Service
2015-05-20 13:18 - 2015-05-21 14:30 - 00000000 ____D () H:\Program Files\Mozilla Firefox
2015-05-20 13:17 - 2015-05-20 13:17 - 00243344 _____ () H:\Users\Don\Downloads\Firefox Setup Stub 38.0.1.exe
2015-05-20 13:16 - 2015-05-20 13:16 - 00983736 _____ (Download Assistant) H:\Users\Don\Downloads\firefox_install.exe
2015-05-20 13:05 - 2015-05-21 22:57 - 00001422 _____ () H:\Windows\PFRO.log
2015-05-20 08:42 - 2015-05-20 08:42 - 01489216 _____ (LogMeIn, Inc.) H:\Users\Don\Downloads\Support-LogMeInRescue(1).exe
2015-05-20 08:38 - 2015-05-20 08:38 - 00000145 _____ () H:\Users\Don\Desktop\CenturyLink PC Services.url
2015-05-20 08:36 - 2015-05-20 08:37 - 00000000 ____D () H:\Users\Don\AppData\Roaming\PCHC
2015-05-20 08:30 - 2015-05-20 08:30 - 02459880 _____ () H:\Users\Don\Downloads\PCHCInstallerPackage.exe
2015-05-20 08:10 - 2015-05-22 22:47 - 00000952 _____ () H:\Windows\setupact.log
2015-05-20 08:10 - 2015-05-21 21:50 - 00000000 ____D () H:\NPE
2015-05-20 08:10 - 2015-05-20 08:10 - 00000000 _____ () H:\Windows\setuperr.log
2015-05-20 08:07 - 2015-05-21 22:00 - 00000000 ____D () H:\Users\Don\AppData\Local\NPE
2015-05-19 18:05 - 2015-05-19 18:05 - 00018432 _____ () H:\Program Files\Uninstall.dat
2015-05-19 18:05 - 2015-05-19 18:05 - 00000000 ____D () H:\Users\Don\AppData\Roaming\SUPERAntiSpyware.com
2015-05-19 18:04 - 2015-05-19 18:04 - 00001744 _____ () H:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-05-19 18:04 - 2015-05-19 18:04 - 00000000 ____D () H:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-05-19 18:04 - 2015-05-19 18:04 - 00000000 ____D () H:\Program Files\Plugins
2015-05-19 18:01 - 2015-05-19 18:02 - 21972920 _____ (SUPERAntiSpyware) H:\Users\Don\Downloads\SUPERAntiSpyware(1).exe
2015-05-18 20:18 - 2015-05-18 20:19 - 00000188 _____ () H:\Users\Public\Documents\cc_20150518_201853.reg
2015-05-17 09:06 - 2015-05-17 09:06 - 00000000 ____H () H:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2015-05-17 08:22 - 2015-05-22 20:41 - 00000179 _____ () H:\Users\Don\Desktop\BloodPressue.txt
2015-05-17 02:24 - 2015-05-01 06:16 - 00102608 _____ (Microsoft Corporation) H:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-17 02:02 - 2015-05-17 02:02 - 00000604 _____ () H:\Users\Public\Documents\cc_20150517_020238.reg
2015-05-15 11:59 - 2015-05-15 11:59 - 06714136 _____ (SUPERAntiSpyware) H:\Program Files\SUPERAntiSpyware.exe
2015-05-13 03:18 - 2015-05-04 18:12 - 00248832 _____ (Microsoft Corporation) H:\Windows\system32\schannel.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 14374400 _____ (Microsoft Corporation) H:\Windows\system32\mshtml.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 13771776 _____ (Microsoft Corporation) H:\Windows\system32\ieframe.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 02864640 _____ (Microsoft Corporation) H:\Windows\system32\jscript9.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 02055680 _____ (Microsoft Corporation) H:\Windows\system32\iertutil.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 01763328 _____ (Microsoft Corporation) H:\Windows\system32\wininet.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 01181696 _____ (Microsoft Corporation) H:\Windows\system32\urlmon.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00690176 _____ (Microsoft Corporation) H:\Windows\system32\jscript.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00524288 _____ (Microsoft Corporation) H:\Windows\system32\vbscript.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00493056 _____ (Microsoft Corporation) H:\Windows\system32\msfeeds.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00391168 _____ (Microsoft Corporation) H:\Windows\system32\ieui.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00357888 _____ (Microsoft Corporation) H:\Windows\system32\dxtmsft.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00226816 _____ (Microsoft Corporation) H:\Windows\system32\iedkcs32.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00226816 _____ (Microsoft Corporation) H:\Windows\system32\dxtrans.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00163840 _____ (Microsoft Corporation) H:\Windows\system32\msrating.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00109056 _____ (Microsoft Corporation) H:\Windows\system32\iesysprep.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00080384 _____ (Microsoft Corporation) H:\Windows\system32\mshtmled.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00061440 _____ (Microsoft Corporation) H:\Windows\system32\iesetup.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00042496 _____ (Microsoft Corporation) H:\Windows\system32\ie4uinit.exe
2015-05-13 03:18 - 2015-04-21 07:33 - 00039424 _____ (Microsoft Corporation) H:\Windows\system32\jsproxy.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00033280 _____ (Microsoft Corporation) H:\Windows\system32\iernonce.dll
2015-05-13 03:18 - 2015-04-21 07:32 - 01441280 _____ (Microsoft Corporation) H:\Windows\system32\inetcpl.cpl
2015-05-13 03:18 - 2015-04-19 19:56 - 01250816 _____ (Microsoft Corporation) H:\Windows\system32\DWrite.dll
2015-05-13 03:18 - 2015-04-19 19:56 - 00909312 _____ (Microsoft Corporation) H:\Windows\system32\FntCache.dll
2015-05-13 03:18 - 2015-04-19 19:03 - 02382336 _____ (Microsoft Corporation) H:\Windows\system32\win32k.sys
2015-05-13 03:18 - 2015-04-17 20:06 - 02706432 _____ (Microsoft Corporation) H:\Windows\system32\mshtml.tlb
2015-05-13 03:18 - 2015-04-17 19:56 - 00342016 _____ (Microsoft Corporation) H:\Windows\system32\certcli.dll
2015-05-13 03:18 - 2015-04-17 19:37 - 00361984 _____ (Microsoft Corporation) H:\Windows\system32\html.iec
2015-05-13 03:18 - 2015-04-17 19:12 - 00071680 _____ (Microsoft Corporation) H:\Windows\system32\RegisterIEPKEYs.exe
2015-05-13 03:18 - 2015-04-12 20:19 - 00259072 _____ (Microsoft Corporation) H:\Windows\system32\services.exe
2015-05-13 03:18 - 2015-04-07 20:14 - 00216064 _____ (Microsoft Corporation) H:\Windows\system32\InkEd.dll
2015-05-13 03:18 - 2015-04-07 20:14 - 00019968 _____ (Microsoft Corporation) H:\Windows\system32\jnwmon.dll
2015-05-13 03:18 - 2015-02-18 00:06 - 00123904 _____ (Microsoft Corporation) H:\Windows\system32\poqexec.exe
2015-05-11 09:37 - 2015-05-11 09:37 - 06484352 _____ (Piriform Ltd) H:\Users\Don\Downloads\ccsetup505.exe
2015-05-05 13:17 - 2015-05-05 13:18 - 00000000 ____D () H:\Users\Public\Documents\Will
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-05-22 22:56 - 2009-07-13 21:34 - 00015936 ____H () H:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-22 22:56 - 2009-07-13 21:34 - 00015936 ____H () H:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-22 22:51 - 2015-03-24 20:58 - 01891107 _____ () H:\Windows\WindowsUpdate.log
2015-05-22 22:47 - 2009-07-13 21:53 - 00000006 ____H () H:\Windows\Tasks\SA.DAT
2015-05-22 08:05 - 2015-04-12 12:37 - 00007891 _____ () H:\Windows\BRRBCOM.INI
2015-05-21 22:57 - 2009-07-13 21:53 - 00032604 _____ () H:\Windows\Tasks\SCHEDLGU.TXT
2015-05-21 21:22 - 2014-04-20 01:09 - 00000000 ____D () H:\Users\Don\AppData\Local\CrashDumps
2015-05-21 20:07 - 2014-04-17 18:12 - 00000000 ____D () H:\Users\Don\AppData\Local\PokerStars.NET
2015-05-21 20:04 - 2014-07-07 23:24 - 00119512 _____ (Malwarebytes Corporation) H:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-20 15:45 - 2009-07-13 19:37 - 00000000 ____D () H:\Windows\rescache
2015-05-20 14:33 - 2014-04-15 23:05 - 00781790 _____ () H:\Windows\system32\PerfStringBackup.INI
2015-05-20 14:22 - 2009-07-13 19:37 - 00000000 ____D () H:\Windows\system32\AdvancedInstallers
2015-05-20 13:06 - 2014-04-16 16:40 - 00000000 ____D () H:\Users\Don\AppData\Local\LogMeIn Rescue Applet
2015-05-20 08:32 - 2014-04-15 23:06 - 00058496 _____ () H:\Users\Don\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-20 08:08 - 2014-04-16 17:01 - 00000000 ____D () H:\ProgramData\Norton
2015-05-19 21:28 - 2014-07-07 23:13 - 00000000 ____D () H:\Program Files\Malwarebytes Anti-Malware
2015-05-19 21:28 - 2014-04-16 23:29 - 00001064 _____ () H:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-19 19:47 - 2013-01-15 00:34 - 00000000 ____D () H:\Users\Don\Documents\My Items
2015-05-18 20:26 - 2014-08-13 07:24 - 00000000 ____D () H:\Users\Don\AppData\Local\Adobe
2015-05-18 20:25 - 2014-04-16 22:53 - 00778416 _____ (Adobe Systems Incorporated) H:\Windows\system32\FlashPlayerApp.exe
2015-05-18 20:25 - 2014-04-16 22:53 - 00142512 _____ (Adobe Systems Incorporated) H:\Windows\system32\FlashPlayerCPLApp.cpl
2015-05-18 20:17 - 2014-04-09 00:56 - 00000000 ____D () H:\Windows\Panther
2015-05-17 09:02 - 2009-07-13 19:37 - 00000000 ____D () H:\Windows\Microsoft.NET
2015-05-17 08:13 - 2009-07-14 00:50 - 00000000 ____D () H:\Program Files\Windows Journal
2015-05-17 07:58 - 2009-07-13 21:33 - 00269104 _____ () H:\Windows\system32\FNTCACHE.DAT
2015-05-17 02:24 - 2014-04-16 13:58 - 00000000 ____D () H:\Windows\system32\MRT
2015-05-17 02:15 - 2014-04-16 13:58 - 137310008 _____ (Microsoft Corporation) H:\Windows\system32\MRT.exe
2015-05-11 09:05 - 2015-04-01 19:59 - 00000000 ____D () H:\Users\Don\Downloads\rempnp
2015-05-05 14:48 - 2014-04-17 18:12 - 00000000 ____D () H:\Program Files\PokerStars.NET
2015-05-05 08:14 - 2014-12-22 02:23 - 00000582 _____ () H:\Users\Don\Desktop\Mark & Greg.txt
2015-04-22 13:31 - 2014-10-17 13:31 - 00000000 ____D () H:\ProgramData\IObit
2015-04-22 00:21 - 2009-07-13 19:37 - 00000000 ____D () H:\Windows\system32\NDF
 
==================== Files in the root of some directories =======
 
2013-10-10 15:55 - 2013-10-10 15:55 - 0049944 _____ (SUPERAdBlocker.com) H:\Program Files\BootSafe.exe
2004-05-20 13:28 - 2004-05-20 13:28 - 0002048 _____ () H:\Program Files\detect.wav
2014-07-14 11:26 - 2014-07-14 11:26 - 0000192 _____ () H:\Program Files\High Contrast Black.set
2004-05-07 15:31 - 2004-05-07 15:31 - 0348160 _____ (Microsoft Corporation) H:\Program Files\msvcr71.dll
2013-10-10 15:55 - 2013-10-10 15:55 - 0316184 _____ (SUPERAdBlocker.com and SUPERAntiSpyware.com) H:\Program Files\RUNSAS.EXE
2014-07-08 12:30 - 2014-07-08 12:30 - 0000192 _____ () H:\Program Files\SAS Default.set
2014-07-22 16:47 - 2014-07-22 16:47 - 0142648 _____ (SUPERAntiSpyware.com) H:\Program Files\SASCore.exe
2014-06-06 11:40 - 2014-06-06 11:40 - 0150808 _____ (SUPERAntiSpyware.com) H:\Program Files\SASCTXMN.DLL
2011-07-22 09:27 - 2011-07-22 09:27 - 0012880 _____ (SUPERAdBlocker.com and SUPERAntiSpyware.com) H:\Program Files\sasdifsv.sys
2011-07-12 14:55 - 2011-07-12 14:55 - 0067664 _____ (SUPERAdBlocker.com and SUPERAntiSpyware.com) H:\Program Files\SASKUTIL.SYS
2012-10-26 10:10 - 2012-10-26 10:10 - 0555008 _____ () H:\Program Files\SASREPAIRS.STG
2013-05-07 15:36 - 2013-05-07 15:36 - 0115440 _____ (SuperAdBlocker.com) H:\Program Files\SASSEH.DLL
2013-11-07 13:08 - 2013-11-07 13:08 - 0049944 _____ (SUPERAdBlocker.com) H:\Program Files\SASTask.exe
2013-11-07 11:21 - 2013-11-07 11:21 - 0041272 _____ (Support.com) H:\Program Files\sas_enum_cookies.exe
2010-12-30 14:48 - 2010-12-30 14:48 - 0004096 _____ () H:\Program Files\SAS_Preconfig.db3
2014-07-29 13:45 - 2014-07-29 13:45 - 0395032 _____ (SUPERAntiSpyware.com) H:\Program Files\SSUpdate.exe
2015-05-15 11:59 - 2015-05-15 11:59 - 6714136 _____ (SUPERAntiSpyware) H:\Program Files\SUPERAntiSpyware.exe
2013-12-04 18:15 - 2013-12-04 18:15 - 0059160 _____ (Support.com) H:\Program Files\SUPERDelete.exe
2015-05-19 18:05 - 2015-05-19 18:05 - 0018432 _____ () H:\Program Files\Uninstall.dat
2014-07-30 16:42 - 2014-07-30 16:42 - 0560408 _____ (SUPERAdBlocker.com) H:\Program Files\Uninstall.exe
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
H:\Windows\explorer.exe => File is digitally signed
H:\Windows\system32\winlogon.exe => File is digitally signed
H:\Windows\system32\wininit.exe => File is digitally signed
H:\Windows\system32\svchost.exe => File is digitally signed
H:\Windows\system32\services.exe => File is digitally signed
H:\Windows\system32\User32.dll => File is digitally signed
H:\Windows\system32\userinit.exe => File is digitally signed
H:\Windows\system32\rpcss.dll => File is digitally signed
H:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-05-14 00:15
 
==================== End of log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-05-2015 01
Ran by Don at 2015-05-22 22:57:16
Running from H:\Users\Don\Desktop
Boot Mode: Normal
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-05-2015 01
Ran by Don at 2015-05-22 22:57:16
Running from H:\Users\Don\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3964834215-2275053063-3108885826-500 - Administrator - Disabled)
Don (S-1-5-21-3964834215-2275053063-3108885826-1000 - Administrator - Enabled) => H:\Users\Don
Guest (S-1-5-21-3964834215-2275053063-3108885826-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3964834215-2275053063-3108885826-1003 - Limited - Enabled)
Merry (S-1-5-21-3964834215-2275053063-3108885826-1001 - Administrator - Enabled) => H:\Users\Merry

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton AntiVirus Online (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton AntiVirus Online (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

1 Media Player version 2.2.0 (HKLM\...\{6C566E3B-CBFB-4A3C-A8B6-88EA54DE7CA8}_is1) (Version: 2.2.0 - OneFloorApp Ltd.)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 15.0.0.249 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Brother MFL-Pro Suite MFC-J425W (HKLM\...\{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}) (Version: 1.0.19.0 - Brother Industries, Ltd.)
Brother MFL-Pro Suite MFC-J650DW (HKLM\...\{7B4C83B6-17C1-4BFD-B86D-4D7AD4498CBB}) (Version: 1.0.4.0 - Brother Industries, Ltd.)
Bytescout XLS Viewer 1.30a (FREEWARE) (HKLM\...\Bytescout XLS Viewer_is1) (Version:  - Bytescout Software)
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
Data Fax SoftModem with SmartCP (HKLM\...\CNXT_MODEM_PCI_VEN_14F1&DEV_2702&SUBSYS_8D88A259) (Version:  - )
Defraggler (HKLM\...\Defraggler) (Version: 2.19 - Piriform)
f.lux (HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\...\Flux) (Version:  - )
Free Opener (HKLM\...\{A1F2C608-32D6-467D-B035-BBEF509042BA}_is1) (Version: 1.0 - EZ Freeware)
Google Chrome (HKLM\...\Google Chrome) (Version: 43.0.2357.65 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.710 - Oracle)
K-Lite Codec Pack 7.0.0 (Standard) (HKLM\...\KLiteCodecPack_is1) (Version: 7.0.0 - )
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Media Player Classic - Home Cinema v1.5.2.3456 (HKLM\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.5.2.3456 - MPC-HC Team)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Excel Viewer (HKLM\...\{95120000-003F-0409-0000-0000000FF1CE}) (Version: 12.0.6219.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 38.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 38.0.1 (x86 en-US)) (Version: 38.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 38.0.1 - Mozilla)
mPlayer version 1.0 (HKLM\...\{B482E758-D602-434C-80B9-DDEFEEAE4BCA}_is1) (Version: 1.0 - Download Freely, LLC)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Norton AntiVirus (HKLM\...\NAV) (Version: 21.7.0.11 - Symantec Corporation)
Nuance PaperPort 12 (HKLM\...\{869FCC6C-5669-4B0B-827E-2BBAACD88A87}) (Version: 12.1.0006 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
PaperPort Image Printer (HKLM\...\{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}) (Version: 14.00.0000 - Nuance Communications, Inc.)
PDF Split And Merge Basic (HKLM\...\{9A40D2F8-9458-458B-95E3-B57797C574E1}) (Version: 2.2.4 - Andrea Vacondio)
PokerStars.net (HKLM\...\PokerStars.net) (Version:  - PokerStars.net)
PrintDeskTop (HKLM\...\PrintDeskTop_is1) (Version:  - PrintDeskTop)
Pro PC Cleaner (HKLM\...\{BED67F4B-AD6C-4DE8-98F2-EFB5BE5AFE5A}) (Version: 2.6.0 - Pro PC Cleaner)
Realtek AC'97 Audio (HKLM\...\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version:  - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7083 - Realtek Semiconductor Corp.)
Scansoft PDF Professional (Version:  - ) Hidden
SiS 900 PCI Fast Ethernet Adapter Driver (HKLM\...\SiSLan) (Version:  - )
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1194 - SUPERAntiSpyware.com)
Windows Driver Package - Silicon Integrated Systems (uagp35) System  (04/14/2010 7.2.0.1232) (HKLM\...\421AF4FC7DA3FA928071877E7EE33B3D2690C950) (Version: 04/14/2010 7.2.0.1232 - Silicon Integrated Systems)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3964834215-2275053063-3108885826-1000_Classes\CLSID\{6d05bf60-3eaf-4a97-87c5-10cce505435b}\localserver32 -> H:\Users\Don\AppData\Local\Temp\{9c0ba3c1-2b67-45eb-bf69-bed9658d28d2}\IDriver.NonElevated.exe No Fi (the data entry has 2 more characters).

==================== Restore Points =========================

17-05-2015 02:04:11 Windows Update
17-05-2015 08:12:28 Windows Update
20-05-2015 13:18:31 LavasoftWeCompanion
20-05-2015 14:19:16 Windows Update
21-05-2015 22:50:06 LavasoftWeCompanion

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:04 - 2009-06-10 14:39 - 00000824 ____N H:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01E5A617-ECA9-4C1E-8534-6B1D95E7102F} - System32\Tasks\{14D13FA0-A47F-48E4-8D6D-0135177D34BC} => Firefox.exe http://ui.skype.com/...=lightinstaller
Task: {214EF93E-A10E-49AE-88AC-FF3B3F6F1EFE} - System32\Tasks\{FC292CCC-C4CD-4146-9A90-CBF662E1D0EC} => pcalua.exe -a H:\Users\Don\Downloads\PCHCInstallerPackage.exe -d H:\Users\Don\Downloads
Task: {2F53881C-2786-4007-B7B6-0B597CBC2EBC} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => H:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {3B6FABC5-6772-4F67-A376-D52626CBBF8D} - \ProPCCleaner_Popup No Task File <==== ATTENTION
Task: {4522B405-449B-466F-AC8A-591288739956} - System32\Tasks\watchHealth => H:\ProgramData\CouponAlert\watcher\watcher.exe [2015-05-20] (Microsoft)
Task: {4F7D2622-07EB-423B-99D4-DB635EB35C66} - System32\Tasks\Norton AntiVirus\Norton Error Processor => H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {6072D411-F70B-47C5-83D2-E62FD10932A4} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => H:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
Task: {61D447A9-A53F-4C0F-9D33-B6CE10DB7BB7} - \Driver Booster SkipUAC (Don) No Task File <==== ATTENTION
Task: {6DA09067-6D78-4D57-8911-6ADC1F4D9D6E} - System32\Tasks\{0F073963-AFAF-4FD1-9C64-0DE30E40F61A} => Chrome.exe
Task: {6DA65DAE-52BF-4278-B18A-E3A9FE9B396F} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => H:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {755CE52F-3ED0-4742-B174-C253B1188975} - System32\Tasks\{FB2A723C-03E7-47B5-BB1A-799D24D5AC6C} => H:\Program Files\DriverRestore\DriverRestore.exe
Task: {8D983CB6-34A8-4F58-B0DA-9C51CC0DF66C} - \Driver Booster Update No Task File <==== ATTENTION
Task: {986BE30A-77DF-4BCA-BC50-301F2F41304D} - System32\Tasks\Norton WSC Integration => H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\WSCStub.exe [2015-03-06] (Symantec Corporation)
Task: {C6574CC7-F89A-4176-8635-86625ED9C6F8} - System32\Tasks\{6A8A0EF1-795E-47AF-BBA6-54CCAAD12224} => H:\Program Files\DriverRestore\DriverRestore.exe
Task: {CA345D8F-7B89-428C-ABBE-128698082F1F} - \ProPCCleaner_Start No Task File <==== ATTENTION
Task: {CE76E854-63AD-4378-A785-A8A7A1DCD283} - System32\Tasks\{4089B4ED-BA7E-4A36-9BA4-21CDA5E19CEE} => Firefox.exe http://ui.skype.com/...#38;page=tsMain
Task: {D9647C7F-CBD0-4217-A19A-B8C425B49887} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => H:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {EC91BCFD-FE61-46DE-A8A6-1314126E3B82} - System32\Tasks\CCleanerSkipUAC => H:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)
Task: {F0AA9CB3-B8FA-4B98-B3CA-3B2BE3CB43F7} - System32\Tasks\Norton AntiVirus\Norton Error Analyzer => H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {FD6BCCA0-CFB5-4281-A660-CF71A928ED6A} - \Driver Booster Scan No Task File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Loaded Modules (Whitelisted) ==============

2015-04-01 22:06 - 2009-02-27 16:38 - 00139264 ____R () H:\Program Files\Brother\BrUtilities\BrLogAPI.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\Control Panel\Desktop\\Wallpaper -> H:\Users\Don\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1 - 205.171.2.25

==================== MSCONFIG/TASK MANAGER Error getting ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: 083B39FB7B958A0F78E959FDA72E539905C51D18._service_run => "H:\Program Files\Google\Chrome\Application\chrome.exe" --type=service
MSCONFIG\startupreg: Adobe ARM => "H:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AlcxMonitor => ALCXMNTR.EXE
MSCONFIG\startupreg: BrHelp => H:\Program Files\Brother\Brother Help\BrotherHelp.exe /AUTORUN
MSCONFIG\startupreg: BrStsMon00 => H:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: ControlCenter4 => H:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: f.lux => "H:\Users\Don\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
MSCONFIG\startupreg: FlashPlayerUpdate => H:\Windows\system32\Macromed\Flash\FlashUtil32_15_0_0_223_Plugin.exe -update plugin
MSCONFIG\startupreg: IndexSearch => "H:\Program Files\Nuance\PaperPort\IndexSearch.exe"
MSCONFIG\startupreg: iSkysoft Helper Compact.exe => H:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
MSCONFIG\startupreg: ISUSPM => H:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: Malwarebytes Anti-Malware => H:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
MSCONFIG\startupreg: PaperPort PTD => "H:\Program Files\Nuance\PaperPort\pptd40nt.exe"
MSCONFIG\startupreg: PDF5 Registry Controller => H:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe
MSCONFIG\startupreg: PDFHook => H:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe
MSCONFIG\startupreg: PPort12reminder => "H:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "H:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
MSCONFIG\startupreg: SunJavaUpdateSched => "H:\Program Files\Common Files\Java\Java Update\jusched.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{4D8B5F7C-751E-480A-9BDA-83E43961C405}] => (Allow) H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{0E5C621C-82DB-4DCE-ACA9-E28FB960FE05}] => (Allow) H:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{B1294B24-8558-4FD3-A389-12E0D0267012}] => (Allow) H:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{1203947C-E12C-4617-A551-6D29348B1A59}] => (Allow) H:\Program Files\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/22/2015 03:03:09 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWN BrtTWN: [2015/05/22 15:03:09.318]: [00003420]: Initialize TwdsMain Class failed!

Error: (05/22/2015 03:03:09 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWN BrtTWN: [2015/05/22 15:03:09.302]: [00003420]: ##### Fatal ERROR!! Create STI-device failed! #####

Error: (05/21/2015 10:53:31 PM) (Source: MsiInstaller) (EventID: 10005) (User: Don-PC)
Description: Product: Pro PC Cleaner -- Error 2753. The File 'Uninst000.CA.dll' is not marked for installation.

Error: (05/21/2015 10:50:17 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.


Details:
AddWin32ServiceFiles: Unable to back up image of service Util Triple Pose since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (05/21/2015 09:22:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 38.0.1.5611, time stamp: 0x55541a90
Faulting module name: mozalloc.dll, version: 38.0.1.5611, time stamp: 0x55540a1e
Exception code: 0x80000003
Fault offset: 0x00001aa1
Faulting process id: 0x1330
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3

Error: (05/20/2015 02:30:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ISightHost.exe, version: 0.0.0.0, time stamp: 0x54653b10
Faulting module name: ISightSDK.DLL, version: 0.0.0.0, time stamp: 0x54653b2a
Exception code: 0x40000015
Fault offset: 0x000455c6
Faulting process id: 0x3d8
Faulting application start time: 0xISightHost.exe0
Faulting application path: ISightHost.exe1
Faulting module path: ISightHost.exe2
Report Id: ISightHost.exe3

Error: (05/20/2015 02:19:22 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.


Details:
AddWin32ServiceFiles: Unable to back up image of service Util Triple Pose since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (05/20/2015 02:11:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ISightHost.exe, version: 0.0.0.0, time stamp: 0x54653b10
Faulting module name: ISightSDK.DLL, version: 0.0.0.0, time stamp: 0x54653b2a
Exception code: 0x40000015
Fault offset: 0x000455c6
Faulting process id: 0x6b4
Faulting application start time: 0xISightHost.exe0
Faulting application path: ISightHost.exe1
Faulting module path: ISightHost.exe2
Report Id: ISightHost.exe3

Error: (05/20/2015 01:58:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ISightHost.exe, version: 0.0.0.0, time stamp: 0x54653b10
Faulting module name: ISightSDK.DLL, version: 0.0.0.0, time stamp: 0x54653b2a
Exception code: 0x40000015
Fault offset: 0x000455c6
Faulting process id: 0x13f8
Faulting application start time: 0xISightHost.exe0
Faulting application path: ISightHost.exe1
Faulting module path: ISightHost.exe2
Report Id: ISightHost.exe3

Error: (05/20/2015 08:34:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: PCHealthCheck.exe, version: 1.0.0.1, time stamp: 0x5203de92
Faulting module name: PCHealthCheck.exe, version: 1.0.0.1, time stamp: 0x5203de92
Exception code: 0xc0000005
Fault offset: 0x0000d060
Faulting process id: 0x65c
Faulting application start time: 0xPCHealthCheck.exe0
Faulting application path: PCHealthCheck.exe1
Faulting module path: PCHealthCheck.exe2
Report Id: PCHealthCheck.exe3


System errors:
=============
Error: (05/22/2015 10:50:11 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: )
Description: 0x800700b7

Error: (05/22/2015 10:50:11 PM) (Source: WMPNetworkSvc) (EventID: 14353) (User: )
Description: 00x800700b7http://+:10243/WMPNSSv4/2539395219/

Error: (05/22/2015 10:50:11 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: )
Description: 0x800700b7

Error: (05/22/2015 10:50:11 PM) (Source: WMPNetworkSvc) (EventID: 14353) (User: )
Description: 00x800700b7http://+:10243/WMPNSSv4/2539395219/

Error: (05/22/2015 10:47:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Update Triple Pose service failed to start due to the following error:
%%2

Error: (05/22/2015 10:47:03 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT AUTHORITY)
Description: Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware.

Error: (05/22/2015 06:23:43 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (05/22/2015 06:23:38 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (05/22/2015 04:52:07 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (05/22/2015 04:52:06 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.


Microsoft Office:
=========================
Error: (05/22/2015 03:03:09 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWNBrtTWN: [2015/05/22 15:03:09.318]: [00003420]: Initialize TwdsMain Class failed!

Error: (05/22/2015 03:03:09 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWNBrtTWN: [2015/05/22 15:03:09.302]: [00003420]: ##### Fatal ERROR!! Create STI-device failed! #####

Error: (05/21/2015 10:53:31 PM) (Source: MsiInstaller) (EventID: 10005) (User: Don-PC)
Description: Product: Pro PC Cleaner -- Error 2753. The File 'Uninst000.CA.dll' is not marked for installation.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (05/21/2015 10:50:17 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service Util Triple Pose since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (05/21/2015 09:22:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe38.0.1.561155541a90mozalloc.dll38.0.1.561155540a1e8000000300001aa1133001d09446d4a06935H:\Program Files\Mozilla Firefox\plugin-container.exeH:\Program Files\Mozilla Firefox\mozalloc.dll29a2af0c-003a-11e5-a5da-0011d851ae52

Error: (05/20/2015 02:30:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ISightHost.exe0.0.0.054653b10ISightSDK.DLL0.0.0.054653b2a40000015000455c63d801d09343b081bd4aH:\Users\Don\AppData\Local\Temp\isdkjfQuVUl9\ISightHost.exeH:\Users\Don\AppData\Local\Temp\isdkjfQuVUl9\ISightSDK.DLL608d93cc-ff37-11e4-ad52-0011d851ae52

Error: (05/20/2015 02:19:22 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service Util Triple Pose since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (05/20/2015 02:11:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ISightHost.exe0.0.0.054653b10ISightSDK.DLL0.0.0.054653b2a40000015000455c66b401d09340e9485339H:\Users\Don\AppData\Local\Temp\isdkQMbk34Gw\ISightHost.exeH:\Users\Don\AppData\Local\Temp\isdkQMbk34Gw\ISightSDK.DLLd3da62f3-ff34-11e4-973f-0011d851ae52

Error: (05/20/2015 01:58:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ISightHost.exe0.0.0.054653b10ISightSDK.DLL0.0.0.054653b2a40000015000455c613f801d0933f2765b27fH:\Users\Don\AppData\Local\Temp\isdkNf4ObokH\ISightHost.exeH:\Users\Don\AppData\Local\Temp\isdkNf4ObokH\ISightSDK.DLLfc88da65-ff32-11e4-942c-0011d851ae52

Error: (05/20/2015 08:34:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: PCHealthCheck.exe1.0.0.15203de92PCHealthCheck.exe1.0.0.15203de92c00000050000d06065c01d0931269f04d69H:\Users\Don\AppData\Roaming\PCHC\PCHealthCheck.exeH:\Users\Don\AppData\Roaming\PCHC\PCHealthCheck.exea98e3fdc-ff05-11e4-8dbb-0011d851ae52


==================== Memory info ===========================

Processor: AMD Sempron™ Processor 3100+
Percentage of memory in use: 43%
Total physical RAM: 1919.55 MB
Available physical RAM: 1090.7 MB
Total Pagefile: 3839.11 MB
Available Pagefile: 2952.74 MB
Total Virtual: 2047.88 MB
Available Virtual: 1910.4 MB

==================== Drives ================================

Drive h: () (Fixed) (Total:127.99 GB) (Free:72.9 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: C6E09F94)
Partition 1: (Active) - (Size=128 GB) - (Type=07 NTFS)

==================== End of log ============================

Edited by Don Stewart, 23 May 2015 - 09:37 AM.

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there should be a second log called additions could you post that

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
FF user.js: detected! => H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\user.js [2015-05-21]
S2 Update Triple Pose; "H:\Program Files\Triple Pose\updateTriplePose.exe" [X]
R1 {ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw; H:\Windows\System32\drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys [43152 2015-05-20] (StdLib)
2015-05-20 13:53 - 2015-05-20 13:53 - 00000000 ____D () H:\Users\Don\AppData\Local\WebDiscoverBrowser
2015-05-20 13:48 - 2015-05-20 13:48 - 00000000 ____D () H:\Users\Don\Documents\ProPCCleaner
2015-05-20 13:25 - 2015-05-20 07:43 - 00043152 _____ (StdLib) H:\Windows\system32\Drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys
2015-05-20 13:24 - 2015-05-21 22:47 - 00000000 ____D () H:\Program Files\WebDiscoverBrowser
2015-05-20 13:22 - 2015-05-21 22:57 - 00000000 ____D () H:\Program Files\Triple Pose
2015-05-20 13:22 - 2015-05-20 13:22 - 00000000 ____D () H:\ProgramData\CouponAlert
2015-05-20 13:21 - 2015-05-20 13:21 - 00002848 _____ () H:\Windows\system32\LavasoftTcpServiceOff.ini
2015-05-20 13:21 - 2015-04-30 10:50 - 00347976 _____ (Lavasoft Limited) H:\Windows\system32\LavasoftTcpService.dll
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.

  • 0

#3
Don Stewart

Don Stewart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 239 posts

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-05-2015 01
Ran by Don at 2015-05-22 22:57:16
Running from H:\Users\Don\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3964834215-2275053063-3108885826-500 - Administrator - Disabled)
Don (S-1-5-21-3964834215-2275053063-3108885826-1000 - Administrator - Enabled) => H:\Users\Don
Guest (S-1-5-21-3964834215-2275053063-3108885826-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3964834215-2275053063-3108885826-1003 - Limited - Enabled)
Merry (S-1-5-21-3964834215-2275053063-3108885826-1001 - Administrator - Enabled) => H:\Users\Merry

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton AntiVirus Online (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton AntiVirus Online (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

1 Media Player version 2.2.0 (HKLM\...\{6C566E3B-CBFB-4A3C-A8B6-88EA54DE7CA8}_is1) (Version: 2.2.0 - OneFloorApp Ltd.)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 15.0.0.249 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Brother MFL-Pro Suite MFC-J425W (HKLM\...\{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}) (Version: 1.0.19.0 - Brother Industries, Ltd.)
Brother MFL-Pro Suite MFC-J650DW (HKLM\...\{7B4C83B6-17C1-4BFD-B86D-4D7AD4498CBB}) (Version: 1.0.4.0 - Brother Industries, Ltd.)
Bytescout XLS Viewer 1.30a (FREEWARE) (HKLM\...\Bytescout XLS Viewer_is1) (Version:  - Bytescout Software)
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
Data Fax SoftModem with SmartCP (HKLM\...\CNXT_MODEM_PCI_VEN_14F1&DEV_2702&SUBSYS_8D88A259) (Version:  - )
Defraggler (HKLM\...\Defraggler) (Version: 2.19 - Piriform)
f.lux (HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\...\Flux) (Version:  - )
Free Opener (HKLM\...\{A1F2C608-32D6-467D-B035-BBEF509042BA}_is1) (Version: 1.0 - EZ Freeware)
Google Chrome (HKLM\...\Google Chrome) (Version: 43.0.2357.65 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.710 - Oracle)
K-Lite Codec Pack 7.0.0 (Standard) (HKLM\...\KLiteCodecPack_is1) (Version: 7.0.0 - )
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Media Player Classic - Home Cinema v1.5.2.3456 (HKLM\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.5.2.3456 - MPC-HC Team)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Excel Viewer (HKLM\...\{95120000-003F-0409-0000-0000000FF1CE}) (Version: 12.0.6219.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 38.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 38.0.1 (x86 en-US)) (Version: 38.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 38.0.1 - Mozilla)
mPlayer version 1.0 (HKLM\...\{B482E758-D602-434C-80B9-DDEFEEAE4BCA}_is1) (Version: 1.0 - Download Freely, LLC)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Norton AntiVirus (HKLM\...\NAV) (Version: 21.7.0.11 - Symantec Corporation)
Nuance PaperPort 12 (HKLM\...\{869FCC6C-5669-4B0B-827E-2BBAACD88A87}) (Version: 12.1.0006 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
PaperPort Image Printer (HKLM\...\{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}) (Version: 14.00.0000 - Nuance Communications, Inc.)
PDF Split And Merge Basic (HKLM\...\{9A40D2F8-9458-458B-95E3-B57797C574E1}) (Version: 2.2.4 - Andrea Vacondio)
PokerStars.net (HKLM\...\PokerStars.net) (Version:  - PokerStars.net)
PrintDeskTop (HKLM\...\PrintDeskTop_is1) (Version:  - PrintDeskTop)
Pro PC Cleaner (HKLM\...\{BED67F4B-AD6C-4DE8-98F2-EFB5BE5AFE5A}) (Version: 2.6.0 - Pro PC Cleaner)
Realtek AC'97 Audio (HKLM\...\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version:  - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7083 - Realtek Semiconductor Corp.)
Scansoft PDF Professional (Version:  - ) Hidden
SiS 900 PCI Fast Ethernet Adapter Driver (HKLM\...\SiSLan) (Version:  - )
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1194 - SUPERAntiSpyware.com)
Windows Driver Package - Silicon Integrated Systems (uagp35) System  (04/14/2010 7.2.0.1232) (HKLM\...\421AF4FC7DA3FA928071877E7EE33B3D2690C950) (Version: 04/14/2010 7.2.0.1232 - Silicon Integrated Systems)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3964834215-2275053063-3108885826-1000_Classes\CLSID\{6d05bf60-3eaf-4a97-87c5-10cce505435b}\localserver32 -> H:\Users\Don\AppData\Local\Temp\{9c0ba3c1-2b67-45eb-bf69-bed9658d28d2}\IDriver.NonElevated.exe No Fi (the data entry has 2 more characters).

==================== Restore Points =========================

17-05-2015 02:04:11 Windows Update
17-05-2015 08:12:28 Windows Update
20-05-2015 13:18:31 LavasoftWeCompanion
20-05-2015 14:19:16 Windows Update
21-05-2015 22:50:06 LavasoftWeCompanion

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:04 - 2009-06-10 14:39 - 00000824 ____N H:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01E5A617-ECA9-4C1E-8534-6B1D95E7102F} - System32\Tasks\{14D13FA0-A47F-48E4-8D6D-0135177D34BC} => Firefox.exe http://ui.skype.com/...=lightinstaller
Task: {214EF93E-A10E-49AE-88AC-FF3B3F6F1EFE} - System32\Tasks\{FC292CCC-C4CD-4146-9A90-CBF662E1D0EC} => pcalua.exe -a H:\Users\Don\Downloads\PCHCInstallerPackage.exe -d H:\Users\Don\Downloads
Task: {2F53881C-2786-4007-B7B6-0B597CBC2EBC} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => H:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {3B6FABC5-6772-4F67-A376-D52626CBBF8D} - \ProPCCleaner_Popup No Task File <==== ATTENTION
Task: {4522B405-449B-466F-AC8A-591288739956} - System32\Tasks\watchHealth => H:\ProgramData\CouponAlert\watcher\watcher.exe [2015-05-20] (Microsoft)
Task: {4F7D2622-07EB-423B-99D4-DB635EB35C66} - System32\Tasks\Norton AntiVirus\Norton Error Processor => H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {6072D411-F70B-47C5-83D2-E62FD10932A4} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => H:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
Task: {61D447A9-A53F-4C0F-9D33-B6CE10DB7BB7} - \Driver Booster SkipUAC (Don) No Task File <==== ATTENTION
Task: {6DA09067-6D78-4D57-8911-6ADC1F4D9D6E} - System32\Tasks\{0F073963-AFAF-4FD1-9C64-0DE30E40F61A} => Chrome.exe
Task: {6DA65DAE-52BF-4278-B18A-E3A9FE9B396F} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => H:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {755CE52F-3ED0-4742-B174-C253B1188975} - System32\Tasks\{FB2A723C-03E7-47B5-BB1A-799D24D5AC6C} => H:\Program Files\DriverRestore\DriverRestore.exe
Task: {8D983CB6-34A8-4F58-B0DA-9C51CC0DF66C} - \Driver Booster Update No Task File <==== ATTENTION
Task: {986BE30A-77DF-4BCA-BC50-301F2F41304D} - System32\Tasks\Norton WSC Integration => H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\WSCStub.exe [2015-03-06] (Symantec Corporation)
Task: {C6574CC7-F89A-4176-8635-86625ED9C6F8} - System32\Tasks\{6A8A0EF1-795E-47AF-BBA6-54CCAAD12224} => H:\Program Files\DriverRestore\DriverRestore.exe
Task: {CA345D8F-7B89-428C-ABBE-128698082F1F} - \ProPCCleaner_Start No Task File <==== ATTENTION
Task: {CE76E854-63AD-4378-A785-A8A7A1DCD283} - System32\Tasks\{4089B4ED-BA7E-4A36-9BA4-21CDA5E19CEE} => Firefox.exe http://ui.skype.com/...#38;page=tsMain
Task: {D9647C7F-CBD0-4217-A19A-B8C425B49887} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => H:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {EC91BCFD-FE61-46DE-A8A6-1314126E3B82} - System32\Tasks\CCleanerSkipUAC => H:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)
Task: {F0AA9CB3-B8FA-4B98-B3CA-3B2BE3CB43F7} - System32\Tasks\Norton AntiVirus\Norton Error Analyzer => H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {FD6BCCA0-CFB5-4281-A660-CF71A928ED6A} - \Driver Booster Scan No Task File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Loaded Modules (Whitelisted) ==============

2015-04-01 22:06 - 2009-02-27 16:38 - 00139264 ____R () H:\Program Files\Brother\BrUtilities\BrLogAPI.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\Control Panel\Desktop\\Wallpaper -> H:\Users\Don\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1 - 205.171.2.25

==================== MSCONFIG/TASK MANAGER Error getting ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: 083B39FB7B958A0F78E959FDA72E539905C51D18._service_run => "H:\Program Files\Google\Chrome\Application\chrome.exe" --type=service
MSCONFIG\startupreg: Adobe ARM => "H:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AlcxMonitor => ALCXMNTR.EXE
MSCONFIG\startupreg: BrHelp => H:\Program Files\Brother\Brother Help\BrotherHelp.exe /AUTORUN
MSCONFIG\startupreg: BrStsMon00 => H:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: ControlCenter4 => H:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: f.lux => "H:\Users\Don\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
MSCONFIG\startupreg: FlashPlayerUpdate => H:\Windows\system32\Macromed\Flash\FlashUtil32_15_0_0_223_Plugin.exe -update plugin
MSCONFIG\startupreg: IndexSearch => "H:\Program Files\Nuance\PaperPort\IndexSearch.exe"
MSCONFIG\startupreg: iSkysoft Helper Compact.exe => H:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
MSCONFIG\startupreg: ISUSPM => H:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: Malwarebytes Anti-Malware => H:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
MSCONFIG\startupreg: PaperPort PTD => "H:\Program Files\Nuance\PaperPort\pptd40nt.exe"
MSCONFIG\startupreg: PDF5 Registry Controller => H:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe
MSCONFIG\startupreg: PDFHook => H:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe
MSCONFIG\startupreg: PPort12reminder => "H:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "H:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
MSCONFIG\startupreg: SunJavaUpdateSched => "H:\Program Files\Common Files\Java\Java Update\jusched.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{4D8B5F7C-751E-480A-9BDA-83E43961C405}] => (Allow) H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{0E5C621C-82DB-4DCE-ACA9-E28FB960FE05}] => (Allow) H:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{B1294B24-8558-4FD3-A389-12E0D0267012}] => (Allow) H:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{1203947C-E12C-4617-A551-6D29348B1A59}] => (Allow) H:\Program Files\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/22/2015 03:03:09 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWN BrtTWN: [2015/05/22 15:03:09.318]: [00003420]: Initialize TwdsMain Class failed!

Error: (05/22/2015 03:03:09 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWN BrtTWN: [2015/05/22 15:03:09.302]: [00003420]: ##### Fatal ERROR!! Create STI-device failed! #####

Error: (05/21/2015 10:53:31 PM) (Source: MsiInstaller) (EventID: 10005) (User: Don-PC)
Description: Product: Pro PC Cleaner -- Error 2753. The File 'Uninst000.CA.dll' is not marked for installation.

Error: (05/21/2015 10:50:17 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.


Details:
AddWin32ServiceFiles: Unable to back up image of service Util Triple Pose since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (05/21/2015 09:22:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 38.0.1.5611, time stamp: 0x55541a90
Faulting module name: mozalloc.dll, version: 38.0.1.5611, time stamp: 0x55540a1e
Exception code: 0x80000003
Fault offset: 0x00001aa1
Faulting process id: 0x1330
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3

Error: (05/20/2015 02:30:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ISightHost.exe, version: 0.0.0.0, time stamp: 0x54653b10
Faulting module name: ISightSDK.DLL, version: 0.0.0.0, time stamp: 0x54653b2a
Exception code: 0x40000015
Fault offset: 0x000455c6
Faulting process id: 0x3d8
Faulting application start time: 0xISightHost.exe0
Faulting application path: ISightHost.exe1
Faulting module path: ISightHost.exe2
Report Id: ISightHost.exe3

Error: (05/20/2015 02:19:22 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.


Details:
AddWin32ServiceFiles: Unable to back up image of service Util Triple Pose since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (05/20/2015 02:11:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ISightHost.exe, version: 0.0.0.0, time stamp: 0x54653b10
Faulting module name: ISightSDK.DLL, version: 0.0.0.0, time stamp: 0x54653b2a
Exception code: 0x40000015
Fault offset: 0x000455c6
Faulting process id: 0x6b4
Faulting application start time: 0xISightHost.exe0
Faulting application path: ISightHost.exe1
Faulting module path: ISightHost.exe2
Report Id: ISightHost.exe3

Error: (05/20/2015 01:58:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ISightHost.exe, version: 0.0.0.0, time stamp: 0x54653b10
Faulting module name: ISightSDK.DLL, version: 0.0.0.0, time stamp: 0x54653b2a
Exception code: 0x40000015
Fault offset: 0x000455c6
Faulting process id: 0x13f8
Faulting application start time: 0xISightHost.exe0
Faulting application path: ISightHost.exe1
Faulting module path: ISightHost.exe2
Report Id: ISightHost.exe3

Error: (05/20/2015 08:34:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: PCHealthCheck.exe, version: 1.0.0.1, time stamp: 0x5203de92
Faulting module name: PCHealthCheck.exe, version: 1.0.0.1, time stamp: 0x5203de92
Exception code: 0xc0000005
Fault offset: 0x0000d060
Faulting process id: 0x65c
Faulting application start time: 0xPCHealthCheck.exe0
Faulting application path: PCHealthCheck.exe1
Faulting module path: PCHealthCheck.exe2
Report Id: PCHealthCheck.exe3


System errors:
=============
Error: (05/22/2015 10:50:11 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: )
Description: 0x800700b7

Error: (05/22/2015 10:50:11 PM) (Source: WMPNetworkSvc) (EventID: 14353) (User: )
Description: 00x800700b7http://+:10243/WMPNSSv4/2539395219/

Error: (05/22/2015 10:50:11 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: )
Description: 0x800700b7

Error: (05/22/2015 10:50:11 PM) (Source: WMPNetworkSvc) (EventID: 14353) (User: )
Description: 00x800700b7http://+:10243/WMPNSSv4/2539395219/

Error: (05/22/2015 10:47:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Update Triple Pose service failed to start due to the following error:
%%2

Error: (05/22/2015 10:47:03 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT AUTHORITY)
Description: Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware.

Error: (05/22/2015 06:23:43 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (05/22/2015 06:23:38 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (05/22/2015 04:52:07 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (05/22/2015 04:52:06 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.


Microsoft Office:
=========================
Error: (05/22/2015 03:03:09 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWNBrtTWN: [2015/05/22 15:03:09.318]: [00003420]: Initialize TwdsMain Class failed!

Error: (05/22/2015 03:03:09 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWNBrtTWN: [2015/05/22 15:03:09.302]: [00003420]: ##### Fatal ERROR!! Create STI-device failed! #####

Error: (05/21/2015 10:53:31 PM) (Source: MsiInstaller) (EventID: 10005) (User: Don-PC)
Description: Product: Pro PC Cleaner -- Error 2753. The File 'Uninst000.CA.dll' is not marked for installation.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (05/21/2015 10:50:17 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service Util Triple Pose since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (05/21/2015 09:22:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe38.0.1.561155541a90mozalloc.dll38.0.1.561155540a1e8000000300001aa1133001d09446d4a06935H:\Program Files\Mozilla Firefox\plugin-container.exeH:\Program Files\Mozilla Firefox\mozalloc.dll29a2af0c-003a-11e5-a5da-0011d851ae52

Error: (05/20/2015 02:30:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ISightHost.exe0.0.0.054653b10ISightSDK.DLL0.0.0.054653b2a40000015000455c63d801d09343b081bd4aH:\Users\Don\AppData\Local\Temp\isdkjfQuVUl9\ISightHost.exeH:\Users\Don\AppData\Local\Temp\isdkjfQuVUl9\ISightSDK.DLL608d93cc-ff37-11e4-ad52-0011d851ae52

Error: (05/20/2015 02:19:22 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service Util Triple Pose since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (05/20/2015 02:11:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ISightHost.exe0.0.0.054653b10ISightSDK.DLL0.0.0.054653b2a40000015000455c66b401d09340e9485339H:\Users\Don\AppData\Local\Temp\isdkQMbk34Gw\ISightHost.exeH:\Users\Don\AppData\Local\Temp\isdkQMbk34Gw\ISightSDK.DLLd3da62f3-ff34-11e4-973f-0011d851ae52

Error: (05/20/2015 01:58:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ISightHost.exe0.0.0.054653b10ISightSDK.DLL0.0.0.054653b2a40000015000455c613f801d0933f2765b27fH:\Users\Don\AppData\Local\Temp\isdkNf4ObokH\ISightHost.exeH:\Users\Don\AppData\Local\Temp\isdkNf4ObokH\ISightSDK.DLLfc88da65-ff32-11e4-942c-0011d851ae52

Error: (05/20/2015 08:34:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: PCHealthCheck.exe1.0.0.15203de92PCHealthCheck.exe1.0.0.15203de92c00000050000d06065c01d0931269f04d69H:\Users\Don\AppData\Roaming\PCHC\PCHealthCheck.exeH:\Users\Don\AppData\Roaming\PCHC\PCHealthCheck.exea98e3fdc-ff05-11e4-8dbb-0011d851ae52


==================== Memory info ===========================

Processor: AMD Sempron™ Processor 3100+
Percentage of memory in use: 43%
Total physical RAM: 1919.55 MB
Available physical RAM: 1090.7 MB
Total Pagefile: 3839.11 MB
Available Pagefile: 2952.74 MB
Total Virtual: 2047.88 MB
Available Virtual: 1910.4 MB

==================== Drives ================================

Drive h: () (Fixed) (Total:127.99 GB) (Free:72.9 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: C6E09F94)
Partition 1: (Active) - (Size=128 GB) - (Type=07 NTFS)

==================== End of log ============================

 

 

When I try the next step: run FRST, then hit Fix I get this error "Warning looks you don't know what to do.  To prevent damage to the system the tool will exit.  Guess it was right, I don't know what I'm doing .....help!   I waiting for futurer instructions before proceeding.


Edited by Don Stewart, 23 May 2015 - 10:12 AM.

  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
You probably made a copy error when making the fixlist .. No matter :)

Download the attached fixlist to your desktop
Start FRST
Press Fix
On completion a log will be generated please post that
Attached File  fixlist.txt   2.4KB   256 downloads

THEN

Run adwcleaner as previously described
  • 0

#5
Don Stewart

Don Stewart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 239 posts
Hope this is what you wanted, as still getting same error.-
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-05-2015 01
Ran by Don (administrator) on DON-PC on 23-05-2015 09:34:30
Running from H:\Users\Don\Desktop
Loaded Profiles: Don (Available Profiles: Don & Merry)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(SUPERAntiSpyware.com) H:\Program Files\SASCore.exe
(Symantec Corporation) H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\nav.exe
(Nuance Communications, Inc.) H:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
(Symantec Corporation) H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\nav.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) H:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
(Adobe Systems, Inc.) H:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
(Microsoft Corporation) H:\Windows\System32\dllhost.exe
(Microsoft Corporation) H:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\S-1-5-18\...\RunOnce: [SPReview] => H:\Windows\System32\SPReview\SPReview.exe [280576 2014-04-17] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?...OIE8MSE&PC=UP09
HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/...nlogo=CT3331981
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKU\S-1-5-21-3964834215-2275053063-3108885826-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3964834215-2275053063-3108885826-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...q={searchTerms}
BHO: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> H:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\IPS\IPSBHO.DLL [2015-03-04] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> H:\Program Files\Java\jre7\bin\ssv.dll [2014-09-26] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> H:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-26] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.2.25

FireFox:
========
FF ProfilePath: H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833
FF DefaultSearchEngine: Bing
FF DefaultSearchEngine.US: Bing
FF Plugin: @adobe.com/FlashPlayer -> H:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-18] ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> H:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> H:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @tools.google.com/Google Update;version=3 -> H:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-14] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> H:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-14] (Google Inc.)
FF Plugin: Adobe Reader -> H:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF user.js: detected! => H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\user.js [2015-05-21]
FF Extension: Flashblock - H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2014-12-10]
FF Extension: NoScript - H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-10-23]
FF Extension: Adblock Plus - H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-23]

Chrome:
=======
CHR Profile: H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bookmark Manager) - H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-16]
CHR Extension: (Chrome Hotword Shared Module) - H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-16]
CHR Extension: (Google Wallet) - H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-19]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; H:\Program Files\SASCORE.EXE [142648 2014-07-22] (SUPERAntiSpyware.com)
S3 BrYNSvc; H:\Program Files\Browny02\BrYNSvc.exe [282112 2012-10-26] (Brother Industries, Ltd.) []
R2 DiagTrack; H:\Windows\system32\diagtrack.dll [851456 2015-04-27] (Microsoft Corporation)
S2 MBAMService; H:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 NAV; H:\Program Files\Norton AntiVirus\Engine\21.7.0.11\NAV.exe [262928 2015-03-06] (Symantec Corporation)
R2 PDFProFiltSrvPP; H:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [145256 2011-08-02] (Nuance Communications, Inc.)
S3 WinDefend; H:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ALCXWDM; H:\Windows\System32\drivers\ALCXWDM.SYS [3844032 2006-01-11] (Realtek Semiconductor Corp.)
R1 BHDrvx86; H:\Program Files\Norton AntiVirus\NortonData\21.1.0.18\Definitions\BASHDefs\20150519.001\BHDrvx86.sys [1172184 2015-05-01] (Symantec Corporation)
R1 ccSet_NAV; H:\Windows\system32\drivers\NAV\1507000.00B\ccSetx86.sys [127064 2013-09-25] (Symantec Corporation)
R1 eeCtrl; H:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2015-03-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; H:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [111408 2015-03-15] (Symantec Corporation)
S3 GKUPRO2D; H:\Windows\System32\DRIVERS\GKUPRO2D.sys [90240 2012-11-05] (Gemalto)
R1 IDSVix86; H:\Program Files\Norton AntiVirus\NortonData\21.1.0.18\Definitions\IPSDefs\20150521.003\IDSvix86.sys [505048 2015-03-30] (Symantec Corporation)
R3 MBAMProtector; H:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMSwissArmy; H:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-05-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; H:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R3 NAVENG; H:\Program Files\Norton AntiVirus\NortonData\21.1.0.18\Definitions\VirusDefs\20150522.017\NAVENG.SYS [95704 2015-03-15] (Symantec Corporation)
R3 NAVEX15; H:\Program Files\Norton AntiVirus\NortonData\21.1.0.18\Definitions\VirusDefs\20150522.017\NAVEX15.SYS [1636696 2015-03-15] (Symantec Corporation)
R1 SASDIFSV; H:\Program Files\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; H:\Program Files\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SISNIC; H:\Windows\System32\DRIVERS\sisnic.sys [40840 2006-07-13] (SiS Corporation)
S3 SISNICXP; H:\Windows\System32\DRIVERS\sisnicxp.sys [32768 2006-02-14] (SiS Corporation)
R3 SRTSP; H:\Windows\System32\Drivers\NAV\1507000.00B\SRTSP.SYS [664792 2014-08-25] (Symantec Corporation)
R1 SRTSPX; H:\Windows\system32\drivers\NAV\1507000.00B\SRTSPX.SYS [32984 2014-08-25] (Symantec Corporation)
S3 SrvHsfPCI; H:\Windows\System32\DRIVERS\VSTBS23.SYS [266752 2009-07-13] (Conexant Systems, Inc.)
R0 SymDS; H:\Windows\System32\drivers\NAV\1507000.00B\SYMDS.SYS [367704 2013-09-09] (Symantec Corporation)
R0 SymEFA; H:\Windows\System32\drivers\NAV\1507000.00B\SYMEFA.SYS [936152 2014-03-03] (Symantec Corporation)
R3 SymEvent; H:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2014-04-16] (Symantec Corporation)
R1 SymIRON; H:\Windows\system32\drivers\NAV\1507000.00B\Ironx86.SYS [209624 2014-08-06] (Symantec Corporation)
R1 SymNetS; H:\Windows\System32\Drivers\NAV\1507000.00B\SYMNETS.SYS [447704 2014-02-17] (Symantec Corporation)
R1 {ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw; H:\Windows\System32\drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys [43152 2015-05-20] (StdLib)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-23 08:52 - 2015-05-23 08:53 - 00022756 _____ () H:\Users\Don\Desktop\Addition.txt
2015-05-23 08:09 - 2015-05-23 08:09 - 00070699 _____ () H:\Users\Don\Downloads\Options.xul
2015-05-23 07:58 - 2015-05-23 07:58 - 00000056 _____ () H:\Windows\setupact.log
2015-05-23 07:58 - 2015-05-23 07:58 - 00000000 _____ () H:\Windows\setuperr.log
2015-05-22 23:53 - 2015-05-22 23:53 - 00010218 _____ () H:\Users\Public\Documents\cc_20150522_235320.reg
2015-05-22 22:57 - 2015-05-22 22:57 - 00024472 _____ () H:\Users\Don\Desktop\fixlist.txt
2015-05-22 22:56 - 2015-05-23 09:34 - 00010280 _____ () H:\Users\Don\Desktop\FRST.txt
2015-05-22 22:54 - 2015-05-23 09:34 - 00000000 ____D () H:\FRST
2015-05-22 22:54 - 2015-05-22 22:54 - 00000000 ____D () H:\Users\Don\Desktop\FRST-OlderVersion
2015-05-22 22:53 - 2015-05-22 22:54 - 01147392 _____ (Farbar) H:\Users\Don\Desktop\FRST.exe
2015-05-22 15:30 - 2015-05-22 15:30 - 00000000 ____D () H:\Users\Public\Documents\Sewer
2015-05-21 22:06 - 2015-05-21 22:06 - 00000000 ____D () H:\Users\Don\Desktop\DVDIRECT_DISC_00100002052
2015-05-21 21:46 - 2015-05-21 21:46 - 03060320 ____N (Symantec Corporation) H:\Users\Don\Downloads\NPE.exe
2015-05-21 14:13 - 2015-05-21 14:13 - 00000000 _____ () H:\Users\Don\Documents\Nuance Image Printer Writer Port
2015-05-21 13:41 - 2015-05-21 13:43 - 00000000 _____ () H:\Users\Merry\Documents\Nuance Image Printer Writer Port
2015-05-21 13:33 - 2015-05-21 13:33 - 00000000 ____D () H:\Users\Merry\AppData\Roaming\Zeon
2015-05-20 14:18 - 2015-04-27 12:11 - 03989440 _____ (Microsoft Corporation) H:\Windows\system32\ntkrnlpa.exe
2015-05-20 14:18 - 2015-04-27 12:11 - 03934144 _____ (Microsoft Corporation) H:\Windows\system32\ntoskrnl.exe
2015-05-20 14:18 - 2015-04-27 12:11 - 00137664 _____ (Microsoft Corporation) H:\Windows\system32\Drivers\ksecpkg.sys
2015-05-20 14:18 - 2015-04-27 12:11 - 00067520 _____ (Microsoft Corporation) H:\Windows\system32\Drivers\ksecdd.sys
2015-05-20 14:18 - 2015-04-27 12:08 - 01307648 _____ (Microsoft Corporation) H:\Windows\system32\ntdll.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00851456 _____ (Microsoft Corporation) H:\Windows\system32\diagtrack.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00635392 _____ (Microsoft Corporation) H:\Windows\system32\tdh.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00400896 _____ (Microsoft Corporation) H:\Windows\system32\srcore.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00259584 _____ (Microsoft Corporation) H:\Windows\system32\msv1_0.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00221184 _____ (Microsoft Corporation) H:\Windows\system32\ncrypt.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00172032 _____ (Microsoft Corporation) H:\Windows\system32\wdigest.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00100352 _____ (Microsoft Corporation) H:\Windows\system32\sspicli.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00092160 _____ (Microsoft Corporation) H:\Windows\system32\sechost.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00065536 _____ (Microsoft Corporation) H:\Windows\system32\TSpkg.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00043008 _____ (Microsoft Corporation) H:\Windows\system32\srclient.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00022016 _____ (Microsoft Corporation) H:\Windows\system32\secur32.dll
2015-05-20 14:18 - 2015-04-27 12:05 - 00015872 _____ (Microsoft Corporation) H:\Windows\system32\sspisrv.dll
2015-05-20 14:18 - 2015-04-27 12:04 - 01061376 _____ (Microsoft Corporation) H:\Windows\system32\lsasrv.dll
2015-05-20 14:18 - 2015-04-27 12:04 - 00641536 _____ (Microsoft Corporation) H:\Windows\system32\advapi32.dll
2015-05-20 14:18 - 2015-04-27 12:04 - 00550912 _____ (Microsoft Corporation) H:\Windows\system32\kerberos.dll
2015-05-20 14:18 - 2015-04-27 12:04 - 00364544 _____ (Microsoft Corporation) H:\Windows\system32\tracerpt.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00262656 _____ (Microsoft Corporation) H:\Windows\system32\rstrui.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00082944 _____ (Microsoft Corporation) H:\Windows\system32\logman.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00069632 _____ (Microsoft Corporation) H:\Windows\system32\smss.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00040448 _____ (Microsoft Corporation) H:\Windows\system32\typeperf.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00038912 _____ (Microsoft Corporation) H:\Windows\system32\csrsrv.dll
2015-05-20 14:18 - 2015-04-27 12:04 - 00037888 _____ (Microsoft Corporation) H:\Windows\system32\relog.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00022528 _____ (Microsoft Corporation) H:\Windows\system32\lsass.exe
2015-05-20 14:18 - 2015-04-27 12:04 - 00017408 _____ (Microsoft Corporation) H:\Windows\system32\credssp.dll
2015-05-20 14:18 - 2015-04-27 12:03 - 00050176 _____ (Microsoft Corporation) H:\Windows\system32\auditpol.exe
2015-05-20 14:18 - 2015-04-27 12:03 - 00017408 _____ (Microsoft Corporation) H:\Windows\system32\diskperf.exe
2015-05-20 14:18 - 2015-04-27 12:01 - 00146432 _____ (Microsoft Corporation) H:\Windows\system32\msaudite.dll
2015-05-20 14:18 - 2015-04-27 12:01 - 00060416 _____ (Microsoft Corporation) H:\Windows\system32\msobjs.dll
2015-05-20 14:18 - 2015-04-27 11:59 - 00686080 _____ (Microsoft Corporation) H:\Windows\system32\adtschema.dll
2015-05-20 14:18 - 2015-04-27 11:59 - 00006656 _____ (Microsoft Corporation) H:\Windows\system32\apisetschema.dll
2015-05-20 14:18 - 2015-04-27 11:00 - 00036864 _____ (Microsoft Corporation) H:\Windows\system32\UtcResources.dll
2015-05-20 14:18 - 2015-01-28 20:02 - 02311168 _____ (Microsoft Corporation) H:\Windows\system32\wpdshext.dll
2015-05-20 14:16 - 2015-04-10 20:07 - 00054656 _____ (Microsoft Corporation) H:\Windows\system32\Drivers\stream.sys
2015-05-20 14:16 - 2015-03-13 20:04 - 01372160 _____ (Microsoft Corporation) H:\Windows\system32\dwmcore.dll
2015-05-20 14:16 - 2015-03-13 20:04 - 00067584 _____ (Microsoft Corporation) H:\Windows\system32\dwmapi.dll
2015-05-20 14:16 - 2015-03-03 21:11 - 00005120 _____ (Microsoft Corporation) H:\Windows\system32\shimeng.dll
2015-05-20 14:16 - 2015-03-03 21:10 - 00295936 _____ (Microsoft Corporation) H:\Windows\system32\apphelp.dll
2015-05-20 14:16 - 2015-03-03 21:10 - 00062464 _____ (Microsoft Corporation) H:\Windows\system32\aelupsvc.dll
2015-05-20 14:16 - 2015-03-03 21:10 - 00020992 _____ (Microsoft Corporation) H:\Windows\system32\sdbinst.exe
2015-05-20 13:53 - 2015-05-20 13:53 - 00000000 ____D () H:\Users\Don\AppData\Local\WebDiscoverBrowser
2015-05-20 13:48 - 2015-05-20 13:48 - 00000000 ____D () H:\Users\Don\Documents\ProPCCleaner
2015-05-20 13:25 - 2015-05-20 07:43 - 00043152 _____ (StdLib) H:\Windows\system32\Drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys
2015-05-20 13:24 - 2015-05-21 22:47 - 00000000 ____D () H:\Program Files\WebDiscoverBrowser
2015-05-20 13:22 - 2015-05-21 22:57 - 00000000 ____D () H:\Program Files\Triple Pose
2015-05-20 13:22 - 2015-05-20 13:22 - 00000000 ____D () H:\ProgramData\CouponAlert
2015-05-20 13:21 - 2015-05-20 13:21 - 00002848 _____ () H:\Windows\system32\LavasoftTcpServiceOff.ini
2015-05-20 13:21 - 2015-04-30 10:50 - 00347976 _____ (Lavasoft Limited) H:\Windows\system32\LavasoftTcpService.dll
2015-05-20 13:19 - 2015-05-20 13:19 - 00001117 _____ () H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-05-20 13:19 - 2015-05-20 13:19 - 00001105 _____ () H:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-05-20 13:19 - 2015-05-20 13:19 - 00000000 ____D () H:\Program Files\Mozilla Maintenance Service
2015-05-20 13:18 - 2015-05-21 14:30 - 00000000 ____D () H:\Program Files\Mozilla Firefox
2015-05-20 13:17 - 2015-05-20 13:17 - 00243344 _____ () H:\Users\Don\Downloads\Firefox Setup Stub 38.0.1.exe
2015-05-20 13:16 - 2015-05-20 13:16 - 00983736 _____ (Download Assistant) H:\Users\Don\Downloads\firefox_install.exe
2015-05-20 08:42 - 2015-05-20 08:42 - 01489216 _____ (LogMeIn, Inc.) H:\Users\Don\Downloads\Support-LogMeInRescue(1).exe
2015-05-20 08:38 - 2015-05-20 08:38 - 00000145 _____ () H:\Users\Don\Desktop\CenturyLink PC Services.url
2015-05-20 08:36 - 2015-05-20 08:37 - 00000000 ____D () H:\Users\Don\AppData\Roaming\PCHC
2015-05-20 08:30 - 2015-05-20 08:30 - 02459880 _____ () H:\Users\Don\Downloads\PCHCInstallerPackage.exe
2015-05-20 08:10 - 2015-05-21 21:50 - 00000000 ____D () H:\NPE
2015-05-20 08:07 - 2015-05-21 22:00 - 00000000 ____D () H:\Users\Don\AppData\Local\NPE
2015-05-19 18:05 - 2015-05-19 18:05 - 00018432 _____ () H:\Program Files\Uninstall.dat
2015-05-19 18:05 - 2015-05-19 18:05 - 00000000 ____D () H:\Users\Don\AppData\Roaming\SUPERAntiSpyware.com
2015-05-19 18:04 - 2015-05-19 18:04 - 00001744 _____ () H:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-05-19 18:04 - 2015-05-19 18:04 - 00000000 ____D () H:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-05-19 18:04 - 2015-05-19 18:04 - 00000000 ____D () H:\Program Files\Plugins
2015-05-19 18:01 - 2015-05-19 18:02 - 21972920 _____ (SUPERAntiSpyware) H:\Users\Don\Downloads\SUPERAntiSpyware(1).exe
2015-05-18 20:18 - 2015-05-18 20:19 - 00000188 _____ () H:\Users\Public\Documents\cc_20150518_201853.reg
2015-05-17 09:06 - 2015-05-17 09:06 - 00000000 ____H () H:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2015-05-17 08:22 - 2015-05-23 08:23 - 00000195 _____ () H:\Users\Don\Desktop\BloodPressue.txt
2015-05-17 02:24 - 2015-05-01 06:16 - 00102608 _____ (Microsoft Corporation) H:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-17 02:02 - 2015-05-17 02:02 - 00000604 _____ () H:\Users\Public\Documents\cc_20150517_020238.reg
2015-05-15 11:59 - 2015-05-15 11:59 - 06714136 _____ (SUPERAntiSpyware) H:\Program Files\SUPERAntiSpyware.exe
2015-05-13 03:18 - 2015-05-04 18:12 - 00248832 _____ (Microsoft Corporation) H:\Windows\system32\schannel.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 14374400 _____ (Microsoft Corporation) H:\Windows\system32\mshtml.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 13771776 _____ (Microsoft Corporation) H:\Windows\system32\ieframe.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 02864640 _____ (Microsoft Corporation) H:\Windows\system32\jscript9.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 02055680 _____ (Microsoft Corporation) H:\Windows\system32\iertutil.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 01763328 _____ (Microsoft Corporation) H:\Windows\system32\wininet.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 01181696 _____ (Microsoft Corporation) H:\Windows\system32\urlmon.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00690176 _____ (Microsoft Corporation) H:\Windows\system32\jscript.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00524288 _____ (Microsoft Corporation) H:\Windows\system32\vbscript.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00493056 _____ (Microsoft Corporation) H:\Windows\system32\msfeeds.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00391168 _____ (Microsoft Corporation) H:\Windows\system32\ieui.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00357888 _____ (Microsoft Corporation) H:\Windows\system32\dxtmsft.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00226816 _____ (Microsoft Corporation) H:\Windows\system32\iedkcs32.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00226816 _____ (Microsoft Corporation) H:\Windows\system32\dxtrans.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00163840 _____ (Microsoft Corporation) H:\Windows\system32\msrating.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00109056 _____ (Microsoft Corporation) H:\Windows\system32\iesysprep.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00080384 _____ (Microsoft Corporation) H:\Windows\system32\mshtmled.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00061440 _____ (Microsoft Corporation) H:\Windows\system32\iesetup.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00042496 _____ (Microsoft Corporation) H:\Windows\system32\ie4uinit.exe
2015-05-13 03:18 - 2015-04-21 07:33 - 00039424 _____ (Microsoft Corporation) H:\Windows\system32\jsproxy.dll
2015-05-13 03:18 - 2015-04-21 07:33 - 00033280 _____ (Microsoft Corporation) H:\Windows\system32\iernonce.dll
2015-05-13 03:18 - 2015-04-21 07:32 - 01441280 _____ (Microsoft Corporation) H:\Windows\system32\inetcpl.cpl
2015-05-13 03:18 - 2015-04-19 19:56 - 01250816 _____ (Microsoft Corporation) H:\Windows\system32\DWrite.dll
2015-05-13 03:18 - 2015-04-19 19:56 - 00909312 _____ (Microsoft Corporation) H:\Windows\system32\FntCache.dll
2015-05-13 03:18 - 2015-04-19 19:03 - 02382336 _____ (Microsoft Corporation) H:\Windows\system32\win32k.sys
2015-05-13 03:18 - 2015-04-17 20:06 - 02706432 _____ (Microsoft Corporation) H:\Windows\system32\mshtml.tlb
2015-05-13 03:18 - 2015-04-17 19:56 - 00342016 _____ (Microsoft Corporation) H:\Windows\system32\certcli.dll
2015-05-13 03:18 - 2015-04-17 19:37 - 00361984 _____ (Microsoft Corporation) H:\Windows\system32\html.iec
2015-05-13 03:18 - 2015-04-17 19:12 - 00071680 _____ (Microsoft Corporation) H:\Windows\system32\RegisterIEPKEYs.exe
2015-05-13 03:18 - 2015-04-12 20:19 - 00259072 _____ (Microsoft Corporation) H:\Windows\system32\services.exe
2015-05-13 03:18 - 2015-04-07 20:14 - 00216064 _____ (Microsoft Corporation) H:\Windows\system32\InkEd.dll
2015-05-13 03:18 - 2015-04-07 20:14 - 00019968 _____ (Microsoft Corporation) H:\Windows\system32\jnwmon.dll
2015-05-13 03:18 - 2015-02-18 00:06 - 00123904 _____ (Microsoft Corporation) H:\Windows\system32\poqexec.exe
2015-05-11 09:37 - 2015-05-11 09:37 - 06484352 _____ (Piriform Ltd) H:\Users\Don\Downloads\ccsetup505.exe
2015-05-05 13:17 - 2015-05-05 13:18 - 00000000 ____D () H:\Users\Public\Documents\Will

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-23 08:06 - 2009-07-13 21:34 - 00015936 ____H () H:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-23 08:06 - 2009-07-13 21:34 - 00015936 ____H () H:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-23 08:03 - 2015-03-24 20:58 - 01906714 _____ () H:\Windows\WindowsUpdate.log
2015-05-23 08:00 - 2015-04-12 12:37 - 00007891 _____ () H:\Windows\BRRBCOM.INI
2015-05-23 07:58 - 2009-07-13 21:53 - 00000006 ____H () H:\Windows\Tasks\SA.DAT
2015-05-22 23:51 - 2014-04-20 01:09 - 00000000 ____D () H:\Users\Don\AppData\Local\CrashDumps
2015-05-21 22:57 - 2009-07-13 21:53 - 00032604 _____ () H:\Windows\Tasks\SCHEDLGU.TXT
2015-05-21 20:07 - 2014-04-17 18:12 - 00000000 ____D () H:\Users\Don\AppData\Local\PokerStars.NET
2015-05-21 20:04 - 2014-07-07 23:24 - 00119512 _____ (Malwarebytes Corporation) H:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-20 15:45 - 2009-07-13 19:37 - 00000000 ____D () H:\Windows\rescache
2015-05-20 14:33 - 2014-04-15 23:05 - 00781790 _____ () H:\Windows\system32\PerfStringBackup.INI
2015-05-20 14:22 - 2009-07-13 19:37 - 00000000 ____D () H:\Windows\system32\AdvancedInstallers
2015-05-20 13:06 - 2014-04-16 16:40 - 00000000 ____D () H:\Users\Don\AppData\Local\LogMeIn Rescue Applet
2015-05-20 08:32 - 2014-04-15 23:06 - 00058496 _____ () H:\Users\Don\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-20 08:08 - 2014-04-16 17:01 - 00000000 ____D () H:\ProgramData\Norton
2015-05-19 21:28 - 2014-07-07 23:13 - 00000000 ____D () H:\Program Files\Malwarebytes Anti-Malware
2015-05-19 21:28 - 2014-04-16 23:29 - 00001064 _____ () H:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-19 19:47 - 2013-01-15 00:34 - 00000000 ____D () H:\Users\Don\Documents\My Items
2015-05-18 20:26 - 2014-08-13 07:24 - 00000000 ____D () H:\Users\Don\AppData\Local\Adobe
2015-05-18 20:25 - 2014-04-16 22:53 - 00778416 _____ (Adobe Systems Incorporated) H:\Windows\system32\FlashPlayerApp.exe
2015-05-18 20:25 - 2014-04-16 22:53 - 00142512 _____ (Adobe Systems Incorporated) H:\Windows\system32\FlashPlayerCPLApp.cpl
2015-05-18 20:17 - 2014-04-09 00:56 - 00000000 ____D () H:\Windows\Panther
2015-05-17 09:02 - 2009-07-13 19:37 - 00000000 ____D () H:\Windows\Microsoft.NET
2015-05-17 08:13 - 2009-07-14 00:50 - 00000000 ____D () H:\Program Files\Windows Journal
2015-05-17 07:58 - 2009-07-13 21:33 - 00269104 _____ () H:\Windows\system32\FNTCACHE.DAT
2015-05-17 02:24 - 2014-04-16 13:58 - 00000000 ____D () H:\Windows\system32\MRT
2015-05-17 02:15 - 2014-04-16 13:58 - 137310008 _____ (Microsoft Corporation) H:\Windows\system32\MRT.exe
2015-05-11 09:05 - 2015-04-01 19:59 - 00000000 ____D () H:\Users\Don\Downloads\rempnp
2015-05-05 14:48 - 2014-04-17 18:12 - 00000000 ____D () H:\Program Files\PokerStars.NET
2015-05-05 08:14 - 2014-12-22 02:23 - 00000582 _____ () H:\Users\Don\Desktop\Mark & Greg.txt

==================== Files in the root of some directories =======

2013-10-10 15:55 - 2013-10-10 15:55 - 0049944 _____ (SUPERAdBlocker.com) H:\Program Files\BootSafe.exe
2004-05-20 13:28 - 2004-05-20 13:28 - 0002048 _____ () H:\Program Files\detect.wav
2014-07-14 11:26 - 2014-07-14 11:26 - 0000192 _____ () H:\Program Files\High Contrast Black.set
2004-05-07 15:31 - 2004-05-07 15:31 - 0348160 _____ (Microsoft Corporation) H:\Program Files\msvcr71.dll
2013-10-10 15:55 - 2013-10-10 15:55 - 0316184 _____ (SUPERAdBlocker.com and SUPERAntiSpyware.com) H:\Program Files\RUNSAS.EXE
2014-07-08 12:30 - 2014-07-08 12:30 - 0000192 _____ () H:\Program Files\SAS Default.set
2014-07-22 16:47 - 2014-07-22 16:47 - 0142648 _____ (SUPERAntiSpyware.com) H:\Program Files\SASCore.exe
2014-06-06 11:40 - 2014-06-06 11:40 - 0150808 _____ (SUPERAntiSpyware.com) H:\Program Files\SASCTXMN.DLL
2011-07-22 09:27 - 2011-07-22 09:27 - 0012880 _____ (SUPERAdBlocker.com and SUPERAntiSpyware.com) H:\Program Files\sasdifsv.sys
2011-07-12 14:55 - 2011-07-12 14:55 - 0067664 _____ (SUPERAdBlocker.com and SUPERAntiSpyware.com) H:\Program Files\SASKUTIL.SYS
2012-10-26 10:10 - 2012-10-26 10:10 - 0555008 _____ () H:\Program Files\SASREPAIRS.STG
2013-05-07 15:36 - 2013-05-07 15:36 - 0115440 _____ (SuperAdBlocker.com) H:\Program Files\SASSEH.DLL
2013-11-07 13:08 - 2013-11-07 13:08 - 0049944 _____ (SUPERAdBlocker.com) H:\Program Files\SASTask.exe
2013-11-07 11:21 - 2013-11-07 11:21 - 0041272 _____ (Support.com) H:\Program Files\sas_enum_cookies.exe
2010-12-30 14:48 - 2010-12-30 14:48 - 0004096 _____ () H:\Program Files\SAS_Preconfig.db3
2014-07-29 13:45 - 2014-07-29 13:45 - 0395032 _____ (SUPERAntiSpyware.com) H:\Program Files\SSUpdate.exe
2015-05-15 11:59 - 2015-05-15 11:59 - 6714136 _____ (SUPERAntiSpyware) H:\Program Files\SUPERAntiSpyware.exe
2013-12-04 18:15 - 2013-12-04 18:15 - 0059160 _____ (Support.com) H:\Program Files\SUPERDelete.exe
2015-05-19 18:05 - 2015-05-19 18:05 - 0018432 _____ () H:\Program Files\Uninstall.dat
2014-07-30 16:42 - 2014-07-30 16:42 - 0560408 _____ (SUPERAdBlocker.com) H:\Program Files\Uninstall.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

H:\Windows\explorer.exe => File is digitally signed
H:\Windows\system32\winlogon.exe => File is digitally signed
H:\Windows\system32\wininit.exe => File is digitally signed
H:\Windows\system32\svchost.exe => File is digitally signed
H:\Windows\system32\services.exe => File is digitally signed
H:\Windows\system32\User32.dll => File is digitally signed
H:\Windows\system32\userinit.exe => File is digitally signed
H:\Windows\system32\rpcss.dll => File is digitally signed
H:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-14 00:15

==================== End of log ============================







ran CC Cleaner after I ran FRST last night, hope that didn't impact anything.......running ADWCleaner next.

Edited by Don Stewart, 23 May 2015 - 10:44 AM.

  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Did you press fix on FRST ? As that is a fresh scan Also you do not appear to have download the fixlist that I attached
  • 0

#7
Don Stewart

Don Stewart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 239 posts
I thought I was suppose to hit scan to start FRST & then hit Fix....was I suppose to just hit fix & do you want me to do over?

Here is the log from AdwCleamer: # AdwCleaner v4.205 - Logfile created 23/05/2015 at 10:01:30
# Updated 21/05/2015 by Xplode
# Database : 2015-05-21.2 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x86)
# Username : Don - DON-PC
# Running from : H:\Users\Don\Desktop\AdwCleaner(1).exe
# Option : Cleaning

***** [ Services ] *****

Service Deleted : {ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw

***** [ Files / Folders ] *****

Folder Deleted : H:\Program Files\Triple Pose
File Deleted : H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aeljlhkkoipjimklndofjoafhpccdfjo_0.localstorage
File Deleted : H:\Program Files\Uninstall.exe
File Deleted : H:\Windows\system32\drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys
File Deleted : H:\Users\Don\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iLivid.lnk
File Deleted : H:\Users\Don\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk
File Deleted : H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\user.js

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Classes\iLivid.torrent
Key Deleted : HKLM\SOFTWARE\Classes\iLivid.torrent
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Deleted : HKCU\Software\eSupport.com
Key Deleted : HKCU\Software\ilivid

***** [ Web browsers ] *****

-\\ Internet Explorer v10.0.9200.17356


-\\ Mozilla Firefox v38.0.1 (x86 en-US)


-\\ Google Chrome v43.0.2357.65

[H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[H:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[H:\Users\Merry\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[H:\Users\Merry\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[H:\Users\Merry\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Default_Search_Provider_Data] :

*************************

AdwCleaner[R0].txt - [7612 bytes] - [17/03/2014 07:48:44]
AdwCleaner[R1].txt - [18613 bytes] - [23/05/2015 09:59:13]
AdwCleaner[S0].txt - [2610 bytes] - [23/05/2015 10:01:30]

########## EOF - H:\AdwCleaner\AdwCleaner[S0].txt - [2669 bytes] ##########
  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Download this fixlist.txt by double clicking and selecting save..
Save to your desktop
Attached File  fixlist.txt   2.4KB   152 downloads

Then start FRST and press fix :)
  • 0

#9
Don Stewart

Don Stewart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 239 posts
You stated "Download this fixlist.txt by double clicking and selecting save..
Save to your desktop" and it seems that I was requested to rename options to fixlist.txt, is this fixlist?

Starts with "Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-05-2015 01
Ran by Don at 2015-05-22 22:57:16
Running from H:\Users\Don\Desktop
Boot Mode: Normal" and ends with "==================== Drives ================================

Drive h: () (Fixed) (Total:127.99 GB) (Free:72.9 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: C6E09F94)
Partition 1: (Active) - (Size=128 GB) - (Type=07 NTFS)

==================== End of log ============================"?????????
  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
The contents of the fixlist is as below :

CreateRestorePoint:
FF user.js: detected! => H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\user.js [2015-05-21]
S2 Update Triple Pose; "H:\Program Files\Triple Pose\updateTriplePose.exe" [X]
R1 {ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw; H:\Windows\System32\drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys [43152 2015-05-20] (StdLib)
2015-05-20 13:53 - 2015-05-20 13:53 - 00000000 ____D () H:\Users\Don\AppData\Local\WebDiscoverBrowser
2015-05-20 13:48 - 2015-05-20 13:48 - 00000000 ____D () H:\Users\Don\Documents\ProPCCleaner
2015-05-20 13:25 - 2015-05-20 07:43 - 00043152 _____ (StdLib) H:\Windows\system32\Drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys
2015-05-20 13:24 - 2015-05-21 22:47 - 00000000 ____D () H:\Program Files\WebDiscoverBrowser
2015-05-20 13:22 - 2015-05-21 22:57 - 00000000 ____D () H:\Program Files\Triple Pose
2015-05-20 13:22 - 2015-05-20 13:22 - 00000000 ____D () H:\ProgramData\CouponAlert
2015-05-20 13:21 - 2015-05-20 13:21 - 00002848 _____ () H:\Windows\system32\LavasoftTcpServiceOff.ini
2015-05-20 13:21 - 2015-04-30 10:50 - 00347976 _____ (Lavasoft Limited) H:\Windows\system32\LavasoftTcpService.dll
RemoveProxy:
CustomCLSID: HKU\S-1-5-21-3964834215-2275053063-3108885826-1000_Classes\CLSID\{6d05bf60-3eaf-4a97-87c5-10cce505435b}\localserver32 -> H:\Users\Don\AppData\Local\Temp\{9c0ba3c1-2b67-45eb-bf69-bed9658d28d2}\IDriver.NonElevated.exe No Fi (the data entry has 2 more characters).
Task: {3B6FABC5-6772-4F67-A376-D52626CBBF8D} - \ProPCCleaner_Popup No Task File <==== ATTENTION
Task: {4522B405-449B-466F-AC8A-591288739956} - System32\Tasks\watchHealth => H:\ProgramData\CouponAlert\watcher\watcher.exe [2015-05-20] (Microsoft)
Task: {61D447A9-A53F-4C0F-9D33-B6CE10DB7BB7} - \Driver Booster SkipUAC (Don) No Task File <==== ATTENTION
Task: {8D983CB6-34A8-4F58-B0DA-9C51CC0DF66C} - \Driver Booster Update No Task File <==== ATTENTION
Task: {CA345D8F-7B89-428C-ABBE-128698082F1F} - \ProPCCleaner_Start No Task File <==== ATTENTION
Task: {FD6BCCA0-CFB5-4281-A660-CF71A928ED6A} - \Driver Booster Scan No Task File <==== ATTENTION
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers
  • 0

Advertisements


#11
Don Stewart

Don Stewart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 239 posts

Think I might have it this time, but it might be based on a new scan, as my Norton keeps wiping out FRST!

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 22-05-2015 01
Ran by Don at 2015-05-23 11:33:24 Run:1
Running from H:\Users\Don\Downloads
Loaded Profiles: Don (Available Profiles: Don & Merry)
Boot Mode: Normal

==============================================

fixlist content:
*****************
CreateRestorePoint:
FF user.js: detected! => H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\user.js [2015-05-21]
S2 Update Triple Pose; "H:\Program Files\Triple Pose\updateTriplePose.exe" [X]
R1 {ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw; H:\Windows\System32\drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys [43152 2015-05-20] (StdLib)
2015-05-20 13:53 - 2015-05-20 13:53 - 00000000 ____D () H:\Users\Don\AppData\Local\WebDiscoverBrowser
2015-05-20 13:48 - 2015-05-20 13:48 - 00000000 ____D () H:\Users\Don\Documents\ProPCCleaner
2015-05-20 13:25 - 2015-05-20 07:43 - 00043152 _____ (StdLib) H:\Windows\system32\Drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys
2015-05-20 13:24 - 2015-05-21 22:47 - 00000000 ____D () H:\Program Files\WebDiscoverBrowser
2015-05-20 13:22 - 2015-05-21 22:57 - 00000000 ____D () H:\Program Files\Triple Pose
2015-05-20 13:22 - 2015-05-20 13:22 - 00000000 ____D () H:\ProgramData\CouponAlert
2015-05-20 13:21 - 2015-05-20 13:21 - 00002848 _____ () H:\Windows\system32\LavasoftTcpServiceOff.ini
2015-05-20 13:21 - 2015-04-30 10:50 - 00347976 _____ (Lavasoft Limited) H:\Windows\system32\LavasoftTcpService.dll
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
*****************

Restore point was successfully created.
H:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\hhgro1n2.default-1414124344833\user.js => not found.
Update Triple Pose => Service not found.
{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw => Service not found.
H:\Users\Don\AppData\Local\WebDiscoverBrowser => Moved successfully.
H:\Users\Don\Documents\ProPCCleaner => Moved successfully.
"H:\Windows\system32\Drivers\{ef13e1f4-b828-4ec3-b1ff-46c12bae16a9}Gw.sys" => File/Directory not found.
H:\Program Files\WebDiscoverBrowser => Moved successfully.
"H:\Program Files\Triple Pose" => File/Directory not found.
H:\ProgramData\CouponAlert => Moved successfully.
H:\Windows\system32\LavasoftTcpServiceOff.ini => Moved successfully.
H:\Windows\system32\LavasoftTcpService.dll => Moved successfully.

=========  netsh advfirewall reset =========

Ok.


========= End of CMD: =========


=========  netsh advfirewall set allprofiles state ON =========

Ok.


========= End of CMD: =========


=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


=========  netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


=========  netsh int ip reset c:\resetlog.txt =========

Reseting Global, OK!
Reseting Interface, OK!
Restart the computer to complete this action.


========= End of CMD: =========


=========  ipconfig /release =========


Windows IP Configuration


Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . :
   Link-local IPv6 Address . . . . . : fe80::19f:4bb7:37aa:dc1f%10
   Default Gateway . . . . . . . . . :

========= End of CMD: =========


=========  ipconfig /renew =========


Windows IP Configuration


Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . : Home
   Link-local IPv6 Address . . . . . : fe80::19f:4bb7:37aa:dc1f%10
   IPv4 Address. . . . . . . . . . . : 192.168.0.2
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.0.1

========= End of CMD: =========


=========  netsh int ipv4 reset =========

Reseting Interface, OK!
Restart the computer to complete this action.


========= End of CMD: =========


=========  netsh int ipv6 reset =========

Reseting Interface, OK!
Restart the computer to complete this action.


========= End of CMD: =========


========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value Removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value Removed successfully.
HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value Removed successfully.
HKU\S-1-5-21-3964834215-2275053063-3108885826-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value Removed successfully.


========= End of RemoveProxy: =========


=========  bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

{5E987FEF-665F-4B88-9C7C-E2732A6E5F67} canceled.
1 out of 1 jobs canceled.

========= End of CMD: =========

EmptyTemp: => Removed 76.5 MB temporary data.


The system needed a reboot.

==== End of Fixlog 11:34:32 ====


  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Yep that is it, how is the computer now.. Is it still slow ? If so is it on start up or when opening programmes
  • 0

#13
Don Stewart

Don Stewart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 239 posts

Assume all respondces are suppose to go thru Geeks, anyway PC is hardwired ethernet latency 20 ms; download 30.22 Mbps & 4.75 upload. Still slow as a snail, you type away and later the letters ae filled in & doesn't matter where you are at.  Same with bookmarks, take forever to open, plus yahoo mail is also VERY slow!   PC in this shape is worthless.


  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK looking at the drivers running and the amount of RAM that you have lets try this next

In the search box type Msconfig and select the programme that appears at the top

1.In the System Configuration Utility dialog box, click Selective Startup on the General tab.
Cleanboot1.JPG
2.Click to clear the Load Startup Items check box.
NoteThe Use Original Boot.ini check box is unavailable.
3.Click the Services tab.
4.Click to select the Hide All Microsoft Services check box.
cleanboot2.JPG
5.Click Disable All, and then click OK.
6.When you are prompted, click Restart.
7.Has that made any difference ?
  • 0

#15
Don Stewart

Don Stewart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 239 posts

Litte if any difference.I have to do something for the next 2 hours, are yoou available later and at what time as I want to work at your schedule not mine.  By the way I'm on PST and also note that I have Norton on my PC and it has been having me restart my PC often because of things like SONAR & AUTOPROJECT.....have no idea if that mattters or not!


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP