Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Possible malware; search program changes, tower not shutting down [Sol


  • This topic is locked This topic is locked

#1
jbcteacher

jbcteacher

    Member

  • Member
  • PipPipPip
  • 206 posts

Hello!  I'm helping my neighbor who is experiencing computer issues.  Several times he thought he was using google chrome, only to find out it was a different search program.  Sometimes double pop up screens would open while he was using the computer.

 

The tower no longer shuts down correctly, the power buttons flash non stop but the monitor slows down.  He also states the machine doesn't work as quickly as it did.

 

Pinned icons also disappear.

 

Any help would be appreciated - Joanne

 

Here is the FRST log:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by Tony (administrator) on TONY-PC (29-06-2018 17:07:26)
Running from C:\Users\Tony\Desktop
Loaded Profiles: Tony (Available Profiles: Tony)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(© 2015 Microsoft Corporation) C:\Users\Tony\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Acer Incorporated) C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
() C:\Windows\SysWOW64\spdsvc.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11580520 2010-11-10] (Realtek Semiconductor)
HKLM\...\Run: [ALU] => C:\Program Files\eMachines\eMachines Updater\ALU.exe [2379056 2017-04-21] (Acer Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10290608 2018-02-07] (Piriform Ltd)
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\Run: [EEDSpeedLauncher] => rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\Run: [BingSvc] => C:\Users\Tony\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2017-12-26] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-13] (Microsoft Corporation)
CHR HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{1414AF8B-1600-4411-BA4E-9DC0DEB26D74}: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{ED8D445D-0FF9-4114-AD17-8AAC465245EC}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=hp-avast&type=agc511
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://www.quafind.com/
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AEMTDF&pc=MAEM&src=IE-SearchBox
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AEMTDF&pc=MAEM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> DefaultScope {DD73391C-88AA-4758-A44B-0332D32FB5B4} URL = hxxp://search.hquickmapsanddirections.com/s?uc=20180619&i_id=maps_spt__1.30&ap=appfocus1&uid=5832f5a9-61b8-4eae-81dd-fc6f1239daaa&source=d-ccc6-lp0-bb8&query={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=U453DF&PC=U453&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {34D82E9A-0675-4E5B-AC8A-0B6FE895141F} URL = hxxps://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {4B63626E-741B-4776-972F-A77742705792} URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {7A8B4688-548A-4996-88E4-B6111E121D2A} URL = hxxps://search.yahoo.com/search?ei=utf-8&fr=befds&p={searchTerms}&type=ieds-4.7-1706
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {8899C699-593C-4A8D-AE8A-DF99C9282907} URL = hxxps://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {A1032D92-6A87-46FF-A15C-AC0E56FE4B14} URL = hxxp://isearch.shopathome.com?user_id={6F914F5F-E315-4177-9E84-FC4B089A2094}&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxps://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {DD73391C-88AA-4758-A44B-0332D32FB5B4} URL = hxxp://search.hquickmapsanddirections.com/s?uc=20180619&i_id=maps_spt__1.30&ap=appfocus1&uid=5832f5a9-61b8-4eae-81dd-fc6f1239daaa&source=d-ccc6-lp0-bb8&query={searchTerms}
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
 
FireFox:
========
FF DefaultProfile: 5zgxxirw.default
FF ProfilePath: C:\Users\Tony\AppData\Roaming\TomTom\HOME\Profiles\tk8eoaie.default [2018-05-27]
FF Extension: (No Name) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\[email protected] [not found]
FF ProfilePath: C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\5zgxxirw.default [2018-06-29]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_30_0_0_113.dll [2018-06-07] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_113.dll [2018-06-07] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1229199.dll [2017-03-31] (Adobe Systems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-14] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-05-10] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR HomePage: Default -> msn.com
CHR NewTab: Default ->  Not-active:"chrome-extension://docbdkefdologaagieallljeedjpdlfk/newtab/slim_newtabpage.html", Not-active:"chrome-extension://aggobjdbghchcnapfoplmgekgjipjlke/newtabproduct.html"
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSuggestURL: Default -> hxxp://www.bing.com/osjson.aspx?FORM=__PARAM__DF&PC=__PARAM__&query={searchTerms}
CHR Profile: C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default [2018-06-29]
CHR Extension: (Slides) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-27]
CHR Extension: (OnlineRouteFinder) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aggobjdbghchcnapfoplmgekgjipjlke [2018-05-27]
CHR Extension: (Docs) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-27]
CHR Extension: (Google Drive) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-17]
CHR Extension: (YouTube) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-17]
CHR Extension: (Easy File Converter) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\docbdkefdologaagieallljeedjpdlfk [2018-06-23]
CHR Extension: (Bing) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2018-05-27]
CHR Extension: (Sheets) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-27]
CHR Extension: (Google Docs Offline) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-05-27]
CHR Extension: (Scanguard Safe Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkljlnkimgcfmiklhilenokeckdiiepf [2018-05-27]
CHR Extension: (Ask Web Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgfehfbnofiffladdncogfobimealokp [2018-05-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-27]
CHR Extension: (Gmail) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-03-17]
CHR Extension: (Chrome Media Router) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-09]
CHR HKLM\...\Chrome\Extension: [kkljlnkimgcfmiklhilenokeckdiiepf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kkljlnkimgcfmiklhilenokeckdiiepf] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 GREGService; C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe [36456 2011-05-29] (Acer Incorporated)
R2 Live Updater Service; C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [257440 2016-06-08] (Acer Incorporated)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 Samsung Printer Dianostics Service; C:\Windows\SysWOW64\\spdsvc.exe [498488 2016-04-01] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 ElRawDisk; C:\Windows\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
S3 ssmirrdr; C:\Windows\System32\DRIVERS\ssmirrdr.sys [10112 2014-01-09] (support.com, Inc)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13920 2017-08-31] ()
R3 WNDA3100v3; C:\Windows\System32\DRIVERS\WNDA3100v3.sys [2225808 2014-12-08] (MediaTek Inc.)
S3 cpuz134; \??\C:\Users\Tony\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] <==== ATTENTION
S1 ESProtectionDriver; \??\C:\Windows\system32\drivers\mbae64.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-06-29 17:07 - 2018-06-29 17:07 - 000015918 _____ C:\Users\Tony\Desktop\FRST.txt
2018-06-29 17:06 - 2018-06-29 17:07 - 000000000 ____D C:\FRST
2018-06-29 16:57 - 2018-06-29 16:58 - 002412544 _____ (Farbar) C:\Users\Tony\Desktop\FRST64.exe
2018-06-25 11:21 - 2018-06-25 11:22 - 029720784 _____ (Microsoft Corporation) C:\Users\Tony\Downloads\IE11-Windows6.1-x86-en-us.exe
2018-06-23 08:41 - 2018-06-23 08:42 - 055915216 _____ (Microsoft Corporation) C:\Users\Tony\Downloads\IE11-Windows6.1-x64-en-us.exe
2018-06-20 11:07 - 2018-06-20 11:07 - 000858702 _____ C:\Users\Tony\Downloads\finance - Google Search.html
2018-06-19 18:39 - 2018-06-19 18:39 - 000000000 ____D C:\Users\Tony\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}
2018-06-13 16:28 - 2018-05-29 16:36 - 000396960 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-06-13 16:28 - 2018-05-29 15:40 - 000348824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-06-13 16:28 - 2018-05-28 22:43 - 000631640 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-06-13 16:28 - 2018-05-28 22:41 - 005577408 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-06-13 16:28 - 2018-05-28 22:41 - 000708288 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-06-13 16:28 - 2018-05-28 22:41 - 000262336 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-06-13 16:28 - 2018-05-28 22:41 - 000154816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-06-13 16:28 - 2018-05-28 22:41 - 000095424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-06-13 16:28 - 2018-05-28 22:35 - 001665336 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 004050624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-06-13 16:28 - 2018-05-28 22:32 - 003962048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-06-13 16:28 - 2018-05-28 22:32 - 001461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 001211904 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:25 - 001314064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:03 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-06-13 16:28 - 2018-05-28 22:03 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-06-13 16:28 - 2018-05-28 22:03 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-06-13 16:28 - 2018-05-28 22:03 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-06-13 16:28 - 2018-05-28 22:03 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-06-13 16:28 - 2018-05-28 21:59 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-06-13 16:28 - 2018-05-28 21:59 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-06-13 16:28 - 2018-05-28 21:59 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-06-13 16:28 - 2018-05-28 21:59 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-06-13 16:28 - 2018-05-28 21:59 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-06-13 16:28 - 2018-05-28 21:59 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-06-13 16:28 - 2018-05-28 21:59 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-06-13 16:28 - 2018-05-28 21:58 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-06-13 16:28 - 2018-05-28 21:58 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 21:58 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 21:58 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 21:58 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 21:56 - 000160256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-06-13 16:28 - 2018-05-28 21:55 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-06-13 16:28 - 2018-05-28 21:55 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-06-13 16:28 - 2018-05-28 21:54 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-06-13 16:28 - 2018-05-28 21:54 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-06-13 16:28 - 2018-05-28 20:04 - 000634272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-06-13 16:28 - 2018-05-25 01:10 - 025742848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-06-13 16:28 - 2018-05-25 00:59 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-06-13 16:28 - 2018-05-25 00:59 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-06-13 16:28 - 2018-05-25 00:46 - 002902016 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-06-13 16:28 - 2018-05-25 00:45 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-06-13 16:28 - 2018-05-25 00:44 - 000578048 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-06-13 16:28 - 2018-05-25 00:44 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-06-13 16:28 - 2018-05-25 00:44 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-06-13 16:28 - 2018-05-25 00:43 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-06-13 16:28 - 2018-05-25 00:38 - 005779968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-06-13 16:28 - 2018-05-25 00:37 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-06-13 16:28 - 2018-05-25 00:36 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-06-13 16:28 - 2018-05-25 00:34 - 020286976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-06-13 16:28 - 2018-05-25 00:33 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-06-13 16:28 - 2018-05-25 00:32 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-06-13 16:28 - 2018-05-25 00:32 - 000794624 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-06-13 16:28 - 2018-05-25 00:32 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-06-13 16:28 - 2018-05-25 00:32 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-06-13 16:28 - 2018-05-25 00:28 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-06-13 16:28 - 2018-05-25 00:24 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-06-13 16:28 - 2018-05-25 00:21 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-06-13 16:28 - 2018-05-25 00:16 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-06-13 16:28 - 2018-05-25 00:16 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-06-13 16:28 - 2018-05-25 00:15 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-06-13 16:28 - 2018-05-25 00:15 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-06-13 16:28 - 2018-05-25 00:14 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-06-13 16:28 - 2018-05-25 00:14 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-06-13 16:28 - 2018-05-25 00:14 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-06-13 16:28 - 2018-05-25 00:13 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-06-13 16:28 - 2018-05-25 00:12 - 002295296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-06-13 16:28 - 2018-05-25 00:10 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-06-13 16:28 - 2018-05-25 00:10 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-06-13 16:28 - 2018-05-25 00:09 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-06-13 16:28 - 2018-05-25 00:08 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-06-13 16:28 - 2018-05-25 00:08 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-06-13 16:28 - 2018-05-25 00:07 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-06-13 16:28 - 2018-05-25 00:06 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-06-13 16:28 - 2018-05-25 00:06 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-06-13 16:28 - 2018-05-25 00:05 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-06-13 16:28 - 2018-05-25 00:05 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-06-13 16:28 - 2018-05-24 23:57 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-06-13 16:28 - 2018-05-24 23:57 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-06-13 16:28 - 2018-05-24 23:55 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-06-13 16:28 - 2018-05-24 23:55 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-06-13 16:28 - 2018-05-24 23:53 - 015283200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-06-13 16:28 - 2018-05-24 23:53 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-06-13 16:28 - 2018-05-24 23:53 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-06-13 16:28 - 2018-05-24 23:52 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-06-13 16:28 - 2018-05-24 23:52 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-06-13 16:28 - 2018-05-24 23:51 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-06-13 16:28 - 2018-05-24 23:49 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-06-13 16:28 - 2018-05-24 23:48 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-06-13 16:28 - 2018-05-24 23:47 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-06-13 16:28 - 2018-05-24 23:45 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-06-13 16:28 - 2018-05-24 23:42 - 004496896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-06-13 16:28 - 2018-05-24 23:40 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-06-13 16:28 - 2018-05-24 23:39 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-06-13 16:28 - 2018-05-24 23:39 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-06-13 16:28 - 2018-05-24 23:38 - 013679616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-06-13 16:28 - 2018-05-24 23:38 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-06-13 16:28 - 2018-05-24 23:37 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-06-13 16:28 - 2018-05-24 23:29 - 001546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-06-13 16:28 - 2018-05-24 23:19 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-06-13 16:28 - 2018-05-24 23:17 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-06-13 16:28 - 2018-05-24 23:15 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-06-13 16:28 - 2018-05-24 23:14 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-06-13 16:28 - 2018-05-15 00:16 - 001681088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-06-13 16:28 - 2018-05-14 23:44 - 004120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2018-06-13 16:28 - 2018-05-14 23:44 - 001159680 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2018-06-13 16:28 - 2018-05-14 23:44 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2018-06-13 16:28 - 2018-05-14 23:44 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2018-06-13 16:28 - 2018-05-14 23:24 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2018-06-13 16:28 - 2018-05-14 23:23 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2018-06-13 16:28 - 2018-05-14 23:13 - 003207168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2018-06-13 16:28 - 2018-05-14 23:13 - 000782848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2018-06-13 16:28 - 2018-05-14 23:13 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2018-06-13 16:28 - 2018-05-14 23:13 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2018-06-13 16:28 - 2018-05-14 23:01 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2018-06-13 16:28 - 2018-05-14 23:01 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2018-06-13 16:28 - 2018-05-14 21:20 - 000467856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2018-06-13 16:28 - 2018-05-14 21:20 - 000459632 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2018-06-13 16:28 - 2018-05-11 22:07 - 000076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2018-06-13 16:28 - 2018-05-11 22:07 - 000033152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-06-13 16:28 - 2018-05-11 22:07 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2018-06-13 16:28 - 2018-05-11 17:19 - 000977408 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-06-13 16:28 - 2018-05-11 17:19 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2018-06-13 16:28 - 2018-05-11 17:19 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2018-06-13 16:28 - 2018-05-10 20:40 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2018-06-13 16:28 - 2018-05-10 20:40 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2018-06-13 16:28 - 2018-05-10 20:39 - 000084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2018-06-13 16:28 - 2018-04-06 12:39 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-06-13 16:28 - 2018-04-06 12:38 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-06-29 16:43 - 2017-05-17 12:59 - 000016345 _____ C:\Users\Tony\Documents\5-21-new way.ods
2018-06-29 16:35 - 2018-04-05 17:14 - 000016358 _____ C:\Users\Tony\Documents\Untitled 1.ods
2018-06-29 14:13 - 2009-07-14 00:45 - 000024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-06-29 14:13 - 2009-07-14 00:45 - 000024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-06-29 13:58 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-06-27 13:44 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf
2018-06-27 10:42 - 2009-07-14 01:13 - 000782510 _____ C:\Windows\system32\PerfStringBackup.INI
2018-06-27 06:49 - 2018-03-17 19:37 - 000002233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-25 11:16 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\NDF
2018-06-25 11:12 - 2013-04-15 19:05 - 000000000 ____D C:\Windows\system32\Macromed
2018-06-23 08:59 - 2013-05-25 15:20 - 000000000 ____D C:\Users\Tony\AppData\Local\Deployment
2018-06-22 20:24 - 2014-04-19 08:18 - 000000000 ___HD C:\Windows\msdownld.tmp
2018-06-21 09:46 - 2009-07-14 01:08 - 000032648 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-06-20 11:07 - 2018-03-07 19:18 - 000000000 ____D C:\Users\Tony\Downloads\finance - Google Search_files
2018-06-13 20:58 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\rescache
2018-06-13 16:11 - 2013-08-14 13:04 - 000000000 ____D C:\Windows\system32\MRT
2018-06-13 16:03 - 2017-10-11 09:31 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-06-13 16:03 - 2013-04-05 19:03 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-06-07 15:29 - 2017-09-19 09:23 - 000004470 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-06-07 15:29 - 2013-04-15 19:05 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-06-07 15:29 - 2013-04-15 19:05 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-06-07 15:29 - 2011-08-10 08:01 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-06-07 15:29 - 2011-08-10 08:01 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-06-07 14:29 - 2018-03-13 09:29 - 000004458 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-06-04 14:42 - 2011-08-10 08:01 - 000000000 ____D C:\ProgramData\Norton
2018-06-04 13:58 - 2018-01-02 10:29 - 000000000 ____D C:\Users\Public\Downloads\Norton
2018-06-04 13:03 - 2013-04-04 09:42 - 000000000 ____D C:\Users\Tony\AppData\Local\CrashDumps
 
==================== Files in the root of some directories =======
 
2014-11-29 09:22 - 2014-12-01 19:19 - 000000115 _____ () C:\Users\Tony\AppData\Roaming\LogFile.txt
2014-12-16 15:04 - 2014-12-16 15:04 - 000000600 _____ () C:\Users\Tony\AppData\Roaming\winscp.rnd
2016-05-30 14:50 - 2017-11-23 11:42 - 000007601 _____ () C:\Users\Tony\AppData\Local\resmon.resmoncfg
2014-12-16 14:59 - 2014-05-13 11:15 - 000010240 _____ () C:\Users\Tony\AppData\Local\[email protected]!-9f71b30d-7b27-44e2-a606-a256cc0d5988.tmp
2014-12-16 14:59 - 2014-05-13 11:15 - 000009216 _____ () C:\Users\Tony\AppData\Local\[email protected]!-ff6c6c67-859b-4911-a61f-5f6bc529b9b2.tmp
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-06-27 07:10
 
==================== End of FRST.txt ============================
 
Here is the addition log:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by Tony (29-06-2018 17:09:26)
Running from C:\Users\Tony\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-04-01 10:12:01)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1688004940-62920522-2967697596-500 - Administrator - Disabled)
Guest (S-1-5-21-1688004940-62920522-2967697596-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1688004940-62920522-2967697596-1002 - Limited - Enabled)
Tony (S-1-5-21-1688004940-62920522-2967697596-1000 - Administrator - Enabled) => C:\Users\Tony
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20040 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated)
Adobe Flash Player 30 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Adobe Flash Player 30 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Adobe Flash Player 30 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.9.199 - Adobe Systems, Inc.)
Agatha Christie - Death on the Nile (HKLM-x32\...\WTA-5c2e059b-617b-4fed-82b6-4fc634d1aefa) (Version: 2.2.0.98 - WildTangent) Hidden
ATI AVIVO64 Codecs (HKLM\...\{40D63515-FF59-9430-BFF0-BF2D26A6AB76}) (Version: 11.6.0.10524 - ATI Technologies Inc.) Hidden
ATI Catalyst Install Manager (HKLM\...\{F7F1A2DA-481A-1B41-8959-4B224C6B20B6}) (Version: 3.0.829.0 - ATI Technologies, Inc.)
Bejeweled 2 Deluxe (HKLM-x32\...\WTA-deb3040b-c90c-4e4c-aaad-ca5864fa08ea) (Version: 2.2.0.95 - WildTangent) Hidden
Build-a-lot 4 - Power Source (HKLM-x32\...\WTA-3a716b28-e8a2-4cf3-883a-a3b8caeb2a75) (Version: 2.2.0.97 - WildTangent) Hidden
Cash Back Assistant (HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\{644CF48B-61FE-43E4-8B2E-7EAE916B49C4}_is1) (Version: 2017.4.7.1 - Capital Intellect, Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.40 - Piriform)
Chronicles of Albian (HKLM-x32\...\WTA-ca657c69-8bfb-489b-a19f-807c4bf073cb) (Version: 2.2.0.95 - WildTangent) Hidden
Common Desktop Agent (HKLM\...\{031A0E14-0413-4C97-9772-2639B782F46F}) (Version: 1.62.0 - OEM) Hidden
Cradle of Rome 2 (HKLM-x32\...\WTA-d5450cc6-46c2-4a19-b61f-ab408f55b4a3) (Version: 2.2.0.95 - WildTangent) Hidden
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Do Not Track Me Add-on 2.2.9.515 (HKLM-x32\...\Do Not Track Me Add-on_is1) (Version: 2.2.9.515 - Abine Inc)
Dora's World Adventure (HKLM-x32\...\WTA-db8a00c1-c07d-49f9-907f-85392ba2e198) (Version: 2.2.0.95 - WildTangent) Hidden
eBay Worldwide (HKLM-x32\...\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
eMachines Games (HKLM-x32\...\WildTangent emachines Master Uninstall) (Version: 1.0.2.5 - WildTangent)
eMachines Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3502 - Acer Incorporated)
eMachines Registration (HKLM-x32\...\eMachines Registration) (Version: 1.04.3503 - Acer Incorporated)
eMachines ScreenSaver (HKLM-x32\...\eMachines Screensaver) (Version: 1.1.0221.2011 - Acer Incorporated)
eMachines Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3504 - Acer Incorporated)
Etron USB3.0 Host Controller (HKLM-x32\...\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.96 - Etron Technology) Hidden
Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.96 - Etron Technology)
Evernote v. 4.5.1 (HKLM-x32\...\{28921580-E4BB-11E0-9FD7-1CC1DEF07CBE}) (Version: 4.5.1.5451 - Evernote Corp.)
Final Drive: Nitro (HKLM-x32\...\WTA-002781fd-bcba-4892-b9cd-42f5ec0eaa62) (Version: 2.2.0.95 - WildTangent) Hidden
Flash Cookie Cleaner (HKLM-x32\...\{E4E1D7C7-6561-4462-96B5-E6439488ED41}) (Version: 2.0 - ConsumerSoft)
Fooz Kids (HKLM-x32\...\{A4E908E5-EE02-843C-9D01-9EA69410B3AB}) (Version: 3.0.8 - FUHU, Inc.) Hidden
Fooz Kids (HKLM-x32\...\FoozKids) (Version: 3.0.8 - FUHU, Inc.)
Fooz Kids Platform (HKLM-x32\...\{8D68CE08-9A14-4B7B-9857-3C646A2F34C7}) (Version: 2.1 - FUHU, Inc.)
Galerie de photos Windows Live (HKLM-x32\...\{488F0347-C4A7-4374-91A7-30818BEDA710}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (HKLM-x32\...\WTA-4a7a1f8b-95ef-4b1c-b7f3-8e6121735af5) (Version: 2.2.0.95 - WildTangent) Hidden
Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3505 - Acer Incorporated)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
Jewel Match 3 (HKLM-x32\...\WTA-07b35df1-23d6-4993-938a-ded40b164203) (Version: 2.2.0.97 - WildTangent) Hidden
Junk Mail filter update (HKLM-x32\...\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LibreOffice 4.4 Help Pack (English (United States)) (HKLM-x32\...\{70B711C0-15AF-41A7-AA74-214B821C9EB6}) (Version: 4.4.4.3 - The Document Foundation)
LibreOffice 5.4.2.2 (HKLM\...\{71F5B603-BA9F-41E1-BC94-9839DFE5A83E}) (Version: 5.4.2.2 - The Document Foundation)
Mesh Runtime (HKLM-x32\...\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Mystery of Mortlake Mansion (HKLM-x32\...\WTA-2ae1e4a1-1a74-4b95-aa2e-bd1d1b4ee6b0) (Version: 2.2.0.98 - WildTangent) Hidden
Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12000.21.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.5.10300 - Nero AG)
Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
NETGEAR WNDA3100v3 (HKLM-x32\...\{60C50FCC-545B-4D5D-B0D1-4A773143BCE7}) (Version: 1.0.0.10 - NETGEAR) Hidden
NETGEAR WNDA3100v3 Genie (HKLM-x32\...\InstallShield_{60C50FCC-545B-4D5D-B0D1-4A773143BCE7}) (Version: 1.0.0.10 - NETGEAR)
NOOK for PC (HKLM-x32\...\BN_DesktopReader) (Version: 2.5.4.7070 - Barnesandnoble.com)
Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Penguins! (HKLM-x32\...\WTA-5ad9af41-4bb6-43c2-b7b7-e89d08bda186) (Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (HKLM-x32\...\WTA-b2c12114-0d47-4098-9eeb-dea1d02a1a75) (Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (HKLM-x32\...\WTA-a63d6f7f-3614-4ae3-8ad4-fc2b996cbd7e) (Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (HKLM-x32\...\WTA-eccd2bc6-2552-4459-9ffd-b1e54b6d3350) (Version: 2.2.0.95 - WildTangent) Hidden
Quick Maps And Directions (HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 4.4.0.3 - SpringTech Ltd.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6242 - Realtek Semiconductor Corp.)
Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.05.79.00(3/26/2015) - Samsung Electronics Co., Ltd.)
Samsung M283x Series (HKLM-x32\...\Samsung M283x Series) (Version: 1.14 (7/17/2015) - Samsung Electronics Co., Ltd.)
Samsung Printer Diagnostics (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.4.7 - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Speedtest by Ookla (HKLM\...\{4CB99888-11EE-4B49-BC91-447FF7FCD975}) (Version: 1.0.14.001 - Ookla)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Torchlight (HKLM-x32\...\WTA-9bfbe13d-2761-454a-9fcd-fe12eb3e3eef) (Version: 2.2.0.97 - WildTangent) Hidden
Update Installer for WildTangent Games App (HKLM-x32\...\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version:  - WildTangent) Hidden
Virtual Villagers 5 - New Believers (HKLM-x32\...\WTA-79d63b1a-26dc-4afa-bedf-5a9f56b1c6d7) (Version: 2.2.0.97 - WildTangent) Hidden
Welcome Center (HKLM-x32\...\eMachines Welcome Center) (Version: 1.02.3504 - Acer Incorporated)
WildTangent Games App (eMachines Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-emachines) (Version: 4.0.5.14 - WildTangent) Hidden
Windows 7 Upgrade Advisor (HKLM-x32\...\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Yahoo Toolbar (HKLM-x32\...\Yahoo! Companion) (Version:  - Yahoo Inc.)
Zuma's Revenge (HKLM-x32\...\WTA-e53f302b-7388-4065-8d00-7fa84715f49f) (Version: 2.2.0.97 - WildTangent) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2011-05-25] (Advanced Micro Devices, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {01823A1A-8875-451C-BD04-8F7467DD9A45} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-03-17] (Google Inc.)
Task: {0875BB75-B060-47BB-BCA3-F43E5FF4E093} - System32\Tasks\UALU notificatin => C:\Program Files\eMachines\eMachines Updater\UALU.exe [2016-06-08] (Acer Incorporated)
Task: {0B7703B3-6C47-4EC9-B8AA-9F43C929A738} - System32\Tasks\{8B1863CD-1CF8-4BE4-B2E1-DEDA7FCF0539} => C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe [2016-04-01] ()
Task: {0C0F0F2F-C147-42D4-B194-F5306A1AA20B} - System32\Tasks\{A21E57C9-325E-49F4-8636-93FE02FB2729} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Task: {0D964143-9C9A-4563-8CE1-DF0F19ADBB15} - System32\Tasks\{B3FD088A-0FED-4B3C-80BF-580CDA018E1F} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {164263C4-E99F-4BEE-BF5B-E4D75DCF0ACB} - System32\Tasks\{DFFC1542-E027-4B8E-AEA3-90D776E41A3E} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Task: {21D664C5-B280-4D0D-8144-76B08CA4D39B} - System32\Tasks\{78B31507-B117-43EA-BAC7-6F373578569B} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Task: {2849E99A-35B9-4F47-98CA-0196A6A403F6} - System32\Tasks\{38A67DA2-9BE9-4DC0-BB9E-C02671D7A523} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {2C9CE3E8-F32F-4343-8056-AAD0F400F438} - System32\Tasks\{0EB495D6-8C40-4BE6-8E30-A9E75F5AD142} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {383761C9-B287-4F11-ABBB-2F4D949B8D0D} - System32\Tasks\Adobe Reader Speed Launcher => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe
Task: {3B7477A8-1C15-4125-A4B0-6ABCA569E476} - System32\Tasks\{58DD7D4B-946E-4F55-B746-EB4B9C4A53C3} => C:\Windows\system32\pcalua.exe -a D:\setup.exe -d D:\
Task: {3DC36A66-0360-4886-A1D8-B4FC6EA0D1BD} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-02-07] (Piriform Ltd)
Task: {40990DEB-CA08-41F7-847D-512FE2992193} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {412F3D00-C5DB-4D53-963B-E2A47AE25BAF} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_113_Plugin.exe [2018-06-07] (Adobe Systems Incorporated)
Task: {5EAB325A-5033-4F04-A766-0F0EC1BD5ED7} - System32\Tasks\{D1943BA7-09D0-4318-BA3F-2C47D2200F97} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Task: {66FD9F74-5DF1-4F77-BBCC-7A581766A831} - System32\Tasks\{C5C4C726-EF2D-4BDB-BDA7-7F73692629F1} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {68C9C3E2-B945-4B32-AB2C-9805917FC7CD} - System32\Tasks\{766F8B29-7A29-4659-9689-CC6E637EAC6D} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {6FC4D8C0-EE31-4E10-953C-3780BDF2EFAB} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {6FC4D8C0-EE31-4E10-953C-3780BDF2EFAB} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(2): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshContent
Task: {6FC4D8C0-EE31-4E10-953C-3780BDF2EFAB} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(3): C:\Windows\system32\GWX\GWXDetector.exe [2015-12-08] (Microsoft Corporation)
Task: {7341CFE4-483D-49B8-899E-05CCA0AF4FFC} - System32\Tasks\{D10355E7-55CD-447A-8FA1-E020748CF2EA} => C:\Program Files (x86)\NETGEAR\WNDA3100v3\WNDA3100v3.EXE [2015-01-15] (NETGEAR)
Task: {7366A2EA-94AE-4289-AE55-E35107F2D7BF} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {7366A2EA-94AE-4289-AE55-E35107F2D7BF} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2015-12-08] (Microsoft Corporation)
Task: {7CABCE86-561C-4148-8E29-94D3A74D2B1B} - System32\Tasks\{F6104194-9F54-4D00-AE42-E2ED93E726B7} => C:\Users\Tony\Desktop\DesktopTickerSetup(1).exe
Task: {7F154A77-266E-4372-A56A-CB7B95115C0A} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent
Task: {7F154A77-266E-4372-A56A-CB7B95115C0A} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2015-12-08] (Microsoft Corporation)
Task: {7F6D0E45-51D7-4D0C-835C-B27A7DD11C69} - System32\Tasks\Adobe ARM => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {85311682-456F-428D-B427-B4C2F223CBE2} - System32\Tasks\{8774AC72-491C-4B5A-96C1-F79B9773A292} => C:\Program Files (x86)\NETGEAR\WNDA3100v3\WNDA3100v3.EXE [2015-01-15] (NETGEAR)
Task: {862549AC-EC08-4807-91D6-7EC3D2C72CE0} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {8BC1865B-2F55-4F35-AF33-BBD04831036A} - System32\Tasks\{487234CC-9FD4-4AB7-9B87-C41A810C7A82} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {9DE717A9-DD4B-4DC8-AF0C-6063699B7AD6} - System32\Tasks\{576DF417-9B1D-479E-9DF4-D3E9114919BD} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {A21B8774-2D10-4BCE-A6C5-617447885C83} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-02-07] (Piriform Ltd)
Task: {A43FCCBE-20CD-4732-814B-4CBEB822F279} - System32\Tasks\{11517C53-4E54-4183-B20B-F085912AF9E5} => C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe [2016-04-01] ()
Task: {A817C154-E8A1-49E3-B86E-F4AA4E9E2445} - System32\Tasks\{F78F1D0A-75C4-491D-A268-624A274D0579} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {A9B056E1-E75E-4FE2-BDA0-5C185B0AC06B} - System32\Tasks\{F0858436-8187-4706-8D44-16FB5E143267} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {AB3998E9-E1BA-4EAA-8040-93396EC91016} - System32\Tasks\{17618F22-8943-45FE-9076-1EE6845A1CCE} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe [2018-05-10] (Adobe Systems Incorporated)
Task: {AF1A5F95-3B7A-401A-BC4C-DEFC53DA615D} - System32\Tasks\{D2F1A770-5A8B-46B2-BEE2-FB4299A395A7} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe [2018-05-10] (Adobe Systems Incorporated)
Task: {B2822BCB-9CAC-4576-8A99-84AE4EC11C4B} - System32\Tasks\{183FCDF8-1471-4094-9CE5-706CBD3D458F} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Task: {BDAF9086-3863-48A0-B529-FACDE727584F} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(1): %windir%\system32\GWX\GWXUXWorker.exe -> /ScheduleUpgradeReminderTime
Task: {BDAF9086-3863-48A0-B529-FACDE727584F} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2015-12-08] (Microsoft Corporation)
Task: {C005BFE8-BEA5-45A0-8959-008ADEA03D3B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-06-07] (Adobe Systems Incorporated)
Task: {CDAB0BED-7A76-40EA-8AC8-0FE3C98BF4FA} - System32\Tasks\{EE46ACE3-7E41-42D7-B540-4D559ABCBF99} => C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe [2016-04-01] ()
Task: {D3122B84-1007-4BC9-85A2-90139B748022} - System32\Tasks\{9C0D182F-40EE-4D88-B090-12EF71DC90CF} => C:\Windows\system32\pcalua.exe -a "C:\Users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CTNBT9KD\BingDesktopSetup.exe" -d C:\Users\Tony\Desktop
Task: {D5AB5270-8C0D-4C3F-A63A-BFCB60D9F9DA} - System32\Tasks\{1A9630D5-2ABC-41A9-8E4A-CDF5B32A20CA} => C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe
Task: {D7768AFE-8167-4408-8B33-36549946B135} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-03-17] (Google Inc.)
Task: {DB5410F5-CBF1-4132-A4AD-8D137ABAE05B} - System32\Tasks\{5F2D0EAE-1750-4B8E-A6C8-34FAF674B3CF} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {DCF1C83E-F79D-47F2-A0FD-609DD509303B} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_113_pepper.exe [2018-06-07] (Adobe Systems Incorporated)
Task: {E901DCC1-AB87-4E22-A623-9A1FF2FA8E0B} - System32\Tasks\{88607A67-2A8D-45E8-8457-CE546DBF4B20} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {EA369158-4B44-458C-90F4-CA25D5A4D665} - System32\Tasks\{2B849E15-0960-4F9E-B30F-7F9574D58E11} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {F0F68262-494D-4696-B54E-383A35DBDEC2} - System32\Tasks\{CD3C9149-F157-4F1B-9103-518BA35617ED} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe [2018-05-10] (Adobe Systems Incorporated)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-04-23 06:16 - 2015-06-26 11:27 - 000022528 _____ () C:\Windows\System32\ssk5mlm.dll
2015-02-20 08:01 - 2015-02-20 08:01 - 000022528 _____ () C:\Windows\System32\us001lm.dll
2015-12-17 13:21 - 2016-04-01 18:38 - 000498488 ____N () C:\Windows\SysWOW64\spdsvc.exe
2014-09-08 13:39 - 2014-09-08 13:39 - 000464608 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
2014-09-08 13:38 - 2014-09-08 13:38 - 000051200 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll
2011-05-25 01:50 - 2011-05-25 01:50 - 000243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-11-09 12:55 - 2011-11-09 12:55 - 000016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2009-06-10 17:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: GamesAppService => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NETGEAR WNDA3100v3 Genie.lnk => C:\Windows\pss\NETGEAR WNDA3100v3 Genie.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: CDAServer => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
MSCONFIG\startupreg: Global Registration => "C:\Program Files (x86)\eMachines\Registration\GREG.exe" /boot
MSCONFIG\startupreg: Hotkey Utility => C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: hpqSRMon => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{37C1F83D-3D4F-4021-93AF-E804F9D4BC99}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{0AD4294E-60F3-4F96-BA43-EA6E64A90E1C}] => (Allow) LPort=2869
FirewallRules: [{2EA2A314-F20B-4113-A768-0282D8DD83D2}] => (Allow) LPort=1900
FirewallRules: [{D7A0D108-9495-45B3-9C0F-4E295C7A37A4}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{AC0B9D9A-0CAD-41E4-B684-180DA8016CAA}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{7B2C0DE6-782A-4517-983E-5159B07E5DB8}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe
FirewallRules: [{7DE2E58F-5350-4D7D-9D49-434E76172C2C}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe
FirewallRules: [{AFCE17FB-9DD5-4CAA-914E-342ED0B82D61}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe
FirewallRules: [{47938683-F784-4091-86B3-2A88AF39294C}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\uninstall.exe
FirewallRules: [{1B7AB9D5-27F7-4778-8DE2-A9D78FE1694F}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe
FirewallRules: [{6ABE13B0-6850-4BB4-BD62-75480DC06535}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\ScanProcess.exe
FirewallRules: [{2407940A-BEE4-4EE9-ACDD-043795CFB6F6}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\Scan2PCNotify.exe
FirewallRules: [{06D04A50-B748-4D10-82D0-326290E5070F}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
FirewallRules: [{18597985-6BFF-4864-AC82-ECDCE55FB699}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
FirewallRules: [{BF850ADB-934C-4620-8572-BF8B808480CB}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe
FirewallRules: [{5687E6EB-DE0D-41A2-9A9F-0C038BBFE71C}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe
FirewallRules: [{77FB52CB-A9D9-4EAD-8EAB-AE035CDDED5C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
25-04-2018 11:22:02 Scheduled Checkpoint
26-04-2018 04:55:26 Windows Update
29-04-2018 08:51:38 Windows Update
03-05-2018 14:38:14 Windows Update
07-05-2018 11:43:11 Windows Update
09-05-2018 12:47:28 Windows Update
13-05-2018 06:25:25 Windows Update
16-05-2018 09:30:02 Windows Update
17-05-2018 08:05:39 Removed Adobe Acrobat Reader DC.
20-05-2018 07:52:36 Windows Update
23-05-2018 11:51:22 Windows Update
27-05-2018 09:16:13 Windows Update
27-05-2018 10:24:00 Restore Operation
27-05-2018 11:19:35 Windows Update
31-05-2018 11:21:19 Windows Update
04-06-2018 08:11:49 Windows Update
04-06-2018 14:38:39 Removed Norton Online Backup
04-06-2018 14:39:48 Removed Norton Online Backup
07-06-2018 13:42:05 Windows Update
11-06-2018 11:04:26 Windows Update
13-06-2018 16:02:44 Windows Update
13-06-2018 17:10:52 Windows Update
17-06-2018 10:01:48 Windows Update
21-06-2018 08:23:55 Windows Update
24-06-2018 20:54:42 Windows Update
28-06-2018 11:30:53 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Malwarebytes Anti-Exploit
Description: Malwarebytes Anti-Exploit
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: ESProtectionDriver
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/29/2018 01:59:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (06/29/2018 01:16:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (06/29/2018 07:40:34 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (06/28/2018 08:43:12 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (06/28/2018 07:36:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (06/28/2018 07:15:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (06/28/2018 04:14:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (06/28/2018 02:48:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
 
System errors:
=============
Error: (06/29/2018 01:58:24 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
ESProtectionDriver
 
Error: (06/29/2018 01:58:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error: 
The system cannot find the path specified.
 
Error: (06/29/2018 01:22:06 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} did not register with DCOM within the required timeout.
 
Error: (06/29/2018 01:21:42 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
ESProtectionDriver
 
Error: (06/29/2018 01:21:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error: 
The system cannot find the path specified.
 
Error: (06/29/2018 01:20:16 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} did not register with DCOM within the required timeout.
 
Error: (06/29/2018 01:15:22 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
ESProtectionDriver
 
Error: (06/29/2018 01:15:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error: 
The system cannot find the path specified.
 
 
Windows Defender:
===================================
Date: 2015-05-28 06:38:19.747
Description: 
Windows Defender scan has been stopped before completion.
Scan ID:{D5B2BD5A-0510-4A45-A683-D26A899B54F4}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan
 
Date: 2015-06-04 16:18:09.113
Description: 
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified. 
Signature version:0.0.0.0
Engine version:0.0.0.0
 
==================== Memory info =========================== 
 
Processor: AMD E-350 APU with Radeon™ HD Graphics
Percentage of memory in use: 37%
Total physical RAM: 3576.26 MB
Available physical RAM: 2241.16 MB
Total Virtual: 7150.69 MB
Available Virtual: 5597.55 MB
 
==================== Drives ================================
 
Drive c: (eMachines) (Fixed) (Total:446.13 GB) (Free:337.09 GB) NTFS
 
\\?\Volume{8b9557a3-d226-11e1-939d-806e6f6e6963}\ (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.03 GB) NTFS
\\?\Volume{8b9557a2-d226-11e1-939d-806e6f6e6963}\ (PQSERVICE) (Fixed) (Total:19.53 GB) (Free:7.88 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: B25EC62F)
Partition 1: (Not Active) - (Size=19.5 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=446.1 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

 


  • 0

Advertisements


#2
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 214 posts

Looking over your logs, back soon.


  • 0

#3
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 214 posts

Hi jbcteacher

I'm Gary R,

Before we start: Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.

Please observe these rules while we work:

  • Do not edit your logs in any way whatsoever.
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to install any new software (other than those I ask you to) until we've got your computer clean.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process. If your defensive programmes warn you about any of those tools, be assured that they are not infected, and are safe to use.

If you can do these things, everything should go smoothly.

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


OK, there's definite signs of infection in the logs you've supplied, but before we deal with them, I'd like you to run a further scan for me, which will give us a more complete picture of what we need to remove to get your computer clean.

Please download AdwCleaner and save it to your desktop.

  • Double click AdwCleaner.exe to run it.
  • Click Scan.
  • A logfile will automatically open after the scan has finished.
  • Close the adwCleaner window, click ok to the prompt.
  • Please post the contents of that logfile with your next reply.
  • You can also find the logfile at C:\AdwCleaner[R1].txt.


AT THIS POINT, DO NOT ATTEMPT TO CLEAN ANYTHING THAT MAY BE FOUND
  • 0

#4
jbcteacher

jbcteacher

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 206 posts

Hello!  Thank you for your quick reply.

 

Here is the log file:

# -------------------------------
# Malwarebytes AdwCleaner 7.2.0.0
# -------------------------------
# Build:    06-05-2018
# Database: 2018-06-29.1
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    06-30-2018
# Duration: 00:02:26
# OS:       Windows 7 Home Premium
# Scanned:  41294
# Detected: 155
 
 
***** [ Services ] *****
 
PUP.Optional.Legacy             YahooAUService
 
***** [ Folders ] *****
 
PUP.MyWebSearch.Heuristic       C:\Users\Tony\AppData\Local\DIRECTIONSACETOOLTAB
PUP.MyWebSearch.Heuristic       C:\Users\Tony\AppData\Local\EASYPDFCOMBINETOOLTAB
PUP.MyWebSearch.Heuristic       C:\Users\Tony\AppData\Local\FROMDOCTOPDFTOOLTAB
PUP.Optional.InboxToolBar       C:\Users\Tony\AppData\LocalLow\Inbox Toolbar
PUP.Optional.Legacy             C:\Program Files (x86)\ConsumerSoft
PUP.Optional.Legacy             C:\Users\Tony\AppData\Local\ConsumerSoft
PUP.Optional.Legacy             C:\Users\Tony\AppData\Local\AtoZManualsTooltab
PUP.Optional.Legacy             C:\Users\Tony\AppData\Local\Downloaded Installers
PUP.Optional.Legacy             C:\Users\Public\Documents\Downloaded Installers
PUP.Optional.Legacy             C:\Program Files (x86)\Yahoo!\Companion
PUP.Optional.Legacy             C:\Users\Tony\AppData\LocalLow\Yahoo!\Companion
PUP.Optional.Legacy             C:\Users\Tony\AppData\Roaming\Yahoo!\Companion
PUP.Optional.Legacy             C:\Users\Tony\AppData\Roaming\DriverCure
PUP.Optional.Legacy             C:\Users\Tony\AppData\LocalLow\ShopAtHome
PUP.Optional.Legacy             C:\Users\Tony\AppData\Roaming\ShopAtHome
PUP.Optional.Legacy             C:\ProgramData\Yahoo! Companion
PUP.Optional.Legacy             C:\Users\Tony\AppData\LocalLow\Yahoo! Companion
PUP.Optional.ScanGuard          C:\Users\Tony\Documents\ScanGuard
PUP.Optional.SlimCleanerPlus    C:\Users\Tony\AppData\Local\slimware utilities inc
PUP.Optional.Spigot             C:\Users\Tony\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}
Rogue.ForcedExtension           C:\ProgramData\apn
Trojan.Agent                    C:\Users\Tony\AppData\LocalLow\iac
 
***** [ Files ] *****
 
PUP.Optional.Legacy             C:\Program Files (x86)\Yahoo!\Common\unyt.exe
PUP.Optional.Legacy             C:\Windows\System32\drivers\swdumon.sys
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
PUP.Optional.BrowseFox.A        HKLM\Software\Wow6432Node\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
PUP.Optional.Legacy             HKCU\Software\EasyPDFCombine
PUP.Optional.Legacy             HKCU\Software\FromDocToPDF
PUP.Optional.Legacy             HKCU\Software\Yahoo\YFriendsBar
PUP.Optional.Legacy             HKCU\Software\AppDataLow\Software\Yahoo\Companion
PUP.Optional.Legacy             HKCU\Software\Yahoo\Companion
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Yahoo\Companion
PUP.Optional.Legacy             HKCU\Software\reimagerepair
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\ytbbroker.EXE
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\ytbbroker.EXE
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\yt.DLL
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\yt.DLL
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\ShopAtHomeHelper.EXE
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\ShopAtHomeHelper.EXE
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{9DE77B51-89F6-468E-9402-16050382E950}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{8E74A0AE-F0ED-47ED-A940-A8E99687646B}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{7DB8B625-DBF0-4491-B544-5A06F7B17BB4}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{6EB4349D-4333-442F-ACA4-4C72AF28B6ED}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{3C16E079-E4C7-493C-BE9F-E0F2BB0B7430}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{FBE30D66-39A2-4b72-8B43-6D4C335A6F34}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{C60CCE95-6AF9-4E74-B66B-3212D19F1D2F}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{9F9C4C5C-2BA8-4E00-A697-9F710BB1026B}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{46140CE4-76FE-440E-AE88-4C2272BC05C7}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{3A06AA27-D94B-48C2-BB55-9FD0FF2120E3}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{31371420-098D-4C0E-A11E-EBEC2305DD01}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{1E57256D-9F39-4267-AB39-D7813D644C5A}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF10C1C0-B598-4ADB-B353-42C991C99A2E}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{067ECE13-6DD2-47C7-8EFE-24DA8BC1D8DA}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{067ECE13-6DD2-47C7-8EFE-24DA8BC1D8DA}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{76481128-CCDC-4073-8F65-B06F23B138FC}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{76481128-CCDC-4073-8F65-B06F23B138FC}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{B944FF5E-EC87-4E1E-8C49-2FF3BC573997}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{B944FF5E-EC87-4E1E-8C49-2FF3BC573997}
PUP.Optional.Legacy             HKCU\Software\Classes\TypeLib\{2A05A54D-0614-4EA3-B955-8814E45DCD83}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
PUP.Optional.Legacy             HKLM\Software\Classes\yt.YToolbarBand
PUP.Optional.Legacy             HKLM\Software\Classes\yt.YTHelper
PUP.Optional.Legacy             HKLM\Software\Classes\yt.Clickstream
PUP.Optional.Legacy             HKLM\Software\Classes\yt.CacheLoader
PUP.Optional.Legacy             HKLM\Software\Classes\Sample.YTBPartnerSample
PUP.Optional.Legacy             HKLM\Software\Classes\Sample.BrowserHandler
PUP.Optional.Legacy             HKCU\Software\Microsoft\Internet Explorer\Main|Search Page
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main|Search Page
PUP.Optional.SafePCKit          HKCU\Software\Sunisoft
PUP.Optional.SlimCleanerPlus    HKCU\Software\SlimWare Utilities Inc
PUP.Optional.SlimCleanerPlus    HKLM\Software\Wow6432Node\SlimWare Utilities Inc
PUP.Optional.SlimCleanerPlus    HKLM\Software\SlimWare Utilities Inc
PUP.Optional.Spigot             HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}
 
***** [ Chromium (and derivatives) ] *****
 
PUP.Optional.Legacy             MSN Homepage & Bing Search Engine
PUP.Optional.MindSpark          Search Extension by Ask
 
***** [ Chromium URLs ] *****
 
PUP.Optional.Legacy             AOL
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries found.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs found.
 
 
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########

  • 0

#5
jbcteacher

jbcteacher

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 206 posts

Gary - I'm Joanne.  Thanks again!


  • 0

#6
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 214 posts

Hi Joanne, OK, lets see if we can get things running properly again.
 

  • Double click AdwCleaner.exe to run it.
  • Click Scan and allow the scan to finish.
  • Now click Clean to remove the items found.
  • Click OK to the prompt.
  • The tool will run & your computer will be rebooted automatically. A logfile will open after the restart.
  • Post the contents of the logfile with your next reply.
  • You can also find the logfile at C:\AdwCleaner[s1].txt.

Next ....



  • Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
  • Press Ctrl+y (Ctrl and y keys at the same time)
  • A blank randomly named .txt Notepad file will open.
  • Copy and paste the following into it ....
createrestorepoint:
CHR HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=hp-avast&type=agc511
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://www.quafind.com/
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
SearchScopes: HKLM-x32 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AEMTDF&pc=MAEM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> DefaultScope {DD73391C-88AA-4758-A44B-0332D32FB5B4} URL = hxxp://search.hquickmapsanddirections.com/s?uc=20180619&i_id=maps_spt__1.30&ap=appfocus1&uid=5832f5a9-61b8-4eae-81dd-fc6f1239daaa&source=d-ccc6-lp0-bb8&query={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=U453DF&PC=U453&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {34D82E9A-0675-4E5B-AC8A-0B6FE895141F} URL = hxxps://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {4B63626E-741B-4776-972F-A77742705792} URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {7A8B4688-548A-4996-88E4-B6111E121D2A} URL = hxxps://search.yahoo.com/search?ei=utf-8&fr=befds&p={searchTerms}&type=ieds-4.7-1706
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {8899C699-593C-4A8D-AE8A-DF99C9282907} URL = hxxps://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {A1032D92-6A87-46FF-A15C-AC0E56FE4B14} URL = hxxp://isearch.shopathome.com?user_id={6F914F5F-E315-4177-9E84-FC4B089A2094}&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxps://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {DD73391C-88AA-4758-A44B-0332D32FB5B4} URL = hxxp://search.hquickmapsanddirections.com/s?uc=20180619&i_id=maps_spt__1.30&ap=appfocus1&uid=5832f5a9-61b8-4eae-81dd-fc6f1239daaa&source=d-ccc6-lp0-bb8&query={searchTerms}
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
CHR Extension: (Scanguard Safe Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkljlnkimgcfmiklhilenokeckdiiepf [2018-05-27]
CHR Extension: (Scanguard Safe Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkljlnkimgcfmiklhilenokeckdiiepf [2018-05-27]
CHR Extension: (Ask Web Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgfehfbnofiffladdncogfobimealokp [2018-05-27]
CHR HKLM\...\Chrome\Extension: [kkljlnkimgcfmiklhilenokeckdiiepf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kkljlnkimgcfmiklhilenokeckdiiepf] - hxxps://clients2.google.com/service/update2/crx
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
Task: {0D964143-9C9A-4563-8CE1-DF0F19ADBB15} - System32\Tasks\{B3FD088A-0FED-4B3C-80BF-580CDA018E1F} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {2849E99A-35B9-4F47-98CA-0196A6A403F6} - System32\Tasks\{38A67DA2-9BE9-4DC0-BB9E-C02671D7A523} => C:\Program Files\AVAST Software\Avast\AvastUI.exeTask: {2C9CE3E8-F32F-4343-8056-AAD0F400F438} - System32\Tasks\{0EB495D6-8C40-4BE6-8E30-A9E75F5AD142} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {66FD9F74-5DF1-4F77-BBCC-7A581766A831} - System32\Tasks\{C5C4C726-EF2D-4BDB-BDA7-7F73692629F1} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {68C9C3E2-B945-4B32-AB2C-9805917FC7CD} - System32\Tasks\{766F8B29-7A29-4659-9689-CC6E637EAC6D} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {8BC1865B-2F55-4F35-AF33-BBD04831036A} - System32\Tasks\{487234CC-9FD4-4AB7-9B87-C41A810C7A82} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {9DE717A9-DD4B-4DC8-AF0C-6063699B7AD6} - System32\Tasks\{576DF417-9B1D-479E-9DF4-D3E9114919BD} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {A817C154-E8A1-49E3-B86E-F4AA4E9E2445} - System32\Tasks\{F78F1D0A-75C4-491D-A268-624A274D0579} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {A9B056E1-E75E-4FE2-BDA0-5C185B0AC06B} - System32\Tasks\{F0858436-8187-4706-8D44-16FB5E143267} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {DB5410F5-CBF1-4132-A4AD-8D137ABAE05B} - System32\Tasks\{5F2D0EAE-1750-4B8E-A6C8-34FAF674B3CF} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {E901DCC1-AB87-4E22-A623-9A1FF2FA8E0B} - System32\Tasks\{88607A67-2A8D-45E8-8457-CE546DBF4B20} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {EA369158-4B44-458C-90F4-CA25D5A4D665} - System32\Tasks\{2B849E15-0960-4F9E-B30F-7F9574D58E11} => C:\Program Files\AVAST Software\Avast\avastui.exe
cmd:ipconfig /flushdns
emptytemp:
  • Press Ctrl+s to save fixlist.txt

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system


  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log

 

 


  • 0

#7
jbcteacher

jbcteacher

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 206 posts

Hi again Gary - There were 3 log files.  Not sure if this is the one you want...  I'll be taking care of the next part of your directions now.

 

# -------------------------------
# Malwarebytes AdwCleaner 7.2.0.0
# -------------------------------
# Build:    06-05-2018
# Database: 2018-06-29.1
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    06-30-2018
# Duration: 00:00:10
# OS:       Windows 7 Home Premium
# Cleaned:  155
# Failed:   0
 
 
***** [ Services ] *****
 
Deleted       YahooAUService
 
***** [ Folders ] *****
 
Deleted       C:\Users\Tony\AppData\Local\DIRECTIONSACETOOLTAB
Deleted       C:\Users\Tony\AppData\Local\EASYPDFCOMBINETOOLTAB
Deleted       C:\Users\Tony\AppData\Local\FROMDOCTOPDFTOOLTAB
Deleted       C:\Users\Tony\AppData\LocalLow\Inbox Toolbar
Deleted       C:\Program Files (x86)\ConsumerSoft
Deleted       C:\Users\Tony\AppData\Local\ConsumerSoft
Deleted       C:\Users\Tony\AppData\Local\AtoZManualsTooltab
Deleted       C:\Users\Tony\AppData\Local\Downloaded Installers
Deleted       C:\Users\Public\Documents\Downloaded Installers
Deleted       C:\Program Files (x86)\Yahoo!\Companion
Deleted       C:\Users\Tony\AppData\LocalLow\Yahoo!\Companion
Deleted       C:\Users\Tony\AppData\Roaming\Yahoo!\Companion
Deleted       C:\Users\Tony\AppData\Roaming\DriverCure
Deleted       C:\Users\Tony\AppData\LocalLow\ShopAtHome
Deleted       C:\Users\Tony\AppData\Roaming\ShopAtHome
Deleted       C:\ProgramData\Yahoo! Companion
Deleted       C:\Users\Tony\AppData\LocalLow\Yahoo! Companion
Deleted       C:\Users\Tony\Documents\ScanGuard
Deleted       C:\Users\Tony\AppData\Local\slimware utilities inc
Deleted       C:\Users\Tony\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}
Deleted       C:\ProgramData\apn
Deleted       C:\Users\Tony\AppData\LocalLow\iac
 
***** [ Files ] *****
 
Deleted       C:\Program Files (x86)\Yahoo!\Common\unyt.exe
Deleted       C:\Windows\System32\drivers\swdumon.sys
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks cleaned.
 
***** [ Registry ] *****
 
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Deleted       HKCU\Software\EasyPDFCombine
Deleted       HKCU\Software\FromDocToPDF
Deleted       HKCU\Software\Yahoo\YFriendsBar
Deleted       HKCU\Software\AppDataLow\Software\Yahoo\Companion
Deleted       HKCU\Software\Yahoo\Companion
Deleted       HKLM\Software\Wow6432Node\Yahoo\Companion
Deleted       HKCU\Software\reimagerepair
Deleted       HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Deleted       HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Deleted       HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\ytbbroker.EXE
Deleted       HKLM\SOFTWARE\Classes\AppID\ytbbroker.EXE
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\yt.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\yt.DLL
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\ShopAtHomeHelper.EXE
Deleted       HKLM\SOFTWARE\Classes\AppID\ShopAtHomeHelper.EXE
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{9DE77B51-89F6-468E-9402-16050382E950}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{8E74A0AE-F0ED-47ED-A940-A8E99687646B}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{7DB8B625-DBF0-4491-B544-5A06F7B17BB4}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{6EB4349D-4333-442F-ACA4-4C72AF28B6ED}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{3C16E079-E4C7-493C-BE9F-E0F2BB0B7430}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
Deleted       HKLM\Software\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
Deleted       HKLM\Software\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
Deleted       HKLM\Software\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
Deleted       HKLM\Software\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
Deleted       HKLM\Software\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
Deleted       HKLM\Software\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
Deleted       HKLM\Software\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
Deleted       HKLM\Software\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
Deleted       HKLM\Software\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
Deleted       HKLM\Software\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
Deleted       HKLM\Software\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
Deleted       HKLM\Software\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
Deleted       HKLM\Software\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
Deleted       HKLM\Software\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
Deleted       HKLM\Software\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
Deleted       HKLM\Software\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
Deleted       HKLM\Software\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
Deleted       HKLM\Software\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
Deleted       HKLM\Software\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
Deleted       HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Deleted       HKLM\Software\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
Deleted       HKLM\Software\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{FBE30D66-39A2-4b72-8B43-6D4C335A6F34}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{C60CCE95-6AF9-4E74-B66B-3212D19F1D2F}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{9F9C4C5C-2BA8-4E00-A697-9F710BB1026B}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{46140CE4-76FE-440E-AE88-4C2272BC05C7}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{3A06AA27-D94B-48C2-BB55-9FD0FF2120E3}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{31371420-098D-4C0E-A11E-EBEC2305DD01}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{1E57256D-9F39-4267-AB39-D7813D644C5A}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
Deleted       HKLM\Software\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}
Deleted       HKLM\Software\Classes\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}
Deleted       HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF10C1C0-B598-4ADB-B353-42C991C99A2E}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{067ECE13-6DD2-47C7-8EFE-24DA8BC1D8DA}
Deleted       HKLM\Software\Classes\Interface\{067ECE13-6DD2-47C7-8EFE-24DA8BC1D8DA}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{76481128-CCDC-4073-8F65-B06F23B138FC}
Deleted       HKLM\Software\Classes\TypeLib\{76481128-CCDC-4073-8F65-B06F23B138FC}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{B944FF5E-EC87-4E1E-8C49-2FF3BC573997}
Deleted       HKLM\Software\Classes\TypeLib\{B944FF5E-EC87-4E1E-8C49-2FF3BC573997}
Deleted       HKCU\Software\Classes\TypeLib\{2A05A54D-0614-4EA3-B955-8814E45DCD83}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Deleted       HKLM\Software\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Deleted       HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Deleted       HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Deleted       HKLM\Software\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Deleted       HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Deleted       HKLM\Software\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Deleted       HKLM\Software\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Deleted       HKLM\Software\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Deleted       HKLM\Software\Classes\yt.YToolbarBand
Deleted       HKLM\Software\Classes\yt.YTHelper
Deleted       HKLM\Software\Classes\yt.Clickstream
Deleted       HKLM\Software\Classes\yt.CacheLoader
Deleted       HKLM\Software\Classes\Sample.YTBPartnerSample
Deleted       HKLM\Software\Classes\Sample.BrowserHandler
Deleted       HKCU\Software\Microsoft\Internet Explorer\Main|Search Page
Deleted       HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main|Search Page
Deleted       HKCU\Software\Sunisoft
Deleted       HKCU\Software\SlimWare Utilities Inc
Deleted       HKLM\Software\Wow6432Node\SlimWare Utilities Inc
Deleted       HKLM\Software\SlimWare Utilities Inc
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}
 
***** [ Chromium (and derivatives) ] *****
 
Deleted       MSN Homepage & Bing Search Engine
Deleted       Search Extension by Ask
 
***** [ Chromium URLs ] *****
 
Deleted       AOL
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries cleaned.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs cleaned.
 
 
*************************
 
[+] Delete Tracing Keys
[+] Reset Winsock
 
*************************
 
AdwCleaner[S00].txt - [16589 octets] - [30/06/2018 10:39:24]
AdwCleaner[S01].txt - [16651 octets] - [30/06/2018 12:43:29]
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########

  • 0

#8
jbcteacher

jbcteacher

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 206 posts

Here's the other:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by Tony (30-06-2018 12:51:21) Run:1
Running from C:\Users\Tony\Desktop
Loaded Profiles: Tony (Available Profiles: Tony)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
createrestorepoint:
CHR HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=hp-avast&type=agc511
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://www.quafind.com/
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
SearchScopes: HKLM-x32 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AEMTDF&pc=MAEM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> DefaultScope {DD73391C-88AA-4758-A44B-0332D32FB5B4} URL = hxxp://search.hquickmapsanddirections.com/s?uc=20180619&i_id=maps_spt__1.30&ap=appfocus1&uid=5832f5a9-61b8-4eae-81dd-fc6f1239daaa&source=d-ccc6-lp0-bb8&query={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=U453DF&PC=U453&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {34D82E9A-0675-4E5B-AC8A-0B6FE895141F} URL = hxxps://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {4B63626E-741B-4776-972F-A77742705792} URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {7A8B4688-548A-4996-88E4-B6111E121D2A} URL = hxxps://search.yahoo.com/search?ei=utf-8&fr=befds&p={searchTerms}&type=ieds-4.7-1706
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {8899C699-593C-4A8D-AE8A-DF99C9282907} URL = hxxps://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {A1032D92-6A87-46FF-A15C-AC0E56FE4B14} URL = hxxp://isearch.shopathome.com?user_id={6F914F5F-E315-4177-9E84-FC4B089A2094}&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxps://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {DD73391C-88AA-4758-A44B-0332D32FB5B4} URL = hxxp://search.hquickmapsanddirections.com/s?uc=20180619&i_id=maps_spt__1.30&ap=appfocus1&uid=5832f5a9-61b8-4eae-81dd-fc6f1239daaa&source=d-ccc6-lp0-bb8&query={searchTerms}
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
CHR Extension: (Scanguard Safe Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkljlnkimgcfmiklhilenokeckdiiepf [2018-05-27]
CHR Extension: (Scanguard Safe Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkljlnkimgcfmiklhilenokeckdiiepf [2018-05-27]
CHR Extension: (Ask Web Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgfehfbnofiffladdncogfobimealokp [2018-05-27]
CHR HKLM\...\Chrome\Extension: [kkljlnkimgcfmiklhilenokeckdiiepf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kkljlnkimgcfmiklhilenokeckdiiepf] - hxxps://clients2.google.com/service/update2/crx
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
Task: {0D964143-9C9A-4563-8CE1-DF0F19ADBB15} - System32\Tasks\{B3FD088A-0FED-4B3C-80BF-580CDA018E1F} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {2849E99A-35B9-4F47-98CA-0196A6A403F6} - System32\Tasks\{38A67DA2-9BE9-4DC0-BB9E-C02671D7A523} => C:\Program Files\AVAST Software\Avast\AvastUI.exeTask: {2C9CE3E8-F32F-4343-8056-AAD0F400F438} - System32\Tasks\{0EB495D6-8C40-4BE6-8E30-A9E75F5AD142} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {66FD9F74-5DF1-4F77-BBCC-7A581766A831} - System32\Tasks\{C5C4C726-EF2D-4BDB-BDA7-7F73692629F1} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {68C9C3E2-B945-4B32-AB2C-9805917FC7CD} - System32\Tasks\{766F8B29-7A29-4659-9689-CC6E637EAC6D} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {8BC1865B-2F55-4F35-AF33-BBD04831036A} - System32\Tasks\{487234CC-9FD4-4AB7-9B87-C41A810C7A82} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {9DE717A9-DD4B-4DC8-AF0C-6063699B7AD6} - System32\Tasks\{576DF417-9B1D-479E-9DF4-D3E9114919BD} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {A817C154-E8A1-49E3-B86E-F4AA4E9E2445} - System32\Tasks\{F78F1D0A-75C4-491D-A268-624A274D0579} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {A9B056E1-E75E-4FE2-BDA0-5C185B0AC06B} - System32\Tasks\{F0858436-8187-4706-8D44-16FB5E143267} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {DB5410F5-CBF1-4132-A4AD-8D137ABAE05B} - System32\Tasks\{5F2D0EAE-1750-4B8E-A6C8-34FAF674B3CF} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {E901DCC1-AB87-4E22-A623-9A1FF2FA8E0B} - System32\Tasks\{88607A67-2A8D-45E8-8457-CE546DBF4B20} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {EA369158-4B44-458C-90F4-CA25D5A4D665} - System32\Tasks\{2B849E15-0960-4F9E-B30F-7F9574D58E11} => C:\Program Files\AVAST Software\Avast\avastui.exe
cmd:ipconfig /flushdns
emptytemp:
*****************
 
Restore point was successfully created.
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Policies\Google" => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" => removed successfully
HKLM\Software\Classes\CLSID\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} => not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{9CB96984-43C3-4D44-90EF-01466EFCF7BB} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => removed successfully
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{34D82E9A-0675-4E5B-AC8A-0B6FE895141F}" => removed successfully
HKLM\Software\Classes\CLSID\{34D82E9A-0675-4E5B-AC8A-0B6FE895141F} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4B63626E-741B-4776-972F-A77742705792}" => removed successfully
HKLM\Software\Classes\CLSID\{4B63626E-741B-4776-972F-A77742705792} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => removed successfully
HKLM\Software\Classes\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7A8B4688-548A-4996-88E4-B6111E121D2A}" => removed successfully
HKLM\Software\Classes\CLSID\{7A8B4688-548A-4996-88E4-B6111E121D2A} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8899C699-593C-4A8D-AE8A-DF99C9282907}" => removed successfully
HKLM\Software\Classes\CLSID\{8899C699-593C-4A8D-AE8A-DF99C9282907} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB}" => removed successfully
HKLM\Software\Classes\CLSID\{9CB96984-43C3-4D44-90EF-01466EFCF7BB} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A1032D92-6A87-46FF-A15C-AC0E56FE4B14}" => removed successfully
HKLM\Software\Classes\CLSID\{A1032D92-6A87-46FF-A15C-AC0E56FE4B14} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" => removed successfully
HKLM\Software\Classes\CLSID\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DD73391C-88AA-4758-A44B-0332D32FB5B4}" => removed successfully
HKLM\Software\Classes\CLSID\{DD73391C-88AA-4758-A44B-0332D32FB5B4} => not found
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => removed successfully
"HKLM\Software\Classes\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => removed successfully
HKLM\Software\Classes\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => not found
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => removed successfully
HKLM\Software\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => not found
CHR Extension: (Scanguard Safe Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkljlnkimgcfmiklhilenokeckdiiepf [2018-05-27] => Error: No automatic fix found for this entry.
CHR Extension: (Scanguard Safe Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkljlnkimgcfmiklhilenokeckdiiepf [2018-05-27] => Error: No automatic fix found for this entry.
CHR Extension: (Ask Web Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgfehfbnofiffladdncogfobimealokp [2018-05-27] => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Google\Chrome\Extensions\kkljlnkimgcfmiklhilenokeckdiiepf" => removed successfully
"HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kkljlnkimgcfmiklhilenokeckdiiepf" => removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt1" => removed successfully
HKLM\Software\Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => not found
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt2" => removed successfully
HKLM\Software\Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => not found
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt3" => removed successfully
HKLM\Software\Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => not found
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4" => removed successfully
HKLM\Software\Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => not found
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => not found
"HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avast" => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0D964143-9C9A-4563-8CE1-DF0F19ADBB15}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D964143-9C9A-4563-8CE1-DF0F19ADBB15}" => removed successfully
C:\Windows\System32\Tasks\{B3FD088A-0FED-4B3C-80BF-580CDA018E1F} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B3FD088A-0FED-4B3C-80BF-580CDA018E1F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2849E99A-35B9-4F47-98CA-0196A6A403F6}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2849E99A-35B9-4F47-98CA-0196A6A403F6}" => removed successfully
C:\Windows\System32\Tasks\{38A67DA2-9BE9-4DC0-BB9E-C02671D7A523} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{38A67DA2-9BE9-4DC0-BB9E-C02671D7A523}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{66FD9F74-5DF1-4F77-BBCC-7A581766A831}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{66FD9F74-5DF1-4F77-BBCC-7A581766A831}" => removed successfully
C:\Windows\System32\Tasks\{C5C4C726-EF2D-4BDB-BDA7-7F73692629F1} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C5C4C726-EF2D-4BDB-BDA7-7F73692629F1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{68C9C3E2-B945-4B32-AB2C-9805917FC7CD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68C9C3E2-B945-4B32-AB2C-9805917FC7CD}" => removed successfully
C:\Windows\System32\Tasks\{766F8B29-7A29-4659-9689-CC6E637EAC6D} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{766F8B29-7A29-4659-9689-CC6E637EAC6D}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8BC1865B-2F55-4F35-AF33-BBD04831036A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8BC1865B-2F55-4F35-AF33-BBD04831036A}" => removed successfully
C:\Windows\System32\Tasks\{487234CC-9FD4-4AB7-9B87-C41A810C7A82} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{487234CC-9FD4-4AB7-9B87-C41A810C7A82}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9DE717A9-DD4B-4DC8-AF0C-6063699B7AD6}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9DE717A9-DD4B-4DC8-AF0C-6063699B7AD6}" => removed successfully
C:\Windows\System32\Tasks\{576DF417-9B1D-479E-9DF4-D3E9114919BD} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{576DF417-9B1D-479E-9DF4-D3E9114919BD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A817C154-E8A1-49E3-B86E-F4AA4E9E2445}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A817C154-E8A1-49E3-B86E-F4AA4E9E2445}" => removed successfully
C:\Windows\System32\Tasks\{F78F1D0A-75C4-491D-A268-624A274D0579} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F78F1D0A-75C4-491D-A268-624A274D0579}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A9B056E1-E75E-4FE2-BDA0-5C185B0AC06B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9B056E1-E75E-4FE2-BDA0-5C185B0AC06B}" => removed successfully
C:\Windows\System32\Tasks\{F0858436-8187-4706-8D44-16FB5E143267} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F0858436-8187-4706-8D44-16FB5E143267}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB5410F5-CBF1-4132-A4AD-8D137ABAE05B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB5410F5-CBF1-4132-A4AD-8D137ABAE05B}" => removed successfully
C:\Windows\System32\Tasks\{5F2D0EAE-1750-4B8E-A6C8-34FAF674B3CF} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5F2D0EAE-1750-4B8E-A6C8-34FAF674B3CF}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E901DCC1-AB87-4E22-A623-9A1FF2FA8E0B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E901DCC1-AB87-4E22-A623-9A1FF2FA8E0B}" => removed successfully
C:\Windows\System32\Tasks\{88607A67-2A8D-45E8-8457-CE546DBF4B20} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{88607A67-2A8D-45E8-8457-CE546DBF4B20}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA369158-4B44-458C-90F4-CA25D5A4D665}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA369158-4B44-458C-90F4-CA25D5A4D665}" => removed successfully
C:\Windows\System32\Tasks\{2B849E15-0960-4F9E-B30F-7F9574D58E11} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2B849E15-0960-4F9E-B30F-7F9574D58E11}" => removed successfully
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12714565 B
Java, Flash, Steam htmlcache => 1246 B
Windows/system/drivers => 5830283 B
Edge => 0 B
Chrome => 210288240 B
Firefox => 8041206 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 42337004 B
systemprofile32 => 11002150 B
LocalService => 0 B
NetworkService => 452818178 B
Tony => 5742247 B
 
RecycleBin => 0 B
EmptyTemp: => 722.1 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 12:56:11 ====

  • 0

#9
jbcteacher

jbcteacher

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 206 posts

Just in case you need this log:

 

# -------------------------------
# Malwarebytes AdwCleaner 7.2.0.0
# -------------------------------
# Build:    06-05-2018
# Database: 2018-06-29.1
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    06-30-2018
# Duration: 00:00:36
# OS:       Windows 7 Home Premium
# Scanned:  41294
# Detected: 155
 
 
***** [ Services ] *****
 
PUP.Optional.Legacy             YahooAUService
 
***** [ Folders ] *****
 
PUP.MyWebSearch.Heuristic       C:\Users\Tony\AppData\Local\DIRECTIONSACETOOLTAB
PUP.MyWebSearch.Heuristic       C:\Users\Tony\AppData\Local\EASYPDFCOMBINETOOLTAB
PUP.MyWebSearch.Heuristic       C:\Users\Tony\AppData\Local\FROMDOCTOPDFTOOLTAB
PUP.Optional.InboxToolBar       C:\Users\Tony\AppData\LocalLow\Inbox Toolbar
PUP.Optional.Legacy             C:\Program Files (x86)\ConsumerSoft
PUP.Optional.Legacy             C:\Users\Tony\AppData\Local\ConsumerSoft
PUP.Optional.Legacy             C:\Users\Tony\AppData\Local\AtoZManualsTooltab
PUP.Optional.Legacy             C:\Users\Tony\AppData\Local\Downloaded Installers
PUP.Optional.Legacy             C:\Users\Public\Documents\Downloaded Installers
PUP.Optional.Legacy             C:\Program Files (x86)\Yahoo!\Companion
PUP.Optional.Legacy             C:\Users\Tony\AppData\LocalLow\Yahoo!\Companion
PUP.Optional.Legacy             C:\Users\Tony\AppData\Roaming\Yahoo!\Companion
PUP.Optional.Legacy             C:\Users\Tony\AppData\Roaming\DriverCure
PUP.Optional.Legacy             C:\Users\Tony\AppData\LocalLow\ShopAtHome
PUP.Optional.Legacy             C:\Users\Tony\AppData\Roaming\ShopAtHome
PUP.Optional.Legacy             C:\ProgramData\Yahoo! Companion
PUP.Optional.Legacy             C:\Users\Tony\AppData\LocalLow\Yahoo! Companion
PUP.Optional.ScanGuard          C:\Users\Tony\Documents\ScanGuard
PUP.Optional.SlimCleanerPlus    C:\Users\Tony\AppData\Local\slimware utilities inc
PUP.Optional.Spigot             C:\Users\Tony\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}
Rogue.ForcedExtension           C:\ProgramData\apn
Trojan.Agent                    C:\Users\Tony\AppData\LocalLow\iac
 
***** [ Files ] *****
 
PUP.Optional.Legacy             C:\Program Files (x86)\Yahoo!\Common\unyt.exe
PUP.Optional.Legacy             C:\Windows\System32\drivers\swdumon.sys
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
PUP.Optional.BrowseFox.A        HKLM\Software\Wow6432Node\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
PUP.Optional.Legacy             HKCU\Software\EasyPDFCombine
PUP.Optional.Legacy             HKCU\Software\FromDocToPDF
PUP.Optional.Legacy             HKCU\Software\Yahoo\YFriendsBar
PUP.Optional.Legacy             HKCU\Software\AppDataLow\Software\Yahoo\Companion
PUP.Optional.Legacy             HKCU\Software\Yahoo\Companion
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Yahoo\Companion
PUP.Optional.Legacy             HKCU\Software\reimagerepair
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\ytbbroker.EXE
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\ytbbroker.EXE
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\yt.DLL
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\yt.DLL
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\ShopAtHomeHelper.EXE
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\ShopAtHomeHelper.EXE
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{9DE77B51-89F6-468E-9402-16050382E950}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{8E74A0AE-F0ED-47ED-A940-A8E99687646B}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{7DB8B625-DBF0-4491-B544-5A06F7B17BB4}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{6EB4349D-4333-442F-ACA4-4C72AF28B6ED}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{3C16E079-E4C7-493C-BE9F-E0F2BB0B7430}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{FBE30D66-39A2-4b72-8B43-6D4C335A6F34}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{C60CCE95-6AF9-4E74-B66B-3212D19F1D2F}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{9F9C4C5C-2BA8-4E00-A697-9F710BB1026B}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{46140CE4-76FE-440E-AE88-4C2272BC05C7}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{3A06AA27-D94B-48C2-BB55-9FD0FF2120E3}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{31371420-098D-4C0E-A11E-EBEC2305DD01}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{1E57256D-9F39-4267-AB39-D7813D644C5A}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF10C1C0-B598-4ADB-B353-42C991C99A2E}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{067ECE13-6DD2-47C7-8EFE-24DA8BC1D8DA}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{067ECE13-6DD2-47C7-8EFE-24DA8BC1D8DA}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{76481128-CCDC-4073-8F65-B06F23B138FC}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{76481128-CCDC-4073-8F65-B06F23B138FC}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{B944FF5E-EC87-4E1E-8C49-2FF3BC573997}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{B944FF5E-EC87-4E1E-8C49-2FF3BC573997}
PUP.Optional.Legacy             HKCU\Software\Classes\TypeLib\{2A05A54D-0614-4EA3-B955-8814E45DCD83}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
PUP.Optional.Legacy             HKLM\Software\Classes\yt.YToolbarBand
PUP.Optional.Legacy             HKLM\Software\Classes\yt.YTHelper
PUP.Optional.Legacy             HKLM\Software\Classes\yt.Clickstream
PUP.Optional.Legacy             HKLM\Software\Classes\yt.CacheLoader
PUP.Optional.Legacy             HKLM\Software\Classes\Sample.YTBPartnerSample
PUP.Optional.Legacy             HKLM\Software\Classes\Sample.BrowserHandler
PUP.Optional.Legacy             HKCU\Software\Microsoft\Internet Explorer\Main|Search Page
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main|Search Page
PUP.Optional.SafePCKit          HKCU\Software\Sunisoft
PUP.Optional.SlimCleanerPlus    HKCU\Software\SlimWare Utilities Inc
PUP.Optional.SlimCleanerPlus    HKLM\Software\Wow6432Node\SlimWare Utilities Inc
PUP.Optional.SlimCleanerPlus    HKLM\Software\SlimWare Utilities Inc
PUP.Optional.Spigot             HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}
 
***** [ Chromium (and derivatives) ] *****
 
PUP.Optional.Legacy             MSN Homepage & Bing Search Engine
PUP.Optional.MindSpark          Search Extension by Ask
 
***** [ Chromium URLs ] *****
 
PUP.Optional.Legacy             AOL
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries found.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs found.
 
 
AdwCleaner[S00].txt - [16589 octets] - [30/06/2018 10:39:24]
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S01].txt ##########

  • 0

#10
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 214 posts

Looks like the things we wanted to remove have been removed, how's your computer behaving now ?

I'd like you to run an online scan for me, to check that there isn't anything else on your machine that we need to deal with.  ADWCleaner and FRST scans are fairly targeted, so it's never a bad idea to have a look around with a more wide-ranging scan to pick up anything they might have missed.

Please run a scan with ESET Online Scanner (please note that this can sometimes take hours to complete)

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go HERE then click on Scan Now
  • You will need to download esetsmartinstaller_enu.exe when prompted, and then double click on it to install.
  • Select the option Accept to accept the terms and conditions, and when prompted by UAC, allow E-Set to make changes.
  • Select the following option.
    • Enable detection of potentially unwanted applications
  • Now click on Scan
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When complete the scan will begin.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed you will be presented with a list of found threats ....
    • Do not clean any of the found threats
    • Click on Save to text file
    • Save as ESET.txt to your Desktop
  • Exit out of ESET Online Scanner.
  • Post me the contents of ESET.txt please.

 

 


  • 0

Advertisements


#11
jbcteacher

jbcteacher

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 206 posts

Hi Gary.  Tony - my neighbor says it is working better.  He is 81 years young!  Here is the next log:

 

C:\AdwCleaner\Quarantine\v1\20180630.124355\10\Downloaded Installers\{055C7DA5-A1F5-41FB-932C-82474ED3487A}\setup.msi#7B238CD47778005F a variant of Win32/UwS.SlimDrivers.A application
C:\AdwCleaner\Quarantine\v1\20180630.124355\10\Downloaded Installers\{3B2D9BF5-A435-41C4-8118-F3D21A054F4D}\setup.msi#7B238CD47778005F a variant of Win32/UwS.SlimDrivers.A application
C:\AdwCleaner\Quarantine\v1\20180630.124355\10\Downloaded Installers\{53C9EBD2-F3F7-49BB-BDB4-147D3A4D5E6D}\setup.msi#7B238CD47778005F a variant of Win32/UwS.SlimDrivers.A application
C:\AdwCleaner\Quarantine\v1\20180630.124355\10\Downloaded Installers\{76F909AC-80EB-47F4-AE1C-299741F83F76}\setup.msi#7B238CD47778005F a variant of Win32/UwS.SlimDrivers.A application
C:\AdwCleaner\Quarantine\v1\20180630.124355\10\Downloaded Installers\{94FC5B48-F3EC-4F7A-B70E-D4F697C56739}\setup.msi#7B238CD47778005F a variant of Win32/UwS.SlimDrivers.A application
C:\AdwCleaner\Quarantine\v1\20180630.124355\9\Downloaded Installers\{DAAA600A-9F08-4BC8-ABE2-6763F93957C6}\setup.msi#7B238CD47778005F a variant of Win32/UwS.SlimDrivers.A application
C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aggobjdbghchcnapfoplmgekgjipjlke\13.611.13.2836_0\js\PartnerId.js JS/Mindspark.G potentially unwanted application
C:\Users\Tony\AppData\Local\Programs\CouponViewer\Add-On\2017.4.7.1\CVNB.dll a variant of Win32/Toolbar.BeFrugal.A potentially unwanted application
C:\Users\Tony\Downloads\Geek Tech Tool Box (1).exe a variant of Win32/RegCure.A potentially unwanted application
C:\Users\Tony\Downloads\Soda_PDF_10_Installer.exe a variant of Win32/LuluSoftware.A potentially unwanted application
 
 
Thanks for your help!

  • 0

#12
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 214 posts

Most of what was found are the quarantine files for ADWCleaner, and we'll remove them in due course, but for the moment we'll leave them alone.

What we will do now, is to remove the things found by e-set that were not quarantined by ADWCleaner.

So ......
 

  • Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
  • Press Ctrl+y (Ctrl and y keys at the same time)
  • A blank randomly named .txt Notepad file will open.
  • Copy and paste the following into it ....
CreateRestorePoint:
C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aggobjdbghchcnapfoplmgekgjipjlke
C:\Users\Tony\AppData\Local\Programs\CouponViewer\Add-On\2017.4.7.1\CVNB.dll
C:\Users\Tony\Downloads\Geek Tech Tool Box (1).exe
C:\Users\Tony\Downloads\Soda_PDF_10_Installer.exe
  • Press Ctrl+s to save fixlist.txt

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system


  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log

 

 


  • 0

#13
jbcteacher

jbcteacher

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 206 posts
Fix result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by Tony (01-07-2018 15:09:02) Run:2
Running from C:\Users\Tony\Desktop
Loaded Profiles: Tony (Available Profiles: Tony)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aggobjdbghchcnapfoplmgekgjipjlke
C:\Users\Tony\AppData\Local\Programs\CouponViewer\Add-On\2017.4.7.1\CVNB.dll
C:\Users\Tony\Downloads\Geek Tech Tool Box (1).exe
C:\Users\Tony\Downloads\Soda_PDF_10_Installer.exe
*****************
 
Restore point was successfully created.
C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aggobjdbghchcnapfoplmgekgjipjlke => moved successfully
C:\Users\Tony\AppData\Local\Programs\CouponViewer\Add-On\2017.4.7.1\CVNB.dll => moved successfully
C:\Users\Tony\Downloads\Geek Tech Tool Box (1).exe => moved successfully
C:\Users\Tony\Downloads\Soda_PDF_10_Installer.exe => moved successfully
 
 
The system needed a reboot.
 
==== End of Fixlog 15:10:12 ====

  • 0

#14
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 214 posts

Looks like everything was removed OK, so looks like we can tie things up now ....

To remove ADWCleaner ....
 

  • Double click AdwCleaner.exe to run it.
  • Click Uninstall.
  • Click Yes to the prompt.
  • AdwCleaner will close and uninstall itself

Note: If AdwCleaner prompts you an update is available, click Cancel and continue to uninstall.

Next ...

To fully remove FRST ...



  • Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
  • Press Ctrl+y (Ctrl and y keys at the same time)
  • A blank randomly named .txt Notepad file will open.
  • Copy and paste the following into it ....
Move: C:\Users\Tony\Desktop\Frst64.exe C:\Users\Tony\Desktop\Uninstall.exe
Cmd: start Uninstall.exe
  • Press Ctrl+s to save fixlist.txt

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system


  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt which will cause it to reboot the computer.
  • On boot up it will delete FRST and any files it created (including the logs).

As far as I can see, your friend's computer looks clear of infection now.

Please read the article below which I wrote some time back, it will give you a few suggestions for how to minimise his chances of getting another infection.



    

 

 


  • 0

#15
jbcteacher

jbcteacher

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 206 posts
Hi Gary! Its all done thank you for your help!

Happy 4th!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP