I went to bed and when I got up it had finished. Here are the log files;
Fix result of Farbar Recovery Scan Tool (x64) Version:13-07-2015
Ran by Tiffany Barron at 2015-07-17 21:38:47 Run:1
Running from C:\Users\Tiffany Barron\Desktop
Loaded Profiles: Tiffany Barron (Available Profiles: Tiffany Barron)
Boot Mode: Normal
==============================================
fixlist content:
*****************
CreateRestorePoint:
HKU\S-1-5-21-174260949-2547485650-4126252976-1000\...\Run: [BluetoothManager] => rundll32.exe "%appdata%\Microsoft\bstack.dll",bs_init
HKU\S-1-5-21-174260949-2547485650-4126252976-1000\...A8F59079A8D5}\localserver32: <==== ATTENTION!
2015-03-30 00:11 - 2015-03-30 00:11 - 0008680 _____ () C:\Users\Tiffany Barron\AppData\Roaming\HELP_DECRYPT.HTML
2015-03-30 00:11 - 2015-03-30 00:11 - 0046087 _____ () C:\Users\Tiffany Barron\AppData\Roaming\HELP_DECRYPT.PNG
2015-03-30 00:09 - 2015-03-30 00:11 - 0001408 _____ () C:\Users\Tiffany Barron\AppData\Roaming\HELP_DECRYPT.TXT.irpqlyf
2015-03-30 00:11 - 2015-03-30 00:11 - 0000300 _____ () C:\Users\Tiffany Barron\AppData\Roaming\HELP_DECRYPT.URL
2015-06-03 20:47 - 2015-06-03 20:47 - 0001344 _____ () C:\Users\Tiffany Barron\AppData\Local\bq5uzce1f3.dll
2015-03-30 00:10 - 2015-03-30 00:10 - 0008680 _____ () C:\Users\Tiffany Barron\AppData\Local\HELP_DECRYPT.HTML
2015-03-30 00:10 - 2015-03-30 00:10 - 0046087 _____ () C:\Users\Tiffany Barron\AppData\Local\HELP_DECRYPT.PNG
2015-03-30 00:09 - 2015-03-30 00:10 - 0001408 _____ () C:\Users\Tiffany Barron\AppData\Local\HELP_DECRYPT.TXT.irpqlyf
2015-03-30 00:10 - 2015-03-30 00:10 - 0000300 _____ () C:\Users\Tiffany Barron\AppData\Local\HELP_DECRYPT.URL
2015-03-29 23:10 - 2015-03-31 15:34 - 0000600 ____H () C:\ProgramData\@system.temp
2015-03-29 23:10 - 2015-03-31 15:35 - 0000336 ____H () C:\ProgramData\@system3.att
2015-03-30 00:08 - 2015-03-30 00:08 - 0008680 _____ () C:\ProgramData\HELP_DECRYPT.HTML
2015-03-30 00:08 - 2015-03-0 00:08 - 0046087 _____ () C:\ProgramData\HELP_DECRYPT.PNG
2014-06-04 22:20 - 2015-03-30 00:08 - 0001408 _____ () C:\ProgramData\HELP_DECRYPT.TXT.irpqlyf
2015-03-30 00:08 - 2015-03-30 00:08 - 0000300 _____ () C:\ProgramData\HELP_DECRYPT.URL
2015-05-27 16:26 - 2015-05-27 16:42 - 0405009 _____ () C:\ProgramData\lgnhmzb.html
CMD: del /F /Q /S "C:\HELP_DECRYPT.HTML"
CMD: del /F /Q /S "C:\HELP_DECRYPT.PNG"
CMD: del /F /Q /S "C:\HELP_DECRYPT.URL"
CMD: del /F /Q /S "C:\HELP_DECRYPT.TXT"
CustomCLSID: HKU\S-1-5-21-174260949-2547485650-4126252976-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> No Filepath
Task: {199AE266-ED07-43F8-8E6C-605E5076D9C9} - System32\Tasks\tnsqyin => C:\Users\TIFFAN~1\AppData\Local\Temp\noiatnd.exe <==== ATTENTION
Task: {F404218C-783A-4BB0-BCC5-A3CDEE0DBDC5} - System32\Tasks\{4ED9D91D-6A8D-4BD6-906F-8FFFDA64F632} => pcalua.exe -a "C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D446X2UF\epson13319.exe" -d "C:\Users\Tiffany Barron\Desktop"
C:\Users\TIFFAN~1\AppData\Local\Temp\noiatnd.exe
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
*****************
Restore point was successfully created.
HKU\S-1-5-21-174260949-2547485650-4126252976-1000\Software\Microsoft\Windows\CurrentVersion\Run\\BluetoothManager => value removed successfully
"HKU\S-1-5-21-174260949-2547485650-4126252976-1000\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32" => key removed successfully
"HKU\S-1-5-21-174260949-2547485650-4126252976-1000\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => key removed successfully
C:\Users\Tiffany Barron\AppData\Roaming\HELP_DECRYPT.HTML => moved successfully.
C:\Users\Tiffany Barron\AppData\Roaming\HELP_DECRYPT.PNG => moved successfully.
C:\Users\Tiffany Barron\AppData\Roaming\HELP_DECRYPT.TXT.irpqlyf => moved successfully.
C:\Users\Tiffany Barron\AppData\Roaming\HELP_DECRYPT.URL => moved successfully.
C:\Users\Tiffany Barron\AppData\Local\bq5uzce1f3.dll => moved successfully.
C:\Users\Tiffany Barron\AppData\Local\HELP_DECRYPT.HTML => moved successfully.
C:\Users\Tiffany Barron\AppData\Local\HELP_DECRYPT.PNG => moved successfully.
C:\Users\Tiffany Barron\AppData\Local\HELP_DECRYPT.TXT.irpqlyf => moved successfully.
C:\Users\Tiffany Barron\AppData\Local\HELP_DECRYPT.URL => moved successfully.
C:\ProgramData\@system.temp => moved successfully.
C:\ProgramData\@system3.att => moved successfully.
C:\ProgramData\HELP_DECRYPT.HTML => moved successfully.
C:\ProgramData\HELP_DECRYPT.PNG => moved successfully.
C:\ProgramData\HELP_DECRYPT.TXT.irpqlyf => moved successfully.
C:\ProgramData\HELP_DECRYPT.URL => moved successfully.
C:\ProgramData\lgnhmzb.html => moved successfully.
========= del /F /Q /S "C:\HELP_DECRYPT.HTML" =========
Deleted file - C:\$Recycle.Bin\S-1-5-21-174260949-2547485650-4126252976-1000\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Battle.net\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Battle.net\Agent\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Battle.net\Client\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1974\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1974\Support\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1997\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1997\Support\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Garmin\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Garmin\Logs\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Garmin\Logs\ExpressClient\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Garmin\Logs\ExpressClient\Devices\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Garmin\Logs\ExpressTray\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Microsoft\RAC\PublishedData\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Spybot - Search & Destroy\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Logs\HELP_DECRYPT.HTML
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Recovery\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AIM\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\ChromelyAIMUSGM\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\ChromelyAIMUSGM\Win32\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\ChromelyAIMUSGM\Win32\1.2.1.6\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\Win32\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\Win32\1.1.0.4\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\Win32\1.2.0.2\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Audible\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\databases\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Extensions\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.com_0.indexeddb.leveldb\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\T4SHETKS\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\def\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\def\databases\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Sync Data Backup\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\ehome\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Internet Explorer\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Media Player\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Media Player\Art Cache\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\Backup\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\Backup\new\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\Stationery\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Media\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Media\12.0\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft Games\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft Games\Solitaire\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\SniperV2\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\SniperV2\PC_ProfileSaves\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Local\SniperV2\PC_ProfileSaves\76561193844319094\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\Google\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\Google\GoogleEarth\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\Google\GoogleEarth\unified_cache_leveldb_leveldb2\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\Flash Player\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\Flash Player\AssetCache\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\Flash Player\AssetCache\VGY72CQH\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Garmin\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Garmin\WebUpdate\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Document Building Blocks\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Document Building Blocks\1033\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\LiveContent\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\HELP_DECRYPT.HTML
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\HELP_DECRYPT.HTML
========= End of CMD: =========
========= del /F /Q /S "C:\HELP_DECRYPT.PNG" =========
Deleted file - C:\$Recycle.Bin\S-1-5-21-174260949-2547485650-4126252976-1000\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Battle.net\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Battle.net\Agent\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Battle.net\Client\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1974\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1974\Support\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1997\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1997\Support\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Garmin\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Garmin\Logs\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Garmin\Logs\ExpressClient\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Garmin\Logs\ExpressClient\Devices\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Garmin\Logs\ExpressTray\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Microsoft\RAC\PublishedData\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Spybot - Search & Destroy\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Logs\HELP_DECRYPT.PNG
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Recovery\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AIM\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\ChromelyAIMUSGM\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\ChromelyAIMUSGM\Win32\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\ChromelyAIMUSGM\Win32\1.2.1.6\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\Win32\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\Win32\1.1.0.4\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\Win32\1.2.0.2\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Audible\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\databases\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Extensions\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.com_0.indexeddb.leveldb\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\T4SHETKS\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\def\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\def\databases\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Sync Data Backup\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\ehome\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Internet Explorer\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Media Player\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Media Player\Art Cache\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\Backup\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\Backup\new\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\Stationery\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Media\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Media\12.0\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft Games\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft Games\Solitaire\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\SniperV2\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\SniperV2\PC_ProfileSaves\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Local\SniperV2\PC_ProfileSaves\76561193844319094\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\Google\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\Google\GoogleEarth\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\Google\GoogleEarth\unified_cache_leveldb_leveldb2\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\Flash Player\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\Flash Player\AssetCache\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\Flash Player\AssetCache\VGY72CQH\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Garmin\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Garmin\WebUpdate\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Document Building Blocks\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Document Building Blocks\1033\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\LiveContent\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\HELP_DECRYPT.PNG
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\HELP_DECRYPT.PNG
========= End of CMD: =========
========= del /F /Q /S "C:\HELP_DECRYPT.URL" =========
Deleted file - C:\$Recycle.Bin\S-1-5-21-174260949-2547485650-4126252976-1000\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Battle.net\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Battle.net\Agent\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Battle.net\Client\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1974\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1974\Support\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1997\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Battle.net\Client\Blizzard Launcher.1997\Support\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Garmin\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Garmin\Logs\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Garmin\Logs\ExpressClient\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Garmin\Logs\ExpressClient\Devices\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Garmin\Logs\ExpressTray\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Microsoft\RAC\PublishedData\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Spybot - Search & Destroy\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Logs\HELP_DECRYPT.URL
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Recovery\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AIM\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\ChromelyAIMUSGM\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\ChromelyAIMUSGM\Win32\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\ChromelyAIMUSGM\Win32\1.2.1.6\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\Win32\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\Win32\1.1.0.4\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\AOL\AOLDiag\AOL\chromely_aim\Win32\1.2.0.2\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Audible\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\databases\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Extensions\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.com_0.indexeddb.leveldb\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\T4SHETKS\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\def\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\def\databases\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Sync Data Backup\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\ehome\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Internet Explorer\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Media Player\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Media Player\Art Cache\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\Backup\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\Backup\new\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Mail\Stationery\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Media\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft\Windows Media\12.0\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft Games\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\Microsoft Games\Solitaire\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\SniperV2\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\SniperV2\PC_ProfileSaves\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Local\SniperV2\PC_ProfileSaves\76561193844319094\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\Google\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\Google\GoogleEarth\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\LocalLow\Google\GoogleEarth\unified_cache_leveldb_leveldb2\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\Flash Player\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\Flash Player\AssetCache\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Adobe\Flash Player\AssetCache\VGY72CQH\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Garmin\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Garmin\WebUpdate\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Document Building Blocks\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Document Building Blocks\1033\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\LiveContent\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\HELP_DECRYPT.URL
Deleted file - C:\Users\Tiffany Barron\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\HELP_DECRYPT.URL
========= End of CMD: =========
========= del /F /Q /S "C:\HELP_DECRYPT.TXT" =========
Deleted file - C:\$Recycle.Bin\S-1-5-21-174260949-2547485650-4126252976-1000\HELP_DECRYPT.TXT
========= End of CMD: =========
HKU\S-1-5-21-174260949-2547485650-4126252976-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5} => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{199AE266-ED07-43F8-8E6C-605E5076D9C9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{199AE266-ED07-43F8-8E6C-605E5076D9C9}" => key removed successfully
C:\Windows\System32\Tasks\tnsqyin => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\tnsqyin" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F404218C-783A-4BB0-BCC5-A3CDEE0DBDC5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F404218C-783A-4BB0-BCC5-A3CDEE0DBDC5}" => key removed successfully
C:\Windows\System32\Tasks\{4ED9D91D-6A8D-4BD6-906F-8FFFDA64F632} => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4ED9D91D-6A8D-4BD6-906F-8FFFDA64F632}" => key removed successfully
"C:\Users\TIFFAN~1\AppData\Local\Temp\noiatnd.exe" => File/Folder not found.
========= netsh advfirewall reset =========
Ok.
========= End of CMD: =========
========= netsh advfirewall set allprofiles state ON =========
Ok.
========= End of CMD: =========
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
========= netsh winsock reset catalog =========
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
========= End of CMD: =========
========= netsh int ip reset c:\resetlog.txt =========
Reseting Global, OK!
Reseting Interface, OK!
Reseting Unicast Address, OK!
Restart the computer to complete this action.
========= End of CMD: =========
========= ipconfig /release =========
Windows IP Configuration
No operation can be performed on Local Area Connection 2 while it has its media disconnected.
No operation can be performed on Local Area Connection while it has its media disconnected.
No operation can be performed on Wireless Network Connection 3 while it has its media disconnected.
No operation can be performed on Bluetooth Network Connection while it has its media disconnected.
Ethernet adapter Local Area Connection 2:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Wireless LAN adapter Wireless Network Connection 3:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Wireless LAN adapter Wireless Network Connection:
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::15f1:1a9:16a5:adf1%13
Default Gateway . . . . . . . . . :
Ethernet adapter Bluetooth Network Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{06B07B14-871D-4CE6-94AB-93BF94EE6897}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{DBC37BC0-F7B0-4F82-8891-C09208C19F81}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{5E6703C2-446C-4268-A2B8-C53CF549AD9B}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{17DC85A1-F065-45D8-A9C1-D73BFDBDAF15}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{45961C95-61D5-415A-97BD-BCCAB1EC88E9}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
========= End of CMD: =========
========= ipconfig /renew =========
Windows IP Configuration
No operation can be performed on Local Area Connection 2 while it has its media disconnected.
No operation can be performed on Local Area Connection while it has its media disconnected.
No operation can be performed on Wireless Network Connection 3 while it has its media disconnected.
No operation can be performed on Bluetooth Network Connection while it has its media disconnected.
Ethernet adapter Local Area Connection 2:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Wireless LAN adapter Wireless Network Connection 3:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Wireless LAN adapter Wireless Network Connection:
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::15f1:1a9:16a5:adf1%13
IPv4 Address. . . . . . . . . . . : 192.168.1.6
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
Ethernet adapter Bluetooth Network Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{06B07B14-871D-4CE6-94AB-93BF94EE6897}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{DBC37BC0-F7B0-4F82-8891-C09208C19F81}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{5E6703C2-446C-4268-A2B8-C53CF549AD9B}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{17DC85A1-F065-45D8-A9C1-D73BFDBDAF15}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{45961C95-61D5-415A-97BD-BCCAB1EC88E9}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
========= End of CMD: =========
========= netsh int ipv4 reset =========
Reseting Interface, OK!
Restart the computer to complete this action.
========= End of CMD: =========
========= netsh int ipv6 reset =========
Reseting Interface, OK!
Restart the computer to complete this action.
========= End of CMD: =========
========= RemoveProxy: =========
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-174260949-2547485650-4126252976-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-174260949-2547485650-4126252976-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
========= End of RemoveProxy: =========
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
0 out of 0 jobs canceled.
========= End of CMD: =========
# AdwCleaner v4.208 - Logfile created 18/07/2015 at 09:29:45
# Updated 09/07/2015 by Xplode
# Database : 2015-07-15.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Tiffany Barron - TIFFANYBARRON
# Running from : C:\Users\Tiffany Barron\Desktop\AdwCleaner.exe
# Option : Cleaning
***** [ Services ] *****
[#] Service Deleted : vToolbarUpdater18.7.0
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\Program Files (x86)\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility
Folder Deleted : C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn
File Deleted : C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage
File Deleted : C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage-journal
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKCU\Software\Avg Secure Update
Key Deleted : HKLM\SOFTWARE\Avg Secure Update
Key Deleted : HKU\.DEFAULT\Software\Avg Secure Update
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
***** [ Web browsers ] *****
-\\ Internet Explorer v0.0.0.0
-\\ Google Chrome v43.0.2357.134
[C:\Users\Tiffany Barron\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] : management","nativeMessaging","searchProvider","startupPages","storage","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"commands":{"_execute_page_action":{"suggested_key":"Alt+Shift+P","was_assigned":true}},"content_settings":[],"creation_flags":9,"disable_reasons":33,"events":[],"extension_can_script_all_urls":true,"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["browsingData","cookies","downloads","downloadsInternal","history","homepage","management","nativeMessaging","searchProvider","startupPages","storage","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13080698975469215","lastpingday":"13081589979604230","location":1,"manifest":{"background":{"page":"background.html","persistent":true},"chrome_settings_overrides":{"homepage":"hxxps://mysearch.avg.com/?rvt=1","search_provider":{"encoding":"UTF-8","favicon_url":"hxxps://mysearch.avg.com/favicon.ico","is_default":true,"keyword":"hxxps://mysearch.avg.com","name":"AVG Secure Search
*************************
AdwCleaner[R0].txt - [5914 bytes] - [18/07/2015 09:11:47]
AdwCleaner[S0].txt - [5609 bytes] - [18/07/2015 09:29:45]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5668 bytes] ##########