Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Bad Image Popup [Solved]

bad image malaware windows xp

  • This topic is locked This topic is locked

#1
kat3lr

kat3lr

    New Member

  • Member
  • Pip
  • 5 posts

So my laptop started getting the bad image popups every time that I attempted to open any application, for quite a while now.

The application or DLL C:\\PROGRA~1\SearchProtect\bin\VC32Loader.dll is not a valid Windows image. Please check this against your installation diskette.

This wasn't a new laptop when I had gotten it either, it belonged to a friend who was just trying to get money by selling it. I did not relieve any disks, or anything that would come with the laptop when purchased as new. So, over time, when I took a trip to Florida and left my laptop at home, my younger sister was using it without my knowledge, and playing on gaming websites which caused problems. As of last night (8.24.15) I ran a Malawarebites Anti-Maliware scan, and it came up with +7,300 threats that were scanned and located in three hours, around 5,000 were quarantined before my laptop had shut down due to my sister pulling out the charger from my laptop (my battery doesn't hold a charge).

 

I ran the FRST scan, and here's the results it gave me:

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:24-08-2015
Ran by Administrator (administrator) on D620 (25-08-2015 12:00:35)
Running from C:\Documents and Settings\Writing\Desktop
Loaded Profiles: Writing & Administrator (Available Profiles: Katie & Kat3lr & sheofourtris & Writing & Trial & Administrator & Guest)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
(Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\PROGRA~1\YTDOWN~1\BROWSE~2.EXE
() C:\Program Files\Compliant Host Controller\comc.exe
(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(SigmaTel, Inc.) C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\hidfind.exe
() C:\Documents and Settings\Writing\Local Settings\Application Data\UpdaterSvcSmarterPower1024\updatersvcsmarterpower.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Copyright © Microsoft 2015) C:\Program Files\Microsoft.NET\v2.0.507279\msnetcore.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SigmaTel, Inc.) C:\WINDOWS\system32\stacsv.exe
(US Tech Support LLC) C:\Program Files\USTechSupport\SchedulerService\SchedulerService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Opera Software) C:\Program Files\Opera\31.0.1889.161\opera.exe
(Opera Software) C:\Program Files\Opera\31.0.1889.161\opera.exe
(Opera Software) C:\Program Files\Opera\31.0.1889.161\opera.exe
(Opera Software) C:\Program Files\Opera\31.0.1889.161\opera.exe
(Opera Software) C:\Program Files\Opera\31.0.1889.161\opera.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Opera Software) C:\Program Files\Opera\31.0.1889.161\opera.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Opera Software) C:\Program Files\Opera\31.0.1889.161\opera.exe
(Goobzo) C:\PROGRA~1\YTDOWN~1\BrowserHelper.exe
(Opera Software) C:\Program Files\Opera\31.0.1889.161\opera.exe
(Opera Software) C:\Program Files\Opera\31.0.1889.161\opera.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /installquiet
HKLM\...\Run: [NVHotkey] => rundll32.exe nvHotkey.dll,Start
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [176128 2005-10-07] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IntelZeroConfig] => C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe [1392640 2009-09-21] (Intel® Corporation)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1206544 2009-09-21] (Intel® Corporation)
HKLM\...\Run: [SigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2007-05-10] (SigmaTel, Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM\...\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1
HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1
HKU\S-1-5-21-854245398-616249376-1801674531-1023\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6453528 2015-07-17] (Piriform Ltd)
AppInit_DLLs: C:\PROGRA~1\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll [213776 2015-07-02] ()
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk [2013-07-20]
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Documents and Settings\Katie\Start Menu\Programs\Startup\BlitzMediaPlayer.lnk [2014-09-07]
ShortcutTarget: BlitzMediaPlayer.lnk -> C:\Program Files\BlitzMediaPlayer\BlitzMediaPlayerApp.exe (No File)
Startup: C:\Documents and Settings\sheofourtris\Start Menu\Programs\Startup\Download.lnk [2015-07-07]
ShortcutTarget: Download.lnk -> C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d}\Download.exe (No File)
Startup: C:\Documents and Settings\Writing\Start Menu\Programs\Startup\bm.lnk [2015-07-20]
ShortcutTarget: bm.lnk -> C:\Documents and Settings\Writing\Local Settings\Application Data\m1a0vtytzklhbmn\m3a0bzzwzl9hdwn.exe ()
Startup: C:\Documents and Settings\Writing\Start Menu\Programs\Startup\loons.lnk [2015-07-20]
ShortcutTarget: loons.lnk -> C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m\m0w0bzzvzm5hc2m.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-854245398-616249376-1801674531-1023\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:1051;https=127.0.0.1:1051;
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\S-1-5-21-854245398-616249376-1801674531-1023\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
URLSearchHook: [S-1-5-21-854245398-616249376-1801674531-1023] ATTENTION => Default URLSearchHook is missing
URLSearchHook: [S-1-5-21-854245398-616249376-1801674531-500] ATTENTION => Default URLSearchHook is missing
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "www.google.com" <======= ATTENTION
SearchScopes: HKLM -> URL hxxp://www-searching.com/search.aspx?site=shdefault&pid=s&shr=d&q={searchTerms}&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,
SearchScopes: HKU\.DEFAULT -> DefaultScope {4B5B4143-FBDA-4EDB-991B-F2814D7E432E} URL = hxxps://search.yahoo.com/yhs/search?hspart=tightrope&hsimp=yhs-tig1&type=11191_011915&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> {4B5B4143-FBDA-4EDB-991B-F2814D7E432E} URL = hxxps://search.yahoo.com/yhs/search?hspart=tightrope&hsimp=yhs-tig1&type=11191_011915&p={searchTerms}
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-854245398-616249376-1801674531-1023 -> URL hxxp://www-searching.com/search.aspx?site=shdefault&pid=s&shr=d&q={searchTerms}&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,
SearchScopes: HKU\S-1-5-21-854245398-616249376-1801674531-1023 -> {A755D706-0B3C-481D-9896-DBD699A7CA74} URL = 
Toolbar: HKLM - No Name - {96B06AFC-37EC-47DA-88EC-E74D6CE4CBC4} -  No File
Toolbar: HKLM - No Name - {0AC73CDE-9CB4-473A-8196-BF21CA2EF48B} -  No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1297435219125
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{1846F656-928A-4D9A-A6F0-63675E8E1C68}: [NameServer] 208.67.222.222
Tcpip\..\Interfaces\{1846F656-928A-4D9A-A6F0-63675E8E1C68}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{900BA0E0-8D74-4418-AFDC-CC2C11907923}: [DhcpNameServer] 10.1.7.10 10.32.1.11 10.40.4.10
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_257.dll [2015-01-18] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-10-29] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-10-29] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-08-25]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\prefs.js [2015-07-11]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 BrsHelper; C:\Program Files\YTDownloader\BrowserHelperSrv.exe [112560 2015-07-06] ()
R2 chost1394; C:\Program Files\Compliant Host Controller\comc.exe [376832 2015-07-23] () [File not signed]
S2 f104e31c; c:\Program Files\BocaMonitor\BocaMonitor.dll [2725376 2015-08-09] () [File not signed]
R2 GIX38; C:\Documents and Settings\Writing\Local Settings\Application Data\UpdaterSvcSmarterPower1024\updatersvcsmarterpower.exe [33280 2015-07-24] () [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-09-04] (Oracle Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 msdotnetserv_v2050729; C:\Program Files\Microsoft.NET\v2.0.507279\msnetcore.exe [3003880 2015-07-05] (Copyright © Microsoft 2015)
R2 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [954368 2009-09-21] (Intel® Corporation) [File not signed]
R2 STacSV; C:\WINDOWS\system32\StacSV.exe [94208 2007-05-10] (SigmaTel, Inc.)
R2 USTSScheduler; C:\Program Files\USTechSupport\SchedulerService\SchedulerService.exe [737600 2013-01-17] (US Tech Support LLC)
R2 WLANKEEPER; C:\Program Files\Intel\WiFi\bin\WLKeeper.exe [364544 2009-09-21] (Intel® Corporation) [File not signed]
S2 d51c1198; "C:\WINDOWS\system32\rundll32.exe" "c:\Program Files\SoftwareForce\SoftwareForce.dll",serv
S2 ToolGet; C:\Documents and Settings\All Users\Application Data\ToolGet\ToolGet [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 guardian2; C:\WINDOWS\System32\Drivers\oz776.sys [68696 2007-12-23] (O2Micro)
S3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 irsir; C:\WINDOWS\System32\DRIVERS\irsir.sys [18688 2001-08-17] (Microsoft Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [98520 2015-08-24] (Malwarebytes Corporation)
R1 netfilter; C:\WINDOWS\System32\drivers\netfilter.sys [47488 2015-04-02] (NetFilterSDK.com) [File not signed]
R3 NETw5x32; C:\WINDOWS\System32\DRIVERS\NETw5x32.sys [5977216 2009-09-15] (Intel Corporation)
R2 npf; C:\WINDOWS\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [13952 2009-08-10] (Intel Corporation)
R1 sbmntr; C:\Program Files\YTDownloader\sbmntr.sys [28960 2015-07-06] (YTDownloader)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1222840 2007-05-10] (SigmaTel, Inc.)
S3 TIEHDUSB; C:\WINDOWS\System32\drivers\tiehdusb.sys [49536 2004-02-04] (Texas Instruments Incorporated) [File not signed]
S0 cerc6; no ImagePath
S3 cpuz136; \??\C:\DOCUME~1\Katie\LOCALS~1\Temp\cpuz136\cpuz136_x32.sys [X]
S3 HSFHWAZL; system32\DRIVERS\HSFHWAZL.sys [X]
S3 HSF_DPV; system32\DRIVERS\HSF_DPV.sys [X]
S4 IntelIde; no ImagePath
S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X]
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [X]
S3 usbbus; system32\DRIVERS\lgusbbus.sys [X]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X]
S3 winachsf; system32\DRIVERS\HSF_CNXT.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-25 12:00 - 2015-08-25 12:00 - 00000000 ____D C:\FRST
2015-08-25 11:53 - 2015-08-25 11:53 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Spacejock Software
2015-08-25 11:34 - 2015-08-25 11:34 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
2015-08-25 11:29 - 2015-08-25 11:44 - 00000884 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-25 11:29 - 2015-08-25 11:34 - 00000888 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-24 19:05 - 2015-08-24 19:05 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Windows Search
2015-08-24 19:03 - 2015-08-24 20:30 - 00003136 _____ C:\WINDOWS\setupapi.log
2015-08-24 17:39 - 2015-08-24 17:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-08-24 16:45 - 2015-08-24 16:45 - 00000000 ____D C:\Program Files\CCleaner
2015-08-24 16:45 - 2015-08-24 16:45 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2015-08-24 16:37 - 2015-08-24 16:39 - 00098520 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-08-24 16:37 - 2015-08-24 16:37 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-08-24 16:37 - 2015-08-24 16:37 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-24 16:37 - 2015-06-18 08:41 - 00121560 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-08-24 16:37 - 2015-06-18 08:41 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-08-23 22:19 - 2015-08-23 22:19 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\WinRAR
2015-08-23 22:15 - 2012-02-17 14:01 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFC71.dll
2015-08-23 22:15 - 2012-02-17 14:01 - 01047552 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFC71u.dll
2015-08-23 22:14 - 2015-08-23 22:14 - 00000000 ____D C:\Program Files\TI Education
2015-08-23 22:14 - 2015-08-23 22:14 - 00000000 ____D C:\Program Files\Common Files\TI Shared
2015-08-23 22:14 - 2015-08-23 22:14 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\TI Tools
2015-08-23 22:14 - 2004-02-04 10:27 - 00049536 _____ (Texas Instruments Incorporated) C:\WINDOWS\system32\Drivers\tiehdusb.sys
2015-08-23 22:14 - 2004-01-28 15:03 - 00021456 _____ (Texas Instruments Incorporated) C:\WINDOWS\system32\Drivers\SilvrLnk.sys
2015-08-23 22:02 - 2015-08-23 22:15 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2015-08-23 22:02 - 2015-08-23 22:15 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2015-08-23 22:02 - 2015-08-23 22:15 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2015-08-23 22:02 - 2015-08-23 22:15 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2015-08-23 22:02 - 2015-08-23 22:15 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2015-08-23 21:35 - 2015-08-23 21:35 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard
2015-08-23 21:14 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\DailyPcClean Support
2015-08-23 19:30 - 2015-08-23 19:30 - 00000000 ____D C:\Program Files\DNS Unlocker
2015-08-23 15:24 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\Cinema PlusV23.08
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\DailyPcClean Support
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\DailyPCClean
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\DailyPcClean Support
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\DailyPCClean
2015-08-23 15:05 - 2015-08-23 15:05 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\DailyPCClean
2015-08-23 14:41 - 2015-08-23 15:11 - 00000178 ___SH C:\Documents and Settings\Trial\ntuser.ini
2015-08-23 14:41 - 2015-08-23 15:11 - 00000178 ___SH C:\Documents and Settings\Trial\ntuser.ini
2015-08-23 14:41 - 2015-08-23 15:11 - 00000178 ___SH C:\Documents and Settings\Trial\ntuser.ini
2015-08-23 14:41 - 2015-08-23 15:11 - 00000178 ___SH C:\Documents and Settings\Trial\ntuser.ini
2015-08-23 14:41 - 2015-08-23 15:11 - 00000178 ___SH C:\Documents and Settings\Trial\ntuser.ini
2015-08-23 14:41 - 2015-08-23 14:41 - 00045776 _____ C:\Documents and Settings\Trial\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2015-08-23 14:41 - 2015-08-23 14:41 - 00000000 ____D C:\Documents and Settings\Trial\Local Settings\Application Data\gmsd_us_005010047
2015-08-23 14:41 - 2015-08-23 14:41 - 00000000 ____D C:\Documents and Settings\Trial\Local Settings\Application Data\gmsd_us_005010044
2015-08-23 14:41 - 2015-08-23 14:41 - 00000000 ____D C:\Documents and Settings\Trial\Local Settings\Application Data\gmsd_us_005010040
2015-08-23 14:41 - 2015-08-23 14:41 - 00000000 ____D C:\Documents and Settings\Trial\Application Data\SmartWeb
2015-08-23 14:41 - 2015-08-23 14:41 - 00000000 ____D C:\Documents and Settings\Trial\Application Data\Apple Computer
2015-08-23 14:40 - 2015-08-23 14:41 - 00000000 ____D C:\Documents and Settings\Trial\Local Settings\Temp
2015-08-23 14:40 - 2015-08-23 14:41 - 00000000 ____D C:\Documents and Settings\Trial\Local Settings\Application Data\SearchProtect
2015-08-23 14:40 - 2015-08-23 14:41 - 00000000 ____D C:\Documents and Settings\Trial
2015-08-23 14:40 - 2015-06-20 22:00 - 00000000 ____D C:\Documents and Settings\Trial\Application Data\Windows Desktop Search
2015-08-23 14:40 - 2014-09-21 11:13 - 00000000 ____D C:\Documents and Settings\Trial\Application Data\Macromedia
2015-08-23 14:40 - 2013-05-21 22:54 - 00000000 ____D C:\Documents and Settings\Trial\Application Data\Intel
2015-08-23 14:40 - 2012-09-19 20:15 - 00000000 ____D C:\Documents and Settings\Trial\Local Settings\Application Data\Microsoft Help
2015-08-23 14:40 - 2012-03-21 12:44 - 00000000 __SHD C:\Documents and Settings\Trial\IETldCache
2015-08-23 14:40 - 2012-03-21 12:44 - 00000000 __SHD C:\Documents and Settings\Trial\IETldCache
2015-08-23 14:40 - 2012-03-21 12:44 - 00000000 __SHD C:\Documents and Settings\Trial\IETldCache
2015-08-23 14:40 - 2012-03-21 12:44 - 00000000 __SHD C:\Documents and Settings\Trial\IETldCache
2015-08-23 14:40 - 2012-03-21 12:44 - 00000000 __SHD C:\Documents and Settings\Trial\IETldCache
2015-08-20 22:02 - 2015-08-20 22:02 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010047
2015-08-20 22:02 - 2015-08-20 22:02 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010044
2015-08-17 10:10 - 2015-08-17 10:10 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\Opera Software
2015-08-17 10:10 - 2015-08-17 10:10 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Opera Software
2015-08-17 10:09 - 2015-08-25 11:24 - 00000380 _____ C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1439820538.job
2015-08-17 10:09 - 2015-08-17 10:09 - 00000675 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk
2015-08-16 17:46 - 2015-08-16 17:46 - 00000000 ____D C:\Program Files\Sm2y0nty1zjjhzgn
2015-08-16 15:17 - 2015-08-16 15:17 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Super Optimizer
2015-08-16 15:11 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\Super Optimizer
2015-08-16 15:11 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Super Optimizer
2015-08-16 15:11 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{d8d4fe72-4b13-8f6d-d8d4-4fe724b1f9c9}
2015-08-13 19:49 - 2015-08-13 19:49 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\Sun
2015-08-09 11:46 - 2015-08-09 11:47 - 00000000 ____D C:\Program Files\System Cleaner Pro
2015-08-09 11:46 - 2015-08-09 11:46 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\JV Update
2015-08-09 11:26 - 2015-08-09 11:26 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Itibiti
2015-08-09 11:25 - 2015-08-09 11:25 - 00000000 ____D C:\Program Files\Itibiti Soft Phone
2015-08-09 11:25 - 2015-08-09 11:25 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\KNCTR
2015-08-09 11:22 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV09.08
2015-08-09 11:15 - 2015-08-09 11:15 - 00000000 ____D C:\Program Files\BocaMonitor
2015-08-01 22:00 - 2015-08-01 22:09 - 00153747 _____ C:\Documents and Settings\All Users\Application Data\8AN2gJxF.dat
2015-07-31 20:53 - 2015-08-24 20:41 - 00000000 ____D C:\Program Files\gmsd_us_005010047
2015-07-31 20:53 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\gmsd_us_005010047
2015-07-31 20:49 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\6FD6BF4E-8A83-49A0-AB7-1DBB4B3A410
2015-07-30 14:59 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV30.07
2015-07-29 16:26 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\33DA8500-CC25-48E1-8D27-B1A1377D9DAE
2015-07-28 23:02 - 2015-07-28 23:02 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\m0q0tzztzkjhlwn
2015-07-28 21:04 - 2015-07-28 21:04 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{60e253a7-2f92-bf74-60e2-253a72f94e9c}
2015-07-28 21:00 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Desktop Search
2015-07-28 21:00 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\DesktopSearch
2015-07-28 20:44 - 2015-08-24 20:41 - 00000000 ____D C:\Program Files\gmsd_us_005010044
2015-07-28 20:44 - 2015-08-24 20:41 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\gmsd_us_005010044
2015-07-28 20:41 - 2015-07-28 20:41 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\iStreamlite
2015-07-28 20:41 - 2015-07-28 20:41 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\iStreamLite
2015-07-28 20:24 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV28.07
2015-07-27 15:09 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV27.07
2015-07-27 11:00 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\A2B67FD3-FE0A-48AA-8744-C7178357EA0
2015-07-26 22:30 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\2CEEE2A8-EB6C-46C4-B963-4272DBFD7BFF
2015-07-26 22:00 - 2015-07-26 22:00 - 00000000 _____ C:\Documents and Settings\Writing\Number of results
2015-07-26 22:00 - 2015-07-26 22:00 - 00000000 _____ C:\Documents and Settings\Writing\Number of results
2015-07-26 22:00 - 2015-07-26 22:00 - 00000000 _____ C:\Documents and Settings\Writing\Number of results
2015-07-26 22:00 - 2015-07-26 22:00 - 00000000 _____ C:\Documents and Settings\Writing\Number of results
2015-07-26 22:00 - 2015-07-26 22:00 - 00000000 _____ C:\Documents and Settings\Writing\Number of results
2015-07-26 17:54 - 2015-07-26 17:54 - 00000000 _____ C:\Documents and Settings\Writing\Local Settings\Application Data\{28AC3160-E789-44E2-B6C7-A7E9A8FF83B7}
2015-07-26 16:50 - 2015-07-26 16:50 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\Adobe
2015-07-26 16:00 - 2015-07-26 16:00 - 00000930 _____ C:\Documents and Settings\Writing\${LOGFILE}
2015-07-26 16:00 - 2015-07-26 16:00 - 00000930 _____ C:\Documents and Settings\Writing\${LOGFILE}
2015-07-26 16:00 - 2015-07-26 16:00 - 00000930 _____ C:\Documents and Settings\Writing\${LOGFILE}
2015-07-26 16:00 - 2015-07-26 16:00 - 00000930 _____ C:\Documents and Settings\Writing\${LOGFILE}
2015-07-26 16:00 - 2015-07-26 16:00 - 00000930 _____ C:\Documents and Settings\Writing\${LOGFILE}
2015-07-26 15:31 - 2015-07-26 15:31 - 00000000 _____ C:\355.tmp
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-25 12:01 - 2015-07-12 17:06 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Temp
2015-08-25 12:01 - 2015-01-19 19:11 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Temp
2015-08-25 11:57 - 2014-09-08 17:57 - 00000480 _____ C:\WINDOWS\Tasks\PETN Update.job
2015-08-25 11:36 - 2014-09-07 15:36 - 00000414 _____ C:\WINDOWS\Tasks\At1.job
2015-08-25 11:35 - 2015-07-07 12:47 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\BrowserHelper
2015-08-25 11:33 - 2014-09-06 01:10 - 00000000 ____D C:\Program Files\Google
2015-08-25 11:29 - 2011-02-11 08:33 - 01272704 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-25 11:27 - 2008-04-14 03:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-08-25 11:25 - 2011-02-11 10:19 - 00153495 _____ C:\WINDOWS\system32\nvModes.001
2015-08-25 11:25 - 2011-02-11 10:18 - 00184314 _____ C:\WINDOWS\system32\nvapps.xml
2015-08-25 11:25 - 2011-02-11 03:28 - 00000157 _____ C:\WINDOWS\wiadebug.log
2015-08-25 11:25 - 2011-02-11 03:28 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-08-25 11:24 - 2015-07-24 15:51 - 00001076 _____ C:\WINDOWS\Tasks\CxhJ5rDXjW2LZlw88S0K.job
2015-08-25 11:24 - 2015-07-12 15:51 - 00001082 _____ C:\WINDOWS\Tasks\liyfRBnpd3oV16DBx2Xb07O.job
2015-08-25 11:24 - 2015-07-12 15:51 - 00001062 _____ C:\WINDOWS\Tasks\r9OrLWuQuGNQs.job
2015-08-25 11:24 - 2015-07-11 12:59 - 00001054 _____ C:\WINDOWS\Tasks\S8v28p5NITjC1ZgbysVFsUo.job
2015-08-25 11:24 - 2015-07-10 22:36 - 00001054 _____ C:\WINDOWS\Tasks\Uandd9YYBmihfvXNPCbNbYh.job
2015-08-25 11:24 - 2015-07-07 12:47 - 00000372 _____ C:\WINDOWS\Tasks\YTDownloader.job
2015-08-25 11:24 - 2015-07-07 12:47 - 00000362 _____ C:\WINDOWS\Tasks\YTDownloaderUpd.job
2015-08-25 11:24 - 2015-07-06 12:59 - 00000508 ____H C:\WINDOWS\Tasks\BDLYHBMDHLAGVOIA.job
2015-08-25 11:24 - 2015-07-06 12:53 - 00000496 _____ C:\WINDOWS\Tasks\GlobalUpdate-m2y0yzzxzmthbwn.job
2015-08-25 11:24 - 2015-05-28 21:47 - 00000580 _____ C:\WINDOWS\Tasks\companion_for_gamers_helper_service.job
2015-08-25 11:24 - 2015-01-19 18:43 - 00000634 _____ C:\WINDOWS\Tasks\Client.job
2015-08-25 11:24 - 2015-01-19 18:43 - 00000578 _____ C:\WINDOWS\Tasks\Check Updates.job
2015-08-25 11:24 - 2015-01-19 18:43 - 00000574 _____ C:\WINDOWS\Tasks\Run Tasks.job
2015-08-25 11:24 - 2014-12-12 16:48 - 00000000 ____D C:\Program Files\Opera
2015-08-25 11:24 - 2014-09-04 21:33 - 00000222 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-08-25 11:24 - 2011-02-11 08:39 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-24 21:10 - 2014-10-23 15:35 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-08-24 20:43 - 2011-02-11 08:39 - 00031966 _____ C:\WINDOWS\SchedLgU.Txt
2015-08-24 20:42 - 2015-07-12 17:06 - 00000178 ___SH C:\Documents and Settings\Writing\ntuser.ini
2015-08-24 20:42 - 2015-07-12 17:06 - 00000178 ___SH C:\Documents and Settings\Writing\ntuser.ini
2015-08-24 20:42 - 2015-07-12 17:06 - 00000178 ___SH C:\Documents and Settings\Writing\ntuser.ini
2015-08-24 20:42 - 2015-07-12 17:06 - 00000178 ___SH C:\Documents and Settings\Writing\ntuser.ini
2015-08-24 20:42 - 2015-07-12 17:06 - 00000178 ___SH C:\Documents and Settings\Writing\ntuser.ini
2015-08-24 20:42 - 2015-07-06 12:32 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\abc
2015-08-24 20:41 - 2015-07-24 15:40 - 00000000 ____D C:\Program Files\gmsd_us_005010040
2015-08-24 20:41 - 2015-07-12 16:22 - 00000000 ____D C:\Documents and Settings\Katie\Local Settings\Application Data\gmsd_us_005010029
2015-08-24 20:41 - 2015-07-12 15:45 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010029
2015-08-24 20:41 - 2015-07-07 13:30 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvexvac
2015-08-24 20:41 - 2015-07-07 12:50 - 00000000 ____D C:\Program Files\Common Files\ShopperPro
2015-08-24 20:41 - 2015-07-07 12:50 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ShopperPro
2015-08-24 20:41 - 2015-07-06 12:43 - 00000000 ____D C:\Program Files\shopperz
2015-08-24 20:41 - 2015-06-24 19:33 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvdxvy
2015-08-24 20:41 - 2015-06-09 10:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbavad
2015-08-24 20:41 - 2015-06-04 15:43 - 00000000 ____D C:\Documents and Settings\Guest\Local Settings\Application Data\avabvbyvyc
2015-08-24 20:41 - 2015-06-04 10:02 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbyvyc
2015-08-24 20:41 - 2015-05-27 18:07 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbxvh
2015-08-24 20:41 - 2015-02-01 22:33 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602
2015-08-24 20:41 - 2015-01-10 14:57 - 00000000 ____D C:\Program Files\TNT2
2015-08-24 20:41 - 2015-01-02 17:12 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TakeTHECoupOn
2015-08-24 20:41 - 2014-09-08 19:36 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\Astromenda
2015-08-24 20:41 - 2014-09-07 15:29 - 00000000 ____D C:\Documents and Settings\Katie\Application Data\VOPackage
2015-08-24 20:41 - 2014-09-07 15:25 - 00000000 ____D C:\Documents and Settings\Katie\Local Settings\Application Data\Genesis_09071925
2015-08-24 20:40 - 2015-07-25 16:45 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\F05F5344-ADA3-48F4-9628-C3F74B3D3D3
2015-08-24 20:40 - 2015-07-24 15:40 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010040
2015-08-24 20:40 - 2015-07-24 15:40 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\StormWarnings
2015-08-24 20:40 - 2015-07-24 15:38 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\StormWarnings
2015-08-24 20:40 - 2015-07-24 15:37 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\StormWarnings
2015-08-24 20:40 - 2015-07-24 15:34 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\6CBF5050-5AD4-4D5A-816-4F547B2D15BC
2015-08-24 20:40 - 2015-07-24 13:59 - 00000000 ____D C:\Program Files\Common Files\hdquhtjl.th1
2015-08-24 20:40 - 2015-07-20 20:35 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m
2015-08-24 20:40 - 2015-07-20 19:36 - 00000000 ____D C:\Program Files\4C4C4544-1436755823-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-20 19:36 - 00000000 ____D C:\Program Files\4C4C4544-1436199977-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:54 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741657-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:54 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741641-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:52 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{7ac4b295-06f9-c702-7ac4-4b29506fca54}
2015-08-24 20:40 - 2015-07-12 22:51 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741496-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:50 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\4C4C4544-1436755823-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 18:26 - 00000000 ____D C:\Program Files\Consumer Input
2015-08-24 20:40 - 2015-07-12 18:23 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\BF476A5D-4D14-4415-A54A-14E2A8B4D66C
2015-08-24 20:40 - 2015-07-12 17:38 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\BrowserHelper
2015-08-24 20:40 - 2015-07-08 14:49 - 00000000 ____D C:\Program Files\FriendlyError
2015-08-24 20:40 - 2015-07-07 13:31 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\4C4C4544-1436290292-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-07 13:30 - 00000000 ____D C:\Program Files\SearchProtect
2015-08-24 20:40 - 2015-07-07 12:51 - 00000000 ____D C:\Program Files\Ge-Force
2015-08-24 20:40 - 2015-07-07 12:50 - 00000000 ____D C:\Program Files\ShopperPro
2015-08-24 20:40 - 2015-07-07 12:46 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\DeskBar
2015-08-24 20:40 - 2015-07-07 12:45 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SearchModule
2015-08-24 20:40 - 2015-07-07 11:27 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d}
2015-08-24 20:40 - 2015-07-06 16:22 - 00000000 ____D C:\Documents and Settings\Katie\Local Settings\Application Data\StormWatch
2015-08-24 20:40 - 2015-07-06 12:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Service1291
2015-08-24 20:40 - 2015-07-06 12:39 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\SmartWeb
2015-08-24 20:40 - 2015-07-06 12:39 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\80F7805B-BCCD-42C6-B8D-47320B2EEAD
2015-08-24 20:40 - 2015-07-06 12:29 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\4C4C4544-1436185766-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-06 12:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\6635
2015-08-24 20:40 - 2015-07-06 12:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\4C4C4544-1436199977-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-06-04 15:42 - 00000000 ____D C:\Documents and Settings\Guest\Local Settings\Application Data\CrimeWatch
2015-08-24 20:40 - 2015-05-27 18:01 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Temp
2015-08-24 20:40 - 2015-05-06 19:13 - 00000000 ____D C:\Program Files\Games Bot
2015-08-24 20:40 - 2015-05-01 21:01 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{1158b7dd-d0b8-a80b-1158-8b7ddd0bdf77}
2015-08-24 20:40 - 2015-01-19 18:41 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\StormWatch
2015-08-24 20:40 - 2015-01-11 21:31 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Browser
2015-08-24 20:40 - 2015-01-10 14:56 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\UpdateAdmin
2015-08-24 20:40 - 2015-01-08 22:33 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\fopneeomcncoadkhijbapjiidaedkcfg
2015-08-24 20:40 - 2014-12-01 10:55 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\14e8c327e3c6ddb5
2015-08-24 20:40 - 2014-11-23 16:06 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\1506668651448032693
2015-08-24 20:40 - 2014-11-23 16:05 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\dnonpahagjngllclmkgiokobafojjpel
2015-08-24 20:40 - 2014-09-28 16:44 - 00000000 ____D C:\Documents and Settings\Katie\Application Data\7148
2015-08-24 20:40 - 2014-09-08 17:57 - 00000000 ____D C:\Program Files\PETN
2015-08-24 20:40 - 2014-09-07 15:28 - 00000000 ____D C:\Documents and Settings\Katie\Application Data\30865
2015-08-24 20:40 - 2014-09-03 06:26 - 00000000 ____D C:\Documents and Settings\Katie\Local Settings\Temp
2015-08-24 20:39 - 2015-07-24 13:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ToolGet
2015-08-24 20:39 - 2015-07-07 13:18 - 00000000 ____D C:\Program Files\WordShark_1.10.0.19
2015-08-24 20:39 - 2015-07-07 10:57 - 00000000 ____D C:\Program Files\GUPlayer
2015-08-24 20:39 - 2015-07-06 12:58 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\FlashBeat
2015-08-24 20:39 - 2015-05-29 17:32 - 00000000 ____D C:\Program Files\JavaScript Notepad
2015-08-24 20:39 - 2015-05-08 18:38 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SharkManCoupon
2015-08-24 20:39 - 2015-04-14 18:50 - 00000000 ____D C:\Program Files\Optimizer Pro 3.79
2015-08-24 20:39 - 2014-12-12 16:47 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\AdBlocker Manger
2015-08-24 20:39 - 2014-09-10 19:38 - 00000000 ____D C:\Program Files\SmarterPower
2015-08-24 19:19 - 2015-06-14 18:41 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-08-24 17:19 - 2013-10-19 15:04 - 00000000 ____D C:\WINDOWS\Minidump
2015-08-24 17:12 - 2015-07-12 17:06 - 00000000 ____D C:\Documents and Settings\Writing
2015-08-24 16:24 - 2015-07-12 17:06 - 00049712 _____ C:\Documents and Settings\Writing\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2015-08-24 16:24 - 2015-03-14 22:42 - 00000004 _____ C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7
2015-08-24 16:18 - 2011-02-11 03:24 - 00206512 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-23 23:00 - 2015-07-06 12:26 - 00000000 ____D C:\Program Files\Coupoon
2015-08-23 22:19 - 2011-02-11 03:25 - 00621830 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-23 22:14 - 2011-02-11 03:16 - 00000000 ____D C:\WINDOWS\twain_32
2015-08-23 22:14 - 2011-02-11 03:16 - 00000000 ____D C:\WINDOWS\system
2015-08-23 22:02 - 2015-01-19 19:11 - 00000000 ___SD C:\Documents and Settings\Administrator
2015-08-23 21:59 - 2013-07-20 21:15 - 00000000 ____D C:\Program Files\Windows Media Connect 2
2015-08-23 21:15 - 2015-05-27 18:01 - 00000178 ___SH C:\Documents and Settings\sheofourtris\ntuser.ini
2015-08-23 21:15 - 2015-05-27 18:01 - 00000178 ___SH C:\Documents and Settings\sheofourtris\ntuser.ini
2015-08-23 21:15 - 2015-05-27 18:01 - 00000178 ___SH C:\Documents and Settings\sheofourtris\ntuser.ini
2015-08-23 21:15 - 2015-05-27 18:01 - 00000178 ___SH C:\Documents and Settings\sheofourtris\ntuser.ini
2015-08-23 21:15 - 2015-05-27 18:01 - 00000178 ___SH C:\Documents and Settings\sheofourtris\ntuser.ini
2015-08-23 21:15 - 2015-05-27 18:00 - 00000000 ____D C:\Documents and Settings\sheofourtris
2015-08-23 21:14 - 2015-07-07 11:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\SmartWeb
2015-08-23 14:44 - 2012-03-23 12:11 - 00000000 ____D C:\Temp
2015-08-23 14:41 - 2011-02-11 10:19 - 00153495 _____ C:\WINDOWS\system32\nvModes.dat
2015-08-23 14:23 - 2015-07-12 17:06 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\SmartWeb
2015-08-18 14:57 - 2008-04-14 03:00 - 00000657 _____ C:\WINDOWS\win.ini
2015-08-17 14:28 - 2015-07-20 20:35 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\m1a0vtytzklhbmn
2015-08-15 22:54 - 2014-12-14 19:29 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2015-08-15 21:02 - 2011-02-11 10:56 - 129304528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-13 19:52 - 2013-07-20 22:41 - 15728640 _____ C:\WINDOWS\system32\config\WindowsPowerShell.evt
2015-08-09 12:30 - 2013-07-17 09:30 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-09 11:15 - 2015-07-13 14:49 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\731d3bff00001862
2015-08-01 17:16 - 2015-06-14 16:39 - 00000000 ____D C:\Program Files\RoughDraft
2015-07-30 18:13 - 2014-12-25 10:05 - 00000020 ____H C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
2015-07-29 20:51 - 2014-09-10 19:39 - 00000480 _____ C:\WINDOWS\Tasks\Driver Support-RTMScan.job
2015-07-29 17:45 - 2014-12-25 10:05 - 00000020 ____H C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
2015-07-27 16:31 - 2015-07-21 22:16 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Nikon
2015-07-26 16:41 - 2015-07-15 12:38 - 00000000 ____D C:\Program Files\3b5f9141-4e41-45af-8a2d-b4e0390a2c25
2015-07-26 16:04 - 2015-07-06 12:26 - 00000000 ____D C:\Program Files\AnySend
2015-07-26 16:00 - 2015-07-12 22:49 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Nosibay
 
==================== Files in the root of some directories =======
 
2015-05-11 18:46 - 2015-05-26 15:50 - 0000079 _____ () C:\Program Files\prefs.js
 
Files to move or delete:
====================
C:\Windows\Tasks\At1.job
 
 
Some files in TEMP:
====================
C:\Documents and Settings\Katie\Local Settings\Temp\Uninstall.exe
C:\Documents and Settings\sheofourtris\Local Settings\Temp\1607.exe
C:\Documents and Settings\sheofourtris\Local Settings\Temp\1787.exe
C:\Documents and Settings\sheofourtris\Local Settings\Temp\5452.exe
C:\Documents and Settings\sheofourtris\Local Settings\Temp\7359.exe
C:\Documents and Settings\sheofourtris\Local Settings\Temp\9393.exe
C:\Documents and Settings\sheofourtris\Local Settings\Temp\KUIU.EXE
C:\Documents and Settings\sheofourtris\Local Settings\Temp\of3w58846.exe
C:\Documents and Settings\sheofourtris\Local Settings\Temp\oprun9953.exe
C:\Documents and Settings\sheofourtris\Local Settings\Temp\SpOrder.dll
C:\Documents and Settings\sheofourtris\Local Settings\Temp\Uninstall.exe
C:\Documents and Settings\sheofourtris\Local Settings\Temp\UninstallModule.exe
 
 
Some zero byte size files/folders:
==========================
C:\Windows\System32\d3dx9_25.dll
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version:24-08-2015
Ran by Administrator (2015-08-25 12:02:10)
Running from C:\Documents and Settings\Writing\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 

 


  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
HI there, this is a bit of a mess... What antivirus are you using ?

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
AppInit_DLLs: C:\PROGRA~1\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll [213776 2015-07-02] ()
Startup: C:\Documents and Settings\Katie\Start Menu\Programs\Startup\BlitzMediaPlayer.lnk [2014-09-07]
ShortcutTarget: BlitzMediaPlayer.lnk -> C:\Program Files\BlitzMediaPlayer\BlitzMediaPlayerApp.exe (No File)
Startup: C:\Documents and Settings\sheofourtris\Start Menu\Programs\Startup\Download.lnk [2015-07-07]
ShortcutTarget: Download.lnk -> C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d}\Download.exe (No File)
Startup: C:\Documents and Settings\Writing\Start Menu\Programs\Startup\bm.lnk [2015-07-20]
ShortcutTarget: bm.lnk -> C:\Documents and Settings\Writing\Local Settings\Application Data\m1a0vtytzklhbmn\m3a0bzzwzl9hdwn.exe ()
Startup: C:\Documents and Settings\Writing\Start Menu\Programs\Startup\loons.lnk [2015-07-20]
ShortcutTarget: loons.lnk -> C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m\m0w0bzzvzm5hc2m.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-854245398-616249376-1801674531-1023\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:1051;https=127.0.0.1:1051;
URLSearchHook: [S-1-5-21-854245398-616249376-1801674531-1023] ATTENTION => Default URLSearchHook is missing
URLSearchHook: [S-1-5-21-854245398-616249376-1801674531-500] ATTENTION => Default URLSearchHook is missing
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "www.google.com" <======= ATTENTION
SearchScopes: HKLM -> URL hxxp://www-searching.com/search.aspx?site=shdefault&pid=s&shr=d&q={searchTerms}&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,
SearchScopes: HKU\.DEFAULT -> DefaultScope {4B5B4143-FBDA-4EDB-991B-F2814D7E432E} URL = hxxps://search.yahoo.com/yhs/search?hspart=tightrope&hsimp=yhs-tig1&type=11191_011915&p={searchTerms}
SearchScopes: HKU\S-1-5-21-854245398-616249376-1801674531-1023 -> URL hxxp://www-searching.com/search.aspx?site=shdefault&pid=s&shr=d&q={searchTerms}&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,
Toolbar: HKLM - No Name - {96B06AFC-37EC-47DA-88EC-E74D6CE4CBC4} - No File
Toolbar: HKLM - No Name - {0AC73CDE-9CB4-473A-8196-BF21CA2EF48B} - No File
R2 BrsHelper; C:\Program Files\YTDownloader\BrowserHelperSrv.exe [112560 2015-07-06] ()
R2 chost1394; C:\Program Files\Compliant Host Controller\comc.exe [376832 2015-07-23] () [File not signed]
S2 f104e31c; c:\Program Files\BocaMonitor\BocaMonitor.dll [2725376 2015-08-09] () [File not signed]
R2 GIX38; C:\Documents and Settings\Writing\Local Settings\Application Data\UpdaterSvcSmarterPower1024\updatersvcsmarterpower.exe [33280 2015-07-24] () [File not signed]
S2 d51c1198; "C:\WINDOWS\system32\rundll32.exe" "c:\Program Files\SoftwareForce\SoftwareForce.dll",serv
S2 ToolGet; C:\Documents and Settings\All Users\Application Data\ToolGet\ToolGet [X]
R1 sbmntr; C:\Program Files\YTDownloader\sbmntr.sys [28960 2015-07-06] (YTDownloader)
S0 cerc6; no ImagePath
S3 cpuz136; \??\C:\DOCUME~1\Katie\LOCALS~1\Temp\cpuz136\cpuz136_x32.sys [X]
S3 HSFHWAZL; system32\DRIVERS\HSFHWAZL.sys [X]
S3 HSF_DPV; system32\DRIVERS\HSF_DPV.sys [X]
2015-08-24 17:39 - 2015-08-24 17:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-08-23 21:14 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\DailyPcClean Support
2015-08-23 19:30 - 2015-08-23 19:30 - 00000000 ____D C:\Program Files\DNS Unlocker
2015-08-23 15:24 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\Cinema PlusV23.08
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\DailyPcClean Support
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\DailyPCClean
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\DailyPcClean Support
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\DailyPCClean
2015-08-23 15:05 - 2015-08-23 15:05 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\DailyPCClean
2015-08-20 22:02 - 2015-08-20 22:02 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010047
2015-08-20 22:02 - 2015-08-20 22:02 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010044
2015-08-16 17:46 - 2015-08-16 17:46 - 00000000 ____D C:\Program Files\Sm2y0nty1zjjhzgn
2015-08-16 15:17 - 2015-08-16 15:17 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Super Optimizer
2015-08-16 15:11 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\Super Optimizer
2015-08-16 15:11 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Super Optimizer
2015-08-16 15:11 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{d8d4fe72-4b13-8f6d-d8d4-4fe724b1f9c9}
2015-08-09 11:46 - 2015-08-09 11:47 - 00000000 ____D C:\Program Files\System Cleaner Pro
2015-08-09 11:46 - 2015-08-09 11:46 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\JV Update
2015-08-09 11:26 - 2015-08-09 11:26 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Itibiti
2015-08-09 11:25 - 2015-08-09 11:25 - 00000000 ____D C:\Program Files\Itibiti Soft Phone
2015-08-09 11:25 - 2015-08-09 11:25 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\KNCTR
2015-08-09 11:22 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV09.08
2015-08-09 11:15 - 2015-08-09 11:15 - 00000000 ____D C:\Program Files\BocaMonitor
2015-08-01 22:00 - 2015-08-01 22:09 - 00153747 _____ C:\Documents and Settings\All Users\Application Data\8AN2gJxF.dat
2015-07-31 20:53 - 2015-08-24 20:41 - 00000000 ____D C:\Program Files\gmsd_us_005010047
2015-07-31 20:53 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\gmsd_us_005010047
2015-07-31 20:49 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\6FD6BF4E-8A83-49A0-AB7-1DBB4B3A410
2015-07-30 14:59 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV30.07
2015-07-29 16:26 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\33DA8500-CC25-48E1-8D27-B1A1377D9DAE
2015-07-28 23:02 - 2015-07-28 23:02 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\m0q0tzztzkjhlwn
2015-07-28 21:04 - 2015-07-28 21:04 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{60e253a7-2f92-bf74-60e2-253a72f94e9c}
2015-07-28 21:00 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Desktop Search
2015-07-28 21:00 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\DesktopSearch
2015-07-28 20:44 - 2015-08-24 20:41 - 00000000 ____D C:\Program Files\gmsd_us_005010044
2015-07-28 20:44 - 2015-08-24 20:41 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\gmsd_us_005010044
2015-07-28 20:41 - 2015-07-28 20:41 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\iStreamlite
2015-07-28 20:41 - 2015-07-28 20:41 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\iStreamLite
2015-07-28 20:24 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV28.07
2015-07-27 15:09 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV27.07
2015-07-27 11:00 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\A2B67FD3-FE0A-48AA-8744-C7178357EA0
2015-07-26 22:30 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\2CEEE2A8-EB6C-46C4-B963-4272DBFD7BFF
2015-07-26 17:54 - 2015-07-26 17:54 - 00000000 _____ C:\Documents and Settings\Writing\Local Settings\Application Data\{28AC3160-E789-44E2-B6C7-A7E9A8FF83B7}
2015-08-25 11:57 - 2014-09-08 17:57 - 00000480 _____ C:\WINDOWS\Tasks\PETN Update.job
2015-08-25 11:36 - 2014-09-07 15:36 - 00000414 _____ C:\WINDOWS\Tasks\At1.job
2015-08-25 11:35 - 2015-07-07 12:47 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\BrowserHelper
2015-08-25 11:24 - 2015-07-24 15:51 - 00001076 _____ C:\WINDOWS\Tasks\CxhJ5rDXjW2LZlw88S0K.job
2015-08-25 11:24 - 2015-07-12 15:51 - 00001082 _____ C:\WINDOWS\Tasks\liyfRBnpd3oV16DBx2Xb07O.job
2015-08-25 11:24 - 2015-07-12 15:51 - 00001062 _____ C:\WINDOWS\Tasks\r9OrLWuQuGNQs.job
2015-08-25 11:24 - 2015-07-11 12:59 - 00001054 _____ C:\WINDOWS\Tasks\S8v28p5NITjC1ZgbysVFsUo.job
2015-08-25 11:24 - 2015-07-10 22:36 - 00001054 _____ C:\WINDOWS\Tasks\Uandd9YYBmihfvXNPCbNbYh.job
2015-08-25 11:24 - 2015-07-07 12:47 - 00000372 _____ C:\WINDOWS\Tasks\YTDownloader.job
2015-08-25 11:24 - 2015-07-07 12:47 - 00000362 _____ C:\WINDOWS\Tasks\YTDownloaderUpd.job
2015-08-25 11:24 - 2015-07-06 12:59 - 00000508 ____H C:\WINDOWS\Tasks\BDLYHBMDHLAGVOIA.job
2015-08-25 11:24 - 2015-07-06 12:53 - 00000496 _____ C:\WINDOWS\Tasks\GlobalUpdate-m2y0yzzxzmthbwn.job
2015-08-25 11:24 - 2015-05-28 21:47 - 00000580 _____ C:\WINDOWS\Tasks\companion_for_gamers_helper_service.job
2015-08-25 11:24 - 2015-01-19 18:43 - 00000634 _____ C:\WINDOWS\Tasks\Client.job
2015-08-25 11:24 - 2015-01-19 18:43 - 00000578 _____ C:\WINDOWS\Tasks\Check Updates.job
2015-08-25 11:24 - 2015-01-19 18:43 - 00000574 _____ C:\WINDOWS\Tasks\Run Tasks.job
2015-08-24 20:42 - 2015-07-06 12:32 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\abc
2015-08-24 20:41 - 2015-07-24 15:40 - 00000000 ____D C:\Program Files\gmsd_us_005010040
2015-08-24 20:41 - 2015-07-12 16:22 - 00000000 ____D C:\Documents and Settings\Katie\Local Settings\Application Data\gmsd_us_005010029
2015-08-24 20:41 - 2015-07-12 15:45 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010029
2015-08-24 20:41 - 2015-07-07 13:30 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvexvac
2015-08-24 20:41 - 2015-07-07 12:50 - 00000000 ____D C:\Program Files\Common Files\ShopperPro
2015-08-24 20:41 - 2015-07-07 12:50 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ShopperPro
2015-08-24 20:41 - 2015-07-06 12:43 - 00000000 ____D C:\Program Files\shopperz
2015-08-24 20:41 - 2015-06-24 19:33 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvdxvy
2015-08-24 20:41 - 2015-06-09 10:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbavad
2015-08-24 20:41 - 2015-06-04 15:43 - 00000000 ____D C:\Documents and Settings\Guest\Local Settings\Application Data\avabvbyvyc
2015-08-24 20:41 - 2015-06-04 10:02 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbyvyc
2015-08-24 20:41 - 2015-05-27 18:07 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbxvh
2015-08-24 20:41 - 2015-02-01 22:33 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602
2015-08-24 20:41 - 2015-01-10 14:57 - 00000000 ____D C:\Program Files\TNT2
2015-08-24 20:41 - 2015-01-02 17:12 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TakeTHECoupOn
2015-08-24 20:41 - 2014-09-08 19:36 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\Astromenda
2015-08-24 20:41 - 2014-09-07 15:29 - 00000000 ____D C:\Documents and Settings\Katie\Application Data\VOPackage
2015-08-24 20:41 - 2014-09-07 15:25 - 00000000 ____D C:\Documents and Settings\Katie\Local Settings\Application Data\Genesis_09071925
2015-08-24 20:40 - 2015-07-25 16:45 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\F05F5344-ADA3-48F4-9628-C3F74B3D3D3
2015-08-24 20:40 - 2015-07-24 15:40 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010040
2015-08-24 20:40 - 2015-07-24 15:40 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\StormWarnings
2015-08-24 20:40 - 2015-07-24 15:38 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\StormWarnings
2015-08-24 20:40 - 2015-07-24 15:37 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\StormWarnings
2015-08-24 20:40 - 2015-07-24 15:34 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\6CBF5050-5AD4-4D5A-816-4F547B2D15BC
2015-08-24 20:40 - 2015-07-24 13:59 - 00000000 ____D C:\Program Files\Common Files\hdquhtjl.th1
2015-08-24 20:40 - 2015-07-20 20:35 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m
2015-08-24 20:40 - 2015-07-20 19:36 - 00000000 ____D C:\Program Files\4C4C4544-1436755823-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-20 19:36 - 00000000 ____D C:\Program Files\4C4C4544-1436199977-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:54 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741657-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:54 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741641-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:52 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{7ac4b295-06f9-c702-7ac4-4b29506fca54}
2015-08-24 20:40 - 2015-07-12 22:51 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741496-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:50 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\4C4C4544-1436755823-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 18:26 - 00000000 ____D C:\Program Files\Consumer Input
2015-08-24 20:40 - 2015-07-12 18:23 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\BF476A5D-4D14-4415-A54A-14E2A8B4D66C
2015-08-24 20:40 - 2015-07-12 17:38 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\BrowserHelper
2015-08-24 20:40 - 2015-07-08 14:49 - 00000000 ____D C:\Program Files\FriendlyError
2015-08-24 20:40 - 2015-07-07 13:31 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\4C4C4544-1436290292-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-07 13:30 - 00000000 ____D C:\Program Files\SearchProtect
2015-08-24 20:40 - 2015-07-07 12:51 - 00000000 ____D C:\Program Files\Ge-Force
2015-08-24 20:40 - 2015-07-07 12:50 - 00000000 ____D C:\Program Files\ShopperPro
2015-08-24 20:40 - 2015-07-07 12:46 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\DeskBar
2015-08-24 20:40 - 2015-07-07 12:45 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SearchModule
2015-08-24 20:40 - 2015-07-07 11:27 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d}
2015-08-24 20:40 - 2015-07-06 16:22 - 00000000 ____D C:\Documents and Settings\Katie\Local Settings\Application Data\StormWatch
2015-08-24 20:40 - 2015-07-06 12:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Service1291
2015-08-24 20:40 - 2015-07-06 12:39 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\SmartWeb
2015-08-24 20:40 - 2015-07-06 12:39 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\80F7805B-BCCD-42C6-B8D-47320B2EEAD
2015-08-24 20:40 - 2015-07-06 12:29 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\4C4C4544-1436185766-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-06 12:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\6635
2015-08-24 20:40 - 2015-07-06 12:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\4C4C4544-1436199977-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-06-04 15:42 - 00000000 ____D C:\Documents and Settings\Guest\Local Settings\Application Data\CrimeWatch
2015-08-24 20:40 - 2015-05-06 19:13 - 00000000 ____D C:\Program Files\Games Bot
2015-08-24 20:40 - 2015-05-01 21:01 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{1158b7dd-d0b8-a80b-1158-8b7ddd0bdf77}
2015-08-24 20:40 - 2015-01-19 18:41 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\StormWatch
2015-08-24 20:40 - 2015-01-11 21:31 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Browser
2015-08-24 20:40 - 2015-01-10 14:56 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\UpdateAdmin
2015-08-24 20:40 - 2015-01-08 22:33 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\fopneeomcncoadkhijbapjiidaedkcfg
2015-08-24 20:40 - 2014-12-01 10:55 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\14e8c327e3c6ddb5
2015-08-24 20:40 - 2014-11-23 16:06 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\1506668651448032693
2015-08-24 20:40 - 2014-11-23 16:05 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\dnonpahagjngllclmkgiokobafojjpel
2015-08-24 20:40 - 2014-09-28 16:44 - 00000000 ____D C:\Documents and Settings\Katie\Application Data\7148
2015-08-24 20:40 - 2014-09-08 17:57 - 00000000 ____D C:\Program Files\PETN
2015-08-24 20:40 - 2014-09-07 15:28 - 00000000 ____D C:\Documents and Settings\Katie\Application Data\30865
2015-08-24 20:39 - 2015-07-24 13:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ToolGet
2015-08-24 20:39 - 2015-07-07 13:18 - 00000000 ____D C:\Program Files\WordShark_1.10.0.19
2015-08-24 20:39 - 2015-07-07 10:57 - 00000000 ____D C:\Program Files\GUPlayer
2015-08-24 20:39 - 2015-07-06 12:58 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\FlashBeat
2015-08-24 20:39 - 2015-05-29 17:32 - 00000000 ____D C:\Program Files\JavaScript Notepad
2015-08-24 20:39 - 2015-05-08 18:38 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SharkManCoupon
2015-08-24 20:39 - 2015-04-14 18:50 - 00000000 ____D C:\Program Files\Optimizer Pro 3.79
2015-08-24 20:39 - 2014-12-12 16:47 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\AdBlocker Manger
2015-08-24 20:39 - 2014-09-10 19:38 - 00000000 ____D C:\Program Files\SmarterPower
2015-08-24 16:24 - 2015-03-14 22:42 - 00000004 _____ C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7
2015-08-23 23:00 - 2015-07-06 12:26 - 00000000 ____D C:\Program Files\Coupoon
2015-08-23 21:14 - 2015-07-07 11:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\SmartWeb
2015-08-09 11:15 - 2015-07-13 14:49 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\731d3bff00001862
2015-08-01 17:16 - 2015-06-14 16:39 - 00000000 ____D C:\Program Files\RoughDraft
2015-07-30 18:13 - 2014-12-25 10:05 - 00000020 ____H C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
2015-07-29 20:51 - 2014-09-10 19:39 - 00000480 _____ C:\WINDOWS\Tasks\Driver Support-RTMScan.job
2015-07-29 17:45 - 2014-12-25 10:05 - 00000020 ____H C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
2015-07-26 16:04 - 2015-07-06 12:26 - 00000000 ____D C:\Program Files\AnySend
2015-07-26 16:00 - 2015-07-12 22:49 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Nosibay
2015-05-11 18:46 - 2015-05-26 15:50 - 0000079 _____ () C:\Program Files\prefs.js
C:\Program Files\BlitzMediaPlayer
C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m
C:\Documents and Settings\Writing\Local Settings\Application Data\m1a0vtytzklhbmn
C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d}
c:\Program Files\BocaMonitor
C:\Program Files\SoftwareForce
C:\Documents and Settings\All Users\Application Data\ToolGet
C:\Documents and Settings\Writing\Local Settings\Application Data\UpdaterSvcSmarterPower1024
C:\Program Files\Compliant Host Controller
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.
FINALLY

Please download Junkware Removal Tool to your desktop.
  • Right-mouse click JRT.exe and select "Run as Administrator" the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • post the contents of JRT.txt into your next message.

  • 0

#3
kat3lr

kat3lr

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts

As for the virus scan, the friend I got it from said he had something through microsoft turned on, and when I got the money for an actual virus program, I was to speak with him on turning it off.

 

Just as a note, while running the first FRST fix file, my laptop blue screened twice. The first one said:

A problem has been detected and windows has been shut down to prevent damage to your computer.

The problem seems to be caused by the following file: sbmntr.sys 

DRIVER_UNLOADED_WITOUT_CANCELING_PENDING_OPERATIONS

...

Technical information:

*** STOP 0x000000CE

 

The second one just said that windows had dectected a problem and shut down to prevent damage.

 

 

 

Anyway, here are the files you asked for:

 

 

 

 

 

 

Fix result of Farbar Recovery Scan Tool (x86) Version:24-08-2015
Ran by Writing (2015-08-26 11:53:54) Run:2
Running from C:\Documents and Settings\Writing\Desktop
Loaded Profiles: Writing (Available Profiles: Katie & Kat3lr & sheofourtris & Writing & Trial & Administrator & Guest)
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
AppInit_DLLs: C:\PROGRA~1\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll [213776 2015-07-02] ()
Startup: C:\Documents and Settings\Katie\Start Menu\Programs\Startup\BlitzMediaPlayer.lnk [2014-09-07]
ShortcutTarget: BlitzMediaPlayer.lnk -> C:\Program Files\BlitzMediaPlayer\BlitzMediaPlayerApp.exe (No File)
Startup: C:\Documents and Settings\sheofourtris\Start Menu\Programs\Startup\Download.lnk [2015-07-07]
ShortcutTarget: Download.lnk -> C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d}\Download.exe (No File)
Startup: C:\Documents and Settings\Writing\Start Menu\Programs\Startup\bm.lnk [2015-07-20]
ShortcutTarget: bm.lnk -> C:\Documents and Settings\Writing\Local Settings\Application Data\m1a0vtytzklhbmn\m3a0bzzwzl9hdwn.exe ()
Startup: C:\Documents and Settings\Writing\Start Menu\Programs\Startup\loons.lnk [2015-07-20]
ShortcutTarget: loons.lnk -> C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m\m0w0bzzvzm5hc2m.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft INTERNET EXPLORER: Policy restriction <======= ATTENTION
HKU\S-1-5-21-854245398-616249376-1801674531-1023\SOFTWARE\Policies\Microsoft INTERNET EXPLORER: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => INTERNET EXPLORER proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:1051;https=127.0.0.1:1051;
URLSearchHook: [S-1-5-21-854245398-616249376-1801674531-1023] ATTENTION => Default URLSearchHook is missing
URLSearchHook: [S-1-5-21-854245398-616249376-1801674531-500] ATTENTION => Default URLSearchHook is missing
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "www.google.com" <======= ATTENTION
SearchScopes: HKLM -> URL hxxp://www-searching.com/search.aspx?site=shdefault&pid=s&shr=d&q={searchTerms}&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,
SearchScopes: HKU\.DEFAULT -> DefaultScope {4B5B4143-FBDA-4EDB-991B-F2814D7E432E} URL = hxxps://search.yahoo.com/yhs/search?hspart=tightrope&hsimp=yhs-tig1&type=11191_011915&p={searchTerms}
SearchScopes: HKU\S-1-5-21-854245398-616249376-1801674531-1023 -> URL hxxp://www-searching.com/search.aspx?site=shdefault&pid=s&shr=d&q={searchTerms}&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,
Toolbar: HKLM - No Name - {96B06AFC-37EC-47DA-88EC-E74D6CE4CBC4} - No File
Toolbar: HKLM - No Name - {0AC73CDE-9CB4-473A-8196-BF21CA2EF48B} - No File
R2 BrsHelper; C:\Program Files\YTDownloader\BrowserHelperSrv.exe [112560 2015-07-06] ()
R2 chost1394; C:\Program Files\Compliant Host Controller\comc.exe [376832 2015-07-23] () [File not signed]
S2 f104e31c; c:\Program Files\BocaMonitor\BocaMonitor.dll [2725376 2015-08-09] () [File not signed]
R2 GIX38; C:\Documents and Settings\Writing\Local Settings\Application Data\UpdaterSvcSmarterPower1024\updatersvcsmarterpower.exe [33280 2015-07-24] () [File not signed]
S2 d51c1198; "C:\WINDOWS\system32\rundll32.exe" "c:\Program Files\SoftwareForce\SoftwareForce.dll",serv
S2 ToolGet; C:\Documents and Settings\All Users\Application Data\ToolGet\ToolGet [X]
R1 sbmntr; C:\Program Files\YTDownloader\sbmntr.sys [28960 2015-07-06] (YTDownloader)
S0 cerc6; no ImagePath
S3 cpuz136; \??\C:\DOCUME~1\Katie\LOCALS~1\Temp\cpuz136\cpuz136_x32.sys [X]
S3 HSFHWAZL; system32\DRIVERS\HSFHWAZL.sys [X]
S3 HSF_DPV; system32\DRIVERS\HSF_DPV.sys [X]
2015-08-24 17:39 - 2015-08-24 17:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-08-23 21:14 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\DailyPcClean Support
2015-08-23 19:30 - 2015-08-23 19:30 - 00000000 ____D C:\Program Files\DNS Unlocker
2015-08-23 15:24 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\Cinema PlusV23.08
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\DailyPcClean Support
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\DailyPCClean
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\DailyPcClean Support
2015-08-23 15:05 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\DailyPCClean
2015-08-23 15:05 - 2015-08-23 15:05 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\DailyPCClean
2015-08-20 22:02 - 2015-08-20 22:02 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010047
2015-08-20 22:02 - 2015-08-20 22:02 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010044
2015-08-16 17:46 - 2015-08-16 17:46 - 00000000 ____D C:\Program Files\Sm2y0nty1zjjhzgn
2015-08-16 15:17 - 2015-08-16 15:17 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Super Optimizer
2015-08-16 15:11 - 2015-08-24 20:40 - 00000000 ____D C:\Program Files\Super Optimizer
2015-08-16 15:11 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Super Optimizer
2015-08-16 15:11 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{d8d4fe72-4b13-8f6d-d8d4-4fe724b1f9c9}
2015-08-09 11:46 - 2015-08-09 11:47 - 00000000 ____D C:\Program Files\System CLEANER PRO
2015-08-09 11:46 - 2015-08-09 11:46 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\JV Update
2015-08-09 11:26 - 2015-08-09 11:26 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Itibiti
2015-08-09 11:25 - 2015-08-09 11:25 - 00000000 ____D C:\Program Files\Itibiti Soft Phone
2015-08-09 11:25 - 2015-08-09 11:25 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\KNCTR
2015-08-09 11:22 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV09.08
2015-08-09 11:15 - 2015-08-09 11:15 - 00000000 ____D C:\Program Files\BocaMonitor
2015-08-01 22:00 - 2015-08-01 22:09 - 00153747 _____ C:\Documents and Settings\All Users\Application Data\8AN2gJxF.dat
2015-07-31 20:53 - 2015-08-24 20:41 - 00000000 ____D C:\Program Files\gmsd_us_005010047
2015-07-31 20:53 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\gmsd_us_005010047
2015-07-31 20:49 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\6FD6BF4E-8A83-49A0-AB7-1DBB4B3A410
2015-07-30 14:59 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV30.07
2015-07-29 16:26 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\33DA8500-CC25-48E1-8D27-B1A1377D9DAE
2015-07-28 23:02 - 2015-07-28 23:02 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\m0q0tzztzkjhlwn
2015-07-28 21:04 - 2015-07-28 21:04 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{60e253a7-2f92-bf74-60e2-253a72f94e9c}
2015-07-28 21:00 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Desktop Search
2015-07-28 21:00 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\DesktopSearch
2015-07-28 20:44 - 2015-08-24 20:41 - 00000000 ____D C:\Program Files\gmsd_us_005010044
2015-07-28 20:44 - 2015-08-24 20:41 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\gmsd_us_005010044
2015-07-28 20:41 - 2015-07-28 20:41 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\iStreamlite
2015-07-28 20:41 - 2015-07-28 20:41 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\iStreamLite
2015-07-28 20:24 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV28.07
2015-07-27 15:09 - 2015-08-24 20:39 - 00000000 ____D C:\Program Files\CinemaPlus-3.2cV27.07
2015-07-27 11:00 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\A2B67FD3-FE0A-48AA-8744-C7178357EA0
2015-07-26 22:30 - 2015-08-24 20:40 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\2CEEE2A8-EB6C-46C4-B963-4272DBFD7BFF
2015-07-26 17:54 - 2015-07-26 17:54 - 00000000 _____ C:\Documents and Settings\Writing\Local Settings\Application Data\{28AC3160-E789-44E2-B6C7-A7E9A8FF83B7}
2015-08-25 11:57 - 2014-09-08 17:57 - 00000480 _____ C:\WINDOWS\Tasks\PETN Update.job
2015-08-25 11:36 - 2014-09-07 15:36 - 00000414 _____ C:\WINDOWS\Tasks\At1.job
2015-08-25 11:35 - 2015-07-07 12:47 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\BrowserHelper
2015-08-25 11:24 - 2015-07-24 15:51 - 00001076 _____ C:\WINDOWS\Tasks\CxhJ5rDXjW2LZlw88S0K.job
2015-08-25 11:24 - 2015-07-12 15:51 - 00001082 _____ C:\WINDOWS\Tasks\liyfRBnpd3oV16DBx2Xb07O.job
2015-08-25 11:24 - 2015-07-12 15:51 - 00001062 _____ C:\WINDOWS\Tasks\r9OrLWuQuGNQs.job
2015-08-25 11:24 - 2015-07-11 12:59 - 00001054 _____ C:\WINDOWS\Tasks\S8v28p5NITjC1ZgbysVFsUo.job
2015-08-25 11:24 - 2015-07-10 22:36 - 00001054 _____ C:\WINDOWS\Tasks\Uandd9YYBmihfvXNPCbNbYh.job
2015-08-25 11:24 - 2015-07-07 12:47 - 00000372 _____ C:\WINDOWS\Tasks\YTDownloader.job
2015-08-25 11:24 - 2015-07-07 12:47 - 00000362 _____ C:\WINDOWS\Tasks\YTDownloaderUpd.job
2015-08-25 11:24 - 2015-07-06 12:59 - 00000508 ____H C:\WINDOWS\Tasks\BDLYHBMDHLAGVOIA.job
2015-08-25 11:24 - 2015-07-06 12:53 - 00000496 _____ C:\WINDOWS\Tasks\GlobalUpdate-m2y0yzzxzmthbwn.job
2015-08-25 11:24 - 2015-05-28 21:47 - 00000580 _____ C:\WINDOWS\Tasks\companion_for_gamers_helper_service.job
2015-08-25 11:24 - 2015-01-19 18:43 - 00000634 _____ C:\WINDOWS\Tasks\Client.job
2015-08-25 11:24 - 2015-01-19 18:43 - 00000578 _____ C:\WINDOWS\Tasks\Check Updates.job
2015-08-25 11:24 - 2015-01-19 18:43 - 00000574 _____ C:\WINDOWS\Tasks\Run Tasks.job
2015-08-24 20:42 - 2015-07-06 12:32 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\abc
2015-08-24 20:41 - 2015-07-24 15:40 - 00000000 ____D C:\Program Files\gmsd_us_005010040
2015-08-24 20:41 - 2015-07-12 16:22 - 00000000 ____D C:\Documents and Settings\Katie\Local Settings\Application Data\gmsd_us_005010029
2015-08-24 20:41 - 2015-07-12 15:45 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010029
2015-08-24 20:41 - 2015-07-07 13:30 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvexvac
2015-08-24 20:41 - 2015-07-07 12:50 - 00000000 ____D C:\Program Files\Common Files\ShopperPro
2015-08-24 20:41 - 2015-07-07 12:50 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ShopperPro
2015-08-24 20:41 - 2015-07-06 12:43 - 00000000 ____D C:\Program Files\shopperz
2015-08-24 20:41 - 2015-06-24 19:33 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvdxvy
2015-08-24 20:41 - 2015-06-09 10:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbavad
2015-08-24 20:41 - 2015-06-04 15:43 - 00000000 ____D C:\Documents and Settings\Guest\Local Settings\Application Data\avabvbyvyc
2015-08-24 20:41 - 2015-06-04 10:02 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbyvyc
2015-08-24 20:41 - 2015-05-27 18:07 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbxvh
2015-08-24 20:41 - 2015-02-01 22:33 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602
2015-08-24 20:41 - 2015-01-10 14:57 - 00000000 ____D C:\Program Files\TNT2
2015-08-24 20:41 - 2015-01-02 17:12 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TakeTHECoupOn
2015-08-24 20:41 - 2014-09-08 19:36 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\Astromenda
2015-08-24 20:41 - 2014-09-07 15:29 - 00000000 ____D C:\Documents and Settings\Katie\Application Data\VOPackage
2015-08-24 20:41 - 2014-09-07 15:25 - 00000000 ____D C:\Documents and Settings\Katie\Local Settings\Application Data\Genesis_09071925
2015-08-24 20:40 - 2015-07-25 16:45 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\F05F5344-ADA3-48F4-9628-C3F74B3D3D3
2015-08-24 20:40 - 2015-07-24 15:40 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010040
2015-08-24 20:40 - 2015-07-24 15:40 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\StormWarnings
2015-08-24 20:40 - 2015-07-24 15:38 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\StormWarnings
2015-08-24 20:40 - 2015-07-24 15:37 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\StormWarnings
2015-08-24 20:40 - 2015-07-24 15:34 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\6CBF5050-5AD4-4D5A-816-4F547B2D15BC
2015-08-24 20:40 - 2015-07-24 13:59 - 00000000 ____D C:\Program Files\Common Files\hdquhtjl.th1
2015-08-24 20:40 - 2015-07-20 20:35 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m
2015-08-24 20:40 - 2015-07-20 19:36 - 00000000 ____D C:\Program Files\4C4C4544-1436755823-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-20 19:36 - 00000000 ____D C:\Program Files\4C4C4544-1436199977-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:54 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741657-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:54 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741641-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:52 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{7ac4b295-06f9-c702-7ac4-4b29506fca54}
2015-08-24 20:40 - 2015-07-12 22:51 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741496-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 22:50 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\4C4C4544-1436755823-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-12 18:26 - 00000000 ____D C:\Program Files\Consumer Input
2015-08-24 20:40 - 2015-07-12 18:23 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\BF476A5D-4D14-4415-A54A-14E2A8B4D66C
2015-08-24 20:40 - 2015-07-12 17:38 - 00000000 ____D C:\Documents and Settings\Writing\Local Settings\Application Data\BrowserHelper
2015-08-24 20:40 - 2015-07-08 14:49 - 00000000 ____D C:\Program Files\FriendlyError
2015-08-24 20:40 - 2015-07-07 13:31 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\4C4C4544-1436290292-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-07 13:30 - 00000000 ____D C:\Program Files\SearchProtect
2015-08-24 20:40 - 2015-07-07 12:51 - 00000000 ____D C:\Program Files\Ge-Force
2015-08-24 20:40 - 2015-07-07 12:50 - 00000000 ____D C:\Program Files\ShopperPro
2015-08-24 20:40 - 2015-07-07 12:46 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\DeskBar
2015-08-24 20:40 - 2015-07-07 12:45 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SearchModule
2015-08-24 20:40 - 2015-07-07 11:27 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d}
2015-08-24 20:40 - 2015-07-06 16:22 - 00000000 ____D C:\Documents and Settings\Katie\Local Settings\Application Data\StormWatch
2015-08-24 20:40 - 2015-07-06 12:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Service1291
2015-08-24 20:40 - 2015-07-06 12:39 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\SmartWeb
2015-08-24 20:40 - 2015-07-06 12:39 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\80F7805B-BCCD-42C6-B8D-47320B2EEAD
2015-08-24 20:40 - 2015-07-06 12:29 - 00000000 ____D C:\Documents and Settings\sheofourtris\Local Settings\Application Data\4C4C4544-1436185766-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-07-06 12:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\6635
2015-08-24 20:40 - 2015-07-06 12:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\4C4C4544-1436199977-4B10-8039-C8C04F4B4831
2015-08-24 20:40 - 2015-06-04 15:42 - 00000000 ____D C:\Documents and Settings\Guest\Local Settings\Application Data\CrimeWatch
2015-08-24 20:40 - 2015-05-06 19:13 - 00000000 ____D C:\Program Files\Games Bot
2015-08-24 20:40 - 2015-05-01 21:01 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\{1158b7dd-d0b8-a80b-1158-8b7ddd0bdf77}
2015-08-24 20:40 - 2015-01-19 18:41 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\StormWatch
2015-08-24 20:40 - 2015-01-11 21:31 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Browser
2015-08-24 20:40 - 2015-01-10 14:56 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\UpdateAdmin
2015-08-24 20:40 - 2015-01-08 22:33 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\fopneeomcncoadkhijbapjiidaedkcfg
2015-08-24 20:40 - 2014-12-01 10:55 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\14e8c327e3c6ddb5
2015-08-24 20:40 - 2014-11-23 16:06 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\1506668651448032693
2015-08-24 20:40 - 2014-11-23 16:05 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\dnonpahagjngllclmkgiokobafojjpel
2015-08-24 20:40 - 2014-09-28 16:44 - 00000000 ____D C:\Documents and Settings\Katie\Application Data\7148
2015-08-24 20:40 - 2014-09-08 17:57 - 00000000 ____D C:\Program Files\PETN
2015-08-24 20:40 - 2014-09-07 15:28 - 00000000 ____D C:\Documents and Settings\Katie\Application Data\30865
2015-08-24 20:39 - 2015-07-24 13:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ToolGet
2015-08-24 20:39 - 2015-07-07 13:18 - 00000000 ____D C:\Program Files\WordShark_1.10.0.19
2015-08-24 20:39 - 2015-07-07 10:57 - 00000000 ____D C:\Program Files\GUPlayer
2015-08-24 20:39 - 2015-07-06 12:58 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\FlashBeat
2015-08-24 20:39 - 2015-05-29 17:32 - 00000000 ____D C:\Program Files\JavaScript Notepad
2015-08-24 20:39 - 2015-05-08 18:38 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SharkManCoupon
2015-08-24 20:39 - 2015-04-14 18:50 - 00000000 ____D C:\Program Files OPTIMIZER PRO 3.79
2015-08-24 20:39 - 2014-12-12 16:47 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\AdBlocker Manger
2015-08-24 20:39 - 2014-09-10 19:38 - 00000000 ____D C:\Program Files\SmarterPower
2015-08-24 16:24 - 2015-03-14 22:42 - 00000004 _____ C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7
2015-08-23 23:00 - 2015-07-06 12:26 - 00000000 ____D C:\Program Files\Coupoon
2015-08-23 21:14 - 2015-07-07 11:26 - 00000000 ____D C:\Documents and Settings\sheofourtris\Application Data\SmartWeb
2015-08-09 11:15 - 2015-07-13 14:49 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\731d3bff00001862
2015-08-01 17:16 - 2015-06-14 16:39 - 00000000 ____D C:\Program Files\RoughDraft
2015-07-30 18:13 - 2014-12-25 10:05 - 00000020 ____H C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
2015-07-29 20:51 - 2014-09-10 19:39 - 00000480 _____ C:\WINDOWS\Tasks\Driver Support-RTMScan.job
2015-07-29 17:45 - 2014-12-25 10:05 - 00000020 ____H C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
2015-07-26 16:04 - 2015-07-06 12:26 - 00000000 ____D C:\Program Files\AnySend
2015-07-26 16:00 - 2015-07-12 22:49 - 00000000 ____D C:\Documents and Settings\Writing\Application Data\Nosibay
2015-05-11 18:46 - 2015-05-26 15:50 - 0000079 _____ () C:\Program Files\prefs.js
C:\Program Files\BlitzMediaPlayer
C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m
C:\Documents and Settings\Writing\Local Settings\Application Data\m1a0vtytzklhbmn
C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d}
c:\Program Files\BocaMonitor
C:\Program Files\SoftwareForce
C:\Documents and Settings\All Users\Application Data\ToolGet
C:\Documents and Settings\Writing\Local Settings\Application Data\UpdaterSvcSmarterPower1024
C:\Program Files\Compliant Host Controller
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers
*****************
 
Restore point was successfully created.
"C:\PROGRA~1\SearchProtect\SearchProtect\bin\VC32Loader.dll" => Value data removed successfully..
C:\Documents and Settings\Katie\Start Menu\Programs\Startup\BlitzMediaPlayer.lnk not found.
C:\Program Files\BlitzMediaPlayer\BlitzMediaPlayerApp.exe not found.
C:\Documents and Settings\sheofourtris\Start Menu\Programs\Startup\Download.lnk not found.
C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d}\Download.exe not found.
C:\Documents and Settings\Writing\Start Menu\Programs\Startup\bm.lnk not found.
C:\Documents and Settings\Writing\Local Settings\Application Data\m1a0vtytzklhbmn\m3a0bzzwzl9hdwn.exe not found.
C:\Documents and Settings\Writing\Start Menu\Programs\Startup\loons.lnk not found.
C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m\m0w0bzzvzm5hc2m.exe not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully.
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. 
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt1" => key removed successfully.
HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt2" => key removed successfully.
HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt3" => key removed successfully.
HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4" => key removed successfully.
HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
"C:\WINDOWS\system32\GroupPolicy\Machine" => File/Folder not found.
HKLM\SOFTWARE\Policies\Google => key not found. 
HKLM\SOFTWARE\Policies\Microsoft INTERNET EXPLORER: Policy restriction <======= ATTENTION => Error: No automatic fix found for this entry.
HKU\S-1-5-21-854245398-616249376-1801674531-1023\SOFTWARE\Policies\Microsoft INTERNET EXPLORER: Policy restriction <======= ATTENTION => Error: No automatic fix found for this entry.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully.
Could not restore Default URLSearchHook.
Could not restore Default URLSearchHook.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\Tabs => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-21-854245398-616249376-1801674531-1023\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value removed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{96B06AFC-37EC-47DA-88EC-E74D6CE4CBC4} => value removed successfully.
HKCR\CLSID\{96B06AFC-37EC-47DA-88EC-E74D6CE4CBC4} => key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{0AC73CDE-9CB4-473A-8196-BF21CA2EF48B} => value removed successfully.
HKCR\CLSID\{0AC73CDE-9CB4-473A-8196-BF21CA2EF48B} => key not found. 
BrsHelper => Unable to stop service.
BrsHelper => service removed successfully.
chost1394 => Unable to stop service.
chost1394 => service removed successfully.
f104e31c => service removed successfully.
GIX38 => Unable to stop service.
GIX38 => service removed successfully.
d51c1198 => service removed successfully.
ToolGet => service removed successfully.
sbmntr => Service stopped successfully.
sbmntr => service removed successfully.
cerc6 => service removed successfully.
cpuz136 => service removed successfully.
HSFHWAZL => service removed successfully.
HSF_DPV => service removed successfully.
C:\Documents and Settings\All Users\Application Data\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\DailyPcClean Support => moved successfully
C:\Program Files\DNS Unlocker => moved successfully
C:\Program Files\Cinema PlusV23.08 => moved successfully
C:\Program Files\DailyPcClean Support => moved successfully
C:\Program Files\DailyPCClean => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\DailyPcClean Support => moved successfully
C:\Documents and Settings\All Users\Start Menu\Programs\DailyPCClean => moved successfully
C:\Documents and Settings\Writing\Application Data\DailyPCClean => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010047 => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010044 => moved successfully
C:\Program Files\Sm2y0nty1zjjhzgn => moved successfully
C:\Documents and Settings\Writing\Application Data\Super Optimizer => moved successfully
C:\Program Files\Super Optimizer => moved successfully
C:\Documents and Settings\All Users\Start Menu\Programs\Super Optimizer => moved successfully
C:\Documents and Settings\All Users\Application Data\{d8d4fe72-4b13-8f6d-d8d4-4fe724b1f9c9} => moved successfully
C:\Program Files\System CLEANER PRO => moved successfully
C:\Documents and Settings\Writing\Application Data\JV Update => moved successfully
C:\Documents and Settings\Writing\Application Data\Itibiti => moved successfully
C:\Program Files\Itibiti Soft Phone => moved successfully
C:\Documents and Settings\All Users\Start Menu\Programs\KNCTR => moved successfully
C:\Program Files\CinemaPlus-3.2cV09.08 => moved successfully
C:\Program Files\BocaMonitor => moved successfully
C:\Documents and Settings\All Users\Application Data\8AN2gJxF.dat => moved successfully
C:\Program Files\gmsd_us_005010047 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\gmsd_us_005010047 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\6FD6BF4E-8A83-49A0-AB7-1DBB4B3A410 => moved successfully
C:\Program Files\CinemaPlus-3.2cV30.07 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\33DA8500-CC25-48E1-8D27-B1A1377D9DAE => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\m0q0tzztzkjhlwn => moved successfully
C:\Documents and Settings\All Users\Application Data\{60e253a7-2f92-bf74-60e2-253a72f94e9c} => moved successfully
C:\Documents and Settings\All Users\Start Menu\Programs\Desktop Search => moved successfully
C:\Documents and Settings\All Users\Application Data\DesktopSearch => moved successfully
C:\Program Files\gmsd_us_005010044 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\gmsd_us_005010044 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\iStreamlite => moved successfully
C:\Documents and Settings\Writing\Application Data\iStreamLite => moved successfully
C:\Program Files\CinemaPlus-3.2cV28.07 => moved successfully
C:\Program Files\CinemaPlus-3.2cV27.07 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\A2B67FD3-FE0A-48AA-8744-C7178357EA0 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\2CEEE2A8-EB6C-46C4-B963-4272DBFD7BFF => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\{28AC3160-E789-44E2-B6C7-A7E9A8FF83B7} => moved successfully
C:\WINDOWS\Tasks\PETN Update.job => moved successfully
C:\WINDOWS\Tasks\At1.job => moved successfully
C:\Documents and Settings\LocalService\Local Settings\Application Data\BrowserHelper => moved successfully
C:\WINDOWS\Tasks\CxhJ5rDXjW2LZlw88S0K.job => moved successfully
C:\WINDOWS\Tasks\liyfRBnpd3oV16DBx2Xb07O.job => moved successfully
C:\WINDOWS\Tasks\r9OrLWuQuGNQs.job => moved successfully
C:\WINDOWS\Tasks\S8v28p5NITjC1ZgbysVFsUo.job => moved successfully
C:\WINDOWS\Tasks\Uandd9YYBmihfvXNPCbNbYh.job => moved successfully
C:\WINDOWS\Tasks\YTDownloader.job => moved successfully
C:\WINDOWS\Tasks\YTDownloaderUpd.job => moved successfully
C:\WINDOWS\Tasks\BDLYHBMDHLAGVOIA.job => moved successfully
C:\WINDOWS\Tasks\GlobalUpdate-m2y0yzzxzmthbwn.job => moved successfully
C:\WINDOWS\Tasks\companion_for_gamers_helper_service.job => moved successfully
C:\WINDOWS\Tasks\Client.job => moved successfully
C:\WINDOWS\Tasks\Check Updates.job => moved successfully
C:\WINDOWS\Tasks\Run Tasks.job => moved successfully
C:\Documents and Settings\All Users\Application Data\abc => moved successfully
C:\Program Files\gmsd_us_005010040 => moved successfully
C:\Documents and Settings\Katie\Local Settings\Application Data\gmsd_us_005010029 => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010029 => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvexvac => moved successfully
C:\Program Files\Common Files\ShopperPro => moved successfully
C:\Documents and Settings\All Users\Application Data\ShopperPro => moved successfully
C:\Program Files\shopperz => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvdxvy => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbavad => moved successfully
C:\Documents and Settings\Guest\Local Settings\Application Data\avabvbyvyc => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbyvyc => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\avabvbxvh => moved successfully
C:\Documents and Settings\All Users\Application Data\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602 => moved successfully
C:\Program Files\TNT2 => moved successfully
C:\Documents and Settings\All Users\Application Data\TakeTHECoupOn => moved successfully
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Astromenda => moved successfully
C:\Documents and Settings\Katie\Application Data\VOPackage => moved successfully
C:\Documents and Settings\Katie\Local Settings\Application Data\Genesis_09071925 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\F05F5344-ADA3-48F4-9628-C3F74B3D3D3 => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\gmsd_us_005010040 => moved successfully
C:\Documents and Settings\LocalService\Application Data\StormWarnings => moved successfully
C:\Documents and Settings\LocalService\Local Settings\Application Data\StormWarnings => moved successfully
C:\Documents and Settings\All Users\Start Menu\Programs\StormWarnings => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\6CBF5050-5AD4-4D5A-816-4F547B2D15BC => moved successfully
C:\Program Files\Common Files\hdquhtjl.th1 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m => moved successfully
C:\Program Files\4C4C4544-1436755823-4B10-8039-C8C04F4B4831 => moved successfully
C:\Program Files\4C4C4544-1436199977-4B10-8039-C8C04F4B4831 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741657-4B10-8039-C8C04F4B4831 => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741641-4B10-8039-C8C04F4B4831 => moved successfully
C:\Documents and Settings\All Users\Application Data\{7ac4b295-06f9-c702-7ac4-4b29506fca54} => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\4C4C4544-1436741496-4B10-8039-C8C04F4B4831 => moved successfully
C:\Documents and Settings\Writing\Application Data\4C4C4544-1436755823-4B10-8039-C8C04F4B4831 => moved successfully
C:\Program Files\Consumer Input => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\BF476A5D-4D14-4415-A54A-14E2A8B4D66C => moved successfully
C:\Documents and Settings\Writing\Local Settings\Application Data\BrowserHelper => moved successfully
C:\Program Files\FriendlyError => moved successfully
C:\Documents and Settings\sheofourtris\Application Data\4C4C4544-1436290292-4B10-8039-C8C04F4B4831 => moved successfully
C:\Program Files\SearchProtect => moved successfully
C:\Program Files\Ge-Force => moved successfully
C:\Program Files\ShopperPro => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\DeskBar => moved successfully
C:\Documents and Settings\All Users\Application Data\SearchModule => moved successfully
C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d} => moved successfully
C:\Documents and Settings\Katie\Local Settings\Application Data\StormWatch => moved successfully
C:\Documents and Settings\All Users\Application Data\Service1291 => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\SmartWeb => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\80F7805B-BCCD-42C6-B8D-47320B2EEAD => moved successfully
C:\Documents and Settings\sheofourtris\Local Settings\Application Data\4C4C4544-1436185766-4B10-8039-C8C04F4B4831 => moved successfully
C:\Documents and Settings\sheofourtris\Application Data\6635 => moved successfully
C:\Documents and Settings\sheofourtris\Application Data\4C4C4544-1436199977-4B10-8039-C8C04F4B4831 => moved successfully
C:\Documents and Settings\Guest\Local Settings\Application Data\CrimeWatch => moved successfully
C:\Program Files\Games Bot => moved successfully
C:\Documents and Settings\All Users\Application Data\{1158b7dd-d0b8-a80b-1158-8b7ddd0bdf77} => moved successfully
C:\Documents and Settings\LocalService\Local Settings\Application Data\StormWatch => moved successfully
C:\Documents and Settings\All Users\Application Data\Browser => moved successfully
C:\Documents and Settings\All Users\Start Menu\Programs\UpdateAdmin => moved successfully
C:\Documents and Settings\All Users\Application Data\fopneeomcncoadkhijbapjiidaedkcfg => moved successfully
C:\Documents and Settings\All Users\Application Data\14e8c327e3c6ddb5 => moved successfully
C:\Documents and Settings\All Users\Application Data\1506668651448032693 => moved successfully
C:\Documents and Settings\All Users\Application Data\dnonpahagjngllclmkgiokobafojjpel => moved successfully
C:\Documents and Settings\Katie\Application Data\7148 => moved successfully
C:\Program Files\PETN => moved successfully
C:\Documents and Settings\Katie\Application Data\30865 => moved successfully
C:\Documents and Settings\All Users\Application Data\ToolGet => moved successfully
C:\Program Files\WordShark_1.10.0.19 => moved successfully
C:\Program Files\GUPlayer => moved successfully
C:\Documents and Settings\All Users\Application Data\FlashBeat => moved successfully
C:\Program Files\JavaScript Notepad => moved successfully
C:\Documents and Settings\All Users\Application Data\SharkManCoupon => moved successfully
"C:\Program Files OPTIMIZER PRO 3.79" => File/Folder not found.
C:\Documents and Settings\All Users\Application Data\AdBlocker Manger => moved successfully
C:\Program Files\SmarterPower => moved successfully
C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7 => moved successfully
C:\Program Files\Coupoon => moved successfully
C:\Documents and Settings\sheofourtris\Application Data\SmartWeb => moved successfully
C:\Documents and Settings\All Users\Application Data\731d3bff00001862 => moved successfully
C:\Program Files\RoughDraft => moved successfully
C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT => moved successfully
C:\WINDOWS\Tasks\Driver Support-RTMScan.job => moved successfully
C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT => moved successfully
C:\Program Files\AnySend => moved successfully
C:\Documents and Settings\Writing\Application Data\Nosibay => moved successfully
C:\Program Files\prefs.js => moved successfully
"C:\Program Files\BlitzMediaPlayer" => File/Folder not found.
"C:\Documents and Settings\Writing\Local Settings\Application Data\m0w0bzzvzm5hc2m" => File/Folder not found.
C:\Documents and Settings\Writing\Local Settings\Application Data\m1a0vtytzklhbmn => moved successfully
"C:\Documents and Settings\All Users\Application Data\{96af2a23-618d-7a19-96af-f2a23618a88d}" => File/Folder not found.
"c:\Program Files\BocaMonitor" => File/Folder not found.
"C:\Program Files\SoftwareForce" => File/Folder not found.
"C:\Documents and Settings\All Users\Application Data\ToolGet" => File/Folder not found.
C:\Documents and Settings\Writing\Local Settings\Application Data\UpdaterSvcSmarterPower1024 => moved successfully
C:\Program Files\Compliant Host Controller => moved successfully
 
========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
 
The operation completed successfully
 
 
========= End of Reg: =========
 
 
========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
 
The operation completed successfully
 
 
========= End of Reg: =========
 
 
========= Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F =========
 
 
The operation completed successfully
 
 
========= End of Reg: =========
 
 
========= Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F =========
 
 
The operation completed successfully
 
 
========= End of Reg: =========
 
 
========= RemoveProxy: =========
 
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\S-1-5-21-854245398-616249376-1801674531-1023\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => value removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully.
HKU\S-1-5-21-854245398-616249376-1801674531-1023\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\S-1-5-21-854245398-616249376-1801674531-1023\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully.
 
 
========= End of RemoveProxy: =========
 
 
=========  netsh advfirewall reset =========
 
The following command was not found: advfirewall reset.
 
========= End of CMD: =========
 
 
=========  netsh advfirewall set allprofiles state ON =========
 
The following command was not found: advfirewall set allprofiles state ON.
 
========= End of CMD: =========
 
 
=========  ipconfig /flushdns =========
 
 
 
Windows IP Configuration
 
 
 
Successfully flushed the DNS Resolver Cache.
 
 
========= End of CMD: =========
 
 
=========  netsh winsock reset catalog =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the machine in order to complete the reset.
 
 
========= End of CMD: =========
 
 
=========  netsh int ip reset c:\resetlog.txt =========
 
 
 
========= End of CMD: =========
 
 
=========  ipconfig /release =========
 
 
 
Windows IP Configuration
 
 
 
No operation can be performed on Local Area Connection 2 while it has its media disconnected.
 
 
 
Ethernet adapter Local Area Connection 2:
 
 
 
        Media State . . . . . . . . . . . : Media disconnected
 
 
 
Ethernet adapter Wireless Network Connection 2:
 
 
 
        Connection-specific DNS Suffix  . : 
 
        IP Address. . . . . . . . . . . . : 0.0.0.0
 
        Subnet Mask . . . . . . . . . . . : 0.0.0.0
 
        Default Gateway . . . . . . . . . : 
 
 
========= End of CMD: =========
 
 
=========  ipconfig /renew =========
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
# AdwCleaner v5.003 - Logfile created 26/08/2015 at 12:02:20
# Updated 20/08/2015 by Xplode
# Database : 2015-08-25.1 [Server]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : Writing - D620
# Running from : C:\Documents and Settings\Writing\Desktop\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
Service Found : netfilter
Service Found : sbmntr
Service Found : d51c1198
 
***** [ Folders ] *****
 
Folder Found : C:\CrimeWatch
Folder Found : C:\Documents and Settings\All Users\Application Data\Conduit
Folder Found : C:\Documents and Settings\All Users\Application Data\Trusted Publisher
Folder Found : C:\Documents and Settings\All Users\Application Data\Video Converter
Folder Found : C:\Documents and Settings\All Users\Application Data\Driver Support
Folder Found : C:\Documents and Settings\All Users\Application Data\Fun2Save
Folder Found : C:\Documents and Settings\All Users\Application Data\USTechSupport
Folder Found : C:\Documents and Settings\All Users\Application Data\ToolGets
Folder Found : C:\Documents and Settings\All Users\Application Data\ExStrraSavIngs
Folder Found : C:\Documents and Settings\All Users\Application Data\RRoboSavErr
Folder Found : C:\Documents and Settings\All Users\Application Data\2b1a347b00004cda
Folder Found : C:\Documents and Settings\All Users\Application Data\78ac854400001119
Folder Found : C:\Documents and Settings\All Users\Application Data\846087de0000350b
Folder Found : C:\Documents and Settings\All Users\Start Menu\Programs\GAMESDESKTOP
Folder Found : C:\Documents and Settings\Guest\Local Settings\Application Data\Crossbrowse
Folder Found : C:\Documents and Settings\Guest\Local Settings\Application Data\Crossbrowse
Folder Found : C:\Documents and Settings\Katie\Application Data\ap_logs
Folder Found : C:\Documents and Settings\Katie\Application Data\wse_astromenda
Folder Found : C:\Documents and Settings\Katie\Application Data\SmartWeb
Folder Found : C:\Documents and Settings\Katie\Application Data\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Found : C:\Documents and Settings\Katie\Local Settings\Application Data\BlitzMediaPlayer
Folder Found : C:\Documents and Settings\Katie\Local Settings\Application Data\globalUpdate
Folder Found : C:\Documents and Settings\Katie\Local Settings\Application Data\RocketTab
Folder Found : C:\Documents and Settings\Katie\Local Settings\Application Data\Crossbrowse
Folder Found : C:\Documents and Settings\Katie\Local Settings\Application Data\PC_Drivers_Headquarters
Folder Found : C:\Documents and Settings\Katie\Local Settings\Application Data\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Found : C:\Documents and Settings\Katie\Local Settings\Application Data\Crossbrowse
Folder Found : C:\Documents and Settings\sheofourtris\Application Data\AnyProtectEx
Folder Found : C:\Documents and Settings\sheofourtris\Application Data\Nosibay
Folder Found : C:\Documents and Settings\sheofourtris\Application Data\Store
Folder Found : C:\Documents and Settings\sheofourtris\Application Data\WTools
Folder Found : C:\Documents and Settings\sheofourtris\Application Data\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Found : C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
Folder Found : C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\Extensions\[email protected]
Folder Found : C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\Extensions\[email protected]
Folder Found : C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\Extensions\[email protected]
Folder Found : C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\Extensions\[email protected]
Folder Found : C:\Documents and Settings\sheofourtris\Local Settings\Application Data\globalUpdate
Folder Found : C:\Documents and Settings\sheofourtris\Local Settings\Application Data\SearchProtect
Folder Found : C:\Documents and Settings\sheofourtris\Local Settings\Application Data\Consumer Input
Folder Found : C:\Documents and Settings\sheofourtris\Local Settings\Application Data\Crossbrowse
Folder Found : C:\Documents and Settings\sheofourtris\Local Settings\Application Data\Storm_Warnings,_LLC
Folder Found : C:\Documents and Settings\sheofourtris\Local Settings\Application Data\StormWarnings
Folder Found : C:\Documents and Settings\sheofourtris\Local Settings\Application Data\Crossbrowse
Folder Found : C:\Documents and Settings\sheofourtris\Start Menu\Programs\YTDownloader
Folder Found : C:\Documents and Settings\sheofourtris\Start Menu\Programs\StormWarnings
Folder Found : C:\Documents and Settings\Trial\Application Data\SmartWeb
Folder Found : C:\Documents and Settings\Trial\Local Settings\Application Data\SearchProtect
Folder Found : C:\Documents and Settings\Writing\Application Data\Store
Folder Found : C:\Documents and Settings\Writing\Application Data\SmartWeb
Folder Found : C:\Documents and Settings\Writing\Application Data\WTools
Folder Found : C:\Documents and Settings\Writing\Application Data\Mozilla\Firefox\Profiles\a3kwoyon.default\Extensions\[email protected]
Folder Found : C:\Documents and Settings\Writing\Application Data\Mozilla\Firefox\Profiles\a3kwoyon.default\Extensions\[email protected]
Folder Found : C:\Documents and Settings\Writing\Application Data\Mozilla\Firefox\Profiles\a3kwoyon.default\Extensions\[email protected]
Folder Found : C:\Documents and Settings\Writing\Application Data\Mozilla\Firefox\Profiles\a3kwoyon.default\Extensions\[email protected]
Folder Found : C:\Documents and Settings\Writing\Application Data\Mozilla\Firefox\Profiles\a3kwoyon.default\Extensions\[email protected]
Folder Found : C:\Documents and Settings\Writing\Local Settings\Application Data\globalUpdate
Folder Found : C:\Documents and Settings\Writing\Local Settings\Application Data\SearchProtect
Folder Found : C:\Documents and Settings\Writing\Local Settings\Application Data\Consumer Input
Folder Found : C:\Documents and Settings\Writing\Local Settings\Application Data\Crossbrowse
Folder Found : C:\Documents and Settings\Writing\Local Settings\Application Data\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Found : C:\Documents and Settings\Writing\Local Settings\Application Data\Crossbrowse
Folder Found : C:\Documents and Settings\Writing\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bmnlcpaleflcfihmhcehcbmpknjjfcho
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\globalUpdate
Folder Found : C:\Program Files\LinkSwift
Folder Found : C:\Program Files\predm
Folder Found : C:\Program Files\YTDownloader
Folder Found : C:\Program Files\Driver Support
Folder Found : C:\Program Files\DeltaFix
Folder Found : C:\Program Files\Crossbrowse
Folder Found : C:\Program Files\StormWarnings
Folder Found : C:\Program Files\USTechSupport
Folder Found : C:\Program Files\ExStrraSavIngs
Folder Found : C:\Program Files\RRoboSavErr
Folder Found : C:\Program Files\Saovernet
Folder Found : C:\Program Files\SaVVerrPro
Folder Found : C:\Program Files\Infonaut_1.10.0.14
Folder Found : C:\Program Files\Crossbrowse
Folder Found : C:\Program Files\Optimizer Pro 3.79
Folder Found : C:\Program Files\Common Files\Goobzo
Folder Found : C:\Program Files\Common Files\Software Update Utility
Folder Found : C:\Program Files\Common Files\USTechSupport
Folder Found : C:\WINDOWS\system32\ARFC
Folder Found : C:\WINDOWS\system32\Browser
Folder Found : C:\WINDOWS\system32\jmdp
Folder Found : C:\WINDOWS\system32\WNLT
 
***** [ Files ] *****
 
File Found : C:\user.js
File Found : C:\Documents and Settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_adobe-photoshop.en.softonic.com_0.localstorage
File Found : C:\Documents and Settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_adobe-photoshop.en.softonic.com_0.localstorage-journal
File Found : C:\Documents and Settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_en.softonic.com_0.localstorage
File Found : C:\Documents and Settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_en.softonic.com_0.localstorage-journal
File Found : C:\Documents and Settings\Katie\Application Data\aps.uninstall.scan.results
File Found : C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\user.js
File Found : C:\Documents and Settings\Writing\Application Data\Microsoft\Internet Explorer\Quick Launch\Knctr.lnk
File Found : C:\Documents and Settings\Writing\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage
File Found : C:\Documents and Settings\Writing\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal
File Found : C:\Documents and Settings\Writing\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_www.plusnetwork.com_0.localstorage
File Found : C:\Documents and Settings\Writing\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_www.plusnetwork.com_0.localstorage-journal
File Found : C:\Program Files\Common Files\System\SysMenu.dll
File Found : C:\WINDOWS\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
File Found : C:\WINDOWS\AppPatch\nbin\VC32Loader.dll
File Found : C:\WINDOWS\rcore.exe
File Found : C:\WINDOWS\system32\ImhxxpComm.dll
File Found : C:\WINDOWS\system32\drivers\netfilter.sys
 
***** [ Shortcuts ] *****
 
Shortcut Infected : C:\Documents and Settings\All Users\Desktop\Opera.lnk ( hxxp://www-searching.com/?pid=s&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,&pi=2 )
Shortcut Infected : C:\Documents and Settings\sheofourtris\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www-searching.com/?pid=s&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,&pi=2 )
Shortcut Infected : C:\Documents and Settings\Writing\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk ( hxxp://www-searching.com/?pid=s&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,&pi=2 )
 
***** [ Scheduled tasks ] *****
 
Task Found : Driver Support-RTMRules
Task Found : Driver Support-RTMScanRunOnce
Task Found : Driver Support-RTMUpdater
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Key Found : HKLM\SOFTWARE\Classes\dnUpdate
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Found : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Key Found : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Key Found : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Key Found : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Key Found : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Key Found : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\YTDownloader.exe
Key Found : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SysMenuExt
Key Found : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
Key Found : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5}
Key Found : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
Key Found : HKLM\SOFTWARE\1a941341-01f3-977c-83a5-09c10da64108
Key Found : HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-137048081
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Found : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Found : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Found : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9C81D00A-3DAA-48AB-90C7-8252119ABB93}
Key Found : HKLM\SOFTWARE\Classes\AppID\{1DA17428-323D-48FF-857C-98CFEE48BFD5}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
Key Found : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Found : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Found : HKLM\SOFTWARE\Classes\Interface\{02F878DF-E2BE-4B85-8CB4-A0D2D4E2ED7F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2AF343DD-3102-4F9D-AC95-DCA4C95382C7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3137BC14-D8D7-4B67-8FFA-2E0B2E9D541B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4CA2AC92-971B-47B1-ACB6-357B552155AC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{52C5395B-1FCD-47FA-A834-FD830701C2D5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5D3DCC39-9233-4330-94E9-DA92BE49CA1A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{615FACDF-DADB-440D-AC91-8AAB0AE9E3AD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{762D463B-C45A-456D-A80D-8689C297C91E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7A6BE473-7960-44D0-BD54-D23DA76353DF}
Key Found : HKLM\SOFTWARE\Classes\Interface\{803F550E-BAAE-42BB-8917-64BA0006AB17}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8D5BC51D-C9D3-43B9-B728-B30677B7C7E8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{991C9D8D-A789-4DB9-BDFC-5F33398B04BF}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A5ACC874-D943-483F-A2D1-14598D51F872}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B0474212-0D9D-4361-90B3-B89D1A44275D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BFDE183A-C6FE-41D2-80F9-586C29210AC2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D83C83BF-3EDD-4410-ADAB-5295116DD8C7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DD260902-9420-4055-A956-9152EB4F3E6A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EB1F9F3C-5526-4DAE-BD4B-3EAA7715DA9F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F1912128-469A-4138-AA26-9699C15BB13E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F68DC16C-9C2B-455B-8853-7E4D34BAA3F4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FBA8498F-B3A0-4942-A2BF-E0CB7BC7E000}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9AE7A6AE-162E-44C4-9A2B-A6B4EF19909D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{99E29823-2F67-41C3-8AA5-6425097A771F}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{14EF423E-3EE8-44AE-9337-07AC3F27B744}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{33B8CF8E-1B37-40DD-A652-F97EDFCA9565}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{532ECD0F-E6C9-4ACE-860A-3730B1F6F1DD}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A63C49A5-6CC1-4579-A883-AE6B3E91108D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{FDA3E1DF-B9C8-4A1A-A646-58E5E01520E4}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKU\.DEFAULT\Software\ImInstaller
Key Found : HKU\.DEFAULT\Software\WNLT
Key Found : HKU\.DEFAULT\Software\DownloadAdmin
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\Store
Key Found : HKCU\Software\Tutorials
Key Found : HKCU\Software\SmartWeb
Key Found : HKCU\Software\YTDownloader
Key Found : HKCU\Software\WTools
Key Found : HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\Crossrider
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKLM\SOFTWARE\NpApp
Key Found : HKLM\SOFTWARE\TBID
Key Found : HKLM\SOFTWARE\WNLT
Key Found : HKLM\SOFTWARE\YTDownloader
Key Found : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Key Found : HKLM\SOFTWARE\SearchModule
Key Found : HKLM\SOFTWARE\WebBar
Key Found : HKLM\SOFTWARE\Universal
Key Found : HKLM\SOFTWARE\Hades
Key Found : HKLM\SOFTWARE\DAILYPCCLEAN
Key Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Uninstall\StormWatch
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2D471A31-4FA7-95BA-1880-D441113ED736}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{614925F9-841A-53FE-A28F-DC30FA07239B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YTDownloader
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B138259A-351E-33FA-2726-8D71704F1DA9}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BE360B8B-0F10-CA89-FC84-A5EAB71A6AF8}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{532970A2-464B-73CB-BBC4-F209EAD3EEBE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hades
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9D9BEFAE-9499-F52B-6CC4-94818CCC2AB5}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\windapp
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Selection Tools
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{ac225167-00fc-452d-94c5-bb93600e7d9a}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Optimizer Pro_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RocketTab
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ShopperPro
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdater
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\VOPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WNLT
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ConvertAd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SmartWeb
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Super Optimizer_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\YTDownloader
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{3119AFD3-545C-0955-573A-494F62E61990}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\wincheck
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Consumer Input Installer
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Positive Finds
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ASPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Search module
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{E1527582-8509-4011-B922-29E3FB548882}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ge-Force
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Hades
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DesktopSearch
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{07B4B423-E4DA-47D1-8327-B589EB4BEB58}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{49F8B4F8-0CD4-4BE4-A9E8-B13A071F7C90}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\StormWarnings
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\FriendlyError
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DailyPCClean_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Infonaut_1.10.0.14
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\324B4B70AD4E1D7438725B98BEB4BE85
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\324B4B70AD4E1D7438725B98BEB4BE85
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\324B4B70AD4E1D7438725B98BEB4BE85
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4
 
***** [ Web browsers ] *****
 
[C:\Documents and Settings\Katie\Application Data\Mozilla\Firefox\Profiles\r82nntth.default-1436292070156\prefs.js] [Preference] Found : user_pref("extensions.crossrider.bic", "14e7b0bbcbda95150f9eafef077cdf6b");
[C:\Documents and Settings\Katie\Application Data\Mozilla\Firefox\Profiles\r82nntth.default-1436292070156\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxp://www-searching.com/search.aspx?site=shdefault&pid=s&shr=d&q={searchTerms}&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,");
[C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\prefs.js] [Preference] Found : user_pref("extensions.44ieVHsYcg4RaOT8.scode", "(function(){try{if(window.location.href.indexOf(\"qdg5qTnEqdkEpjY8rTY6qdUGrE\")>-1){return;}}catch(e){}try{var d=[[\"www.ewoss.com\",\"livewebcams.xyz\"[...]
[C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\prefs.js] [Preference] Found : user_pref("extensions.aTTSD90021300PYDKGV101145942com70881.70881.internaldb.Resources_meta.value", "%7B%22handlebars.js%22%3A%7B%22id%22%3A1002241%2C%22ver%22%3A1%2C%22status%22%3A1%2C%22name%22%3A%22[...]
[C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\prefs.js] [Preference] Found : user_pref("extensions.aTTSD90021300PYDKGV101145942com70881.70881.internaldb.Resources_resource_1002250.value", "%22function%20startAskCom%28e%2Ct%2Cr%29%7Bfunction%20a%28e%29%7Bvar%20t%3Dnew%20RegExp%[...]
[C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\prefs.js] [Preference] Found : user_pref("extensions.aTTSD90021300PYDKGV101145942com70881.70881.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%3[...]
[C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\prefs.js] [Preference] Found : user_pref("extensions.crossrider.bic", "14e690df60555f557d71e8fdcfad0b66");
[C:\Documents and Settings\sheofourtris\Application Data\Mozilla\Firefox\Profiles\8abyd4nr.default\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxp://www-searching.com/search.aspx?site=shdefault&pid=s&shr=d&q={searchTerms}&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,");
[C:\Documents and Settings\Writing\Application Data\Mozilla\Firefox\Profiles\a3kwoyon.default\prefs.js] [Preference] Found : user_pref("extensions.crossrider.bic", "14e8d2f049069bdef199237d7a24e29c");
[C:\Documents and Settings\Writing\Application Data\Mozilla\Firefox\Profiles\a3kwoyon.default\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxp://www-searching.com/search.aspx?site=shdefault&pid=s&shr=d&q={searchTerms}&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,");
[C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\hbf8typt.default\prefs.js] [Preference] Found : user_pref("extensions.J41luQ3dWXPrYCd0.scode", "(function(){try{if(window.location.href.indexOf(\"qdg5qTnEqdkEpjY8rTY6qdUGrE\")>-1){return;}}catch(e){}try{var d=[[\"investkingdom.com\",\"www.viracure.[...]
[C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\hbf8typt.default\prefs.js] [Preference] Found : user_pref("extensions.KuAJqq7y8wpkT2qt.scode", "(function(){try{if(window.location.href.indexOf(\"qdg5qTnEqdkEpjY8rTY6qdUGrE\")>-1){return;}}catch(e){}try{var d=[[\"investkingdom.com\",\"www.viracure.[...]
[C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\hbf8typt.default\prefs.js] [Preference] Found : user_pref("extensions.W5i26V0TZdwlelvp.scode", "(function(){try{if(window.location.href.indexOf(\"qdg5qTnEqdkEpjY8rTY6qdUGrE\")>-1){return;}}catch(e){}try{var d=[[\"investkingdom.com\",\"www.viracure.[...]
[C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\hbf8typt.default\prefs.js] [Preference] Found : user_pref("extensions.jjLG18PRARZJiITe.scode", "(function(){try{if(window.location.href.indexOf(\"qdg5qTnEqdkEpjY8rTY6qdUGrE\")>-1){return;}}catch(e){}try{var d=[[\"investkingdom.com\",\"www.viracure.[...]
[C:\Documents and Settings\Katie\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Documents and Settings\Katie\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Documents and Settings\Katie\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com
[C:\Documents and Settings\Katie\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Found : hxxp://www-searching.com/search.aspx?site=shdefault&pid=s&shr=d&q={searchTerms}&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,
[C:\Documents and Settings\Katie\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Found : hxxp://www-searching.com/?pid=s&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,
[C:\Documents and Settings\Katie\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://www-searching.com/?pid=s&s=F77ztutdk0001,c8ac14aa-5d80-478b-926f-2e83e5b049c9,
[C:\Documents and Settings\sheofourtris\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Documents and Settings\sheofourtris\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Documents and Settings\sheofourtris\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com
[C:\Documents and Settings\Writing\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Documents and Settings\Writing\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Documents and Settings\Writing\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com
[C:\Documents and Settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Documents and Settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [31711 bytes] ##########
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.7 (08.18.2015:1)
OS: Microsoft Windows XP x86
Ran by Administrator on Wed 08/26/2015 at 12:10:39.76
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
Successfully deleted: [Service] ustsscheduler [Reboot required]
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update SmarterPower
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update ViewPlay
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util ViewPlay
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\338.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\339.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\33A.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\33B.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\340.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\341.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\343.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\355.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\awh4.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\awh5.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\awhA.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\awhB.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\awhD.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\awhE.tmp [TDL4 Trace]
Successfully deleted: [File] C:\Documents and Settings\All Users\Microsoft\DRM\awhF.tmp [TDL4 Trace]
Successfully deleted: [File] C:\WINDOWS\System32\drivers\innfd_1_10_0_14.sys
Successfully deleted: [File] C:\WINDOWS\System32\drivers\wsfd_1_10_0_19.sys
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] C:\Program Files\browse~2
Successfully deleted: [Folder] C:\WINDOWS\provider
Successfully deleted: [Folder] C:\Program Files\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602
 
 
 
~~~ Chrome
 
 
[C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 08/26/2015 at 12:12:55.70
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
 
 

  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK that is most of the rubbish removed, sometimes the drivers I remove play awkward

After this next step could you let me know how the computer is behaving

There are free antivirus programmes :)

Please download Malwarebytes Anti-Malware to your desktop
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Ensure that "Enable free trial of Malwarebytes Anti-Malware Premium" is unchecked
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
  • Reboot your computer if prompted.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

To access logs from Malwarebytes Anti-Malware 2.0:

mbamlogs.JPG

1.Open Malwarebytes Anti-Malware 2.0
2.Click History > Application Logs
3.Double-click the log you would like to open

Scan Logs record detections from manual scans, including threats detected and the actions taken against them

To save a Scan Log:

1.Open the log file you would like to save
2.Click Export
3.Choose to export to a .txt
4.Choose a folder to save the log file in, then click Save
5.Post that log here

THEN
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select additions at the bottom
  • Press Scan button.
    frst.JPG
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please attach both logs generated.

  • 0

#5
kat3lr

kat3lr

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts

As of now, my laptop is behaving absolutely fine. No crashing, popups, bluescreens, none of it!

 

I also apologize for the delayed reply, the Malawarebites scan took a while.

 

Attached File  FRST.txt   25.6KB   84 downloads

 

Attached File  Addition.txt   41.1KB   116 downloads

 

Attached File  MBAM scan.txt   94.4KB   95 downloads

Attached Files


  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
You have a lot of users on the system... do you need them all ?
 

Kat3lr (S-1-5-21-854245398-616249376-1801674531-1020 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Kat3lr
Katie (S-1-5-21-854245398-616249376-1801674531-1016 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Katie
sheofourtris (S-1-5-21-854245398-616249376-1801674531-1022 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\sheofourtris
SophosSAUD6200 (S-1-5-21-854245398-616249376-1801674531-1010 - Limited - Enabled)
SUPPORT_388945a0 (S-1-5-21-854245398-616249376-1801674531-1002 - Limited - Disabled)
Trial (S-1-5-21-854245398-616249376-1801674531-1024 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Trial
Writing (S-1-5-21-854245398-616249376-1801674531-1023 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Writing


Looks like we have now killed it all, one further quick run to remove some firewall settings

Have you thought about an antivirus ?

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint:
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
  • 1

#7
kat3lr

kat3lr

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts

Would Avast be an alright antivirus software? I use the mobile versions on my android tablet, but my uncle has been against me using it for my laptop?

 

Fix result of Farbar Recovery Scan Tool (x86) Version:24-08-2015
Ran by Writing (2015-08-26 16:22:56) Run:3
Running from C:\Documents and Settings\Writing\Desktop
Loaded Profiles: Writing (Available Profiles: Kat3lr & sheofourtris & Writing & Administrator & Guest)
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
*****************
 
Restore point was successfully created.
 
========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
 
The operation completed successfully
 
 
========= End of Reg: =========
 
 
========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
 
The operation completed successfully
 
 
========= End of Reg: =========
 
 
==== End of Fixlog 16:23:06 ====

  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
I can give you a look at how to set Avast up on the system and you could then try it for a week, if you do not like it uninstall it :)

How to set up a reasonable and light security regime for your system. All elements are install and forget.

DOWNLOAD AND INSTALL ANTIVIRUS

Download Avast - direct link Avast 2015

Select Custom install
Remove the ticks from the first page for the following unless you want them :
avastchrome.JPG
Dropbox
Chrome
Chrome toolbar


Select Next
Deselect the following from the middle column as you will not need them :
avasttools.JPG
SecureLine
Cleanup


Select Continue and allow the programme to install

Be aware that the first reboot may take a few minutes as Avast builds the virtual machine

Avast will need to be registered as this helps them determine the server load, as updates are downloaded in small bursts every few minutes each is about 2Kb

How to register

Right click the Avast orange blob on the task bar
Select registration
Select Standard Protection
avast%20register1.JPG
Fill in your e-mail address
avast%20register2.JPG
Click register with e-mail address and you are done
Once registered open Avast
Go to Settings > General
Place a tick in "Scan for Potentially Unwanted Programmes (PUP's) "
Place a tick in "Silent /Gaming mode"
pups.JPG


PROTECT AGAINST UNWANTED BUNDLED SOFTWARE

Unchecky

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder
Right click on the Unchecky_setup and choose to Run as Administrator
Once open click the Install button.
Then click on Finish
unchecky.JPG
Unchecky is now installed and will help you keep unwanted check boxes unchecked, this is a fire and forget programme ;)

IF YOU USE USB DRIVES

Download MCShield to your desktop and install
It will initially run a scan and show the result as a toaster by the system clock
Then in the control centre select scanner and tick unhide items on flash drives
mcshield%20unhide.JPG
Plug in the drive and McShield will start a scan
  • 1

#9
kat3lr

kat3lr

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts

Thank you so much! 

My computer is working perfectly fine now.


  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Remove tools

Download and run Delfix
Select the options as shown
delfix.JPG


: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article

I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

If you do need to keep Java then download JavaRa
Run the programme and select Remove Java Runtime. Uninstall all versions of Java present
Once done then run it again and select Update Java runtime > Download and install Latest version
javara.JPG


Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Malwarebytes

Update and run weekly to keep your system clean

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe :wave:
  • 0

#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.


  • 0






Similar Topics


Also tagged with one or more of these keywords: bad image, malaware, windows xp

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP