Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Computer Infected with Coupoon, Crossbrowse, etc. [Solved]


  • This topic is locked This topic is locked

#1
MissJodles

MissJodles

    Member

  • Member
  • PipPip
  • 14 posts

Hi there, my computer is infected with malware/spyware that is popping up everywhere. Not appearing as Chrome plug-ins, but are listed in programs.

Tried to uninstall without success.

The malicious programs include: Coupoon, InfoNaut, GamesDesktop, SmartWeb, CrossBrowse, BlockAndSurf, StormWatch, possibly others.

 

Please help!

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-05-2015
Ran by Jodles (administrator) on SAPPHIRE on 03-06-2015 18:44:09
Running from C:\Users\Jodles\Desktop
Loaded Profiles: Jodles (Available Profiles: Jodles)
Platform: Windows 8.1 Pro (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Advanced Micro Devices) C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\hnsn672.tmp
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\jnsjE396.tmp
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Mad Catz Inc) C:\Program Files\Mad Catz\R.A.T.TE\RAT_TE_Profiler.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\nsu4EE1.tmp
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [R.A.T.TE] => C:\Program Files\Mad Catz\R.A.T.TE\RAT_TE_Profiler.exe [195072 2014-09-12] (Mad Catz Inc)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-01-27] (Apple Inc.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => E:\Program Files\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [gmsd_gb_395] => [X]
HKLM-x32\...\Run: [gmsd_gb_398] => [X]
HKLM-x32\...\RunOnce: [Update] => C:\Users\Jodles\AppData\Roaming\ASPackage\ASPackage.exe /runonce
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\Run: [DAEMON Tools Lite] => E:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\Run: [GoogleChromeAutoLaunch_85780D0100E82B662A94D25DE9304028] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-05-22] (Google Inc.)
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\Run: [WindApp] => "C:\Users\Jodles\AppData\Roaming\Store\WindApp\WindApp.exe" /winstartup
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\MountPoints2: {42e6b9aa-3e8c-11e4-8262-d05099274e52} - "F:\arun.exe" 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\MountPoints2: {7d3fbd6f-5eb4-11e4-826a-ec70d341df29} - "I:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\MountPoints2: {7d3fc0e0-5eb4-11e4-826a-ec70d341df29} - "H:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\MountPoints2: {b062b7b4-36fd-11e4-8250-806e6f6e6963} - "E:\Launch.exe" 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [132608 2014-10-29] (Microsoft Corporation)
AppInit_DLLs-x32: c:\programdata\navright\navright32.dll => "c:\programdata\navright\navright32.dll" File not found
ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => E:\Program Files\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => E:\Program Files\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => E:\Program Files\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartse...q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartse...q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartse...q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartse...q={searchTerms}
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefind...q={searchTerms}
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trovi.com...4C3&SSPV=&SSPV=
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.uk.msn.com/
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefind...q={searchTerms}
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> DefaultScope {E3DE50FD-7834-4B2D-A386-F7F27C172D00} URL = https://uk.search.ya...p={searchTerms}
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com...rchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com...=SPJSBT2B_sp_ie
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {E3DE50FD-7834-4B2D-A386-F7F27C172D00} URL = https://uk.search.ya...p={searchTerms}
BHO: No Name -> {21186475-d4df-43e2-9bba-0b52c00e0e27} ->  No File
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> E:\Program Files\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> E:\Program Files\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
BHO-x32: No Name -> {21186475-d4df-43e2-9bba-0b52c00e0e27} ->  No File
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> E:\Program Files\Arc\Arc\Plugins\ArcPluginIE.dll [2015-04-22] (Perfect World Entertainment Inc)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - E:\Program Files\Office15\MSOSB.DLL [2014-04-01] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> E:\Program Files\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> E:\Program Files\Arc\Arc\plugins\NPSWF32.dll [2015-04-22] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll No File
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> E:\Program Files\Arc\Arc\Plugins\npArcPluginFF.dll [2015-04-22] (Perfect World Entertainment Inc)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.Popcornew.com/Popcornew Update;version=3 -> C:\Program Files (x86)\Popcornew\Update\1.3.25.0\npPopcornewUpdate3.dll No File
FF Plugin-x32: @tools.Popcornew.com/Popcornew Update;version=9 -> C:\Program Files (x86)\Popcornew\Update\1.3.25.0\npPopcornewUpdate3.dll No File
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF HKLM\...\Firefox\Extensions: [{21186475-d4df-43e2-9bba-0b52c00e0e27}] - C:\Program Files\shopperz\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{21186475-d4df-43e2-9bba-0b52c00e0e27}] - C:\Program Files\shopperz\Firefox
 
Chrome: 
=======
CHR Profile: C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-08]
CHR Extension: (Google Docs) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-08]
CHR Extension: (Google Drive) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-08]
CHR Extension: (YouTube) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-08]
CHR Extension: (Google Search) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-08]
CHR Extension: (Google Sheets) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-08]
CHR Extension: (AdBlock) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-06-01]
CHR Extension: (Bookmark Manager) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-22]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Hola Better Internet) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhcmfkkjmkcfgelgdpndepmimbmkbpfp [2015-06-01]
CHR Extension: (Google Wallet) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-08]
CHR Extension: (Gmail) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-08]
CHR Extension: (Dolce & Gabbana Lace) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjpbblimbifbkffcijignfgmaalbcjje [2015-06-01]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [116224 2014-11-20] (Advanced Micro Devices) [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S3 ArcService; E:\Program Files\Arc\Arc\ArcService.exe [88584 2015-04-22] (Perfect World Entertainment Inc)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
S2 CoupoonService64; C:\Program Files (x86)\coupoon\iiwjljrnpc64.exe [172344 2015-04-02] ()
R2 fivyzipo; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\hnsn672.tmp [311296 2015-06-01] () [File not signed]
R2 jydedidi; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\nsu4EE1.tmp [169984 2015-06-03] () [File not signed]
S3 Origin Client Service; E:\Program Files\Origin\OriginClientService.exe [1931632 2015-05-02] (Electronic Arts)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 tyvozyno; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\jnsjE396.tmp [129536 2015-06-01] () [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [656664 2014-08-19] (Wacom Technology, Corp.)
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc [X] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc [X] <==== ATTENTION
S2 Popcornew_update; C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe /svc [X]
S3 Popcornew_update_m; C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe /medsvc [X]
S2 UpdateCheck; C:\Program Files (x86)\Coupoon\UpdateCheck.exe run  [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [294600 2014-11-21] (Advanced Micro Devices)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [223232 2014-06-21] (Advanced Micro Devices)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-09-18] (Disc Soft Ltd)
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [47008 2013-07-30] ()
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2015-04-02] (NetFilterSDK.com)
S3 SaiK0CFA; C:\Windows\system32\DRIVERS\SaiK0CFA.sys [174600 2010-07-21] (Saitek)
R3 SaiMini; C:\Windows\System32\drivers\SaiMini.sys [23968 2014-09-15] (Saitek)
R3 SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [51488 2014-09-15] (Saitek)
S3 SaiU0CFA; C:\Windows\System32\drivers\SaiU0CFA.sys [41352 2010-07-21] (Saitek)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
R3 _hid_0738_1704; C:\Windows\system32\DRIVERS\_hid_0738_1704.sys [179904 2014-09-15] (Saitek)
R3 _usb_0738_1704; C:\Windows\System32\drivers\_usb_0738_1704.sys [46528 2014-09-15] (Saitek)
R1 {992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64; C:\Windows\System32\drivers\{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64.sys [48784 2015-06-01] (StdLib)
S1 cherimoya; system32\drivers\cherimoya.sys [X]
S1 innfd_1_10_0_14; system32\drivers\innfd_1_10_0_14.sys [X]
R1 scfd_1_10_0_16; system32\drivers\scfd_1_10_0_16.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-03 18:44 - 2015-06-03 18:44 - 00021200 _____ () C:\Users\Jodles\Desktop\FRST.txt
2015-06-03 18:43 - 2015-06-03 18:44 - 00000000 ____D () C:\FRST
2015-06-03 18:43 - 2015-06-03 18:43 - 02108928 _____ (Farbar) C:\Users\Jodles\Desktop\FRST64.exe
2015-06-03 18:25 - 2015-06-03 18:25 - 00000005 _____ () C:\end
2015-06-03 18:25 - 2015-06-03 18:25 - 00000000 ____D () C:\Program Files\Coupoon
2015-06-03 18:25 - 2015-06-03 18:25 - 00000000 ____D () C:\Program Files (x86)\coupoon
2015-06-03 08:50 - 2015-06-03 08:50 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nszF32B.tmp
2015-06-02 12:13 - 2015-06-02 12:13 - 00000000 ____D () C:\ProgramData\PastaLeadsAgent
2015-06-01 18:36 - 2015-06-01 19:09 - 00000112 _____ () C:\ProgramData\St3Ln1.dat
2015-06-01 17:57 - 2015-06-01 20:11 - 00003986 _____ () C:\Windows\System32\Tasks\LaunchPreSignup
2015-06-01 16:53 - 2015-06-03 09:10 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2015-06-01 16:53 - 2015-06-03 08:50 - 00002810 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2015-06-01 16:53 - 2015-06-03 08:50 - 00002808 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2015-06-01 16:53 - 2015-06-03 08:50 - 00002808 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2015-06-01 16:53 - 2015-06-03 08:50 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2015-06-01 16:53 - 2015-06-03 08:50 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2015-06-01 16:52 - 2015-06-01 16:52 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsdE38E.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nss21F.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsh9AD3.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 00000000 __SHD () C:\Users\Jodles\AppData\Roaming\AnyProtectEx
2015-06-01 16:11 - 2015-06-03 16:16 - 00000994 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-06-01 16:11 - 2015-06-03 16:16 - 00000990 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-06-01 16:11 - 2015-06-03 16:11 - 00001012 _____ () C:\Windows\Tasks\PCMBRbqht.job
2015-06-01 16:11 - 2015-06-03 08:17 - 00000350 _____ () C:\Windows\Tasks\OGMDSFLC1.job
2015-06-01 16:11 - 2015-06-03 08:17 - 00000000 ____D () C:\ProgramData\FlashBeat
2015-06-01 16:11 - 2015-06-01 18:55 - 00000000 ____D () C:\ProgramData\abc
2015-06-01 16:11 - 2015-06-01 16:11 - 00004020 _____ () C:\Windows\System32\Tasks\PCMBRbqht
2015-06-01 16:11 - 2015-06-01 16:11 - 00003966 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-06-01 16:11 - 2015-06-01 16:11 - 00003730 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-06-01 16:11 - 2015-06-01 16:11 - 00003562 _____ () C:\Windows\System32\Tasks\QAXAZMZF
2015-06-01 16:11 - 2015-06-01 16:11 - 00002864 _____ () C:\Windows\System32\Tasks\OGMDSFLC1
2015-06-01 16:11 - 2015-06-01 16:11 - 00000000 ____D () C:\ProgramData\e10bdc90fa6b4d348805fa4834f77b68
2015-06-01 16:11 - 2015-06-01 16:11 - 00000000 ____D () C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2015-06-01 16:10 - 2015-06-01 16:10 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Crossbrowse
2015-06-01 16:09 - 2015-06-03 08:48 - 00004038 _____ () C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task
2015-06-01 16:09 - 2015-06-03 08:48 - 00000000 ____D () C:\Users\Jodles\AppData\Local\SmartWeb
2015-06-01 16:00 - 2015-06-01 16:24 - 00000000 ____D () C:\Users\Jodles\AppData\Local\03000200-1433174433-0500-0006-000700080009
2015-06-01 15:58 - 2014-11-02 11:10 - 00000913 _____ () C:\Windows\system32\Drivers\etc\hp.bak
2015-06-01 15:57 - 2015-06-03 18:18 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009
2015-06-01 14:05 - 2015-06-01 14:05 - 00000918 _____ () C:\Windows\SysWOW64\${LOGFILE}
2015-06-01 14:03 - 2015-06-01 16:24 - 00003438 _____ () C:\Windows\System32\Tasks\Unjnuglaeb
2015-06-01 14:03 - 2015-06-01 14:03 - 00000000 ____D () C:\ProgramData\Unjnuglaeb
2015-06-01 14:01 - 2015-06-01 14:01 - 00000000 ____D () C:\ProgramData\47d0399b00001855
2015-06-01 13:59 - 2015-06-01 04:37 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64.sys
2015-06-01 13:57 - 2015-06-03 13:57 - 00001044 _____ () C:\Windows\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a.job
2015-06-01 13:57 - 2015-06-03 08:17 - 00000344 _____ () C:\Windows\Tasks\FVYTTDEM1.job
2015-06-01 13:57 - 2015-06-01 14:10 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\Store
2015-06-01 13:57 - 2015-06-01 14:05 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\Nosibay
2015-06-01 13:57 - 2015-06-01 13:57 - 00004052 _____ () C:\Windows\System32\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a
2015-06-01 13:57 - 2015-06-01 13:57 - 00003562 _____ () C:\Windows\System32\Tasks\FWACQQEH
2015-06-01 13:57 - 2015-06-01 13:57 - 00002858 _____ () C:\Windows\System32\Tasks\FVYTTDEM1
2015-06-01 13:57 - 2015-06-01 13:57 - 00000078 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.installation.log
2015-06-01 13:57 - 2015-06-01 13:57 - 00000056 _____ () C:\Windows\Reimage.ini
2015-06-01 13:57 - 2015-06-01 13:57 - 00000051 _____ () C:\Windows\winfix.ini
2015-06-01 13:57 - 2015-06-01 13:57 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN84_01009.Wdf
2015-06-01 13:57 - 2015-06-01 13:57 - 00000000 ____D () C:\ProgramData\1e910f278cdf4ca0ae0a3dc1f227ef74
2015-06-01 13:57 - 2015-06-01 13:57 - 00000000 ____D () C:\ProgramData\12db864551ae4c578eb17db1a9f5d3cf
2015-06-01 13:56 - 2015-06-03 13:56 - 00000360 _____ () C:\Windows\Tasks\Bidaily Synchronize Task[3c32].job
2015-06-01 13:56 - 2015-06-01 19:56 - 00000000 ____D () C:\ProgramData\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}
2015-06-01 13:56 - 2015-06-01 16:20 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-01 13:56 - 2015-06-01 13:56 - 00003248 _____ () C:\Windows\System32\Tasks\Bidaily Synchronize Task[3c32]
2015-06-01 13:56 - 2015-06-01 13:56 - 00000000 ____D () C:\Users\Jodles\AppData\Local\globalUpdate
2015-06-01 13:55 - 2015-06-03 18:00 - 00000946 _____ () C:\Windows\Tasks\PopcornewUpdateTaskMachineUA.job
2015-06-01 13:55 - 2015-06-03 14:00 - 00000942 _____ () C:\Windows\Tasks\PopcornewUpdateTaskMachineCore.job
2015-06-01 13:55 - 2015-06-01 13:57 - 00005717 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.installation.log
2015-06-01 13:55 - 2015-06-01 13:55 - 00003918 _____ () C:\Windows\System32\Tasks\PopcornewUpdateTaskMachineUA
2015-06-01 13:55 - 2015-06-01 13:55 - 00003682 _____ () C:\Windows\System32\Tasks\PopcornewUpdateTaskMachineCore
2015-06-01 13:55 - 2015-06-01 13:55 - 00001216 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.boostrap.log
2015-06-01 13:55 - 2015-06-01 13:55 - 00000097 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.boostrap.log
2015-06-01 13:55 - 2015-06-01 13:55 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Popcornew
2015-06-01 10:10 - 2015-06-01 10:10 - 00001418 _____ () C:\Users\Jodles\Desktop\Adobe Premiere Pro - Shortcut.lnk
2015-06-01 09:58 - 2015-06-01 09:58 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\PACE Anti-Piracy
2015-06-01 09:58 - 2015-06-01 09:58 - 00000000 ____D () C:\Users\Jodles\AppData\Local\PACE Anti-Piracy
2015-06-01 09:58 - 2015-06-01 09:58 - 00000000 ____D () C:\ProgramData\PACE Anti-Piracy
2015-06-01 09:57 - 2015-06-01 09:57 - 00001013 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2015-06-01 09:57 - 2015-06-01 09:57 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-06-01 09:57 - 2015-06-01 09:57 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-06-01 09:57 - 2015-06-01 09:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2015-05-31 17:15 - 2015-05-31 17:15 - 00001390 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-05-31 17:15 - 2015-05-31 17:15 - 00001321 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2015-05-31 17:15 - 2015-05-31 17:15 - 00000000 ____D () C:\Windows\en
2015-05-31 17:14 - 2015-05-31 17:14 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-05-31 17:13 - 2015-05-31 17:14 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-05-31 17:12 - 2015-05-31 17:16 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Windows Live
2015-05-31 15:41 - 2015-06-01 09:41 - 00016896 _____ () C:\Users\Jodles\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-31 15:29 - 2015-05-31 15:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightworks
2015-05-31 15:28 - 2015-05-31 15:28 - 00000000 ____D () C:\ProgramData\Geevs
2015-05-28 15:10 - 2015-05-28 15:10 - 01049194 _____ () C:\Users\Jodles\Downloads\Final.avi
2015-05-16 14:40 - 2015-05-16 14:40 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom
2015-05-13 20:32 - 2015-04-30 21:35 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 20:32 - 2015-04-30 21:35 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 20:02 - 2015-05-01 00:05 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 20:02 - 2015-04-30 23:48 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-13 20:02 - 2015-04-24 22:32 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-13 20:02 - 2015-04-13 23:48 - 04180480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 20:02 - 2015-04-10 02:00 - 01996800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 20:02 - 2015-04-10 01:50 - 01387008 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 20:02 - 2015-04-10 01:34 - 02256896 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-05-13 20:02 - 2015-04-10 01:26 - 01560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-13 20:02 - 2015-04-10 01:11 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-05-13 20:02 - 2015-04-08 23:55 - 00410128 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-13 20:02 - 2015-04-03 01:35 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\PhotoMetadataHandler.dll
2015-05-13 20:02 - 2015-04-03 01:14 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoMetadataHandler.dll
2015-05-13 20:02 - 2015-04-01 23:22 - 02985984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2015-05-13 20:02 - 2015-04-01 23:20 - 04417536 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2015-05-13 20:02 - 2015-04-01 04:45 - 01491456 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2015-05-13 20:02 - 2015-04-01 03:31 - 01207296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2015-05-13 20:02 - 2015-03-20 02:56 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ahcache.sys
2015-05-13 20:02 - 2015-03-17 18:26 - 00467776 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2015-05-13 20:02 - 2015-03-13 05:03 - 00239424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2015-05-13 20:02 - 2015-03-13 05:03 - 00154432 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2015-05-13 20:02 - 2015-03-13 03:02 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2015-05-13 20:02 - 2015-03-13 02:11 - 02162176 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2015-05-13 20:02 - 2015-03-13 01:39 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2015-05-13 20:02 - 2015-03-11 02:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-13 20:02 - 2015-03-11 02:09 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-13 20:02 - 2015-03-09 03:02 - 00057856 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2015-05-13 20:02 - 2015-03-06 03:47 - 01696256 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2015-05-13 20:02 - 2015-03-05 00:09 - 01429504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-13 20:02 - 2015-03-04 02:32 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2015-05-13 20:02 - 2015-03-04 02:12 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2015-05-13 20:02 - 2015-02-18 00:19 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2015-05-13 20:02 - 2015-01-30 01:53 - 02819584 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2015-05-13 20:02 - 2014-11-14 07:58 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsDatabase.dll
2015-05-13 20:01 - 2015-04-21 18:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 20:01 - 2015-04-21 17:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 20:01 - 2015-04-21 17:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 20:01 - 2015-04-21 17:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 20:01 - 2015-04-21 17:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 20:01 - 2015-04-21 17:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 20:01 - 2015-04-21 17:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 20:01 - 2015-04-21 17:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-13 20:01 - 2015-04-21 17:13 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-05-13 20:01 - 2015-04-21 17:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-13 20:01 - 2015-04-21 17:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-13 20:01 - 2015-04-21 17:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 20:01 - 2015-04-21 17:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-05-13 20:01 - 2015-04-21 17:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 20:01 - 2015-04-21 17:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-13 20:01 - 2015-04-21 16:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-05-13 20:01 - 2015-04-21 16:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-13 20:01 - 2015-04-21 16:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-05-13 20:01 - 2015-04-21 16:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 20:01 - 2015-04-21 16:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 20:01 - 2015-04-21 16:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 20:01 - 2015-04-21 16:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 20:01 - 2015-04-21 16:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 20:01 - 2015-04-21 16:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-13 20:01 - 2015-04-21 16:37 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-05-13 20:01 - 2015-04-21 16:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-13 20:01 - 2015-04-21 16:32 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-05-13 20:01 - 2015-04-21 16:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-13 20:01 - 2015-04-21 16:28 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-05-13 20:01 - 2015-04-21 16:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 20:01 - 2015-04-21 16:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-13 20:01 - 2015-04-21 16:26 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-13 20:01 - 2015-04-21 16:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-13 20:01 - 2015-04-21 16:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-13 20:01 - 2015-04-21 16:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 20:01 - 2015-04-21 16:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 20:01 - 2015-04-21 16:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-13 20:01 - 2015-04-21 15:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-13 20:01 - 2015-04-21 15:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-13 20:01 - 2015-03-30 06:47 - 00561928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-05-13 20:01 - 2015-03-27 04:27 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-13 20:01 - 2015-03-27 03:50 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-13 20:01 - 2015-03-27 03:48 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-13 20:01 - 2015-03-13 01:29 - 00410017 _____ () C:\Windows\system32\ApnDatabase.xml
2015-05-13 20:01 - 2015-03-06 04:08 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-13 20:01 - 2015-03-06 03:43 - 01969664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-05-07 21:53 - 2015-05-07 21:53 - 00001401 _____ () C:\Users\Jodles\Desktop\Photoshop.lnk
2015-05-04 10:04 - 2015-05-04 10:04 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\AMD
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-03 18:20 - 2014-09-08 04:14 - 00000924 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-03 18:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2015-06-03 17:20 - 2014-09-08 04:14 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-03 16:40 - 2014-09-08 18:44 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Battle.net
2015-06-03 16:31 - 2015-01-25 19:14 - 00004928 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for SAPPHIRE-Jodles Sapphire
2015-06-03 15:52 - 2014-09-08 03:17 - 01568512 _____ () C:\Windows\WindowsUpdate.log
2015-06-03 14:44 - 2014-09-08 04:13 - 00003930 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{F4A03479-3E54-4F9A-8366-EFFEBA03B3F1}
2015-06-03 12:37 - 2014-09-08 03:25 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-266208001-1606254893-869063284-1001
2015-06-03 08:51 - 2014-09-08 03:20 - 00000000 ____D () C:\Users\Jodles
2015-06-03 08:26 - 2014-10-26 12:21 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Adobe
2015-06-03 08:23 - 2014-03-18 11:04 - 00863592 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-06-03 08:17 - 2015-04-14 09:06 - 00007020 _____ () C:\Windows\setupact.log
2015-06-03 08:17 - 2014-09-15 19:36 - 00000000 ___DO () C:\Users\Jodles\OneDrive
2015-06-03 08:17 - 2014-03-18 10:54 - 00054846 _____ () C:\Windows\PFRO.log
2015-06-03 08:17 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-06-01 16:22 - 2015-04-30 14:57 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2015-06-01 16:19 - 2014-09-08 04:20 - 00065536 _____ () C:\Windows\system32\spu_storage.bin
2015-06-01 16:18 - 2014-09-08 04:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-01 16:15 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-06-01 14:01 - 2015-02-05 18:33 - 00000586 __RSH () C:\ProgramData\ntuser.pol
2015-06-01 13:59 - 2013-08-22 14:25 - 00000269 _____ () C:\Windows\win.ini
2015-06-01 13:57 - 2014-09-15 21:23 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\uTorrent
2015-06-01 13:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2015-06-01 09:58 - 2014-09-08 03:20 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\Adobe
2015-06-01 09:58 - 2014-05-02 10:39 - 00000000 ___HD () C:\Users\Jodles\AppData\Local\PxvcIZ4vm
2015-06-01 09:58 - 2013-06-29 02:57 - 00000000 ___HD () C:\Users\Jodles\AppData\Local\jxzc74yZfNzX
2015-06-01 09:57 - 2014-10-26 12:26 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-06-01 09:57 - 2014-10-26 12:24 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-06-01 09:57 - 2014-10-26 12:21 - 00000000 ____D () C:\ProgramData\Adobe
2015-06-01 09:54 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-05-31 17:13 - 2014-09-18 21:01 - 00059271 _____ () C:\Windows\DirectX.log
2015-05-21 19:30 - 2015-04-05 07:45 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-05-21 19:30 - 2015-04-05 07:45 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-21 19:30 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-05-19 20:17 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF
2015-05-18 17:15 - 2014-09-08 04:14 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-18 17:15 - 2014-09-08 04:14 - 00003660 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-16 14:40 - 2015-02-16 11:09 - 00000000 ____D () C:\Users\Jodles\Desktop\Josh's Cool Stuff
2015-05-16 14:39 - 2014-12-22 19:54 - 00000000 ____D () C:\Program Files\Tablet
2015-05-14 20:24 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2015-05-14 18:23 - 2014-09-08 03:20 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Packages
2015-05-14 18:04 - 2013-08-22 15:44 - 05101432 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-13 22:21 - 2013-08-22 16:36 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2015-05-13 22:21 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-13 20:34 - 2014-10-19 14:28 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-05-13 20:34 - 2014-10-19 14:27 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-05-13 20:32 - 2014-09-13 13:28 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-13 20:31 - 2014-09-13 13:28 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-13 20:27 - 2014-03-18 10:46 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-05 18:59 - 2013-08-22 16:38 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-05-05 18:59 - 2013-08-22 16:38 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
 
==================== Files in the root of some directories =======
 
2015-03-25 19:19 - 2015-03-25 19:19 - 0000132 _____ () C:\Users\Jodles\AppData\Roaming\Adobe PNG Format CS6 Prefs
2015-04-19 13:20 - 2015-04-19 13:20 - 0005872 _____ () C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a
2015-04-20 15:05 - 2015-04-20 15:05 - 1579520 _____ () C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe
2015-06-01 13:55 - 2015-06-01 13:55 - 0001216 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.boostrap.log
2015-06-01 13:55 - 2015-06-01 13:57 - 0005717 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.installation.log
2015-04-12 18:22 - 2015-04-12 18:22 - 0000046 _____ () C:\Users\Jodles\AppData\Roaming\Camdata.ini
2015-04-12 18:22 - 2015-04-12 18:22 - 0000408 _____ () C:\Users\Jodles\AppData\Roaming\CamLayout.ini
2015-04-12 18:22 - 2015-04-12 18:22 - 0000408 _____ () C:\Users\Jodles\AppData\Roaming\CamShapes.ini
2015-04-12 18:22 - 2015-04-12 18:22 - 0004508 _____ () C:\Users\Jodles\AppData\Roaming\CamStudio.cfg
2015-04-19 13:20 - 2015-04-19 13:20 - 0005872 _____ () C:\Users\Jodles\AppData\Roaming\PCMBRbqht
2015-04-20 15:05 - 2015-04-20 15:05 - 1579520 _____ () C:\Users\Jodles\AppData\Roaming\PCMBRbqht.exe
2015-06-01 13:55 - 2015-06-01 13:55 - 0000097 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.boostrap.log
2015-06-01 13:57 - 2015-06-01 13:57 - 0000078 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.installation.log
2015-04-12 19:00 - 2015-04-12 19:00 - 0001456 _____ () C:\Users\Jodles\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-05-31 15:41 - 2015-06-01 09:41 - 0016896 _____ () C:\Users\Jodles\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-01 16:52 - 2015-06-01 16:52 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsdE38E.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsh9AD3.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nss21F.tmp
2015-06-03 08:50 - 2015-06-03 08:50 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nszF32B.tmp
2015-06-01 18:36 - 2015-06-01 19:09 - 0000112 _____ () C:\ProgramData\St3Ln1.dat
 
Files to move or delete:
====================
C:\ProgramData\St3Ln1.dat
 
 
Some files in TEMP:
====================
C:\Users\Jodles\AppData\Local\Temp\2251.exe
C:\Users\Jodles\AppData\Local\Temp\4109.exe
C:\Users\Jodles\AppData\Local\Temp\4135.exe
C:\Users\Jodles\AppData\Local\Temp\4548cAJpEW.exe
C:\Users\Jodles\AppData\Local\Temp\7E6255DD-C9D1-29AA-63D5-49CE02316B70.dll
C:\Users\Jodles\AppData\Local\Temp\7E6255DD-C9D1-29AA-63D5-49CE02316B70.exe
C:\Users\Jodles\AppData\Local\Temp\8783.exe
C:\Users\Jodles\AppData\Local\Temp\94C1DDCE-3E49-F78A-BC16-EB23868D4A35.exe
C:\Users\Jodles\AppData\Local\Temp\bitool.dll
C:\Users\Jodles\AppData\Local\Temp\BQJd1Sh58p.exe
C:\Users\Jodles\AppData\Local\Temp\ICReinstall_CamStudio_2.7_r316_setup.exe
C:\Users\Jodles\AppData\Local\Temp\Iid1uWzvyi.exe
C:\Users\Jodles\AppData\Local\Temp\OnlineBackup.exe
C:\Users\Jodles\AppData\Local\Temp\optprosetup.exe
C:\Users\Jodles\AppData\Local\Temp\ose00000.exe
C:\Users\Jodles\AppData\Local\Temp\QGdU2eehyc.exe
C:\Users\Jodles\AppData\Local\Temp\Ru7VUkboaR.exe
C:\Users\Jodles\AppData\Local\Temp\sdf353D.exe
C:\Users\Jodles\AppData\Local\Temp\sdf724.exe
C:\Users\Jodles\AppData\Local\Temp\sdfA35C.exe
C:\Users\Jodles\AppData\Local\Temp\sdfBF90.exe
C:\Users\Jodles\AppData\Local\Temp\sdfD8B4.exe
C:\Users\Jodles\AppData\Local\Temp\sdfF65B.exe
C:\Users\Jodles\AppData\Local\Temp\setup_644.exe
C:\Users\Jodles\AppData\Local\Temp\setup_648.exe
C:\Users\Jodles\AppData\Local\Temp\TIQnVFQcAs.exe
C:\Users\Jodles\AppData\Local\Temp\Uninstall.exe
C:\Users\Jodles\AppData\Local\Temp\UpIUPSjizA.exe
C:\Users\Jodles\AppData\Local\Temp\uS05wtKZ6B.exe
C:\Users\Jodles\AppData\Local\Temp\WinFixPro.exe
C:\Users\Jodles\AppData\Local\Temp\WinFixProPackage.exe
C:\Users\Jodles\AppData\Local\Temp\WinFixProTemp.exe
C:\Users\Jodles\AppData\Local\Temp\xj1SHKqnTc.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-06-03 12:49
 
==================== End of log ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-05-2015
Ran by Jodles at 2015-06-03 18:44:44
Running from C:\Users\Jodles\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-266208001-1606254893-869063284-500 - Administrator - Disabled)
Guest (S-1-5-21-266208001-1606254893-869063284-501 - Limited - Disabled)
Jodles (S-1-5-21-266208001-1606254893-869063284-1001 - Administrator - Enabled) => C:\Users\Jodles
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.)
ACP Application (Version: 2.15.10.0003 - Advanced Micro Devices, Inc.) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Premiere Pro CS6 (HKLM-x32\...\{7176B973-6011-43C1-AEBC-2D73FE7C6982}) (Version: 6.0 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{2FE00055-C4F3-4F7A-AEDD-E198D54CF12F}) (Version: 3.1.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{28791292-D18D-42FA-AE66-3D3D20AA8618}) (Version: 3.1.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{5ED7462B-EF58-4757-B609-53755021EC34}) (Version: 8.1.0.18 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
Bandicam (HKLM-x32\...\Bandicam) (Version: 2.0.2.655 - Bandisoft.com)
Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version:  - Bandisoft.com)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version:  - Irrational Games)
Black & White® 2 (HKLM-x32\...\{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}) (Version: 1.00.0000 - Lionhead Studios)
Blender (HKLM\...\Blender) (Version: 2.73a - Blender Foundation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CDisplayEx 1.10.29 (HKLM\...\CDisplayEx_is1) (Version:  - Progdigy Software S.A.R.L.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Dragon Age Inquisition / RePack by Baracuda (HKLM-x32\...\{DC4C36DC-4E5B-4262-B0C7-157DF534B969}_is1) (Version: 1.0.859961 - )
Dragon Age™: Inquisition (HKLM-x32\...\{DC4C36DC-4E5B-4262-B0C7-157DF534B969}) (Version: 1.0.0.7 - Electronic Arts)
globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.81 - Google Inc.)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version:  - Blizzard Entertainment)
iTunes (HKLM\...\{7B8D4E8A-EA2B-4A71-BFEB-A4AAAB87C5D0}) (Version: 12.1.0.71 - Apple Inc.)
Lightworks (HKLM-x32\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 12.0.2.0 - Lightworks)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 9.4.23.2817 - Electronic Arts, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
R.A.T.TE (HKLM\...\{F2E84ED0-5657-46BB-AA05-DA63A789A872}) (Version: 7.0.35.0 - Mad Catz Inc)
R.A.T.TE Game Profiles (HKLM-x32\...\{F01C4636-E750-4DDC-B042-B8A7AA9DDCEA}) (Version: 1.0.0.0 - Mad Catz Inc)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version:  - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version:  - Microsoft) Hidden
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
The Binding of Isaac (HKLM-x32\...\Steam App 113200) (Version:  - Edmund McMillen and Florian Himsl)
The Binding of Isaac: Rebirth (HKLM-x32\...\Steam App 250900) (Version:  - Nicalis, Inc.)
The Elder Scrolls V Skyrim (HKLM-x32\...\{4FEF52F2-3C2C-4B80-9443-3D6A654328D0}_is1) (Version:  - Bethesda Softworks)
The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.5.149.1020 - Electronic Arts Inc.)
Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\...\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUS_{40930C8E-A677-414C-A72F-DFDEB10738FB}) (Version:  - Microsoft)
Wacom (HKLM\...\Pen Tablet Driver) (Version: 5.3.5-3 - Wacom Technology Corp.)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.20 beta 2 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.20.2 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version:  - Blizzard Entertainment)
World of Warcraft Public Test (HKLM-x32\...\World of Warcraft Public Test) (Version:  - Blizzard Entertainment)
ZBrush 4R6 (HKLM-x32\...\ZBrush 4R6 4R6) (Version: 4R6 - Pixologic)
Zoo Tycoon 2 (HKLM-x32\...\Zoo Tycoon 2) (Version: 1.0 - Microsoft)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-266208001-1606254893-869063284-1001_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> E:\Program Files\Blender\BlendThumb64.dll ()
 
==================== Restore Points =========================
 
21-05-2015 19:30:27 Windows Update
30-05-2015 22:33:46 Scheduled Checkpoint
01-06-2015 13:57:04 Software Removal Tool
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 14:25 - 2014-11-02 11:10 - 00000913 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1                   bandicam.com
127.0.0.1                   ssl.bandisoft.com
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {236B86F7-CFBB-4105-9912-476E6A9EA4DE} - System32\Tasks\Bidaily Synchronize Task[3c32] => c:\programdata\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}\hqghumeaylnlf.exe [2014-06-01] (PC Utilities Software Limited) <==== ATTENTION
Task: {24F6DBA1-8336-4FC9-9AF3-5065182536A4} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: {2FE23A16-62A4-4A89-8037-93003634A0B7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-07] (Google Inc.)
Task: {368C1995-45AB-4383-950B-C0B5543B2F42} - System32\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a => C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe [2015-04-20] () <==== ATTENTION
Task: {3B701BFD-65AA-4251-A8BB-E3CF6426FB9E} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {3CC6D19C-C0BB-463E-8553-186A21335CAF} - System32\Tasks\FVYTTDEM1 => C:\ProgramData\NavRight\NavRight.exe
Task: {3E43EF72-07F0-4C1A-A6B3-36832F6F24D9} - System32\Tasks\Microsoft Office 15 Sync Maintenance for SAPPHIRE-Jodles Sapphire => E:\Program Files\Office15\MsoSync.exe [2015-04-14] (Microsoft Corporation)
Task: {3EE681A4-CD69-4111-A3D8-ACE120ED7D14} - System32\Tasks\{231CDD85-29EC-4C27-BB24-DCD1A0FCEE23} => pcalua.exe -a C:\Users\Jodles\Downloads\RAT_TE_Mouse_7_0_35_0_x64_Drivers.exe -d C:\Users\Jodles\Downloads
Task: {3FE60775-952B-4AC5-81F8-7C2EA5CB294C} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {4021CB4C-D997-4B01-8D55-50E7BDF19C5A} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {46CC61D9-E852-4DDA-85D3-52E9D67DB498} - System32\Tasks\[email protected] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated)
Task: {47BF98E6-883F-4C47-B6D4-C1A9B51529A7} - System32\Tasks\Unjnuglaeb => C:\ProgramData\Unjnuglaeb\1.0.1.0\llibiano.exe [2015-06-01] ()
Task: {4948C935-759B-4F04-B808-3EA135F3CC93} - System32\Tasks\QAXAZMZF => C:\ProgramData\e10bdc90fa6b4d348805fa4834f77b68\e10bdc90fa6b4d348805fa4834f77b68.exe [2015-05-31] ()
Task: {49FA8AD6-AD33-4B84-8FAB-54A0DE510044} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Jodles\AppData\Local\SmartWeb\SmartWebHelper.exe <==== ATTENTION
Task: {5981C4A9-14D2-456F-98E3-406B99937F7A} - System32\Tasks\PCMBRbqht => C:\Users\Jodles\AppData\Roaming\PCMBRbqht.exe [2015-04-20] () <==== ATTENTION
Task: {64D316BE-24E6-41C6-BD1A-74D01A8F0E4F} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {679FC280-513D-4F61-A274-E196B333027F} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-06] (Microsoft Corporation)
Task: {69F5F082-4716-4BF8-B999-2F6A65D48C90} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: {71DA5A31-8495-48D1-B23F-B0C7CB2568DB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {76D9A2B7-3629-4C96-80E0-767A394E1068} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-05-13] (Microsoft Corporation)
Task: {7CD33CC1-0AAA-4046-A68F-5F100752CA28} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {853F0B50-AFC1-40F0-8727-2F301E7662EB} - System32\Tasks\PopcornewUpdateTaskMachineCore => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
Task: {86FAA3D1-07A7-4E68-8522-0135878B1CB6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe
Task: {8E101E15-137F-489D-BFF9-25ADAF16140B} - System32\Tasks\FWACQQEH => C:\ProgramData\1e910f278cdf4ca0ae0a3dc1f227ef74\1e910f278cdf4ca0ae0a3dc1f227ef74.exe [2015-05-31] ()
Task: {B1775DC2-8E45-411A-A762-EBE1D2F79E93} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {B358C4D6-D62D-4D0A-BC04-5D831FCB1514} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-07] (Google Inc.)
Task: {B82AF6C8-EC49-419B-92C7-D8847CE9D168} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {C48A0CB2-2A63-41B6-B9B2-36A084C0B7EA} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: {CC7BC94D-82BE-4BCC-9C25-27963E4A32CE} - System32\Tasks\OGMDSFLC1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {CE1DA7DD-3AB3-49DD-8BC7-363761B88A48} - System32\Tasks\PopcornewUpdateTaskMachineUA => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
Task: {CE47B0F5-EDC8-40C6-A857-A5A9935EAF8F} - System32\Tasks\{41114785-3371-4877-8D66-063C55A61BBB} => pcalua.exe -a "E:\Battle.net App\Battle.net\Battle.net Launcher.exe" -d "E:\Battle.net App\Battle.net"
Task: {D5A7E58A-BAF2-4BA9-AD20-B94D9970429B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe
Task: {FCA4F64F-3961-46E9-9EB4-9AB72ABC229D} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\Bidaily Synchronize Task[3c32].job => c:\programdata\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a.job => C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe <==== ATTENTION
Task: C:\Windows\Tasks\FVYTTDEM1.job => C:\ProgramData\NavRight\NavRight.exe
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\OGMDSFLC1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\PCMBRbqht.job => C:\Users\Jodles\AppData\Roaming\PCMBRbqht.exe <==== ATTENTION
Task: C:\Windows\Tasks\PopcornewUpdateTaskMachineCore.job => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
Task: C:\Windows\Tasks\PopcornewUpdateTaskMachineUA.job => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-06-01 15:58 - 2015-06-01 15:58 - 00311296 _____ () C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\hnsn672.tmp
2015-06-01 15:58 - 2015-06-01 15:58 - 00129536 _____ () C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\jnsjE396.tmp
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () E:\Program Files\Office15\1033\GrooveIntlResource.dll
2014-12-22 19:54 - 2014-08-19 20:12 - 01356568 _____ () C:\Program Files\Tablet\Pen\libxml2.dll
2014-09-12 15:26 - 2014-09-12 15:26 - 12550144 _____ () C:\Program Files\Mad Catz\R.A.T.TE\Pr0fileEditor_Forms.dll
2014-09-12 15:29 - 2014-09-12 15:29 - 00004096 _____ () C:\Program Files\Mad Catz\R.A.T.TE\en-US\Pr0fileEditor_Forms.resources.dll
2014-09-12 15:29 - 2014-09-12 15:29 - 00007168 _____ () C:\Program Files\Mad Catz\R.A.T.TE\en\Pr0fileEditor_Forms.resources.dll
2015-06-03 18:18 - 2015-06-03 18:18 - 00169984 _____ () C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\nsu4EE1.tmp
2015-05-26 06:20 - 2015-05-22 21:22 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libglesv2.dll
2015-05-26 06:20 - 2015-05-22 21:22 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libegl.dll
2015-05-26 06:20 - 2015-05-22 21:22 - 14982472 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Jodles\Cookies:VEZJcTyXOJkxSqep
AlternateDataStreams: C:\Users\Jodles\OneDrive:ms-properties
AlternateDataStreams: C:\Users\Jodles\AppData\Local\jxzc74yZfNzX:QqJu71WEZA0qMiLalxGK
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Control Panel\Desktop\\Wallpaper -> E:\Pictures\Miscellaneous\Wallpaper\1525572.jpg
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\...\StartupApproved\Run32: => "StartCCC"
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\StartupApproved\Run: => "HydraVisionDesktopManager"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [{B86EDD24-C2F9-4D00-A8AC-59DD513A1095}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{1F21131B-B626-4F32-B899-6EB8F872D6A9}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{4C3F113F-7C0B-4951-B7FC-6F7BB6028015}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{ED6CDE54-21D5-450A-9F5C-888ECC27DCFE}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{0D3DC490-8D38-46BD-8A91-C3AFF98D39AF}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{2EFE84A4-77E6-43B8-B18A-07B0155D5768}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{26A120E9-9CFB-4102-9020-2C70D6F1A4D9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3334\Agent.exe
FirewallRules: [{A996AAE8-58A4-4BCE-BC7C-A18780225BEA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3334\Agent.exe
FirewallRules: [{B3D9BEAD-9F0A-45B4-BDC9-417E001955E9}] => (Allow) E:\Battle.net App\Battle.net\Battle.net.exe
FirewallRules: [{4E2FD009-99B1-4A43-925D-71E37B744780}] => (Allow) E:\Battle.net App\Battle.net\Battle.net.exe
FirewallRules: [{EA3B3C62-781E-4FDD-AC65-82B85F8551A2}] => (Allow) E:\Program Files\Battle.Net\Hearthstone\Hearthstone.exe
FirewallRules: [{83C3F9E9-A4DF-4CD3-9339-7B6A52F381E1}] => (Allow) E:\Program Files\Battle.Net\Hearthstone\Hearthstone.exe
FirewallRules: [{433C8AF3-5261-4C70-8827-92B363E0B429}] => (Allow) E:\Program Files\Steam\Steam.exe
FirewallRules: [{1B607367-C1AE-47F7-AB8E-E0BAFD46570E}] => (Allow) E:\Program Files\Steam\Steam.exe
FirewallRules: [{9448B658-937A-4840-9EF1-573D67AE3F25}] => (Allow) E:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [{D852B0B6-8A1E-459B-90AC-EB03115875F7}] => (Allow) E:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [{3FE89FD5-5E0F-464D-BB0B-1F9592D0E912}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3334\Agent.exe
FirewallRules: [{084D400E-06CD-481C-9475-C4FF66E802C0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3334\Agent.exe
FirewallRules: [{51DC0DCD-371A-43B1-9CF3-0D15E8700963}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3346\Agent.exe
FirewallRules: [{3683A65F-71CE-45F0-A7FF-5B7D7FC9EC39}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3346\Agent.exe
FirewallRules: [TCP Query User{3BC545BC-2216-4CBB-8755-92FC91B2F499}E:\program files\battle.net\hearthstone\hearthstone.exe] => (Allow) E:\program files\battle.net\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{BDB39838-484A-4634-A891-252D167936F5}E:\program files\battle.net\hearthstone\hearthstone.exe] => (Allow) E:\program files\battle.net\hearthstone\hearthstone.exe
FirewallRules: [{37C2389B-719E-47B5-94CD-7DE92DDA3F7B}] => (Allow) C:\Users\Jodles\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{AFC67E49-82BD-4361-A76C-2AB6CB4C57DD}] => (Allow) C:\Users\Jodles\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{25DE8E84-8E1E-42A2-8B6C-2BDF11DD99CC}] => (Allow) E:\Program Files\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
FirewallRules: [{4D035FF5-B1CA-49E3-B2EF-C7A73FBD5855}] => (Allow) E:\Program Files\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
FirewallRules: [{C7E26703-331E-4BB5-93E2-D280BB882929}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{3288F65D-C15A-4348-9AE2-0070DF3B8034}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{9EC90B30-AB05-49B6-BED1-079DF5FB1518}] => (Allow) E:\Program Files\Battle.net App\Battle.net\Battle.net.exe
FirewallRules: [{1A39A091-1EF4-427A-8533-F51375FE43CE}] => (Allow) E:\Program Files\Battle.net App\Battle.net\Battle.net.exe
FirewallRules: [{A5789B63-3A71-4545-8764-1B1B1EF2FD63}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{E9442A23-1DFE-45FC-B79D-702DF9502807}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [TCP Query User{6D547DEB-570D-4C32-A693-8E6CDB390FE9}C:\programdata\battle.net\agent\agent.3427\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3427\agent.exe
FirewallRules: [UDP Query User{CDC074AB-EC3A-4B63-A3CE-AD1623D04C02}C:\programdata\battle.net\agent\agent.3427\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3427\agent.exe
FirewallRules: [{9F9156A1-C2E7-4AAC-AE9D-07E976C2FBF3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe
FirewallRules: [{9D9159B2-641A-4662-9BB1-0180789FA468}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe
FirewallRules: [{EF202870-45AC-49E6-872A-82BD7C37BBF8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe
FirewallRules: [{17382A52-FD5F-4163-BC17-F545E8810BC7}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe
FirewallRules: [TCP Query User{E3C8A86F-A277-4A95-844F-87636B7AD545}C:\users\jodles\downloads\microsoft office 2013 32 and 64 bit with activator\activator\qemu\qemu.exe] => (Allow) C:\users\jodles\downloads\microsoft office 2013 32 and 64 bit with activator\activator\qemu\qemu.exe
FirewallRules: [UDP Query User{4A029D6E-F870-4D10-AC67-9B045D1AE2DD}C:\users\jodles\downloads\microsoft office 2013 32 and 64 bit with activator\activator\qemu\qemu.exe] => (Allow) C:\users\jodles\downloads\microsoft office 2013 32 and 64 bit with activator\activator\qemu\qemu.exe
FirewallRules: [{85866C93-8FD9-459D-829C-C05B890F6870}] => (Allow) E:\Program Files\Office15\lync.exe
FirewallRules: [{EBEC58D2-81CE-426F-ADA7-F11FD7C49E5A}] => (Allow) E:\Program Files\Office15\lync.exe
FirewallRules: [{20489121-5EC5-4743-990A-AFB85548BD9E}] => (Allow) E:\Program Files\Office15\UcMapi.exe
FirewallRules: [{935D9200-87A4-4D00-A63D-520E0178B595}] => (Allow) E:\Program Files\Office15\UcMapi.exe
FirewallRules: [{9A7C59E0-6CAB-4669-852C-7541A16B3C23}] => (Allow) E:\Program Files\Office15\outlook.exe
FirewallRules: [{33BD5222-7971-4538-826C-18C3C63F19AB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe
FirewallRules: [{1FDC918F-4D49-419D-8D80-5DFACDB5DA2C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe
FirewallRules: [{BB358C68-487E-42B6-BFAA-0B03E6A4D8BC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{77AF8FB6-6452-4C89-AA38-277A5076F88A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{2DBB5432-3B6F-4B1E-99EF-472C3A0C97E8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3632\Agent.exe
FirewallRules: [{496A8360-11FD-437A-A00A-74BFBB792F3B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3632\Agent.exe
FirewallRules: [{2E0425C3-AC85-41FC-B528-B30A669EAFAE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{0CEDCD70-97D6-4CDC-BFA1-0C4A0130F4F9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{D6FC7895-65F2-4B9D-9940-5A2B6F4AF49C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D3D8162F-4650-4FCA-A668-BA10B35CA694}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7E56DE21-E62B-4ACD-A2CB-595D81A76D14}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CC619C48-F28C-4458-8ED4-4BD4602C2841}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{188B47BD-3A55-49C2-8D1C-8A7319E9E31B}] => (Allow) E:\Program Files\Zoo Tycoon 2\zt.exe
FirewallRules: [{BB48B23F-6D83-4881-AB57-F9F239C4C397}] => (Allow) E:\Program Files\Zoo Tycoon 2\zt.exe
FirewallRules: [{1D33982F-71FE-496B-AE94-C529C6121381}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{60AF1EF2-88F9-4F2E-9A33-812EDC28E9EF}] => (Allow) E:\Program Files\Steam\SteamApps\common\The Binding Of Isaac\Isaac.exe
FirewallRules: [{8FC81D85-2F77-4DD4-8DCA-67391B532C44}] => (Allow) E:\Program Files\Steam\SteamApps\common\The Binding Of Isaac\Isaac.exe
FirewallRules: [{8F4F4AE1-6BD8-4B45-9CBF-017B22EBB7BC}] => (Allow) E:\Program Files (x86)\Origin Games\The Sims 4\The Sims 4\Game\Bin\TS4.exe
FirewallRules: [{8A6AF36D-0F73-47EA-A19E-85FDE3F5FCEA}] => (Allow) E:\Program Files (x86)\Origin Games\The Sims 4\The Sims 4\Game\Bin\TS4.exe
FirewallRules: [{71FEA47A-C8B4-4094-9359-2311FA912926}] => (Allow) E:\Program Files (x86)\Origin Games\Dragon Age Inquisition\Dragon Age Inquisition\DragonAgeInquisition.exe
FirewallRules: [{3D674F49-F172-4B50-A203-9445BE18F73D}] => (Allow) E:\Program Files (x86)\Origin Games\Dragon Age Inquisition\Dragon Age Inquisition\DragonAgeInquisition.exe
FirewallRules: [{90E013FD-4DD3-4EA2-ADBA-97D80491AD6F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{E0B366C2-A80E-46CC-BF7A-AEC4A21A4279}] => (Allow) E:\Program Files (x86)\Lightworks\Lightworks.exe
FirewallRules: [{0697C98B-2FAC-432D-BB1B-27E454A5230D}] => (Allow) E:\Program Files (x86)\Lightworks\Lightworks.exe
FirewallRules: [{6035893B-87BE-4604-B302-588AC736B70A}] => (Allow) E:\Program Files (x86)\Lightworks\ntcardvt.exe
FirewallRules: [{84508CD6-421B-448E-8A3B-8678831C3D55}] => (Allow) E:\Program Files (x86)\Lightworks\ntcardvt.exe
FirewallRules: [{99A59D44-3FC5-4587-989C-D9CF17E6B197}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{6724AA5C-E5A3-49B5-B334-C04560869839}] => (Allow) LPort=2869
FirewallRules: [{F539767B-3695-4D82-AEB7-191799746933}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{95A86657-8D80-4F76-B5E1-2B3350BF75EF}E:\program files\battle.net\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe] => (Block) E:\program files\battle.net\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{D9AE5783-57D2-4F67-80F1-8EE89F31ED53}E:\program files\battle.net\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe] => (Block) E:\program files\battle.net\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Ethernet Controller
Description: Ethernet Controller
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: SM Bus Controller
Description: SM Bus Controller
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/03/2015 06:25:57 PM) (Source: CoupoonService64) (EventID: 1) (User: )
Description: CoupoonService64In SvcInstall, CreateService failed (1073)
 failed with 1073
 
Error: (06/03/2015 09:58:51 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: pastaleadss.exe, version: 1.0.0.51, time stamp: 0x55646d7a
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17415, time stamp: 0x54505737
Exception code: 0xe06d7363
Fault offset: 0x0000000000008b9c
Faulting process id: 0x11d4
Faulting application start time: 0xpastaleadss.exe0
Faulting application path: pastaleadss.exe1
Faulting module path: pastaleadss.exe2
Report Id: pastaleadss.exe3
Faulting package full name: pastaleadss.exe4
Faulting package-relative application ID: pastaleadss.exe5
 
Error: (06/03/2015 08:50:49 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program AnyProtect.exe version 1.0.0.4 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: ec8
 
Start Time: 01d09dd1fb399fd7
 
Termination Time: 4294967295
 
Application Path: C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe
 
Report Id: 3f50bfc7-09c5-11e5-829f-d05099274e52
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (06/03/2015 08:50:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program nswACA9.tmp version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 16dc
 
Start Time: 01d09dd1dd7e8f0d
 
Termination Time: 4294967295
 
Application Path: C:\Users\Jodles\AppData\Local\Temp\nswACA9.tmp
 
Report Id: 23294047-09c5-11e5-829f-d05099274e52
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (06/03/2015 08:17:49 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (06/03/2015 08:17:47 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
 
Error: (06/03/2015 08:17:35 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (06/02/2015 10:34:35 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/02/2015 10:25:00 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (06/02/2015 10:24:58 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=UserLogon;SessionId=2
 
 
System errors:
=============
Error: (06/03/2015 06:32:01 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The CoupoonService64 service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/03/2015 09:58:51 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The PastaLeads Update service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/03/2015 08:19:25 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Popcornew Update Service (Popcornew_update) service failed to start due to the following error: 
%%2
 
Error: (06/03/2015 08:19:25 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The globalUpdate Update Service (globalUpdate) service failed to start due to the following error: 
%%2
 
Error: (06/03/2015 08:17:25 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The UpdateCheck service failed to start due to the following error: 
%%2
 
Error: (06/03/2015 08:17:25 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The CoupoonService64 service failed to start due to the following error: 
%%2
 
Error: (06/03/2015 08:17:24 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 15:32:44 on ‎02/‎06/‎2015 was unexpected.
 
Error: (06/02/2015 00:15:43 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
 
Error: (06/01/2015 08:31:01 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Rasterise Key service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/01/2015 08:30:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Favourites Clipboard service terminated unexpectedly.  It has done this 1 time(s).
 
 
Microsoft Office:
=========================
Error: (06/03/2015 06:25:57 PM) (Source: CoupoonService64) (EventID: 1) (User: )
Description: CoupoonService64In SvcInstall, CreateService failed (1073)
 failed with 1073
 
Error: (06/03/2015 09:58:51 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: pastaleadss.exe1.0.0.5155646d7aKERNELBASE.dll6.3.9600.1741554505737e06d73630000000000008b9c11d401d09ddb819d30a4C:\Program Files\Common Files\PastaLeads\PastaLeads Client\pastaleadss.exeC:\Windows\system32\KERNELBASE.dllc083b05f-09ce-11e5-829f-d05099274e52
 
Error: (06/03/2015 08:50:49 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: AnyProtect.exe1.0.0.4ec801d09dd1fb399fd74294967295C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe3f50bfc7-09c5-11e5-829f-d05099274e52
 
Error: (06/03/2015 08:50:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: nswACA9.tmp0.0.0.016dc01d09dd1dd7e8f0d4294967295C:\Users\Jodles\AppData\Local\Temp\nswACA9.tmp23294047-09c5-11e5-829f-d05099274e52
 
Error: (06/03/2015 08:17:49 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0xC004F074RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (06/03/2015 08:17:47 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0xC004F074RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
 
Error: (06/03/2015 08:17:35 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0xC004F074RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (06/02/2015 10:34:35 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/02/2015 10:25:00 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0xC004F074RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (06/02/2015 10:24:58 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0xC004F074RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c06b6981-d7fd-4a35-b7b4-054742b7af67;NotificationInterval=1440;Trigger=UserLogon;SessionId=2
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-06-03 12:37:45.471
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-06-02 11:24:08.181
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-05-22 09:10:46.264
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-05-14 20:19:46.470
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-04-30 16:34:11.907
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-04-20 21:36:54.844
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-31 19:59:53.715
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-25 15:45:43.840
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-15 02:20:21.487
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-12 21:58:08.765
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-4690K CPU @ 3.50GHz
Percentage of memory in use: 34%
Total physical RAM: 8140.07 MB
Available physical RAM: 5294.47 MB
Total Pagefile: 9420.07 MB
Available Pagefile: 6290.36 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:111.27 GB) (Free:10.04 GB) NTFS
Drive e: (HDD) (Fixed) (Total:1863.01 GB) (Free:1635.19 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 00000000)
 
Partition: GPT Partition Type.
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 3C4B8CE9)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)
 
==================== End of log ============================
 

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there, there is a high probability that I may have missed some so it may take a few sweeps to ensure that I get it all

I would also recommend that you uninstall Hola http://adios-hola.org/


CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009
HKLM-x32\...\Run: [gmsd_gb_395] => [X]
HKLM-x32\...\Run: [gmsd_gb_398] => [X]
HKLM-x32\...\RunOnce: [Update] => C:\Users\Jodles\AppData\Roaming\ASPackage\ASPackage.exe /runonce
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\Run: [WindApp] => "C:\Users\Jodles\AppData\Roaming\Store\WindApp\WindApp.exe" /winstartup
AppInit_DLLs-x32: c:\programdata\navright\navright32.dll => "c:\programdata\navright\navright32.dll" File not found
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartse...q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartse...q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartse...q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartse...q={searchTerms}
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefind...q={searchTerms}
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trovi.com...4C3&SSPV=&SSPV=
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefind...q={searchTerms}
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> DefaultScope {E3DE50FD-7834-4B2D-A386-F7F27C172D00} URL = https://uk.search.ya...p={searchTerms}
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com...rchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com...=SPJSBT2B_sp_ie
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {E3DE50FD-7834-4B2D-A386-F7F27C172D00} URL = https://uk.search.ya...p={searchTerms}
BHO: No Name -> {21186475-d4df-43e2-9bba-0b52c00e0e27} -> No File
BHO-x32: No Name -> {21186475-d4df-43e2-9bba-0b52c00e0e27} -> No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
CHR Extension: (Hola Better Internet) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhcmfkkjmkcfgelgdpndepmimbmkbpfp [2015-06-01]
S2 CoupoonService64; C:\Program Files (x86)\coupoon\iiwjljrnpc64.exe [172344 2015-04-02] ()
R2 fivyzipo; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\hnsn672.tmp [311296 2015-06-01] () [File not signed]
R2 jydedidi; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\nsu4EE1.tmp [169984 2015-06-03] () [File not signed]
R2 tyvozyno; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\jnsjE396.tmp [129536 2015-06-01] () [File not signed]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc [X] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc [X] <==== ATTENTION
S2 Popcornew_update; C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe /svc [X]
S3 Popcornew_update_m; C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe /medsvc [X]
S2 UpdateCheck; C:\Program Files (x86)\Coupoon\UpdateCheck.exe run [X]
R1 {992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64; C:\Windows\System32\drivers\{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64.sys [48784 2015-06-01] (StdLib)
S1 cherimoya; system32\drivers\cherimoya.sys [X]
2015-06-03 18:25 - 2015-06-03 18:25 - 00000000 ____D () C:\Program Files\Coupoon
2015-06-03 18:25 - 2015-06-03 18:25 - 00000000 ____D () C:\Program Files (x86)\coupoon
2015-06-03 08:50 - 2015-06-03 08:50 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nszF32B.tmp
2015-06-02 12:13 - 2015-06-02 12:13 - 00000000 ____D () C:\ProgramData\PastaLeadsAgent
2015-06-01 18:36 - 2015-06-01 19:09 - 00000112 _____ () C:\ProgramData\St3Ln1.dat
2015-06-01 17:57 - 2015-06-01 20:11 - 00003986 _____ () C:\Windows\System32\Tasks\LaunchPreSignup
2015-06-01 16:53 - 2015-06-03 09:10 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2015-06-01 16:53 - 2015-06-03 08:50 - 00002810 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2015-06-01 16:53 - 2015-06-03 08:50 - 00002808 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2015-06-01 16:53 - 2015-06-03 08:50 - 00002808 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2015-06-01 16:53 - 2015-06-03 08:50 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2015-06-01 16:53 - 2015-06-03 08:50 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2015-06-01 16:52 - 2015-06-01 16:52 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsdE38E.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nss21F.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsh9AD3.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 00000000 __SHD () C:\Users\Jodles\AppData\Roaming\AnyProtectEx
2015-06-01 16:11 - 2015-06-03 16:16 - 00000994 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-06-01 16:11 - 2015-06-03 16:16 - 00000990 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-06-01 16:11 - 2015-06-03 16:11 - 00001012 _____ () C:\Windows\Tasks\PCMBRbqht.job
2015-06-01 16:11 - 2015-06-03 08:17 - 00000350 _____ () C:\Windows\Tasks\OGMDSFLC1.job
2015-06-01 16:11 - 2015-06-03 08:17 - 00000000 ____D () C:\ProgramData\FlashBeat
2015-06-01 16:11 - 2015-06-01 18:55 - 00000000 ____D () C:\ProgramData\abc
2015-06-01 16:11 - 2015-06-01 16:11 - 00004020 _____ () C:\Windows\System32\Tasks\PCMBRbqht
2015-06-01 16:11 - 2015-06-01 16:11 - 00003966 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-06-01 16:11 - 2015-06-01 16:11 - 00003730 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-06-01 16:11 - 2015-06-01 16:11 - 00003562 _____ () C:\Windows\System32\Tasks\QAXAZMZF
2015-06-01 16:11 - 2015-06-01 16:11 - 00002864 _____ () C:\Windows\System32\Tasks\OGMDSFLC1
2015-06-01 16:11 - 2015-06-01 16:11 - 00000000 ____D () C:\ProgramData\e10bdc90fa6b4d348805fa4834f77b68
2015-06-01 16:11 - 2015-06-01 16:11 - 00000000 ____D () C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2015-06-01 16:10 - 2015-06-01 16:10 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Crossbrowse
2015-06-01 16:09 - 2015-06-03 08:48 - 00004038 _____ () C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task
2015-06-01 16:09 - 2015-06-03 08:48 - 00000000 ____D () C:\Users\Jodles\AppData\Local\SmartWeb
2015-06-01 16:00 - 2015-06-01 16:24 - 00000000 ____D () C:\Users\Jodles\AppData\Local\03000200-1433174433-0500-0006-000700080009
2015-06-01 15:57 - 2015-06-03 18:18 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009
2015-06-01 14:05 - 2015-06-01 14:05 - 00000918 _____ () C:\Windows\SysWOW64\${LOGFILE}
2015-06-01 14:03 - 2015-06-01 16:24 - 00003438 _____ () C:\Windows\System32\Tasks\Unjnuglaeb
2015-06-01 14:03 - 2015-06-01 14:03 - 00000000 ____D () C:\ProgramData\Unjnuglaeb
2015-06-01 14:01 - 2015-06-01 14:01 - 00000000 ____D () C:\ProgramData\47d0399b00001855
2015-06-01 13:59 - 2015-06-01 04:37 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64.sys
2015-06-01 13:57 - 2015-06-03 13:57 - 00001044 _____ () C:\Windows\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a.job
2015-06-01 13:57 - 2015-06-03 08:17 - 00000344 _____ () C:\Windows\Tasks\FVYTTDEM1.job
2015-06-01 13:57 - 2015-06-01 14:10 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\Store
2015-06-01 13:57 - 2015-06-01 14:05 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\Nosibay
2015-06-01 13:57 - 2015-06-01 13:57 - 00004052 _____ () C:\Windows\System32\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a
2015-06-01 13:57 - 2015-06-01 13:57 - 00003562 _____ () C:\Windows\System32\Tasks\FWACQQEH
2015-06-01 13:57 - 2015-06-01 13:57 - 00002858 _____ () C:\Windows\System32\Tasks\FVYTTDEM1
2015-06-01 13:57 - 2015-06-01 13:57 - 00000078 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.installation.log
2015-06-01 13:57 - 2015-06-01 13:57 - 00000056 _____ () C:\Windows\Reimage.ini
2015-06-01 13:57 - 2015-06-01 13:57 - 00000051 _____ () C:\Windows\winfix.ini
2015-06-01 13:57 - 2015-06-01 13:57 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN84_01009.Wdf
2015-06-01 13:57 - 2015-06-01 13:57 - 00000000 ____D () C:\ProgramData\1e910f278cdf4ca0ae0a3dc1f227ef74
2015-06-01 13:57 - 2015-06-01 13:57 - 00000000 ____D () C:\ProgramData\12db864551ae4c578eb17db1a9f5d3cf
2015-06-01 13:56 - 2015-06-03 13:56 - 00000360 _____ () C:\Windows\Tasks\Bidaily Synchronize Task[3c32].job
2015-06-01 13:56 - 2015-06-01 19:56 - 00000000 ____D () C:\ProgramData\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}
2015-06-01 13:56 - 2015-06-01 16:20 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-01 13:56 - 2015-06-01 13:56 - 00003248 _____ () C:\Windows\System32\Tasks\Bidaily Synchronize Task[3c32]
2015-06-01 13:56 - 2015-06-01 13:56 - 00000000 ____D () C:\Users\Jodles\AppData\Local\globalUpdate
2015-06-01 13:55 - 2015-06-03 18:00 - 00000946 _____ () C:\Windows\Tasks\PopcornewUpdateTaskMachineUA.job
2015-06-01 13:55 - 2015-06-03 14:00 - 00000942 _____ () C:\Windows\Tasks\PopcornewUpdateTaskMachineCore.job
2015-06-01 13:55 - 2015-06-01 13:57 - 00005717 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.installation.log
2015-06-01 13:55 - 2015-06-01 13:55 - 00003918 _____ () C:\Windows\System32\Tasks\PopcornewUpdateTaskMachineUA
2015-06-01 13:55 - 2015-06-01 13:55 - 00003682 _____ () C:\Windows\System32\Tasks\PopcornewUpdateTaskMachineCore
2015-06-01 13:55 - 2015-06-01 13:55 - 00001216 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.boostrap.log
2015-06-01 13:55 - 2015-06-01 13:55 - 00000097 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.boostrap.log
2015-06-01 13:55 - 2015-06-01 13:55 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Popcornew
2015-06-01 09:58 - 2014-05-02 10:39 - 00000000 ___HD () C:\Users\Jodles\AppData\Local\PxvcIZ4vm
2015-06-01 09:58 - 2013-06-29 02:57 - 00000000 ___HD () C:\Users\Jodles\AppData\Local\jxzc74yZfNzX
2015-04-19 13:20 - 2015-04-19 13:20 - 0005872 _____ () C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a
2015-04-20 15:05 - 2015-04-20 15:05 - 1579520 _____ () C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe
2015-06-01 13:55 - 2015-06-01 13:55 - 0001216 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.boostrap.log
2015-06-01 13:55 - 2015-06-01 13:57 - 0005717 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.installation.log
2015-06-01 13:55 - 2015-06-01 13:55 - 0000097 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.boostrap.log
2015-06-01 13:57 - 2015-06-01 13:57 - 0000078 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.installation.log
2015-06-01 16:52 - 2015-06-01 16:52 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsdE38E.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsh9AD3.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nss21F.tmp
2015-06-03 08:50 - 2015-06-03 08:50 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nszF32B.tmp
2015-06-01 18:36 - 2015-06-01 19:09 - 0000112 _____ () C:\ProgramData\St3Ln1.dat
Task: {236B86F7-CFBB-4105-9912-476E6A9EA4DE} - System32\Tasks\Bidaily Synchronize Task[3c32] => c:\programdata\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}\hqghumeaylnlf.exe [2014-06-01] (PC Utilities Software Limited) <==== ATTENTION
Task: {24F6DBA1-8336-4FC9-9AF3-5065182536A4} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: {368C1995-45AB-4383-950B-C0B5543B2F42} - System32\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a => C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe [2015-04-20] () <==== ATTENTION
Task: {3B701BFD-65AA-4251-A8BB-E3CF6426FB9E} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {3CC6D19C-C0BB-463E-8553-186A21335CAF} - System32\Tasks\FVYTTDEM1 => C:\ProgramData\NavRight\NavRight.exe
Task: {4021CB4C-D997-4B01-8D55-50E7BDF19C5A} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {47BF98E6-883F-4C47-B6D4-C1A9B51529A7} - System32\Tasks\Unjnuglaeb => C:\ProgramData\Unjnuglaeb\1.0.1.0\llibiano.exe [2015-06-01] ()
Task: {4948C935-759B-4F04-B808-3EA135F3CC93} - System32\Tasks\QAXAZMZF => C:\ProgramData\e10bdc90fa6b4d348805fa4834f77b68\e10bdc90fa6b4d348805fa4834f77b68.exe [2015-05-31] ()
Task: {49FA8AD6-AD33-4B84-8FAB-54A0DE510044} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Jodles\AppData\Local\SmartWeb\SmartWebHelper.exe <==== ATTENTION
Task: {5981C4A9-14D2-456F-98E3-406B99937F7A} - System32\Tasks\PCMBRbqht => C:\Users\Jodles\AppData\Roaming\PCMBRbqht.exe [2015-04-20] () <==== ATTENTION
Task: {853F0B50-AFC1-40F0-8727-2F301E7662EB} - System32\Tasks\PopcornewUpdateTaskMachineCore => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
Task: {8E101E15-137F-489D-BFF9-25ADAF16140B} - System32\Tasks\FWACQQEH => C:\ProgramData\1e910f278cdf4ca0ae0a3dc1f227ef74\1e910f278cdf4ca0ae0a3dc1f227ef74.exe [2015-05-31] ()
Task: {B82AF6C8-EC49-419B-92C7-D8847CE9D168} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {C48A0CB2-2A63-41B6-B9B2-36A084C0B7EA} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: {CC7BC94D-82BE-4BCC-9C25-27963E4A32CE} - System32\Tasks\OGMDSFLC1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {CE1DA7DD-3AB3-49DD-8BC7-363761B88A48} - System32\Tasks\PopcornewUpdateTaskMachineUA => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
Task: {FCA4F64F-3961-46E9-9EB4-9AB72ABC229D} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\Bidaily Synchronize Task[3c32].job => c:\programdata\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a.job => C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe <==== ATTENTION
Task: C:\Windows\Tasks\FVYTTDEM1.job => C:\ProgramData\NavRight\NavRight.exe
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\OGMDSFLC1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\PCMBRbqht.job => C:\Users\Jodles\AppData\Roaming\PCMBRbqht.exe <==== ATTENTION
Task: C:\Windows\Tasks\PopcornewUpdateTaskMachineCore.job => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
Task: C:\Windows\Tasks\PopcornewUpdateTaskMachineUA.job => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
AlternateDataStreams: C:\Users\Jodles\Cookies:VEZJcTyXOJkxSqep
AlternateDataStreams: C:\Users\Jodles\AppData\Local\jxzc74yZfNzX:QqJu71WEZA0qMiLalxGK
C:\Users\Jodles\AppData\Roaming\ASPackage
C:\Users\Jodles\AppData\Roaming\Store\WindApp
c:\programdata\navright
C:\Program Files (x86)\coupoon
C:\Program Files (x86)\Popcornew
C:\Program Files (x86)\globalUpdate
C:\Windows\System32\drivers\{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64.sys
C:\Windows\system32\drivers\cherimoya.sys
C:\Program Files (x86)\AnyProtectEx
C:\Users\Jodles\AppData\Local\SmartWeb
C:\ProgramData\e10bdc90fa6b4d348805fa4834f77b68\e10bdc90fa6b4d348805fa4834f77b68.exe
C:\ProgramData\Unjnuglaeb
C:\ProgramData\1e910f278cdf4ca0ae0a3dc1f227ef74
C:\Program Files (x86)\OLBPre
C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe
c:\programdata\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}
C:\Users\Jodles\AppData\Roaming\PCMBRbqht.exe
C:\ProgramData\FlashBeat
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.
FINALLY

Download aswMBR.exe ( 4.5mb ) to your desktop.
Double click the aswMBR.exe to run it.
You may be offered the option of using virtualisation, accept that
When it offers to download the virus database allow that as well
Click the "Scan" button to start scan

AswMBR%20scan.JPG


On completion of the scan click save log, save it to your desktop and post in your next reply
  • 0

#3
MissJodles

MissJodles

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Fix result of Farbar Recovery Scan Tool (x64) Version: 29-05-2015
Ran by Jodles at 2015-06-03 21:15:43 Run:1
Running from C:\Users\Jodles\Desktop
Loaded Profiles: Jodles (Available Profiles: Jodles)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009
HKLM-x32\...\Run: [gmsd_gb_395] => [X]
HKLM-x32\...\Run: [gmsd_gb_398] => [X]
HKLM-x32\...\RunOnce: [Update] => C:\Users\Jodles\AppData\Roaming\ASPackage\ASPackage.exe /runonce
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\Run: [WindApp] => "C:\Users\Jodles\AppData\Roaming\Store\WindApp\WindApp.exe" /winstartup
AppInit_DLLs-x32: c:\programdata\navright\navright32.dll => "c:\programdata\navright\navright32.dll" File not found
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartse...q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartse...q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartse...q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartse...q={searchTerms}
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefind...q={searchTerms}
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trovi.com...4C3&SSPV=&SSPV=
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefind...q={searchTerms}
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> DefaultScope {E3DE50FD-7834-4B2D-A386-F7F27C172D00} URL = https://uk.search.ya...p={searchTerms}
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com...rchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com...=SPJSBT2B_sp_ie
SearchScopes: HKU\S-1-5-21-266208001-1606254893-869063284-1001 -> {E3DE50FD-7834-4B2D-A386-F7F27C172D00} URL = https://uk.search.ya...p={searchTerms}
BHO: No Name -> {21186475-d4df-43e2-9bba-0b52c00e0e27} -> No File
BHO-x32: No Name -> {21186475-d4df-43e2-9bba-0b52c00e0e27} -> No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
CHR Extension: (Hola Better Internet) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhcmfkkjmkcfgelgdpndepmimbmkbpfp [2015-06-01]
S2 CoupoonService64; C:\Program Files (x86)\coupoon\iiwjljrnpc64.exe [172344 2015-04-02] ()
R2 fivyzipo; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\hnsn672.tmp [311296 2015-06-01] () [File not signed]
R2 jydedidi; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\nsu4EE1.tmp [169984 2015-06-03] () [File not signed]
R2 tyvozyno; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\jnsjE396.tmp [129536 2015-06-01] () [File not signed]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc [X] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc [X] <==== ATTENTION
S2 Popcornew_update; C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe /svc [X]
S3 Popcornew_update_m; C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe /medsvc [X]
S2 UpdateCheck; C:\Program Files (x86)\Coupoon\UpdateCheck.exe run [X]
R1 {992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64; C:\Windows\System32\drivers\{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64.sys [48784 2015-06-01] (StdLib)
S1 cherimoya; system32\drivers\cherimoya.sys [X]
2015-06-03 18:25 - 2015-06-03 18:25 - 00000000 ____D () C:\Program Files\Coupoon
2015-06-03 18:25 - 2015-06-03 18:25 - 00000000 ____D () C:\Program Files (x86)\coupoon
2015-06-03 08:50 - 2015-06-03 08:50 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nszF32B.tmp
2015-06-02 12:13 - 2015-06-02 12:13 - 00000000 ____D () C:\ProgramData\PastaLeadsAgent
2015-06-01 18:36 - 2015-06-01 19:09 - 00000112 _____ () C:\ProgramData\St3Ln1.dat
2015-06-01 17:57 - 2015-06-01 20:11 - 00003986 _____ () C:\Windows\System32\Tasks\LaunchPreSignup
2015-06-01 16:53 - 2015-06-03 09:10 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2015-06-01 16:53 - 2015-06-03 08:50 - 00002810 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2015-06-01 16:53 - 2015-06-03 08:50 - 00002808 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2015-06-01 16:53 - 2015-06-03 08:50 - 00002808 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2015-06-01 16:53 - 2015-06-03 08:50 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2015-06-01 16:53 - 2015-06-03 08:50 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2015-06-01 16:52 - 2015-06-01 16:52 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsdE38E.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nss21F.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 00613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsh9AD3.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 00000000 __SHD () C:\Users\Jodles\AppData\Roaming\AnyProtectEx
2015-06-01 16:11 - 2015-06-03 16:16 - 00000994 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-06-01 16:11 - 2015-06-03 16:16 - 00000990 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-06-01 16:11 - 2015-06-03 16:11 - 00001012 _____ () C:\Windows\Tasks\PCMBRbqht.job
2015-06-01 16:11 - 2015-06-03 08:17 - 00000350 _____ () C:\Windows\Tasks\OGMDSFLC1.job
2015-06-01 16:11 - 2015-06-03 08:17 - 00000000 ____D () C:\ProgramData\FlashBeat
2015-06-01 16:11 - 2015-06-01 18:55 - 00000000 ____D () C:\ProgramData\abc
2015-06-01 16:11 - 2015-06-01 16:11 - 00004020 _____ () C:\Windows\System32\Tasks\PCMBRbqht
2015-06-01 16:11 - 2015-06-01 16:11 - 00003966 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-06-01 16:11 - 2015-06-01 16:11 - 00003730 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-06-01 16:11 - 2015-06-01 16:11 - 00003562 _____ () C:\Windows\System32\Tasks\QAXAZMZF
2015-06-01 16:11 - 2015-06-01 16:11 - 00002864 _____ () C:\Windows\System32\Tasks\OGMDSFLC1
2015-06-01 16:11 - 2015-06-01 16:11 - 00000000 ____D () C:\ProgramData\e10bdc90fa6b4d348805fa4834f77b68
2015-06-01 16:11 - 2015-06-01 16:11 - 00000000 ____D () C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2015-06-01 16:10 - 2015-06-01 16:10 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Crossbrowse
2015-06-01 16:09 - 2015-06-03 08:48 - 00004038 _____ () C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task
2015-06-01 16:09 - 2015-06-03 08:48 - 00000000 ____D () C:\Users\Jodles\AppData\Local\SmartWeb
2015-06-01 16:00 - 2015-06-01 16:24 - 00000000 ____D () C:\Users\Jodles\AppData\Local\03000200-1433174433-0500-0006-000700080009
2015-06-01 15:57 - 2015-06-03 18:18 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009
2015-06-01 14:05 - 2015-06-01 14:05 - 00000918 _____ () C:\Windows\SysWOW64\${LOGFILE}
2015-06-01 14:03 - 2015-06-01 16:24 - 00003438 _____ () C:\Windows\System32\Tasks\Unjnuglaeb
2015-06-01 14:03 - 2015-06-01 14:03 - 00000000 ____D () C:\ProgramData\Unjnuglaeb
2015-06-01 14:01 - 2015-06-01 14:01 - 00000000 ____D () C:\ProgramData\47d0399b00001855
2015-06-01 13:59 - 2015-06-01 04:37 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64.sys
2015-06-01 13:57 - 2015-06-03 13:57 - 00001044 _____ () C:\Windows\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a.job
2015-06-01 13:57 - 2015-06-03 08:17 - 00000344 _____ () C:\Windows\Tasks\FVYTTDEM1.job
2015-06-01 13:57 - 2015-06-01 14:10 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\Store
2015-06-01 13:57 - 2015-06-01 14:05 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\Nosibay
2015-06-01 13:57 - 2015-06-01 13:57 - 00004052 _____ () C:\Windows\System32\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a
2015-06-01 13:57 - 2015-06-01 13:57 - 00003562 _____ () C:\Windows\System32\Tasks\FWACQQEH
2015-06-01 13:57 - 2015-06-01 13:57 - 00002858 _____ () C:\Windows\System32\Tasks\FVYTTDEM1
2015-06-01 13:57 - 2015-06-01 13:57 - 00000078 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.installation.log
2015-06-01 13:57 - 2015-06-01 13:57 - 00000056 _____ () C:\Windows\Reimage.ini
2015-06-01 13:57 - 2015-06-01 13:57 - 00000051 _____ () C:\Windows\winfix.ini
2015-06-01 13:57 - 2015-06-01 13:57 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN84_01009.Wdf
2015-06-01 13:57 - 2015-06-01 13:57 - 00000000 ____D () C:\ProgramData\1e910f278cdf4ca0ae0a3dc1f227ef74
2015-06-01 13:57 - 2015-06-01 13:57 - 00000000 ____D () C:\ProgramData\12db864551ae4c578eb17db1a9f5d3cf
2015-06-01 13:56 - 2015-06-03 13:56 - 00000360 _____ () C:\Windows\Tasks\Bidaily Synchronize Task[3c32].job
2015-06-01 13:56 - 2015-06-01 19:56 - 00000000 ____D () C:\ProgramData\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}
2015-06-01 13:56 - 2015-06-01 16:20 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-01 13:56 - 2015-06-01 13:56 - 00003248 _____ () C:\Windows\System32\Tasks\Bidaily Synchronize Task[3c32]
2015-06-01 13:56 - 2015-06-01 13:56 - 00000000 ____D () C:\Users\Jodles\AppData\Local\globalUpdate
2015-06-01 13:55 - 2015-06-03 18:00 - 00000946 _____ () C:\Windows\Tasks\PopcornewUpdateTaskMachineUA.job
2015-06-01 13:55 - 2015-06-03 14:00 - 00000942 _____ () C:\Windows\Tasks\PopcornewUpdateTaskMachineCore.job
2015-06-01 13:55 - 2015-06-01 13:57 - 00005717 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.installation.log
2015-06-01 13:55 - 2015-06-01 13:55 - 00003918 _____ () C:\Windows\System32\Tasks\PopcornewUpdateTaskMachineUA
2015-06-01 13:55 - 2015-06-01 13:55 - 00003682 _____ () C:\Windows\System32\Tasks\PopcornewUpdateTaskMachineCore
2015-06-01 13:55 - 2015-06-01 13:55 - 00001216 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.boostrap.log
2015-06-01 13:55 - 2015-06-01 13:55 - 00000097 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.boostrap.log
2015-06-01 13:55 - 2015-06-01 13:55 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Popcornew
2015-06-01 09:58 - 2014-05-02 10:39 - 00000000 ___HD () C:\Users\Jodles\AppData\Local\PxvcIZ4vm
2015-06-01 09:58 - 2013-06-29 02:57 - 00000000 ___HD () C:\Users\Jodles\AppData\Local\jxzc74yZfNzX
2015-04-19 13:20 - 2015-04-19 13:20 - 0005872 _____ () C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a
2015-04-20 15:05 - 2015-04-20 15:05 - 1579520 _____ () C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe
2015-06-01 13:55 - 2015-06-01 13:55 - 0001216 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.boostrap.log
2015-06-01 13:55 - 2015-06-01 13:57 - 0005717 _____ () C:\Users\Jodles\AppData\Roaming\Bubble Dock.installation.log
2015-06-01 13:55 - 2015-06-01 13:55 - 0000097 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.boostrap.log
2015-06-01 13:57 - 2015-06-01 13:57 - 0000078 _____ () C:\Users\Jodles\AppData\Roaming\WindApp.installation.log
2015-06-01 16:52 - 2015-06-01 16:52 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsdE38E.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nsh9AD3.tmp
2015-06-01 16:13 - 2015-06-01 16:13 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nss21F.tmp
2015-06-03 08:50 - 2015-06-03 08:50 - 0613255 _____ (CMI Limited) C:\Users\Jodles\AppData\Local\nszF32B.tmp
2015-06-01 18:36 - 2015-06-01 19:09 - 0000112 _____ () C:\ProgramData\St3Ln1.dat
Task: {236B86F7-CFBB-4105-9912-476E6A9EA4DE} - System32\Tasks\Bidaily Synchronize Task[3c32] => c:\programdata\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}\hqghumeaylnlf.exe [2014-06-01] (PC Utilities Software Limited) <==== ATTENTION
Task: {24F6DBA1-8336-4FC9-9AF3-5065182536A4} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: {368C1995-45AB-4383-950B-C0B5543B2F42} - System32\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a => C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe [2015-04-20] () <==== ATTENTION
Task: {3B701BFD-65AA-4251-A8BB-E3CF6426FB9E} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {3CC6D19C-C0BB-463E-8553-186A21335CAF} - System32\Tasks\FVYTTDEM1 => C:\ProgramData\NavRight\NavRight.exe
Task: {4021CB4C-D997-4B01-8D55-50E7BDF19C5A} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {47BF98E6-883F-4C47-B6D4-C1A9B51529A7} - System32\Tasks\Unjnuglaeb => C:\ProgramData\Unjnuglaeb\1.0.1.0\llibiano.exe [2015-06-01] ()
Task: {4948C935-759B-4F04-B808-3EA135F3CC93} - System32\Tasks\QAXAZMZF => C:\ProgramData\e10bdc90fa6b4d348805fa4834f77b68\e10bdc90fa6b4d348805fa4834f77b68.exe [2015-05-31] ()
Task: {49FA8AD6-AD33-4B84-8FAB-54A0DE510044} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Jodles\AppData\Local\SmartWeb\SmartWebHelper.exe <==== ATTENTION
Task: {5981C4A9-14D2-456F-98E3-406B99937F7A} - System32\Tasks\PCMBRbqht => C:\Users\Jodles\AppData\Roaming\PCMBRbqht.exe [2015-04-20] () <==== ATTENTION
Task: {853F0B50-AFC1-40F0-8727-2F301E7662EB} - System32\Tasks\PopcornewUpdateTaskMachineCore => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
Task: {8E101E15-137F-489D-BFF9-25ADAF16140B} - System32\Tasks\FWACQQEH => C:\ProgramData\1e910f278cdf4ca0ae0a3dc1f227ef74\1e910f278cdf4ca0ae0a3dc1f227ef74.exe [2015-05-31] ()
Task: {B82AF6C8-EC49-419B-92C7-D8847CE9D168} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {C48A0CB2-2A63-41B6-B9B2-36A084C0B7EA} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: {CC7BC94D-82BE-4BCC-9C25-27963E4A32CE} - System32\Tasks\OGMDSFLC1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {CE1DA7DD-3AB3-49DD-8BC7-363761B88A48} - System32\Tasks\PopcornewUpdateTaskMachineUA => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
Task: {FCA4F64F-3961-46E9-9EB4-9AB72ABC229D} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\Bidaily Synchronize Task[3c32].job => c:\programdata\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a.job => C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe <==== ATTENTION
Task: C:\Windows\Tasks\FVYTTDEM1.job => C:\ProgramData\NavRight\NavRight.exe
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\OGMDSFLC1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\PCMBRbqht.job => C:\Users\Jodles\AppData\Roaming\PCMBRbqht.exe <==== ATTENTION
Task: C:\Windows\Tasks\PopcornewUpdateTaskMachineCore.job => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
Task: C:\Windows\Tasks\PopcornewUpdateTaskMachineUA.job => C:\Program Files (x86)\Popcornew\Update\PopcornewUpdate.exe
AlternateDataStreams: C:\Users\Jodles\Cookies:VEZJcTyXOJkxSqep
AlternateDataStreams: C:\Users\Jodles\AppData\Local\jxzc74yZfNzX:QqJu71WEZA0qMiLalxGK
C:\Users\Jodles\AppData\Roaming\ASPackage
C:\Users\Jodles\AppData\Roaming\Store\WindApp
c:\programdata\navright
C:\Program Files (x86)\coupoon
C:\Program Files (x86)\Popcornew
C:\Program Files (x86)\globalUpdate
C:\Windows\System32\drivers\{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64.sys
C:\Windows\system32\drivers\cherimoya.sys
C:\Program Files (x86)\AnyProtectEx
C:\Users\Jodles\AppData\Local\SmartWeb
C:\ProgramData\e10bdc90fa6b4d348805fa4834f77b68\e10bdc90fa6b4d348805fa4834f77b68.exe
C:\ProgramData\Unjnuglaeb
C:\ProgramData\1e910f278cdf4ca0ae0a3dc1f227ef74
C:\Program Files (x86)\OLBPre
C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe
c:\programdata\{c9beb33d-e996-c34f-c9be-eb33de99ccf7}
C:\Users\Jodles\AppData\Roaming\PCMBRbqht.exe
C:\ProgramData\FlashBeat
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers
*****************
 
Restore point was successfully created.
C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009 => Moved successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_gb_395 => value Removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_gb_398 => value Removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\Update => value Removed successfully
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Windows\CurrentVersion\Run\\WindApp => value Removed successfully
"c:\programdata\navright\navright32.dll" => value data Removed successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => key Removed successfully
"HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => key Removed successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main\\Search Bar => value Removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => key Removed successfully
HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => key not found. 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value Removed successfully
"HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => key Removed successfully
HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => key not found. 
"HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => key Removed successfully
HKCR\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found. 
"HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => key Removed successfully
HKCR\CLSID\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found. 
"HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E3DE50FD-7834-4B2D-A386-F7F27C172D00}" => key Removed successfully
HKCR\CLSID\{E3DE50FD-7834-4B2D-A386-F7F27C172D00} => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21186475-d4df-43e2-9bba-0b52c00e0e27}" => key Removed successfully
HKCR\CLSID\{21186475-d4df-43e2-9bba-0b52c00e0e27} => key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21186475-d4df-43e2-9bba-0b52c00e0e27}" => key Removed successfully
HKCR\Wow6432Node\CLSID\{21186475-d4df-43e2-9bba-0b52c00e0e27} => key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value Removed successfully
"HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}" => key Removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value Removed successfully
"HKCR\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}" => key Removed successfully
C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhcmfkkjmkcfgelgdpndepmimbmkbpfp => Moved successfully.
CoupoonService64 => Service Removed successfully
fivyzipo => Unable to stop service.
fivyzipo => Service Removed successfully
jydedidi => Service not found.
tyvozyno => Unable to stop service.
tyvozyno => Service Removed successfully
globalUpdate => Service Removed successfully
globalUpdatem => Service Removed successfully
Popcornew_update => Service Removed successfully
Popcornew_update_m => Service Removed successfully
UpdateCheck => Service Removed successfully
{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64 => Unable to stop service.
{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64 => Service Removed successfully
cherimoya => Service Removed successfully
C:\Program Files\Coupoon => Moved successfully.
C:\Program Files (x86)\coupoon => Moved successfully.
C:\Users\Jodles\AppData\Local\nszF32B.tmp => Moved successfully.
C:\ProgramData\PastaLeadsAgent => Moved successfully.
C:\ProgramData\St3Ln1.dat => Moved successfully.
C:\Windows\System32\Tasks\LaunchPreSignup => Moved successfully.
C:\Windows\Tasks\APSnotifierPP1.job => Moved successfully.
C:\Windows\System32\Tasks\APSnotifierPP1 => Moved successfully.
C:\Windows\System32\Tasks\APSnotifierPP3 => Moved successfully.
C:\Windows\System32\Tasks\APSnotifierPP2 => Moved successfully.
C:\Windows\Tasks\APSnotifierPP3.job => Moved successfully.
C:\Windows\Tasks\APSnotifierPP2.job => Moved successfully.
C:\Users\Jodles\AppData\Local\nsdE38E.tmp => Moved successfully.
C:\Users\Jodles\AppData\Local\nss21F.tmp => Moved successfully.
C:\Users\Jodles\AppData\Local\nsh9AD3.tmp => Moved successfully.
C:\Users\Jodles\AppData\Roaming\AnyProtectEx => Moved successfully.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\PCMBRbqht.job => Moved successfully.
C:\Windows\Tasks\OGMDSFLC1.job => Moved successfully.
C:\ProgramData\FlashBeat => Moved successfully.
C:\ProgramData\abc => Moved successfully.
C:\Windows\System32\Tasks\PCMBRbqht => Moved successfully.
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA => Moved successfully.
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore => Moved successfully.
C:\Windows\System32\Tasks\QAXAZMZF => Moved successfully.
C:\Windows\System32\Tasks\OGMDSFLC1 => Moved successfully.
C:\ProgramData\e10bdc90fa6b4d348805fa4834f77b68 => Moved successfully.
C:\ProgramData\28341ff220e0446c9fff27c4493d622e => Moved successfully.
C:\Users\Jodles\AppData\Local\Crossbrowse => Moved successfully.
C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task => Moved successfully.
C:\Users\Jodles\AppData\Local\SmartWeb => Moved successfully.
C:\Users\Jodles\AppData\Local\03000200-1433174433-0500-0006-000700080009 => Moved successfully.
"C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009" => File/Folder not found.
C:\Windows\SysWOW64\${LOGFILE} => Moved successfully.
C:\Windows\System32\Tasks\Unjnuglaeb => Moved successfully.
C:\ProgramData\Unjnuglaeb => Moved successfully.
C:\ProgramData\47d0399b00001855 => Moved successfully.
C:\Windows\system32\Drivers\{992da9b2-05a3-48d8-b6b8-b471cc08cfa6}Gw64.sys => Moved successfully.
C:\Windows\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a.job => Moved successfully.
C:\Windows\Tasks\FVYTTDEM1.job => Moved successfully.
C:\Users\Jodles\AppData\Roaming\Store => Moved successfully.
C:\Users\Jodles\AppData\Roaming\Nosibay => Moved successfully.
C:\Windows\System32\Tasks\BqGS4HY7ltKDL1PFYT4THhp1a => Moved successfully.
C:\Windows\System32\Tasks\FWACQQEH => Moved successfully.
C:\Windows\System32\Tasks\FVYTTDEM1 => Moved successfully.
C:\Users\Jodles\AppData\Roaming\WindApp.installation.log => Moved successfully.
C:\Windows\Reimage.ini => Moved successfully.
C:\Windows\winfix.ini => Moved successfully.
C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN84_01009.Wdf => Moved successfully.
C:\ProgramData\1e910f278cdf4ca0ae0a3dc1f227ef74 => Moved successfully.
C:\ProgramData\12db864551ae4c578eb17db1a9f5d3cf => Moved successfully.
C:\Windows\Tasks\Bidaily Synchronize Task[3c32].job => Moved successfully.
C:\ProgramData\{c9beb33d-e996-c34f-c9be-eb33de99ccf7} => Moved successfully.
C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => Moved successfully.
C:\Windows\System32\Tasks\Bidaily Synchronize Task[3c32] => Moved successfully.
C:\Users\Jodles\AppData\Local\globalUpdate => Moved successfully.
C:\Windows\Tasks\PopcornewUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\PopcornewUpdateTaskMachineCore.job => Moved successfully.
C:\Users\Jodles\AppData\Roaming\Bubble Dock.installation.log => Moved successfully.
C:\Windows\System32\Tasks\PopcornewUpdateTaskMachineUA => Moved successfully.
C:\Windows\System32\Tasks\PopcornewUpdateTaskMachineCore => Moved successfully.
C:\Users\Jodles\AppData\Roaming\Bubble Dock.boostrap.log => Moved successfully.
C:\Users\Jodles\AppData\Roaming\WindApp.boostrap.log => Moved successfully.
C:\Users\Jodles\AppData\Local\Popcornew => Moved successfully.
C:\Users\Jodles\AppData\Local\PxvcIZ4vm => Moved successfully.
C:\Users\Jodles\AppData\Local\jxzc74yZfNzX => Moved successfully.
C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a => Moved successfully.
C:\Users\Jodles\AppData\Roaming\BqGS4HY7ltKDL1PFYT4THhp1a.exe => Moved successfully.
"C:\Users\Jodles\AppData\Roaming\Bubble Dock.boostrap.log" => File/Folder not found.
"C:\Users\Jodles\AppData\Roaming\Bubble Dock.installation.log" => File/Folder not found.
"C:\Users\Jodles\AppData\Roaming\WindApp.boostrap.log" => File/Folder not found.
"C:\Users\Jodles\AppData\Roaming\WindApp.installation.log" => File/Folder not found.
"C:\Users\Jodles\AppData\Local\nsdE38E.tmp" => File/Folder not found.
"C:\Users\Jodles\AppData\Local\nsh9AD3.tmp" => File/Folder not found.
"C:\Users\Jodles\AppData\Local\nss21F.tmp" => File/Folder not found.
"C:\Users\Jodles\AppData\Local\nszF32B.tmp" => File/Folder not found.
"C:\ProgramData\St3Ln1.dat" => File/Folder not found.

  • 0

#4
MissJodles

MissJodles

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
# AdwCleaner v4.206 - Logfile created 03/06/2015 at 21:19:18
# Updated 01/06/2015 by Xplode
# Database : 2015-06-01.1 [Server]
# Operating system : Windows 8.1 Pro  (x64)
# Username : Jodles - SAPPHIRE
# Running from : C:\Users\Jodles\Desktop\AdwCleaner.exe
# Option : Cleaning
 
***** [ Services ] *****
 
[#] Service Deleted : cherimoya
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
Service Deleted : netfilter64
[#] Service Deleted : Popcornew_update
[#] Service Deleted : Popcornew_update_m
[#] Service Deleted : CoupoonService64
[#] Service Deleted : innfd_1_10_0_14
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\Users\Jodles\AppData\Local\Temp\Edu App
Folder Deleted : C:\Users\Jodles\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Deleted : C:\Users\Jodles\AppData\Roaming\OpenCandy
File Deleted : C:\END
File Deleted : C:\Users\Jodles\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Windows\System32\drivers\netfilter64.sys
File Deleted : C:\Users\Jodles\AppData\Roaming\PCMBRbqht
File Deleted : C:\Users\Jodles\AppData\Roaming\PCMBRbqht.exe
 
***** [ Scheduled tasks ] *****
 
Task Deleted : APSnotifierPP1
Task Deleted : APSnotifierPP2
Task Deleted : APSnotifierPP3
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : PopcornewUpdateTaskMachineCore
Task Deleted : SmartWeb Upgrade Trigger Task
Task Deleted : LaunchPreSignup
Task Deleted : PCMBRbqht
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\Classes\AppID\PopcornewUpdate.exe
Key Deleted : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
Key Deleted : HKLM\SOFTWARE\5b95c829-675a-17fd-3bea-9f2b7e807e15
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{2BB27047-C938-4EBC-9158-6C84F1CC09D1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6A700506-A641-475A-8538-44AEE2F45DD0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D6A5312-AB4D-41AA-8BED-0E019B87CA11}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADA3F4C6-F003-41AE-968D-6C2FFF09DA28}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C0EE992D-B820-48A3-9339-363F5DA9545E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EFD2925B-400E-4B47-8CC4-33EB2E3232F6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F930C6AB-C4F4-4CBC-97CB-49ED410F99CF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE97B593-B850-47EA-A787-977274C3B5B5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0D692BF5-6C8C-4141-8C24-9CB731D78F75}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0F840CB3-F4B0-4746-9211-94E5372FBD05}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2BB27047-C938-4EBC-9158-6C84F1CC09D1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2C9F2C34-8F06-442D-90BE-B23C0A31983F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3DD579C6-640C-4873-9596-D5BD8ECB8E99}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{52A8C674-98FA-4A0A-9F64-C8B9D161FDC4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6A700506-A641-475A-8538-44AEE2F45DD0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E377247-6BEC-4961-84B4-B0FB7ADF84AD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7081BB03-D2E6-4797-A2E7-C9EB331636C8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{74DDBF4E-EC16-468A-A6F4-6C1D250A4EC9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7CD8A44F-6DEF-4D91-952D-4492AC5E4306}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{909F2E0D-650B-46B9-A27D-5A893BDDF58D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9892108A-038E-4D48-9D3C-D1E2A9B706EC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9AE7A6AE-162E-44C4-9A2B-A6B4EF19909D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{14EF423E-3EE8-44AE-9337-07AC3F27B744}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ADA3F4C6-F003-41AE-968D-6C2FFF09DA28}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{909F2E0D-650B-46B9-A27D-5A893BDDF58D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ADA3F4C6-F003-41AE-968D-6C2FFF09DA28}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7CD8A44F-6DEF-4D91-952D-4492AC5E4306}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909F2E0D-650B-46B9-A27D-5A893BDDF58D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Deleted : HKCU\Software\AnyProtect
Key Deleted : HKCU\Software\Conduit_Search_Protect
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Nosibay
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\Store
Key Deleted : HKCU\Software\Popcornew
Key Deleted : HKCU\Software\Crossbrowse
Key Deleted : HKCU\Software\YorkNewCin
Key Deleted : HKCU\Software\HighDefAction
Key Deleted : HKCU\Software\ArenaHD
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\DynConIE
Key Deleted : HKCU\Software\AppDataLow\Software\coupoon
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\SimpleFiles
Key Deleted : HKLM\SOFTWARE\Tutorials
Key Deleted : HKLM\SOFTWARE\Popcornew
Key Deleted : HKLM\SOFTWARE\LuckyTab
Key Deleted : HKLM\SOFTWARE\mystartsearchSoftware
Key Deleted : HKLM\SOFTWARE\FlashBeat
Key Deleted : HKLM\SOFTWARE\Crossbrowse
Key Deleted : HKLM\SOFTWARE\coupoon
Key Deleted : HKLM\SOFTWARE\YorkNewCin
Key Deleted : HKLM\SOFTWARE\HighDefAction
Key Deleted : HKLM\SOFTWARE\ArenaHD
Key Deleted : HKU\.DEFAULT\Software\Popcornew
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Key Deleted : [x64] HKLM\SOFTWARE\FlashBeat
Key Deleted : [x64] HKLM\SOFTWARE\WebBar
Key Deleted : [x64] HKLM\SOFTWARE\coupoon
Key Deleted : [x64] HKLM\SOFTWARE\YorkNewCin
Key Deleted : [x64] HKLM\SOFTWARE\HighDefAction
Key Deleted : [x64] HKLM\SOFTWARE\ArenaHD
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\globalupdate.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PopcornewUpdate.exe
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17416
 
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
 
-\\ Google Chrome v43.0.2357.81
 
[C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] : 
[C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Startup_URLs] : CE306B918CF05E70577F90FEE588EE57EE0C6A16F29124CF908845D525C32A01"},"software_reporter":{"prompt_reason":"C991FF42597507D5DDB27BC8A68E1AC4E7E1D380B471CEEC1B05B5F08D770880","prompt_seed":"06391C5974AED660A769091BCB6EBD0DF85F8721A6CC2EA0F2397001F8C897DE","prompt_version":"35308B5109C8A26314512F9AE69CA896018964B11C659C4D02090C576D9C7F92"},"sync":{"remaining_rollback_tries":"978E88CD61AF3010EBAA5B7164383C97AF3EF86691619135FC135E1C679E6F8A"}},"super_mac":"392E9FEEEDB1CAF6D3E7213CB2789D916EE2E0A937283A61A62D34FA5C07440E"},"session":{"restore_on_startup":4,"startup_urls":["hxxp://www.trovi.com/?gd=&ctid=CT3325163&octid=EB_ORIGINAL_CTID&ISID=MD3FC98F0-5802-472E-B1FA-3CE0D5170DC0&SearchSource=55&CUI=&UM=6&UP=SP28C95B34-BF2E-457C-9BA7-6684021A44C3&SSPV=&SSPV=
 
*************************
 
AdwCleaner[R0].txt - [20156 bytes] - [03/06/2015 21:18:58]
AdwCleaner[S0].txt - [13625 bytes] - [03/06/2015 21:19:18]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13685  bytes] ##########

  • 0

#5
MissJodles

MissJodles

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2015-06-03 21:23:39
-----------------------------
21:23:39.412    OS Version: Windows x64 6.2.9200 
21:23:39.412    Number of processors: 4 586 0x3C03
21:23:39.412    ComputerName: SAPPHIRE  UserName: Jodles
21:23:39.622    Initialize success
21:23:40.275    VM: initialized successfully
21:23:40.276    VM: Intel CPU supported 
21:23:41.840    VM: supported disk I/O storport.sys
21:29:13.747    AVAST engine defs: 15060300
21:29:31.620    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002d
21:29:31.620    Disk 0 Vendor: Samsung_SSD_840_EVO_120GB EXT0BB6Q Size: 114473MB BusType: 11
21:29:31.635    Disk 1  \Device\Harddisk1\DR1 -> \Device\0000002e
21:29:31.635    Disk 1 Vendor: ST2000DM001-1ER164 CC43 Size: 1907729MB BusType: 11
21:29:31.635    VM: Disk 0 MBR read successfully
21:29:31.635    Disk 0 MBR scan
21:29:31.651    Disk 0 Windows 7 default MBR code
21:29:31.666    Disk 0 Partition 1 00     EE            GPT           2097151 MB offset 1
21:29:31.682    Disk 0 scanning C:\Windows\system32\drivers
21:29:37.123    Service scanning
21:29:47.371    Modules scanning
21:29:47.375    Disk 0 trace - called modules:
21:29:47.378    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll storahci.sys 
21:29:47.381    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe0011f64d4e0]
21:29:47.382    3 CLASSPNP.SYS[fffff801fc73f170] -> nt!IofCallDriver -> [0xffffe0011f478430]
21:29:47.384    5 ACPI.sys[fffff801fc0ffc21] -> nt!IofCallDriver -> [0xffffe0011f47a9d0]
21:29:47.386    7 ACPI.sys[fffff801fc0ffc21] -> nt!IofCallDriver -> \Device\0000002d[0xffffe0011f4787f0]
21:29:47.547    AVAST engine scan C:\Windows
21:29:48.066    AVAST engine scan C:\Windows\system32
21:31:17.088    AVAST engine scan C:\Windows\system32\drivers
21:31:23.335    AVAST engine scan C:\Users\Jodles
21:31:55.221    File: C:\Users\Jodles\AppData\Local\Microsoft\Windows\INetCache\IE\A3LBPVNB\FinalInstaller_dotnet4[1].exe  **INFECTED** Win32:GenMaliciousA-FRH [Adw]
21:32:18.017    File: C:\Users\Jodles\AppData\Local\Temp\7E6255DD-C9D1-29AA-63D5-49CE02316B70.exe  **INFECTED** Win32:Adware-gen [Adw]
21:32:18.916    File: C:\Users\Jodles\AppData\Local\Temp\94C1DDCE-3E49-F78A-BC16-EB23868D4A35.exe  **INFECTED** Win32:Adware-gen [Adw]
21:32:19.385    File: C:\Users\Jodles\AppData\Local\Temp\comh.15235\npglobalupdateUpdate4.dll  **INFECTED** Win32:Adware-gen [Adw]
21:32:19.744    File: C:\Users\Jodles\AppData\Local\Temp\comh.356225\npglobalupdateUpdate4.dll  **INFECTED** Win32:Adware-gen [Adw]
21:32:24.173    File: C:\Users\Jodles\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_90.exe  **INFECTED** Win32:Dropper-gen [Drp]
21:33:07.852    File: C:\Users\Jodles\AppData\Local\Temp\OnlineBackup.exe  **INFECTED** Win32:Malware-gen
21:33:11.403    File: C:\Users\Jodles\AppData\Local\Temp\sdfA35C.exe  **INFECTED** Win32:GenMaliciousA-FRH [Adw]
21:33:11.665    File: C:\Users\Jodles\AppData\Local\Temp\sdfD8B4.exe  **INFECTED** Win32:GenMaliciousA-FRH [Adw]
21:33:18.792    File: C:\Users\Jodles\AppData\Local\Temp\Temp2_How_To_Find_Your_Windows_8_or_8.1_Product_Key_Easily.zip\How_To_Find_Your_Windows_8_or_8.1_Product_Key_Easily_downloader.exe  **INFECTED** Win32:Malware-gen
21:33:39.348    File: C:\Users\Jodles\AppData\Local\Temp\xj1SHKqnTc.exe  **INFECTED** Win32:Malware-gen
21:34:55.912    AVAST engine scan C:\ProgramData
21:35:23.040    Disk 0 statistics 3833869/0/5 @ 37.29 MB/s
21:35:23.055    Scan finished successfully
21:35:42.490    Disk 0 MBR has been saved successfully to "C:\Users\Jodles\Desktop\MBR.dat"
21:35:42.511    The log file has been saved successfully to "C:\Users\Jodles\Desktop\aswMBR.txt"

  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK another run and then we will have a fresh look

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
C:\Users\Jodles\AppData\Local\Microsoft\Windows\INetCache\IE\A3LBPVNB
C:\Users\Jodles\AppData\Local\Temp\7E6255DD-C9D1-29AA-63D5-49CE02316B70.exe
C:\Users\Jodles\AppData\Local\Temp\94C1DDCE-3E49-F78A-BC16-EB23868D4A35.exe
C:\Users\Jodles\AppData\Local\Temp\comh.15235\npglobalupdateUpdate4.dll
C:\Users\Jodles\AppData\Local\Temp\comh.356225\npglobalupdateUpdate4.dll
C:\Users\Jodles\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_90.exe
C:\Users\Jodles\AppData\Local\Temp\OnlineBackup.exe
C:\Users\Jodles\AppData\Local\Temp\sdfA35C.exe
C:\Users\Jodles\AppData\Local\Temp\sdfD8B4.exe
C:\Users\Jodles\AppData\Local\Temp\Temp2_How_To_Find_Your_Windows_8_or_8.1_Product_Key_Easily.zip\How_To_Find_Your_Windows_8_or_8.1_Product_Key_Easily_downloader.exe
c:\Users\Jodles\AppData\Local\Temp\xj1SHKqnTc.exe


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Could you run a fresh FRST scan for me please and let me know how the computer is behaving now
  • 0

#7
MissJodles

MissJodles

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Fix result of Farbar Recovery Scan Tool (x64) Version: 29-05-2015
Ran by Jodles at 2015-06-03 21:46:32 Run:2
Running from C:\Users\Jodles\Desktop
Loaded Profiles: Jodles (Available Profiles: Jodles)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
reateRestorePoint:
C:\Users\Jodles\AppData\Local\Microsoft\Windows\INetCache\IE\A3LBPVNB
C:\Users\Jodles\AppData\Local\Temp\7E6255DD-C9D1-29AA-63D5-49CE02316B70.exe
C:\Users\Jodles\AppData\Local\Temp\94C1DDCE-3E49-F78A-BC16-EB23868D4A35.exe
C:\Users\Jodles\AppData\Local\Temp\comh.15235\npglobalupdateUpdate4.dll
C:\Users\Jodles\AppData\Local\Temp\comh.356225\npglobalupdateUpdate4.dll
C:\Users\Jodles\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_90.exe
C:\Users\Jodles\AppData\Local\Temp\OnlineBackup.exe
C:\Users\Jodles\AppData\Local\Temp\sdfA35C.exe
C:\Users\Jodles\AppData\Local\Temp\sdfD8B4.exe
C:\Users\Jodles\AppData\Local\Temp\Temp2_How_To_Find_Your_Windows_8_or_8.1_Product_Key_Easily.zip\How_To_Find_Your_Windows_8_or_8.1_Product_Key_Easily_downloader.exe
c:\Users\Jodles\AppData\Local\Temp\xj1SHKqnTc.exe
 
*****************
 
reateRestorePoint: => Error: No automatic fix found for this entry.
C:\Users\Jodles\AppData\Local\Microsoft\Windows\INetCache\IE\A3LBPVNB => Moved successfully.
C:\Users\Jodles\AppData\Local\Temp\7E6255DD-C9D1-29AA-63D5-49CE02316B70.exe => Moved successfully.
C:\Users\Jodles\AppData\Local\Temp\94C1DDCE-3E49-F78A-BC16-EB23868D4A35.exe => Moved successfully.
C:\Users\Jodles\AppData\Local\Temp\comh.15235\npglobalupdateUpdate4.dll => Moved successfully.
C:\Users\Jodles\AppData\Local\Temp\comh.356225\npglobalupdateUpdate4.dll => Moved successfully.
C:\Users\Jodles\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_90.exe => Moved successfully.
C:\Users\Jodles\AppData\Local\Temp\OnlineBackup.exe => Moved successfully.
C:\Users\Jodles\AppData\Local\Temp\sdfA35C.exe => Moved successfully.
C:\Users\Jodles\AppData\Local\Temp\sdfD8B4.exe => Moved successfully.
C:\Users\Jodles\AppData\Local\Temp\Temp2_How_To_Find_Your_Windows_8_or_8.1_Product_Key_Easily.zip\How_To_Find_Your_Windows_8_or_8.1_Product_Key_Easily_downloader.exe => Moved successfully.
c:\Users\Jodles\AppData\Local\Temp\xj1SHKqnTc.exe => Moved successfully.
 
==== End of Fixlog 21:46:32 ====

  • 0

#8
MissJodles

MissJodles

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts

Here's the newest scan result :)

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-05-2015
Ran by Jodles (administrator) on SAPPHIRE on 03-06-2015 21:47:17
Running from C:\Users\Jodles\Desktop
Loaded Profiles: Jodles (Available Profiles: Jodles)
Platform: Windows 8.1 Pro (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Advanced Micro Devices) C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Mad Catz Inc) C:\Program Files\Mad Catz\R.A.T.TE\RAT_TE_Profiler.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\livecomm.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [R.A.T.TE] => C:\Program Files\Mad Catz\R.A.T.TE\RAT_TE_Profiler.exe [195072 2014-09-12] (Mad Catz Inc)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-01-27] (Apple Inc.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => E:\Program Files\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\Run: [DAEMON Tools Lite] => E:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\Run: [GoogleChromeAutoLaunch_85780D0100E82B662A94D25DE9304028] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-05-22] (Google Inc.)
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\MountPoints2: {42e6b9aa-3e8c-11e4-8262-d05099274e52} - "F:\arun.exe" 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\MountPoints2: {7d3fbd6f-5eb4-11e4-826a-ec70d341df29} - "I:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\MountPoints2: {7d3fc0e0-5eb4-11e4-826a-ec70d341df29} - "H:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\...\MountPoints2: {b062b7b4-36fd-11e4-8250-806e6f6e6963} - "E:\Launch.exe" 
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [132608 2014-10-29] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => E:\Program Files\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => E:\Program Files\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => E:\Program Files\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKU\S-1-5-21-266208001-1606254893-869063284-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.uk.msn.com/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> E:\Program Files\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> E:\Program Files\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> E:\Program Files\Arc\Arc\Plugins\ArcPluginIE.dll [2015-04-22] (Perfect World Entertainment Inc)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - E:\Program Files\Office15\MSOSB.DLL [2014-04-01] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> E:\Program Files\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> E:\Program Files\Arc\Arc\plugins\NPSWF32.dll [2015-04-22] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll No File
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> E:\Program Files\Arc\Arc\Plugins\npArcPluginFF.dll [2015-04-22] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.Popcornew.com/Popcornew Update;version=3 -> C:\Program Files (x86)\Popcornew\Update\1.3.25.0\npPopcornewUpdate3.dll No File
FF Plugin-x32: @tools.Popcornew.com/Popcornew Update;version=9 -> C:\Program Files (x86)\Popcornew\Update\1.3.25.0\npPopcornewUpdate3.dll No File
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF HKLM\...\Firefox\Extensions: [{21186475-d4df-43e2-9bba-0b52c00e0e27}] - C:\Program Files\shopperz\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{21186475-d4df-43e2-9bba-0b52c00e0e27}] - C:\Program Files\shopperz\Firefox
 
Chrome: 
=======
CHR Profile: C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bookmark Manager) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-22]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Google Wallet) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-08]
CHR Extension: (Dolce & Gabbana Lace) - C:\Users\Jodles\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjpbblimbifbkffcijignfgmaalbcjje [2015-06-01]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [116224 2014-11-20] (Advanced Micro Devices) [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S3 ArcService; E:\Program Files\Arc\Arc\ArcService.exe [88584 2015-04-22] (Perfect World Entertainment Inc)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
S3 Origin Client Service; E:\Program Files\Origin\OriginClientService.exe [1931632 2015-05-02] (Electronic Arts)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [656664 2014-08-19] (Wacom Technology, Corp.)
S2 mozolihu; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\nsa5B1F.tmp [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [294600 2014-11-21] (Advanced Micro Devices)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [223232 2014-06-21] (Advanced Micro Devices)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-09-18] (Disc Soft Ltd)
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [47008 2013-07-30] ()
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
S3 SaiK0CFA; C:\Windows\system32\DRIVERS\SaiK0CFA.sys [174600 2010-07-21] (Saitek)
R3 SaiMini; C:\Windows\System32\drivers\SaiMini.sys [23968 2014-09-15] (Saitek)
R3 SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [51488 2014-09-15] (Saitek)
S3 SaiU0CFA; C:\Windows\System32\drivers\SaiU0CFA.sys [41352 2010-07-21] (Saitek)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
R3 _hid_0738_1704; C:\Windows\system32\DRIVERS\_hid_0738_1704.sys [179904 2014-09-15] (Saitek)
R3 _usb_0738_1704; C:\Windows\System32\drivers\_usb_0738_1704.sys [46528 2014-09-15] (Saitek)
S1 scfd_1_10_0_16; system32\drivers\scfd_1_10_0_16.sys [X]
U3 aswMBR; \??\C:\Users\Jodles\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Jodles\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-03 21:35 - 2015-06-03 21:35 - 00003764 _____ () C:\Users\Jodles\Desktop\aswMBR.txt
2015-06-03 21:35 - 2015-06-03 21:35 - 00000512 _____ () C:\Users\Jodles\Desktop\MBR.dat
2015-06-03 21:21 - 2015-06-03 21:21 - 05200384 _____ (AVAST Software) C:\Users\Jodles\Desktop\aswmbr.exe
2015-06-03 21:18 - 2015-06-03 21:19 - 00000000 ____D () C:\AdwCleaner
2015-06-03 21:17 - 2015-06-03 21:17 - 02231296 _____ () C:\Users\Jodles\Desktop\AdwCleaner.exe
2015-06-03 18:44 - 2015-06-03 21:47 - 00013703 _____ () C:\Users\Jodles\Desktop\FRST.txt
2015-06-03 18:44 - 2015-06-03 18:44 - 00046258 _____ () C:\Users\Jodles\Desktop\Addition.txt
2015-06-03 18:43 - 2015-06-03 21:47 - 00000000 ____D () C:\FRST
2015-06-03 18:43 - 2015-06-03 18:43 - 02108928 _____ (Farbar) C:\Users\Jodles\Desktop\FRST64.exe
2015-06-01 15:58 - 2014-11-02 11:10 - 00000913 _____ () C:\Windows\system32\Drivers\etc\hp.bak
2015-06-01 10:10 - 2015-06-01 10:10 - 00001418 _____ () C:\Users\Jodles\Desktop\Adobe Premiere Pro - Shortcut.lnk
2015-06-01 09:58 - 2015-06-01 09:58 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\PACE Anti-Piracy
2015-06-01 09:58 - 2015-06-01 09:58 - 00000000 ____D () C:\Users\Jodles\AppData\Local\PACE Anti-Piracy
2015-06-01 09:58 - 2015-06-01 09:58 - 00000000 ____D () C:\ProgramData\PACE Anti-Piracy
2015-06-01 09:57 - 2015-06-01 09:57 - 00001013 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2015-06-01 09:57 - 2015-06-01 09:57 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-06-01 09:57 - 2015-06-01 09:57 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-06-01 09:57 - 2015-06-01 09:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2015-05-31 17:15 - 2015-05-31 17:15 - 00001390 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-05-31 17:15 - 2015-05-31 17:15 - 00001321 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2015-05-31 17:15 - 2015-05-31 17:15 - 00000000 ____D () C:\Windows\en
2015-05-31 17:14 - 2015-05-31 17:14 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-05-31 17:13 - 2015-05-31 17:14 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-05-31 17:12 - 2015-05-31 17:16 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Windows Live
2015-05-31 15:41 - 2015-06-01 09:41 - 00016896 _____ () C:\Users\Jodles\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-31 15:29 - 2015-05-31 15:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightworks
2015-05-31 15:28 - 2015-05-31 15:28 - 00000000 ____D () C:\ProgramData\Geevs
2015-05-28 15:10 - 2015-05-28 15:10 - 01049194 _____ () C:\Users\Jodles\Downloads\Final.avi
2015-05-16 14:40 - 2015-05-16 14:40 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom
2015-05-13 20:32 - 2015-04-30 21:35 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 20:32 - 2015-04-30 21:35 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 20:02 - 2015-05-01 00:05 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 20:02 - 2015-04-30 23:48 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-13 20:02 - 2015-04-24 22:32 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-13 20:02 - 2015-04-13 23:48 - 04180480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 20:02 - 2015-04-10 02:00 - 01996800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 20:02 - 2015-04-10 01:50 - 01387008 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 20:02 - 2015-04-10 01:34 - 02256896 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-05-13 20:02 - 2015-04-10 01:26 - 01560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-13 20:02 - 2015-04-10 01:11 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-05-13 20:02 - 2015-04-08 23:55 - 00410128 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-13 20:02 - 2015-04-03 01:35 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\PhotoMetadataHandler.dll
2015-05-13 20:02 - 2015-04-03 01:14 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoMetadataHandler.dll
2015-05-13 20:02 - 2015-04-01 23:22 - 02985984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2015-05-13 20:02 - 2015-04-01 23:20 - 04417536 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2015-05-13 20:02 - 2015-04-01 04:45 - 01491456 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2015-05-13 20:02 - 2015-04-01 03:31 - 01207296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2015-05-13 20:02 - 2015-03-20 02:56 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ahcache.sys
2015-05-13 20:02 - 2015-03-17 18:26 - 00467776 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2015-05-13 20:02 - 2015-03-13 05:03 - 00239424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2015-05-13 20:02 - 2015-03-13 05:03 - 00154432 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2015-05-13 20:02 - 2015-03-13 03:02 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2015-05-13 20:02 - 2015-03-13 02:11 - 02162176 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2015-05-13 20:02 - 2015-03-13 01:39 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2015-05-13 20:02 - 2015-03-11 02:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-13 20:02 - 2015-03-11 02:09 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-13 20:02 - 2015-03-09 03:02 - 00057856 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2015-05-13 20:02 - 2015-03-06 03:47 - 01696256 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2015-05-13 20:02 - 2015-03-05 00:09 - 01429504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-13 20:02 - 2015-03-04 02:32 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2015-05-13 20:02 - 2015-03-04 02:12 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2015-05-13 20:02 - 2015-02-18 00:19 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2015-05-13 20:02 - 2015-01-30 01:53 - 02819584 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2015-05-13 20:02 - 2014-11-14 07:58 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsDatabase.dll
2015-05-13 20:01 - 2015-04-21 18:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 20:01 - 2015-04-21 17:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 20:01 - 2015-04-21 17:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 20:01 - 2015-04-21 17:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 20:01 - 2015-04-21 17:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 20:01 - 2015-04-21 17:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 20:01 - 2015-04-21 17:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 20:01 - 2015-04-21 17:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-13 20:01 - 2015-04-21 17:13 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-05-13 20:01 - 2015-04-21 17:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-13 20:01 - 2015-04-21 17:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-13 20:01 - 2015-04-21 17:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 20:01 - 2015-04-21 17:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-05-13 20:01 - 2015-04-21 17:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 20:01 - 2015-04-21 17:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-13 20:01 - 2015-04-21 16:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-05-13 20:01 - 2015-04-21 16:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-13 20:01 - 2015-04-21 16:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-05-13 20:01 - 2015-04-21 16:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 20:01 - 2015-04-21 16:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 20:01 - 2015-04-21 16:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 20:01 - 2015-04-21 16:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 20:01 - 2015-04-21 16:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 20:01 - 2015-04-21 16:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-13 20:01 - 2015-04-21 16:37 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-05-13 20:01 - 2015-04-21 16:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-13 20:01 - 2015-04-21 16:32 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-05-13 20:01 - 2015-04-21 16:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-13 20:01 - 2015-04-21 16:28 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-05-13 20:01 - 2015-04-21 16:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 20:01 - 2015-04-21 16:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-13 20:01 - 2015-04-21 16:26 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-13 20:01 - 2015-04-21 16:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-13 20:01 - 2015-04-21 16:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-13 20:01 - 2015-04-21 16:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 20:01 - 2015-04-21 16:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 20:01 - 2015-04-21 16:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-13 20:01 - 2015-04-21 15:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-13 20:01 - 2015-04-21 15:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-13 20:01 - 2015-03-30 06:47 - 00561928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-05-13 20:01 - 2015-03-27 04:27 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-13 20:01 - 2015-03-27 03:50 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-13 20:01 - 2015-03-27 03:48 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-13 20:01 - 2015-03-13 01:29 - 00410017 _____ () C:\Windows\system32\ApnDatabase.xml
2015-05-13 20:01 - 2015-03-06 04:08 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-13 20:01 - 2015-03-06 03:43 - 01969664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-05-07 21:53 - 2015-05-07 21:53 - 00001401 _____ () C:\Users\Jodles\Desktop\Photoshop.lnk
2015-05-04 10:04 - 2015-05-04 10:04 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\AMD
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-03 21:43 - 2014-09-08 03:17 - 01646067 _____ () C:\Windows\WindowsUpdate.log
2015-06-03 21:34 - 2015-01-25 19:14 - 00004928 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for SAPPHIRE-Jodles Sapphire
2015-06-03 21:29 - 2014-03-18 11:04 - 00863592 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-06-03 21:23 - 2015-04-14 09:06 - 00007252 _____ () C:\Windows\setupact.log
2015-06-03 21:23 - 2014-09-15 19:36 - 00000000 ___DO () C:\Users\Jodles\OneDrive
2015-06-03 21:23 - 2014-09-08 04:14 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-03 21:23 - 2014-09-08 03:20 - 00000000 ____D () C:\Users\Jodles
2015-06-03 21:23 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-06-03 21:20 - 2014-09-08 04:14 - 00000924 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-03 21:19 - 2015-02-05 18:33 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-06-03 21:19 - 2014-09-08 04:20 - 00065536 _____ () C:\Windows\system32\spu_storage.bin
2015-06-03 21:19 - 2014-03-18 10:54 - 00057500 _____ () C:\Windows\PFRO.log
2015-06-03 21:19 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-06-03 21:15 - 2013-08-22 16:36 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-06-03 21:15 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2015-06-03 21:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2015-06-03 20:56 - 2014-09-08 04:13 - 00003930 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{F4A03479-3E54-4F9A-8366-EFFEBA03B3F1}
2015-06-03 16:40 - 2014-09-08 18:44 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Battle.net
2015-06-03 12:37 - 2014-09-08 03:25 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-266208001-1606254893-869063284-1001
2015-06-03 08:26 - 2014-10-26 12:21 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Adobe
2015-06-01 16:22 - 2015-04-30 14:57 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2015-06-01 16:18 - 2014-09-08 04:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-01 13:59 - 2013-08-22 14:25 - 00000269 _____ () C:\Windows\win.ini
2015-06-01 13:57 - 2014-09-15 21:23 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\uTorrent
2015-06-01 09:58 - 2014-09-08 03:20 - 00000000 ____D () C:\Users\Jodles\AppData\Roaming\Adobe
2015-06-01 09:57 - 2014-10-26 12:26 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-06-01 09:57 - 2014-10-26 12:24 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-06-01 09:57 - 2014-10-26 12:21 - 00000000 ____D () C:\ProgramData\Adobe
2015-06-01 09:54 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-05-31 17:13 - 2014-09-18 21:01 - 00059271 _____ () C:\Windows\DirectX.log
2015-05-21 19:30 - 2015-04-05 07:45 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-05-21 19:30 - 2015-04-05 07:45 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-21 19:30 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-05-19 20:17 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF
2015-05-18 17:15 - 2014-09-08 04:14 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-18 17:15 - 2014-09-08 04:14 - 00003660 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-16 14:40 - 2015-02-16 11:09 - 00000000 ____D () C:\Users\Jodles\Desktop\Josh's Cool Stuff
2015-05-16 14:39 - 2014-12-22 19:54 - 00000000 ____D () C:\Program Files\Tablet
2015-05-14 20:24 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2015-05-14 18:23 - 2014-09-08 03:20 - 00000000 ____D () C:\Users\Jodles\AppData\Local\Packages
2015-05-14 18:04 - 2013-08-22 15:44 - 05101432 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-13 22:21 - 2013-08-22 16:36 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2015-05-13 22:21 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-13 20:34 - 2014-10-19 14:28 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-05-13 20:34 - 2014-10-19 14:27 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-05-13 20:32 - 2014-09-13 13:28 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-13 20:31 - 2014-09-13 13:28 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-13 20:27 - 2014-03-18 10:46 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-05 18:59 - 2013-08-22 16:38 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-05-05 18:59 - 2013-08-22 16:38 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
 
==================== Files in the root of some directories =======
 
2015-03-25 19:19 - 2015-03-25 19:19 - 0000132 _____ () C:\Users\Jodles\AppData\Roaming\Adobe PNG Format CS6 Prefs
2015-04-12 18:22 - 2015-04-12 18:22 - 0000046 _____ () C:\Users\Jodles\AppData\Roaming\Camdata.ini
2015-04-12 18:22 - 2015-04-12 18:22 - 0000408 _____ () C:\Users\Jodles\AppData\Roaming\CamLayout.ini
2015-04-12 18:22 - 2015-04-12 18:22 - 0000408 _____ () C:\Users\Jodles\AppData\Roaming\CamShapes.ini
2015-04-12 18:22 - 2015-04-12 18:22 - 0004508 _____ () C:\Users\Jodles\AppData\Roaming\CamStudio.cfg
2015-04-12 19:00 - 2015-04-12 19:00 - 0001456 _____ () C:\Users\Jodles\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-05-31 15:41 - 2015-06-01 09:41 - 0016896 _____ () C:\Users\Jodles\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
Some files in TEMP:
====================
C:\Users\Jodles\AppData\Local\Temp\2251.exe
C:\Users\Jodles\AppData\Local\Temp\4109.exe
C:\Users\Jodles\AppData\Local\Temp\4135.exe
C:\Users\Jodles\AppData\Local\Temp\4548cAJpEW.exe
C:\Users\Jodles\AppData\Local\Temp\7E6255DD-C9D1-29AA-63D5-49CE02316B70.dll
C:\Users\Jodles\AppData\Local\Temp\8783.exe
C:\Users\Jodles\AppData\Local\Temp\bitool.dll
C:\Users\Jodles\AppData\Local\Temp\BQJd1Sh58p.exe
C:\Users\Jodles\AppData\Local\Temp\ICReinstall_CamStudio_2.7_r316_setup.exe
C:\Users\Jodles\AppData\Local\Temp\Iid1uWzvyi.exe
C:\Users\Jodles\AppData\Local\Temp\optprosetup.exe
C:\Users\Jodles\AppData\Local\Temp\ose00000.exe
C:\Users\Jodles\AppData\Local\Temp\QGdU2eehyc.exe
C:\Users\Jodles\AppData\Local\Temp\Quarantine.exe
C:\Users\Jodles\AppData\Local\Temp\Ru7VUkboaR.exe
C:\Users\Jodles\AppData\Local\Temp\sdf353D.exe
C:\Users\Jodles\AppData\Local\Temp\sdf724.exe
C:\Users\Jodles\AppData\Local\Temp\sdfBF90.exe
C:\Users\Jodles\AppData\Local\Temp\sdfF65B.exe
C:\Users\Jodles\AppData\Local\Temp\setup_644.exe
C:\Users\Jodles\AppData\Local\Temp\setup_648.exe
C:\Users\Jodles\AppData\Local\Temp\sqlite3.dll
C:\Users\Jodles\AppData\Local\Temp\TIQnVFQcAs.exe
C:\Users\Jodles\AppData\Local\Temp\UpIUPSjizA.exe
C:\Users\Jodles\AppData\Local\Temp\uS05wtKZ6B.exe
C:\Users\Jodles\AppData\Local\Temp\WinFixPro.exe
C:\Users\Jodles\AppData\Local\Temp\WinFixProPackage.exe
C:\Users\Jodles\AppData\Local\Temp\WinFixProTemp.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-06-03 12:49
 
==================== End of log ============================

  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
That's looking much better now :)

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
FF Plugin-x32: @tools.Popcornew.com/Popcornew Update;version=3 -> C:\Program Files (x86)\Popcornew\Update\1.3.25.0\npPopcornewUpdate3.dll No File
FF Plugin-x32: @tools.Popcornew.com/Popcornew Update;version=9 -> C:\Program Files (x86)\Popcornew\Update\1.3.25.0\npPopcornewUpdate3.dll No File
FF HKLM\...\Firefox\Extensions: [{21186475-d4df-43e2-9bba-0b52c00e0e27}] - C:\Program Files\shopperz\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{21186475-d4df-43e2-9bba-0b52c00e0e27}] - C:\Program Files\shopperz\Firefox
S2 mozolihu; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\nsa5B1F.tmp [X]
C:\Program Files\shopperz
C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download Malwarebytes Anti-Malware to your desktop
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Ensure that "Enable free trial of Malwarebytes Anti-Malware Premium" is unchecked
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
  • Reboot your computer if prompted.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

To access logs from Malwarebytes Anti-Malware 2.0:

mbamlogs.JPG

1.Open Malwarebytes Anti-Malware 2.0
2.Click History > Application Logs
3.Double-click the log you would like to open

Scan Logs record detections from manual scans, including threats detected and the actions taken against them

To save a Scan Log:

1.Open the log file you would like to save
2.Click Export
3.Choose to export to a .txt
4.Choose a folder to save the log file in, then click Save
5.Post that log here
  • 0

#10
MissJodles

MissJodles

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Fix result of Farbar Recovery Scan Tool (x64) Version: 29-05-2015
Ran by Jodles at 2015-06-03 22:00:23 Run:4
Running from C:\Users\Jodles\Desktop
Loaded Profiles: Jodles (Available Profiles: Jodles)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
FF Plugin-x32: @tools.Popcornew.com/Popcornew Update;version=3 -> C:\Program Files (x86)\Popcornew\Update\1.3.25.0\npPopcornewUpdate3.dll No File
FF Plugin-x32: @tools.Popcornew.com/Popcornew Update;version=9 -> C:\Program Files (x86)\Popcornew\Update\1.3.25.0\npPopcornewUpdate3.dll No File
FF HKLM\...\Firefox\Extensions: [{21186475-d4df-43e2-9bba-0b52c00e0e27}] - C:\Program Files\shopperz\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{21186475-d4df-43e2-9bba-0b52c00e0e27}] - C:\Program Files\shopperz\Firefox
S2 mozolihu; C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009\nsa5B1F.tmp [X]
C:\Program Files\shopperz
C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
*****************
 
Restore point was successfully created.
HKLM\Software\Wow6432Node\MozillaPlugins\@tools.Popcornew.com/Popcornew Update;version=3 => key not found. 
HKLM\Software\Wow6432Node\MozillaPlugins\@tools.Popcornew.com/Popcornew Update;version=9 => key not found. 
HKLM\Software\Mozilla\Firefox\Extensions\\{21186475-d4df-43e2-9bba-0b52c00e0e27} => value not found.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{21186475-d4df-43e2-9bba-0b52c00e0e27} => value not found.
mozolihu => Service not found.
"C:\Program Files\shopperz" => File/Folder not found.
"C:\Users\Jodles\AppData\Roaming\03000200-1433170656-0500-0006-000700080009" => File/Folder not found.
 
========= RemoveProxy: =========
 
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value Removed successfully
HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value Removed successfully
HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value Removed successfully
 
 
========= End of RemoveProxy: =========
 
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.7.9600 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
0 out of 0 jobs canceled.
 
========= End of CMD: =========
 
EmptyTemp: => Removed 18 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 22:00:28 ====

  • 0

Advertisements


#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
How is the computer behaving now ? The MBAM run may take up to 20 minutes, this is a final check that I have not missed anything
  • 0

#12
MissJodles

MissJodles

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 03/06/2015
Scan Time: 22:07:44
Logfile: scanlog.txt
Administrator: Yes
 
Version: 2.01.6.1022
Malware Database: v2015.03.09.05
Rootkit Database: v2015.06.02.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Jodles
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 344457
Time Elapsed: 3 min, 52 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 69
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\Popcornew.OneClickCtrl.9, Quarantined, [fc7d50f35c2e73c38ba231898083ec14], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\Popcornew.OneClickProcessLauncherMachine, Quarantined, [d3a6cb78424890a6012cad0db64d0ff1], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\Popcornew.OneClickProcessLauncherMachine.1.0, Quarantined, [a8d1c67dd7b30b2b1f0e2a906b98f30d], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\Popcornew.Update3WebControl.3, Quarantined, [86f3a69db8d274c23af3dcde3dc6f10f], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.CoCreateAsync, Quarantined, [3b3e350e7119a195d459d2e87f847888], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.CoCreateAsync.1.0, Quarantined, [93e6e3607119d3637bb268524db6f60a], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.CoreClass, Quarantined, [4435ef5499f18da97bb2c2f818ebbe42], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.CoreClass.1, Quarantined, [1762083b226875c1e54893270ef51ce4], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.CoreMachineClass, Quarantined, [7603a89b8406b87e71bc477354af60a0], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.CoreMachineClass.1, Quarantined, [fa7f321193f7a78f45e8caf006fd9070], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.CredentialDialogMachine, Quarantined, [07725fe46b1f1323c4694d6ddd26f40c], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.CredentialDialogMachine.1.0, Quarantined, [7bfe9ea54b3fe3531c116b4fad56758b], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.OnDemandCOMClassMachine, Quarantined, [f188261d64264aec1f0ea91131d2ee12], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [96e3420155353cfae24bdedc6c975fa1], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.OnDemandCOMClassMachineFallback, Quarantined, [4e2b2a193753d75f66c7dcde8b787789], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [bcbd87bce5a552e453dad6e4847f1de3], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.OnDemandCOMClassSvc, Quarantined, [8eeb94afa8e2c571af7e0eac9c6708f8], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [b9c0142f305a3ff7bd705c5e927117e9], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.ProcessLauncher, Quarantined, [ee8b30138208b0862b023b7f2bd832ce], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.ProcessLauncher.1.0, Quarantined, [760398ab03877db989a4299128db8977], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.Update3COMClassService, Quarantined, [c5b484bfc8c247ef5ad35a609172cb35], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.Update3COMClassService.1.0, Quarantined, [0673f54e602af442141958625ea5649c], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.Update3WebMachine, Quarantined, [8beeb192b2d8b086929b4e6c996aab55], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.Update3WebMachine.1.0, Quarantined, [c1b88fb4d9b1c86ee84584368f74de22], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.Update3WebMachineFallback, Quarantined, [afca66dd4446ba7c79b481392fd4f50b], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.Update3WebMachineFallback.1.0, Quarantined, [db9e2023bcce2c0a52db5a604ab909f7], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.Update3WebSvc, Quarantined, [abced96ab9d1231327065a6082818779], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\PopcornewUpdate.Update3WebSvc.1.0, Quarantined, [da9f6ad9d2b8b87e3fee912952b126da], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\MIME\DATABASE\CONTENT TYPE\application/x-vnd.Popcornew.oneclickctrl.9, Quarantined, [532650f399f196a073c12c8bc83b926e], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\MIME\DATABASE\CONTENT TYPE\application/x-vnd.Popcornew.update3webcontrol.3, Quarantined, [5722be85cbbf50e6c66e5c5b897acb35], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\MIME\DATABASE\CONTENT TYPE\application/x-vnd.Popcornew.oneclickctrl.9, Quarantined, [3c3dbe854545f93d4ce852653cc72bd5], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\MIME\DATABASE\CONTENT TYPE\application/x-vnd.Popcornew.update3webcontrol.3, Quarantined, [eb8e01429ded1521d262e5d24eb5fa06], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Popcornew.OneClickCtrl.9, Quarantined, [314887bce0aaa88ed15c506a5ca720e0], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Popcornew.OneClickProcessLauncherMachine, Quarantined, [3e3bb2916723d660bc71209a17ec44bc], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Popcornew.OneClickProcessLauncherMachine.1.0, Quarantined, [90e994af6f1b42f4ac81a2188a796d93], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Popcornew.Update3WebControl.3, Quarantined, [85f486bd6e1c42f4c9648a30b053f907], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.CoCreateAsync, Quarantined, [a1d8b19262281521ef3e0eac58ab6799], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.CoCreateAsync.1.0, Quarantined, [512857ec5b2f9e984fde4674768d29d7], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.CoreClass, Quarantined, [2a4f52f1cebc2a0c0e1f05b5ab58d32d], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.CoreClass.1, Quarantined, [82f7a3a042484cea2eff1d9d956ea55b], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.CoreMachineClass, Quarantined, [85f458eb19715adc42eb0eac91725ea2], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.CoreMachineClass.1, Quarantined, [c9b033101971e452ed4025958d76ad53], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.CredentialDialogMachine, Quarantined, [39401e253f4bc47214193f7b05fe639d], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.CredentialDialogMachine.1.0, Quarantined, [fd7c9ba8256586b0ea432f8b0ef5fb05], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.OnDemandCOMClassMachine, Quarantined, [0b6e62e197f3ce6840ed724845be57a9], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [abce8cb7751568ce77b6e5d547bc8e72], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.OnDemandCOMClassMachineFallback, Quarantined, [91e8f94a5a300f27bf6ecfebc142ba46], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [babfe1627b0fe74f6ebfdfdb8d76d42c], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.OnDemandCOMClassSvc, Quarantined, [f7827fc454364cea30fdf1c953b0ba46], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [3f3a87bc068416203bf2318916ed24dc], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.ProcessLauncher, Quarantined, [1b5e2122abdf38fe5dd008b251b28878], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.ProcessLauncher.1.0, Quarantined, [8dec67dc236792a4b27b3d7dbb48926e], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.Update3COMClassService, Quarantined, [83f63b08eaa071c528059525f40fa858], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.Update3COMClassService.1.0, Quarantined, [e6939da613776dc9002d7d3d08fbae52], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.Update3WebMachine, Quarantined, [ea8ff2516525231336f78634f80b0cf4], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.Update3WebMachine.1.0, Quarantined, [85f42d16206ade5853daefcb986b649c], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.Update3WebMachineFallback, Quarantined, [0871c2817b0f63d3ca6306b417ec6e92], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.Update3WebMachineFallback.1.0, Quarantined, [5e1b66dd1d6d330362cbb30735ce01ff], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.Update3WebSvc, Quarantined, [babfd76cf79382b43cf1b9015ea54bb5], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PopcornewUpdate.Update3WebSvc.1.0, Quarantined, [1c5da49f2b5f3cfaad805367768db947], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\MIME\DATABASE\CONTENT TYPE\application/x-vnd.Popcornew.oneclickctrl.9, Quarantined, [cdac70d30684fd39d3611b9c4fb424dc], 
PUP.Optional.Popcornew.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\MIME\DATABASE\CONTENT TYPE\application/x-vnd.Popcornew.update3webcontrol.3, Quarantined, [ef8ad66d4941f145ff35ae09f40ff40c], 
PUP.Optional.Booster.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{caa89563}, Quarantined, [740551f24446fc3a0d79577a4cb752ae], 
PUP.Optional.CinemaPlus.A, HKU\S-1-5-18\SOFTWARE\CinemaPlus-3.2cV01.06-nv, Quarantined, [f881fb4817731125a52f9621e32025db], 
PUP.Optional.CinemaPlus.A, HKU\S-1-5-18\SOFTWARE\CinemaPlus-3.2cV01.06-nv-ie, Quarantined, [2e4b33103a501323d0048334d52efe02], 
PUP.Optional.CrossRider.A, HKU\S-1-5-18\SOFTWARE\Cinema_Plus-1.2V01.06-nv, Quarantined, [3544f3502f5b94a27183b00d6e95ca36], 
PUP.Optional.CrossRider.A, HKU\S-1-5-18\SOFTWARE\Cinema_Plus-1.2V01.06-nv-ie, Quarantined, [ef8a063dd9b1999d4ca8dae3cd36946c], 
PUP.Optional.CinemaPlus.A, HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\CinemaPlus-3.2cV01.06-nv-ie, Quarantined, [e79256edb4d62016f1e3a413788b0000], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-266208001-1606254893-869063284-1001\SOFTWARE\Cinema_Plus-1.2V01.06-nv-ie, Quarantined, [d4a5d66d5b2f0135ec0818a531d24eb2], 
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

  • 0

#13
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK are there any outstanding problems ?
  • 0

#14
MissJodles

MissJodles

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts

And I can assume that it's behaving well, so far no other malicious programs have installed themselves :)


  • 0

#15
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
I would consider replacing MS Security Essentials with a third party antivirus for better protection

Did you read about the possible problems with Hola ?

Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Remove tools

Download and run Delfix
Select the options as shown
delfix.JPG

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

CryptoPrevent.JPG

Malwarebytes.

Update and run weekly to keep your system clean

Unchecky

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder
Right click on the Unchecky_setup and choose to Run as Administrator
Once open click the Install button.
Then click on Finish
Unchecky is now installed and will help you keep unwanted check boxes unchecked, this is a fire and forget programme ;)

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe :wave:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP