Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Malware/adware infection


  • Please log in to reply

#16
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,107 posts
You right click on the OTL Icon on the desktop first, then choose "Run as administrator"

A Quick scan will be fine.

Joe
  • 0

Advertisements


#17
saoirse

saoirse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
!OTL logfile created on: 7/20/2014 9:16:40 PM - Run 4
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Nancy\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17207)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.96 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 27.66% Memory free
7.92 Gb Paging File | 4.10 Gb Available in Paging File | 51.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 148.76 Gb Free Space | 68.18% Space Free | Partition Type: NTFS
Unable to calculate disk information.
 
Computer Name: NANCY-PC | User Name: Nancy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/07/20 20:44:00 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Nancy\Downloads\OTL (2).exe
PRC - [2014/06/20 03:57:10 | 000,230,792 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
PRC - [2014/05/12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2014/05/12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
PRC - [2014/05/12 07:24:34 | 006,970,168 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
PRC - [2012/04/04 01:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2009/11/17 10:44:54 | 000,040,960 | ---- | M] () -- C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe
PRC - [2009/06/09 12:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2009/06/04 21:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/07/15 05:24:48 | 000,353,096 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppgooglenaclpluginchrome.dll
MOD - [2014/07/15 05:24:46 | 014,664,008 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll
MOD - [2014/07/15 05:24:44 | 008,537,928 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll
MOD - [2014/07/15 05:24:38 | 000,718,664 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\libglesv2.dll
MOD - [2014/07/15 05:24:36 | 000,126,280 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\libegl.dll
MOD - [2014/07/15 05:24:35 | 001,732,936 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/06/18 20:24:12 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/10/07 10:01:37 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
SRV:64bit: - [2009/07/16 21:06:22 | 000,033,280 | ---- | M] () [Auto | Running] -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
SRV:64bit: - [2009/06/29 00:44:38 | 000,240,128 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe -- (STacSV)
SRV:64bit: - [2009/06/09 12:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2014/05/12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014/05/12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/03/21 23:36:46 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/04/04 01:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/02/28 18:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2009/11/17 10:44:54 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe -- (DeviceManager)
SRV - [2009/06/29 00:44:38 | 000,240,128 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe -- (STacSV)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 21:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/07/20 19:50:31 | 000,122,584 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2014/05/12 07:26:10 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:64bit: - [2014/05/12 07:25:56 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/07/22 12:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 17:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/06/24 22:01:12 | 000,122,624 | R--- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smhwser.sys -- (smhwser)
DRV:64bit: - [2010/06/24 22:01:12 | 000,114,432 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smhwdev.sys -- (smhwdev)
DRV:64bit: - [2010/06/24 22:01:12 | 000,031,744 | R--- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smhwadb.sys -- (androidusb)
DRV:64bit: - [2009/08/27 13:18:30 | 000,118,016 | ---- | M] (TCT International Mobile Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qcusbser.sys -- (qcusbser)
DRV:64bit: - [2009/07/16 21:06:20 | 000,022,520 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcm42rly.sys -- (BCM42RLY)
DRV:64bit: - [2009/07/16 21:06:18 | 002,769,400 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/09 05:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/29 00:44:38 | 000,487,424 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2009/06/15 15:06:42 | 000,172,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/04 06:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/06/02 23:16:56 | 007,333,472 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/05/19 23:10:00 | 000,393,728 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009/05/08 04:15:18 | 000,215,552 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2009/02/05 07:54:10 | 000,225,328 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2006/11/01 14:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{654610C7-59C4-42ED-8FD5-12544AEBA3AF}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{39172B5C-E3CD-4F23-8AAF-7616C32FCDF7}: "URL" = http://www.bing.com/...rc=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://[email protected]/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "http://n.porta.net/google.com"
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: ""
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: ""
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: ""
FF - prefs.js..network.proxy.ftp: ""
FF - prefs.js..network.proxy.ftp_port: 8799
FF - prefs.js..network.proxy.http: ""
FF - prefs.js..network.proxy.http_port: ""
FF - prefs.js..network.proxy.share_proxy_settings: ""
FF - prefs.js..network.proxy.socks: ""
FF - prefs.js..network.proxy.socks_port: ""
FF - prefs.js..network.proxy.ssl: ""
FF - prefs.js..network.proxy.ssl_port: ""
FF - prefs.js..network.proxy.type: ""
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.60.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@fuzebox.com/Fuze Meeting NPAPI Plugin,version=1.0.0.1: C:\Users\Nancy\AppData\Local\Fuze Box\Fuze Meeting\npfuzeshare.dll ( )
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Nancy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Nancy\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Nancy\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
 
 
[2011/04/13 21:16:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Nancy\AppData\Roaming\Mozilla\Extensions
File not found (No name found) -- C:\USERS\NANCY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Z7WJSRL3.DEFAULT\EXTENSIONS\D55CD0D7-9F24-4660-95B3-188599E8E4F8@6B2FAF04-E86F-4BCF-A878-632814ACF518.COM
File not found (No name found) -- C:\USERS\NANCY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Z7WJSRL3.DEFAULT\EXTENSIONS\FF806580-6DB3-4C09-BA06-D6CAF0E99172@8453CB25-7FEF-4ED5-8934-B08BE5605617.COM
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Nancy\AppData\Local\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Nancy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5019_0\
CHR - Extension: Google Wallet = C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
 
O1 HOSTS File: ([2014/07/20 07:48:23 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O1364bit: - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.appl...ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.60.2)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.60.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C7D6DB35-8CBE-489D-8859-83FAEEA40232}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E68395D3-ECB1-4278-BEB2-79E8C06FD09F}: NameServer = 200.105.225.2,200.105.225.4
O18:64bit: - Protocol\Handler\cozi - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/07/20 15:56:16 | 000,122,584 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/07/20 15:55:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/07/20 15:55:36 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/07/20 15:55:36 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/07/20 15:55:36 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/07/20 15:55:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014/07/20 15:55:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/07/20 07:45:36 | 000,000,000 | ---D | C] -- C:\_OTL
[2014/07/19 19:58:52 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{F8404204-7BA7-4F64-AEBC-CE551CA1F707}
[2014/07/19 07:57:59 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{3E5A0AD6-99F2-407C-B1A9-54C106B9993B}
[2014/07/18 19:57:07 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{021E84F5-B9E5-41C8-8897-05D8FB2D5A39}
[2014/07/18 07:56:53 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{1BFE49DB-DE26-443E-AA78-88A99AEAD380}
[2014/07/17 19:56:40 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{06E5E672-B0E5-476D-A619-41E4DA0F03ED}
[2014/07/17 07:55:49 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{70497B6D-7C38-46C1-9453-91EEC9119FF9}
[2014/07/16 19:54:57 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{14D48415-6278-48DF-A604-1B12AFFB5750}
[2014/07/16 07:54:44 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{41D2BE0B-D136-449A-8FBB-E87FD47676EB}
[2014/07/15 17:52:40 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{0CFB824D-E472-40FD-817E-3F3562A5B097}
[2014/07/15 05:51:35 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{ACAE3AC8-D84F-466D-B951-816A5F1922F2}
[2014/07/14 17:47:35 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{14635022-2528-49AC-9E21-33846984615D}
[2014/07/14 17:45:41 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{97BB7E00-D51C-4CAC-8BCB-4302D6455535}
[2014/07/14 16:08:24 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\SysWow64\sqlite3.dll
[2014/07/14 16:07:31 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/07/12 16:34:29 | 000,000,000 | -HSD | C] -- C:\Users\Nancy\AppData\Local\EmieUserList
[2014/07/12 16:34:29 | 000,000,000 | -HSD | C] -- C:\Users\Nancy\AppData\Local\EmieSiteList
[2014/07/12 12:43:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014/07/12 12:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/07/11 14:20:25 | 000,000,000 | ---D | C] -- C:\SUPERDelete
[2014/07/10 19:09:13 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{05E5D35C-7B8D-48C7-B52C-A428539C7A17}
[2014/07/10 07:08:49 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{CFCE6609-4768-4F01-AC5A-DF77150AADE0}
[2014/07/08 14:24:56 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{2C9E13A0-9D44-42E0-A81C-A0421C116BCD}
[2014/06/28 13:36:44 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{61570072-25A5-41C3-9FA0-434CE421A929}
[2014/06/28 01:35:49 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{8B33D582-E07B-4A9A-978D-031A00EEDEBE}
[2014/06/27 13:34:55 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{2655DFB9-37EC-4295-8355-9C15FB553E24}
[2014/06/27 01:34:40 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{1EE06C26-D863-40D0-81A2-6B0ABBD5CF8F}
[2014/06/26 13:34:22 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{58032922-04C9-4A07-B3B0-C4FBE1F2513F}
[2014/06/26 00:21:54 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{8E973783-C14F-4D92-A06C-EEC1049AB08D}
[2014/06/25 12:20:57 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{9E418645-FB8F-4EEE-B2C4-3D0780B7E2CA}
[2014/06/25 00:20:43 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{82157E21-23DA-4BED-89F4-0A87F6CEF6AB}
[2014/06/24 12:20:31 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{56F5B925-9031-49FC-9C27-53D8D2E7EAC4}
[2014/06/24 00:20:19 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{5C66800E-287F-410A-B550-FF0ADF215D6A}
[2014/06/23 12:20:05 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{B3492C91-A5BF-4F2D-BA5E-653E9159B260}
[2014/06/23 00:19:54 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{60CFDA94-5449-4C51-A38A-B91496470C36}
[2014/06/22 12:19:01 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{8118CE06-E440-438F-B652-6B0A08A3517C}
[2014/06/22 00:18:49 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{36B38102-EA43-4F00-B8B9-A2222F43886E}
[2014/06/21 12:17:39 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{BE4B2671-1567-4FE6-B356-CF3FCA2377C9}
[2014/06/21 00:17:23 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{D5BDC102-3DA9-4E64-9CC6-945D5D4AD178}
 
========== Files - Modified Within 30 Days ==========
 
[2014/07/20 21:02:01 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/07/20 20:40:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/07/20 20:25:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000UA.job
[2014/07/20 19:50:31 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/07/20 19:21:02 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000Core.job
[2014/07/20 19:21:01 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000UA.job
[2014/07/20 17:25:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000Core.job
[2014/07/20 16:44:20 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/07/20 16:44:20 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/07/20 16:37:21 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/07/20 16:37:14 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2014/07/20 16:36:54 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2014/07/20 16:36:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/07/20 16:36:40 | 3190,050,816 | -HS- | M] () -- C:\hiberfil.sys
[2014/07/20 15:55:40 | 000,001,064 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/07/20 07:48:23 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2014/07/18 14:31:06 | 000,002,328 | ---- | M] () -- C:\Users\Nancy\Desktop\Google Chrome.lnk
[2014/07/10 03:24:27 | 000,343,552 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/07/08 14:20:35 | 000,782,510 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/07/08 14:20:35 | 000,662,650 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/07/08 14:20:35 | 000,122,486 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
 
========== Files Created - No Company Name ==========
 
[2014/07/20 15:55:40 | 000,001,064 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/05/24 22:20:15 | 000,022,754 | ---- | C] () -- C:\Users\Nancy\moonlight.jpg
[2014/02/26 04:09:05 | 000,775,124 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/09/27 20:17:33 | 000,060,864 | ---- | C] () -- C:\Users\Nancy\g2mdlhlpx.exe
[2012/01/24 08:15:54 | 000,000,000 | ---- | C] () -- C:\Users\Nancy\AppData\Local\{95DF6620-02EA-4FA1-AA70-06981FCB299F}
[2011/08/27 10:57:26 | 000,008,704 | ---- | C] () -- C:\Users\Nancy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/22 10:48:59 | 000,000,400 | ---- | C] () -- C:\Users\Nancy\AppData\Roaming\wklnhst.dat
[2010/06/12 00:10:45 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/06/05 18:36:42 | 000,002,154 | ---- | C] () -- C:\Users\Nancy\AppData\Roaming\install.dat
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/24 22:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 22:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013/06/06 23:38:31 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\Canon
[2011/03/05 00:33:27 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\FrostWire
[2011/05/13 17:35:28 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\IObit
[2011/11/24 13:18:57 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\Mikrotik
[2013/03/31 14:55:39 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\mjusbsp
[2011/08/22 15:32:31 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\ooVoo Details
[2010/06/20 17:14:20 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\OurPictures
[2010/06/22 10:52:06 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\Template
[2013/09/30 20:11:42 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\webex
[2011/06/03 09:59:40 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\Windows Live Writer
 
========== Purity Check ==========
 
 
 
< End of report >

  • 0

#18
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,107 posts
Hello,

We need to do another fix to delete some files using OTL just like the great job you did before
  • Double click on the OTLicon.jpg to open the program. On Vista/Win7/Win8 right click select Run As Administrator to start the program. If prompted by UAC, please allow it.
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


    :COMMANDS
    [CREATERESTOREPOINT]
    
    :OTL
    [2014/07/20 16:44:20 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2014/07/20 16:44:20 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    FF - prefs.js..network.proxy.ftp_port: 8799
    File not found (No name found) -- C:\USERS\NANCY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Z7WJSRL3.DEFAULT\EXTENSIONS\D55CD0D7-9F24-4660-95B3-188599E8E4F8@6B2FAF04-E86F-4BCF-A878-632814ACF518.COM
    File not found (No name found) -- C:\USERS\NANCY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Z7WJSRL3.DEFAULT\EXTENSIONS\FF806580-6DB3-4C09-BA06-D6CAF0E99172@8453CB25-7FEF-4ED5-8934-B08BE5605617.COM
     
    :Files
    
    :Commands
    
    [emptytemp]
    
    
  • Make sure all other windows are closed.
  • Click the Run Fix button at the top
  • Let the program run uninterrupted. The computer should reboot when the scan is done. If not, please reboot the computer.
  • Post the log that is found in C:\_OTL\Moved Files in your next reply.
  • Open OTL again and click the Quick Scan button.
In review run OTL fix.
1-Post the OTL Fix Log, it should pop up in front of you after reboot or it's here-->C:\_OTL\Moved Files
2-Then do a quick scan, and post that log.

After that is done above and you posted the log reports:

Next

I want to run another scan. This needs to be downloaded to the desktop, not the downloads folder. If it ends up in the downloads folder drag it to the desktop :)

Please download Farbar Recovery Scan Tool and save it to your Desktop

Note: You need to run the version compatible with your system 64Bit for you. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory (Desktop) the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
Take your time and post those 2 logs above:
1- FRST.txt
2- Addition.txt

Thanks
Joe :)
  • 0

#19
saoirse

saoirse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 moved successfully.
C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 moved successfully.
Prefs.js: 8799 removed from network.proxy.ftp_port
========== FILES ==========
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Nancy
->Temp folder emptied: 12107868 bytes
->Temporary Internet Files folder emptied: 401185 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 351138791 bytes
->Flash cache emptied: 0 bytes
 
User: Public
 
User: TEMP
 
User: TEST
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2078 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 347.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 07212014_085128

  • 0

#20
saoirse

saoirse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts

When I rebooted this time, a window popped up saying that unauthorized changes were made to  WINDOWS. Should I use their fix for it?


  • 0

#21
saoirse

saoirse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
OTL logfile created on: 7/21/2014 9:11:23 AM - Run 5
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Nancy\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17207)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.96 Gb Total Physical Memory | 2.37 Gb Available Physical Memory | 59.75% Memory free
7.92 Gb Paging File | 5.94 Gb Available in Paging File | 75.02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 148.19 Gb Free Space | 67.91% Space Free | Partition Type: NTFS
Unable to calculate disk information.
 
Computer Name: NANCY-PC | User Name: Nancy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/07/19 16:36:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Nancy\Downloads\OTL.exe
PRC - [2014/06/20 03:57:10 | 000,230,792 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
PRC - [2014/05/12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2014/05/12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
PRC - [2014/05/12 07:24:34 | 006,970,168 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
PRC - [2012/04/04 01:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2009/11/17 10:44:54 | 000,040,960 | ---- | M] () -- C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe
PRC - [2009/06/09 12:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2009/06/04 21:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/07/15 05:24:48 | 000,353,096 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppgooglenaclpluginchrome.dll
MOD - [2014/07/15 05:24:44 | 008,537,928 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll
MOD - [2014/07/15 05:24:38 | 000,718,664 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\libglesv2.dll
MOD - [2014/07/15 05:24:36 | 000,126,280 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\libegl.dll
MOD - [2014/07/15 05:24:35 | 001,732,936 | ---- | M] () -- C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/06/18 20:24:12 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/10/07 10:01:37 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
SRV:64bit: - [2009/07/16 21:06:22 | 000,033,280 | ---- | M] () [Auto | Running] -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
SRV:64bit: - [2009/06/29 00:44:38 | 000,240,128 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe -- (STacSV)
SRV:64bit: - [2009/06/09 12:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2014/05/12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014/05/12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/03/21 23:36:46 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/04/04 01:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/02/28 18:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2009/11/17 10:44:54 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe -- (DeviceManager)
SRV - [2009/06/29 00:44:38 | 000,240,128 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe -- (STacSV)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 21:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/07/21 08:59:11 | 000,122,584 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2014/05/12 07:26:10 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:64bit: - [2014/05/12 07:25:56 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/07/22 12:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 17:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/06/24 22:01:12 | 000,122,624 | R--- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smhwser.sys -- (smhwser)
DRV:64bit: - [2010/06/24 22:01:12 | 000,114,432 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smhwdev.sys -- (smhwdev)
DRV:64bit: - [2010/06/24 22:01:12 | 000,031,744 | R--- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smhwadb.sys -- (androidusb)
DRV:64bit: - [2009/08/27 13:18:30 | 000,118,016 | ---- | M] (TCT International Mobile Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qcusbser.sys -- (qcusbser)
DRV:64bit: - [2009/07/16 21:06:20 | 000,022,520 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcm42rly.sys -- (BCM42RLY)
DRV:64bit: - [2009/07/16 21:06:18 | 002,769,400 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/09 05:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/29 00:44:38 | 000,487,424 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2009/06/15 15:06:42 | 000,172,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/04 06:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/06/02 23:16:56 | 007,333,472 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/05/19 23:10:00 | 000,393,728 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009/05/08 04:15:18 | 000,215,552 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2009/02/05 07:54:10 | 000,225,328 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2006/11/01 14:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{654610C7-59C4-42ED-8FD5-12544AEBA3AF}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{39172B5C-E3CD-4F23-8AAF-7616C32FCDF7}: "URL" = http://www.bing.com/...rc=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://[email protected]/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "http://n.porta.net/google.com"
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: ""
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: ""
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: ""
FF - prefs.js..network.proxy.ftp: ""
FF - prefs.js..network.proxy.ftp_port: ""
FF - prefs.js..network.proxy.http: ""
FF - prefs.js..network.proxy.http_port: ""
FF - prefs.js..network.proxy.share_proxy_settings: ""
FF - prefs.js..network.proxy.socks: ""
FF - prefs.js..network.proxy.socks_port: ""
FF - prefs.js..network.proxy.ssl: ""
FF - prefs.js..network.proxy.ssl_port: ""
FF - prefs.js..network.proxy.type: ""
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.60.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@fuzebox.com/Fuze Meeting NPAPI Plugin,version=1.0.0.1: C:\Users\Nancy\AppData\Local\Fuze Box\Fuze Meeting\npfuzeshare.dll ( )
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Nancy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Nancy\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Nancy\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
 
 
[2011/04/13 21:16:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Nancy\AppData\Roaming\Mozilla\Extensions
File not found (No name found) -- C:\USERS\NANCY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Z7WJSRL3.DEFAULT\EXTENSIONS\D55CD0D7-9F24-4660-95B3-188599E8E4F8@6B2FAF04-E86F-4BCF-A878-632814ACF518.COM
File not found (No name found) -- C:\USERS\NANCY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Z7WJSRL3.DEFAULT\EXTENSIONS\FF806580-6DB3-4C09-BA06-D6CAF0E99172@8453CB25-7FEF-4ED5-8934-B08BE5605617.COM
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Nancy\AppData\Local\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Nancy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5019_0\
CHR - Extension: Google Wallet = C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
 
O1 HOSTS File: ([2014/07/20 07:48:23 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O1364bit: - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.appl...ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.60.2)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.60.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C7D6DB35-8CBE-489D-8859-83FAEEA40232}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E68395D3-ECB1-4278-BEB2-79E8C06FD09F}: NameServer = 200.105.225.2,200.105.225.4
O18:64bit: - Protocol\Handler\cozi - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/07/20 15:56:16 | 000,122,584 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/07/20 15:55:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/07/20 15:55:36 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/07/20 15:55:36 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/07/20 15:55:36 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/07/20 15:55:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014/07/20 15:55:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/07/20 07:45:36 | 000,000,000 | ---D | C] -- C:\_OTL
[2014/07/19 19:58:52 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{F8404204-7BA7-4F64-AEBC-CE551CA1F707}
[2014/07/19 07:57:59 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{3E5A0AD6-99F2-407C-B1A9-54C106B9993B}
[2014/07/18 19:57:07 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{021E84F5-B9E5-41C8-8897-05D8FB2D5A39}
[2014/07/18 07:56:53 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{1BFE49DB-DE26-443E-AA78-88A99AEAD380}
[2014/07/17 19:56:40 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{06E5E672-B0E5-476D-A619-41E4DA0F03ED}
[2014/07/17 07:55:49 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{70497B6D-7C38-46C1-9453-91EEC9119FF9}
[2014/07/16 19:54:57 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{14D48415-6278-48DF-A604-1B12AFFB5750}
[2014/07/16 07:54:44 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{41D2BE0B-D136-449A-8FBB-E87FD47676EB}
[2014/07/15 17:52:40 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{0CFB824D-E472-40FD-817E-3F3562A5B097}
[2014/07/15 05:51:35 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{ACAE3AC8-D84F-466D-B951-816A5F1922F2}
[2014/07/14 17:47:35 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{14635022-2528-49AC-9E21-33846984615D}
[2014/07/14 17:45:41 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{97BB7E00-D51C-4CAC-8BCB-4302D6455535}
[2014/07/14 16:08:24 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\SysWow64\sqlite3.dll
[2014/07/14 16:07:31 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/07/12 16:34:29 | 000,000,000 | -HSD | C] -- C:\Users\Nancy\AppData\Local\EmieUserList
[2014/07/12 16:34:29 | 000,000,000 | -HSD | C] -- C:\Users\Nancy\AppData\Local\EmieSiteList
[2014/07/12 12:43:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014/07/12 12:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/07/11 14:20:25 | 000,000,000 | ---D | C] -- C:\SUPERDelete
[2014/07/10 19:09:13 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{05E5D35C-7B8D-48C7-B52C-A428539C7A17}
[2014/07/10 07:08:49 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{CFCE6609-4768-4F01-AC5A-DF77150AADE0}
[2014/07/08 14:24:56 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{2C9E13A0-9D44-42E0-A81C-A0421C116BCD}
[2014/06/28 13:36:44 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{61570072-25A5-41C3-9FA0-434CE421A929}
[2014/06/28 01:35:49 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{8B33D582-E07B-4A9A-978D-031A00EEDEBE}
[2014/06/27 13:34:55 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{2655DFB9-37EC-4295-8355-9C15FB553E24}
[2014/06/27 01:34:40 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{1EE06C26-D863-40D0-81A2-6B0ABBD5CF8F}
[2014/06/26 13:34:22 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{58032922-04C9-4A07-B3B0-C4FBE1F2513F}
[2014/06/26 00:21:54 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{8E973783-C14F-4D92-A06C-EEC1049AB08D}
[2014/06/25 12:20:57 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{9E418645-FB8F-4EEE-B2C4-3D0780B7E2CA}
[2014/06/25 00:20:43 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{82157E21-23DA-4BED-89F4-0A87F6CEF6AB}
[2014/06/24 12:20:31 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{56F5B925-9031-49FC-9C27-53D8D2E7EAC4}
[2014/06/24 00:20:19 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{5C66800E-287F-410A-B550-FF0ADF215D6A}
[2014/06/23 12:20:05 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{B3492C91-A5BF-4F2D-BA5E-653E9159B260}
[2014/06/23 00:19:54 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{60CFDA94-5449-4C51-A38A-B91496470C36}
[2014/06/22 12:19:01 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{8118CE06-E440-438F-B652-6B0A08A3517C}
[2014/06/22 00:18:49 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{36B38102-EA43-4F00-B8B9-A2222F43886E}
[2014/06/21 12:17:39 | 000,000,000 | ---D | C] -- C:\Users\Nancy\AppData\Local\{BE4B2671-1567-4FE6-B356-CF3FCA2377C9}
 
========== Files - Modified Within 30 Days ==========
 
[2014/07/21 09:02:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/07/21 08:59:26 | 000,001,184 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/07/21 08:59:26 | 000,001,184 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/07/21 08:59:11 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/07/21 08:57:28 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/07/21 08:57:25 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2014/07/21 08:57:06 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2014/07/21 08:57:00 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/07/21 08:56:53 | 3190,050,816 | -HS- | M] () -- C:\hiberfil.sys
[2014/07/21 08:40:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/07/21 08:25:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000UA.job
[2014/07/21 07:21:02 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000UA.job
[2014/07/20 19:21:02 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000Core.job
[2014/07/20 17:25:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000Core.job
[2014/07/20 15:55:40 | 000,001,064 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/07/20 07:48:23 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2014/07/18 14:31:06 | 000,002,328 | ---- | M] () -- C:\Users\Nancy\Desktop\Google Chrome.lnk
[2014/07/10 03:24:27 | 000,343,552 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/07/08 14:20:35 | 000,782,510 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/07/08 14:20:35 | 000,662,650 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/07/08 14:20:35 | 000,122,486 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
 
========== Files Created - No Company Name ==========
 
[2014/07/21 08:59:16 | 000,001,184 | -H-- | C] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/07/21 08:59:16 | 000,001,184 | -H-- | C] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/07/20 15:55:40 | 000,001,064 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/05/24 22:20:15 | 000,022,754 | ---- | C] () -- C:\Users\Nancy\moonlight.jpg
[2014/02/26 04:09:05 | 000,775,124 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/09/27 20:17:33 | 000,060,864 | ---- | C] () -- C:\Users\Nancy\g2mdlhlpx.exe
[2012/01/24 08:15:54 | 000,000,000 | ---- | C] () -- C:\Users\Nancy\AppData\Local\{95DF6620-02EA-4FA1-AA70-06981FCB299F}
[2011/08/27 10:57:26 | 000,008,704 | ---- | C] () -- C:\Users\Nancy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/22 10:48:59 | 000,000,400 | ---- | C] () -- C:\Users\Nancy\AppData\Roaming\wklnhst.dat
[2010/06/12 00:10:45 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/06/05 18:36:42 | 000,002,154 | ---- | C] () -- C:\Users\Nancy\AppData\Roaming\install.dat
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/24 22:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 22:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013/06/06 23:38:31 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\Canon
[2011/03/05 00:33:27 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\FrostWire
[2011/05/13 17:35:28 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\IObit
[2011/11/24 13:18:57 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\Mikrotik
[2013/03/31 14:55:39 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\mjusbsp
[2011/08/22 15:32:31 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\ooVoo Details
[2010/06/20 17:14:20 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\OurPictures
[2010/06/22 10:52:06 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\Template
[2013/09/30 20:11:42 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\webex
[2011/06/03 09:59:40 | 000,000,000 | ---D | M] -- C:\Users\Nancy\AppData\Roaming\Windows Live Writer
 
========== Purity Check ==========
 
 
 
< End of report >

  • 0

#22
saoirse

saoirse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-07-2014
Ran by Nancy at 2014-07-21 10:47:07
Running from C:\Users\Nancy\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
 Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version:  - )
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.6.602.180 - Adobe Systems Incorporated)
Adobe Reader X (10.1.3) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.3 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
Banda Ancha Movil (HKLM-x32\...\Banda Ancha Movil ALCATEL_is1) (Version:  - Alcatel)
Bing Bar (HKLM-x32\...\{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}) (Version: 7.0.609.0 - Microsoft Corporation)
Canon MP Navigator EX 3.0 (HKLM-x32\...\MP Navigator EX 3.0) (Version:  - )
Canon MP250 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series) (Version:  - )
Canon Utilities Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version:  - )
Canon Utilities My Printer (HKLM-x32\...\CanonMyPrinter) (Version:  - )
Canon Utilities Solution Menu (HKLM-x32\...\CanonSolutionMenu) (Version:  - )
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cisco WebEx Meetings (HKCU\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Cozi (HKLM-x32\...\{2DA5F129-11AC-4F11-8188-B2F07EAAC20A}) (Version: 1.0.4323.24051 - Cozi Group, Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Dock (HKLM\...\{E60B7350-EA5F-41E0-9D6F-E508781E36D2}) (Version: 2.0.0 - Dell)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.104.115.102 - Alps Electric)
Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 1.40.05 - Creative Technology Ltd)
Dell Wireless WLAN Card Utility (HKLM\...\Dell Wireless WLAN Card Utility) (Version: 5.30.21.0 - Dell Inc.)
Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited)
FrostWire 4.20.7 (HKLM-x32\...\FrostWire) (Version: 4.20.7.0 - FrostWire, LLC)
Fuze Meeting (HKLM-x32\...\{FFC5D11F-83D2-4E74-9521-86CAD955B7E5}) (Version: 1.10.43494 - Fuze Box, Inc.)
Google Chrome (HKCU\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google SketchUp 8 (HKLM-x32\...\{47BBA5AA-CA6F-4A41-858D-A7A776F29A8B}) (Version: 3.0.11752 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Google+ Auto Backup (HKCU\...\Google+ Auto Backup) (Version: 1.0.25.133 - Google, Inc.)
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
GoToMeeting 5.4.0.1082 (HKCU\...\GoToMeeting) (Version: 5.4.0.1082 - CitrixOnline)
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:  - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
InterActual Player (HKLM-x32\...\InterActual Player) (Version:  - )
Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217060FF}) (Version: 7.0.600 - Oracle)
Java Auto Updater (x32 Version: 2.1.60.19 - Oracle, Inc.) Hidden
Java™ 6 Update 17 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416017FF}) (Version: 6.0.170 - Sun Microsystems, Inc.)
Java™ 6 Update 24 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216017FF}) (Version: 6.0.240 - Sun Microsystems, Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Live! Cam Avatar Creator (HKLM-x32\...\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.3009.1 - Creative Technology Ltd)
magicJack (HKCU\...\magicJack) (Version: 2.0.6073.4413 - magicJack L.P.)
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Suite Activation Assistant (HKLM-x32\...\{67635FB6-2F63-4FFB-830B-D4C01597EBA4}) (Version: 1.2.1 - DELL)
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PowerDVD DX (HKLM-x32\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.3.5424 - CyberLink Corp.)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 9.6.6 - Dell Inc.)
Roxio Burn (HKLM-x32\...\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.01 - Roxio)
Roxio Burn (x32 Version: 1.01 - Roxio) Hidden
Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1150 - SUPERAntiSpyware.com)
Uniblue RegistryBooster (HKLM-x32\...\Uniblue RegistryBooster) (Version: 6.0.3.6 - Uniblue Systems Ltd)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version:  - Microsoft)
Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM-x32\...\{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version:  - Microsoft)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version:  - Microsoft)
Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
Update for Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version:  - Microsoft)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WinRAR archiver (HKLM\...\WinRAR archiver) (Version:  - )
 
==================== Restore Points  =========================
 
17-07-2014 07:00:12 Windows Update
18-07-2014 07:00:18 Windows Update
19-07-2014 07:00:12 Windows Update
20-07-2014 07:00:13 Windows Update
20-07-2014 11:45:47 OTL Restore Point - 7/20/2014 7:45:47 AM
21-07-2014 07:00:23 Windows Update
21-07-2014 12:51:44 OTL Restore Point - 7/21/2014 8:51:43 AM
21-07-2014 12:55:02 Windows Update
 
==================== Hosts content: ==========================
 
2009-07-13 22:34 - 2014-07-20 07:48 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1       localhost
 
==================== Scheduled Tasks (whitelisted) =============
 
Task: {02EF7E7B-96C0-4CF3-8DA7-7D836368CFE0} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-2 No Task File <==== ATTENTION
Task: {0B7D7F13-F9CA-44A4-AA7C-1F71BBC1398F} - System32\Tasks\JavaUpdateSched => C:\Windows\System32\jusched.exe [2010-02-16] (Sun Microsystems, Inc.)
Task: {14EB1E0B-3E13-464C-99A4-F8F2840B88DD} - System32\Tasks\{265C0489-6F27-49AD-ADB7-2E0FBDE34CE2} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.)
Task: {167FD5F9-ED52-4F19-81C0-992D6694CB80} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-11 No Task File <==== ATTENTION
Task: {17452488-2815-4946-81B1-4B3C3255F35B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000UA => C:\Users\Nancy\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-14] (Google Inc.)
Task: {1DED38A8-E394-4CB1-8BA6-E2B2780775C2} - System32\Tasks\{DB79F3BE-9AA3-4B38-9836-EB52EAB90996} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.)
Task: {1FD35690-0F42-4EBC-99D6-8FB042FF38DE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000Core => C:\Users\Nancy\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-14] (Google Inc.)
Task: {2328A71D-80EC-4AA7-B4D2-A4B4491E74FB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-21] (Adobe Systems Incorporated)
Task: {2D55DE8F-EBA1-4BF0-86F1-68F8CC00D9FC} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-1 No Task File <==== ATTENTION
Task: {33F3198A-79CD-432E-83F7-0DD523100D6F} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5 No Task File <==== ATTENTION
Task: {35E068A5-EF12-4CCF-AF69-06D26224748A} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5_user No Task File <==== ATTENTION
Task: {362D6CA0-1BEE-4DE3-801D-5449DF0F4585} - System32\Tasks\RegistryBooster => C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe
Task: {39E72AE9-56D2-4D6F-93E8-57909D358A13} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-5 No Task File <==== ATTENTION
Task: {3C12A939-12C1-4134-8496-7ED75D28574D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-12] (Google Inc.)
Task: {3C574D08-097B-4195-913A-E91400C9ED4A} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-7 No Task File <==== ATTENTION
Task: {3CB53BFC-94E1-43C6-A788-62A73D206109} - System32\Tasks\{D1BC675B-2D67-4054-9158-9A22445128AD} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.)
Task: {3D8DC417-A9C4-4BFD-815B-F9E81B8A8F08} - System32\Tasks\{17A44028-30F6-4282-B8EF-AD4F30B8B7EB} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.)
Task: {4FF36279-443C-42D4-A89D-CD1ED628E655} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-3 No Task File <==== ATTENTION
Task: {50A12FA4-A18F-46A1-9530-799EC36662C5} - System32\Tasks\D6VNZ8L1\Administrator - Start WLAN Tray Applet => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE [2009-07-16] (Dell Inc.)
Task: {52B70686-CC1A-48A2-A34B-8E6537D76701} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-12] (Google Inc.)
Task: {55770699-0D06-4AA1-A5D3-71B2053E840A} - System32\Tasks\ASC4_AutoCare => C:\Program Files (x86)\IObit\Advanced SystemCare 4\AutoCare.exe
Task: {56689F47-46C3-46FF-B1CF-196C978DC7AB} - System32\Tasks\{B9487F93-79E8-4569-9652-33B6B0FCAF18} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.)
Task: {594D6170-8FFB-45A5-8C5B-507758ABFFEB} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-6 No Task File <==== ATTENTION
Task: {59B173CD-503E-4B5B-B62B-C7756F9C9479} - System32\Tasks\ASC4_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe
Task: {5B735B94-5300-49F2-8FAE-2355CED34055} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-6 No Task File <==== ATTENTION
Task: {5FB355BB-E8FB-4A4C-B9E7-D94AF6DA1AD9} - System32\Tasks\{E81534FA-76AB-45BC-9204-EF056B4812AD} => Chrome.exe http://ui.skype.com/...e=tsProgressBar
Task: {67858947-01EA-4BB5-BDF7-A15F80363827} - System32\Tasks\{70E7F939-64C8-47A0-94DC-133BB8898D37} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.)
Task: {7BE6E8CB-3D1E-4432-A157-47D98077FE4E} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000UA => C:\Users\Nancy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11] (Facebook Inc.)
Task: {8B63B624-2F11-4055-9D9F-2D3FD2D0D056} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-1 No Task File <==== ATTENTION
Task: {8C2119A0-B8D9-4487-B7A1-FF11DA0FEB86} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-2 No Task File <==== ATTENTION
Task: {9258B12E-CFC6-419A-AB33-502138E1FBA1} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-11 No Task File <==== ATTENTION
Task: {B03D89AB-A11A-48B1-AA0C-5D3A4547B2ED} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-4 No Task File <==== ATTENTION
Task: {BE488F3A-FE68-4BC8-84C4-E50F87C6EF33} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {C3E7F556-BBF8-4422-868B-F3DAED476F0E} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000Core => C:\Users\Nancy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11] (Facebook Inc.)
Task: {C465AABE-7608-46C1-85EE-E08C86163BE4} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-5_user No Task File <==== ATTENTION
Task: {C4F94777-EEB0-4A10-8A22-B9D84B47CBDE} - System32\Tasks\{4B4A98B3-8EFB-4EA9-96DA-859BD311B125} => C:\Program Files (x86)\Banda Ancha Móvil\Banda Ancha Móvil.exe
Task: {C73A4C15-AB17-4B36-A163-8AA95CEA54BB} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-4 No Task File <==== ATTENTION
Task: {D51911E5-B483-4A41-97A4-BCC1670C6F1F} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-7 No Task File <==== ATTENTION
Task: {E1A01EF4-B33C-4582-99DC-B1AA66844B8F} - System32\Tasks\{4C84D047-9E06-4ED5-9291-F966BB365558} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.)
Task: {E1B656EF-78FD-433A-8D3A-B107378DE346} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-3 No Task File <==== ATTENTION
Task: {EEE0B926-AE48-4983-BDE1-A800825EF9AE} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000Core.job => C:\Users\Nancy\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000UA.job => C:\Users\Nancy\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000Core.job => C:\Users\Nancy\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000UA.job => C:\Users\Nancy\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RegistryBooster.job => C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe
 
==================== Loaded Modules (whitelisted) =============
 
2010-02-16 01:46 - 2009-07-16 21:06 - 00033280 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
2010-02-16 01:46 - 2009-07-16 21:06 - 00058368 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll
2011-09-01 00:01 - 2009-11-17 10:44 - 00040960 _____ () C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe
2011-05-13 17:57 - 2010-03-15 11:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
2014-07-18 14:30 - 2014-07-15 05:24 - 00718664 _____ () C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\libglesv2.dll
2014-07-18 14:30 - 2014-07-15 05:24 - 00126280 _____ () C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\libegl.dll
2014-07-18 14:31 - 2014-07-15 05:24 - 08537928 _____ () C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll
2014-07-18 14:31 - 2014-07-15 05:24 - 00353096 _____ () C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll
2014-07-18 14:30 - 2014-07-15 05:24 - 01732936 _____ () C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
AlternateDataStreams: C:\Users\Nancy\Downloads\KOKOPELMANA SEED SANCTUARY New in Cotacachi! Fresh produce and lunch.eml:OECustomProperty
AlternateDataStreams: C:\Users\Nancy\Downloads\sketch (1).eml:OECustomProperty
AlternateDataStreams: C:\Users\Nancy\Downloads\sketch.eml:OECustomProperty
 
==================== Safe Mode (whitelisted) ===================
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== EXE Association (whitelisted) =============
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe
MSCONFIG\startupreg: Broadcom Wireless Manager UI => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAAnotif => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: ModemListener => C:\Program Files (x86)\Banda Ancha Movil\ModemListener.exe start
MSCONFIG\startupreg: QuickSet => C:\Program Files\Dell\QuickSet\QuickSet.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Microsoft 6to4 Adapter
Description: Microsoft 6to4 Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Microsoft ISATAP Adapter
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Microsoft ISATAP Adapter #2
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Microsoft ISATAP Adapter #3
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/21/2014 00:19:08 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (07/20/2014 03:55:42 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (07/20/2014 07:41:30 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wmplayer.exe version 12.0.7601.18150 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: f30
 
Start Time: 01cfa1b4791f96c0
 
Termination Time: 387
 
Application Path: C:\Program Files (x86)\Windows Media Player\wmplayer.exe
 
Report Id: ba651405-1002-11e4-af6d-a4badba10c85
 
Error: (07/20/2014 00:25:57 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (07/19/2014 10:20:24 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (07/18/2014 09:19:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program chrome.exe version 35.0.1916.153 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: f04
 
Start Time: 01cfa288fb4de068
 
Termination Time: 80
 
Application Path: C:\Users\Nancy\AppData\Local\Google\Chrome\Application\chrome.exe
 
Report Id: 4b1e5b63-0ee2-11e4-af6d-a4badba10c85
 
Error: (07/18/2014 02:31:13 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (07/18/2014 09:24:42 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (07/16/2014 10:08:27 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (07/15/2014 03:03:52 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: )
Description: The Cryptographic Services service failed to initialize the Catalog Database. The ESENT error was: -530.
 
 
System errors:
=============
Error: (07/21/2014 08:55:29 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 for x64-based Systems (KB2862330).
 
Error: (07/21/2014 08:51:28 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Dock Login Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (07/21/2014 03:04:13 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 for x64-based Systems (KB2862330).
 
Error: (07/20/2014 07:45:36 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Dock Login Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (07/20/2014 03:03:47 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 for x64-based Systems (KB2862330).
 
Error: (07/19/2014 03:04:20 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 for x64-based Systems (KB2862330).
 
Error: (07/18/2014 03:06:06 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 for x64-based Systems (KB2862330).
 
Error: (07/17/2014 03:03:33 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 for x64-based Systems (KB2862330).
 
Error: (07/16/2014 03:03:56 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 for x64-based Systems (KB2862330).
 
Error: (07/15/2014 03:05:24 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 for x64-based Systems (KB2862330).
 
 
Microsoft Office Sessions:
=========================
 
==================== Memory info =========================== 
 
Percentage of memory in use: 48%
Total physical RAM: 4056.36 MB
Available physi9405515901131440258195cal RAM: 2102.61 MB
Total Pagefile: 8110.91 MB
Available Pagefile: 5860.13 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:218.2 GB) (Free:147.92 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 233 GB) (Disk ID: CF5ACF27)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=218 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================

  • 0

#23
saoirse

saoirse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014
Ran by Nancy (administrator) on NANCY-PC on 21-07-2014 10:46:11
Running from C:\Users\Nancy\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
(Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
() C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Sun Microsystems, Inc.) C:\Windows\System32\jusched.exe
(Microsoft Corporation) C:\Windows\System32\slui.exe
(Google Inc.) C:\Users\Nancy\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Nancy\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Nancy\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Nancy\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Nancy\AppData\Local\Google\Chrome\Application\chrome.exe
(OldTimer Tools) C:\Users\Nancy\Downloads\OTL.exe
 
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [444416 2009-06-29] (IDT, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-21-2222092012-326958857-3758879047-1000\...\Run: [Google Update] => C:\Users\Nancy\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-14] (Google Inc.)
 
==================== Internet (Whitelisted) ====================
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://[email protected]/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
SearchScopes: HKLM - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {39172B5C-E3CD-4F23-8AAF-7616C32FCDF7} URL = 
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.appl...ex/qtplugin.cab
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} -  No File
Handler-x32: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{E68395D3-ECB1-4278-BEB2-79E8C06FD09F}: [NameServer]200.105.225.2,200.105.225.4
 
FireFox:
========
FF ProfilePath: C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\z7wjsrl3.default
FF Homepage: hxxp://n.porta.net/google.com
FF NetworkProxy: "backup.ftp", ""
FF NetworkProxy: "backup.ftp_port", ""
FF NetworkProxy: "backup.socks", ""
FF NetworkProxy: "backup.socks_port", ""
FF NetworkProxy: "backup.ssl", ""
FF NetworkProxy: "backup.ssl_port", ""
FF NetworkProxy: "ftp", ""
FF NetworkProxy: "ftp_port", ""
FF NetworkProxy: "http", ""
FF NetworkProxy: "http_port", ""
FF NetworkProxy: "share_proxy_settings", ""
FF NetworkProxy: "socks", ""
FF NetworkProxy: "socks_port", ""
FF NetworkProxy: "ssl", ""
FF NetworkProxy: "ssl_port", ""
FF NetworkProxy: "type", ""
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @fuzebox.com/Fuze Meeting NPAPI Plugin,version=1.0.0.1 - C:\Users\Nancy\AppData\Local\Fuze Box\Fuze Meeting\npfuzeshare.dll ( )
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Nancy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Nancy\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Nancy\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
 
Chrome: 
=======
CHR HomePage: hxxp://n.porta.net/google.com
CHR DefaultNewTabURL: 
CHR Plugin: (Shockwave Flash) - C:\Users\Nancy\AppData\Local\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\gcswf32.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Nancy\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java™ Platform SE 6 U24) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility) - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Nancy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-21]
CHR Extension: (Google Wallet) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
 
==================== Services (Whitelisted) =================
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-10-07] (SUPERAntiSpyware.com) [File not signed]
R2 DeviceManager; C:\Program Files (x86)\Common Files\DeviceHelper\DeviceManager.exe [40960 2009-11-17] () [File not signed]
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2009-06-09] (Stardock Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe [240128 2009-06-29] (IDT, Inc.)
R2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe [3417088 2009-07-16] (Dell Inc.) [File not signed]
 
==================== Drivers (Whitelisted) ====================
 
S3 androidusb; C:\Windows\System32\Drivers\smhwadb.sys [31744 2010-06-24] (Google Inc)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-21] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 qcusbser; C:\Windows\System32\DRIVERS\qcusbser.sys [118016 2009-08-27] (TCT International Mobile Ltd)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 smhwdev; C:\Windows\System32\DRIVERS\smhwdev.sys [114432 2010-06-24] (Huawei Technologies Co., Ltd.)
S3 smhwser; C:\Windows\System32\DRIVERS\smhwser.sys [122624 2010-06-24] (QUALCOMM Incorporated)
S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2014-07-21 10:46 - 2014-07-21 10:46 - 00013914 _____ () C:\Users\Nancy\Desktop\FRST.txt
2014-07-21 10:45 - 2014-07-21 10:46 - 00000000 ____D () C:\FRST
2014-07-21 10:43 - 2014-07-21 10:42 - 02089984 _____ (Farbar) C:\Users\Nancy\Desktop\FRST64.exe
2014-07-21 10:42 - 2014-07-21 10:42 - 02089984 _____ (Farbar) C:\Users\Nancy\Downloads\FRST64.exe
2014-07-21 09:10 - 2014-07-21 09:10 - 00602112 _____ (OldTimer Tools) C:\Users\Nancy\Downloads\OTL (3).exe
2014-07-21 08:59 - 2014-07-21 10:29 - 00001184 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-21 08:59 - 2014-07-21 10:29 - 00001184 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-21 08:59 - 2014-07-21 08:59 - 00000552 _____ () C:\Windows\system32\spsys.log
2014-07-20 20:43 - 2014-07-20 20:44 - 00602112 _____ (OldTimer Tools) C:\Users\Nancy\Downloads\OTL (2).exe
2014-07-20 20:42 - 2014-07-20 20:42 - 00602112 _____ (OldTimer Tools) C:\Users\Nancy\Downloads\OTL (1).exe
2014-07-20 15:58 - 2014-07-20 15:58 - 00000000 ____D () C:\Users\Nancy\Downloads\New folder
2014-07-20 15:56 - 2014-07-21 10:25 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-20 15:55 - 2014-07-20 15:55 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-20 15:55 - 2014-07-20 15:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-20 15:55 - 2014-07-20 15:55 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-20 15:55 - 2014-07-20 15:55 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-20 15:55 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-20 15:55 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-20 15:55 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-20 15:12 - 2014-07-20 15:12 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Nancy\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-07-20 15:11 - 2014-07-20 15:12 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Nancy\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-20 07:45 - 2014-07-20 07:45 - 00000000 ____D () C:\_OTL
2014-07-19 19:58 - 2014-07-19 19:59 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{F8404204-7BA7-4F64-AEBC-CE551CA1F707}
2014-07-19 16:49 - 2014-07-20 15:05 - 00075260 _____ () C:\Users\Nancy\Downloads\Extras.Txt
2014-07-19 16:46 - 2014-07-21 09:20 - 00074336 _____ () C:\Users\Nancy\Downloads\OTL.Txt
2014-07-19 16:36 - 2014-07-19 16:36 - 00602112 _____ (OldTimer Tools) C:\Users\Nancy\Downloads\OTL.exe
2014-07-19 07:57 - 2014-07-19 07:58 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{3E5A0AD6-99F2-407C-B1A9-54C106B9993B}
2014-07-18 19:57 - 2014-07-18 19:57 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{021E84F5-B9E5-41C8-8897-05D8FB2D5A39}
2014-07-18 07:56 - 2014-07-18 07:57 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{1BFE49DB-DE26-443E-AA78-88A99AEAD380}
2014-07-17 19:56 - 2014-07-17 19:56 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{06E5E672-B0E5-476D-A619-41E4DA0F03ED}
2014-07-17 07:55 - 2014-07-17 07:55 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{70497B6D-7C38-46C1-9453-91EEC9119FF9}
2014-07-16 19:54 - 2014-07-16 19:55 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{14D48415-6278-48DF-A604-1B12AFFB5750}
2014-07-16 12:17 - 2014-07-16 12:17 - 00103286 _____ () C:\Users\Nancy\Downloads\sketch.eml
2014-07-16 12:17 - 2014-07-16 12:17 - 00103286 _____ () C:\Users\Nancy\Downloads\sketch (1).eml
2014-07-16 07:54 - 2014-07-16 07:54 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{41D2BE0B-D136-449A-8FBB-E87FD47676EB}
2014-07-15 17:52 - 2014-07-15 17:52 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{0CFB824D-E472-40FD-817E-3F3562A5B097}
2014-07-15 05:51 - 2014-07-15 05:51 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{ACAE3AC8-D84F-466D-B951-816A5F1922F2}
2014-07-14 17:47 - 2014-07-14 17:47 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{14635022-2528-49AC-9E21-33846984615D}
2014-07-14 17:45 - 2014-07-14 17:45 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{97BB7E00-D51C-4CAC-8BCB-4302D6455535}
2014-07-14 16:08 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-14 16:07 - 2014-07-14 16:38 - 00000000 ____D () C:\AdwCleaner
2014-07-14 16:06 - 2014-07-14 16:06 - 01348263 _____ () C:\Users\Nancy\Downloads\adwcleaner_3.215.exe
2014-07-13 00:48 - 2014-07-13 00:48 - 00000305 _____ () C:\Users\Nancy\Downloads\Kathy Holland Jardone.vcf
2014-07-12 16:34 - 2014-07-12 16:34 - 00000000 __SHD () C:\Users\Nancy\AppData\Local\EmieUserList
2014-07-12 16:34 - 2014-07-12 16:34 - 00000000 __SHD () C:\Users\Nancy\AppData\Local\EmieSiteList
2014-07-12 16:30 - 2014-07-12 16:30 - 05572640 _____ (383 Media, Inc.) C:\Users\Nancy\Downloads\DriverRestore.exe
2014-07-12 12:43 - 2014-07-12 12:42 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-12 12:42 - 2014-07-12 12:42 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-12 12:42 - 2014-07-12 12:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-11 14:20 - 2014-07-11 14:20 - 00000000 ____D () C:\SUPERDelete
2014-07-10 19:09 - 2014-07-10 19:09 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{05E5D35C-7B8D-48C7-B52C-A428539C7A17}
2014-07-10 07:08 - 2014-07-10 07:08 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{CFCE6609-4768-4F01-AC5A-DF77150AADE0}
2014-07-09 11:59 - 2014-06-29 22:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 11:59 - 2014-06-29 22:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 11:59 - 2014-06-20 16:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 11:59 - 2014-06-20 15:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 11:59 - 2014-06-18 21:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 11:59 - 2014-06-18 21:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 11:59 - 2014-06-18 20:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 11:59 - 2014-06-18 20:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 11:59 - 2014-06-18 20:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 11:59 - 2014-06-18 20:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 11:59 - 2014-06-18 20:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 11:59 - 2014-06-18 20:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 11:59 - 2014-06-18 20:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 11:59 - 2014-06-18 20:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 11:59 - 2014-06-18 20:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 11:59 - 2014-06-18 20:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 11:59 - 2014-06-18 20:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 11:59 - 2014-06-18 20:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 11:59 - 2014-06-18 19:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 11:59 - 2014-06-18 19:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 11:59 - 2014-06-18 19:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 11:59 - 2014-06-18 19:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 11:59 - 2014-06-18 19:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 11:59 - 2014-06-18 19:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 11:59 - 2014-06-18 19:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 11:59 - 2014-06-18 19:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 11:59 - 2014-06-18 19:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-09 11:59 - 2014-06-18 19:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 11:59 - 2014-06-18 19:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 11:59 - 2014-06-18 19:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 11:59 - 2014-06-18 19:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 11:59 - 2014-06-18 19:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 11:59 - 2014-06-18 19:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 11:59 - 2014-06-18 19:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 11:59 - 2014-06-18 19:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 11:59 - 2014-06-18 19:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 11:59 - 2014-06-18 19:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-09 11:59 - 2014-06-18 19:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 11:59 - 2014-06-18 19:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 11:59 - 2014-06-18 19:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 11:59 - 2014-06-18 18:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 11:59 - 2014-06-18 18:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 11:59 - 2014-06-18 18:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 11:59 - 2014-06-18 18:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 11:59 - 2014-06-18 18:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 11:59 - 2014-06-18 18:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 11:59 - 2014-06-18 18:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-09 11:59 - 2014-06-18 18:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 11:59 - 2014-06-18 18:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 11:59 - 2014-06-18 18:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 11:59 - 2014-06-18 18:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 11:59 - 2014-06-18 18:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 11:59 - 2014-06-18 18:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 11:59 - 2014-06-18 18:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-09 11:59 - 2014-06-17 22:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 11:59 - 2014-06-17 21:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 11:59 - 2014-06-17 21:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 11:59 - 2014-06-06 06:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 11:59 - 2014-06-06 05:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 11:59 - 2014-05-30 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 11:59 - 2014-05-30 04:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 11:59 - 2014-05-30 04:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 11:59 - 2014-05-30 04:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 11:59 - 2014-05-30 04:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 11:59 - 2014-05-30 04:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 11:59 - 2014-05-30 04:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 11:59 - 2014-05-30 03:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-09 11:59 - 2014-05-30 03:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-09 11:59 - 2014-05-30 03:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-09 11:59 - 2014-05-30 03:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-09 11:59 - 2014-05-30 03:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-09 11:59 - 2014-05-30 03:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-09 11:59 - 2014-05-30 03:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-09 11:59 - 2014-05-30 02:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 11:58 - 2014-06-18 21:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 11:58 - 2014-06-18 20:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 11:58 - 2014-06-18 20:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 11:58 - 2014-06-18 19:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 11:58 - 2014-06-05 10:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 11:58 - 2014-06-05 10:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-09 11:58 - 2014-06-05 10:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-08 14:24 - 2014-07-08 14:25 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{2C9E13A0-9D44-42E0-A81C-A0421C116BCD}
2014-06-28 13:36 - 2014-06-28 13:36 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{61570072-25A5-41C3-9FA0-434CE421A929}
2014-06-28 01:35 - 2014-06-28 01:35 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{8B33D582-E07B-4A9A-978D-031A00EEDEBE}
2014-06-27 13:34 - 2014-06-27 13:35 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{2655DFB9-37EC-4295-8355-9C15FB553E24}
2014-06-27 01:34 - 2014-06-27 01:34 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{1EE06C26-D863-40D0-81A2-6B0ABBD5CF8F}
2014-06-26 13:34 - 2014-06-26 13:34 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{58032922-04C9-4A07-B3B0-C4FBE1F2513F}
2014-06-26 00:21 - 2014-06-26 00:22 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{8E973783-C14F-4D92-A06C-EEC1049AB08D}
2014-06-25 12:20 - 2014-06-25 12:21 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{9E418645-FB8F-4EEE-B2C4-3D0780B7E2CA}
2014-06-25 00:20 - 2014-06-25 00:20 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{82157E21-23DA-4BED-89F4-0A87F6CEF6AB}
2014-06-24 12:20 - 2014-06-24 12:20 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{56F5B925-9031-49FC-9C27-53D8D2E7EAC4}
2014-06-24 00:20 - 2014-06-24 00:20 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{5C66800E-287F-410A-B550-FF0ADF215D6A}
2014-06-23 12:20 - 2014-06-23 12:20 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{B3492C91-A5BF-4F2D-BA5E-653E9159B260}
2014-06-23 00:19 - 2014-06-23 00:20 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{60CFDA94-5449-4C51-A38A-B91496470C36}
2014-06-22 12:19 - 2014-06-22 12:19 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{8118CE06-E440-438F-B652-6B0A08A3517C}
2014-06-22 00:18 - 2014-06-22 00:18 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{36B38102-EA43-4F00-B8B9-A2222F43886E}
2014-06-21 12:17 - 2014-06-21 12:17 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{BE4B2671-1567-4FE6-B356-CF3FCA2377C9}
2014-06-21 00:17 - 2014-06-21 00:17 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{D5BDC102-3DA9-4E64-9CC6-945D5D4AD178}
 
==================== One Month Modified Files and Folders =======
 
2014-07-21 10:46 - 2014-07-21 10:46 - 00013914 _____ () C:\Users\Nancy\Desktop\FRST.txt
2014-07-21 10:46 - 2014-07-21 10:45 - 00000000 ____D () C:\FRST
2014-07-21 10:42 - 2014-07-21 10:43 - 02089984 _____ (Farbar) C:\Users\Nancy\Desktop\FRST64.exe
2014-07-21 10:42 - 2014-07-21 10:42 - 02089984 _____ (Farbar) C:\Users\Nancy\Downloads\FRST64.exe
2014-07-21 10:40 - 2013-03-21 23:36 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-21 10:29 - 2014-07-21 08:59 - 00001184 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-21 10:29 - 2014-07-21 08:59 - 00001184 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-21 10:25 - 2014-07-20 15:56 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-21 10:25 - 2012-08-25 13:08 - 00000908 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000UA.job
2014-07-21 10:21 - 2012-03-03 17:10 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000UA.job
2014-07-21 10:02 - 2011-12-12 14:15 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-21 09:20 - 2014-07-19 16:46 - 00074336 _____ () C:\Users\Nancy\Downloads\OTL.Txt
2014-07-21 09:10 - 2014-07-21 09:10 - 00602112 _____ (OldTimer Tools) C:\Users\Nancy\Downloads\OTL (3).exe
2014-07-21 09:02 - 2009-07-14 01:10 - 01390642 _____ () C:\Windows\WindowsUpdate.log
2014-07-21 08:59 - 2014-07-21 08:59 - 00000552 _____ () C:\Windows\system32\spsys.log
2014-07-21 08:57 - 2011-12-12 14:15 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-21 08:57 - 2011-08-27 03:17 - 00032727 _____ () C:\Windows\setupact.log
2014-07-21 08:57 - 2011-08-22 22:03 - 00000344 _____ () C:\Windows\Tasks\RegistryBooster.job
2014-07-21 08:57 - 2011-08-07 14:10 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-07-21 08:57 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-21 08:56 - 2011-08-27 03:16 - 00167250 _____ () C:\Windows\PFRO.log
2014-07-21 08:51 - 2010-06-06 08:18 - 00000000 ____D () C:\Users\Nancy\AppData\Roaming\Skype
2014-07-20 20:44 - 2014-07-20 20:43 - 00602112 _____ (OldTimer Tools) C:\Users\Nancy\Downloads\OTL (2).exe
2014-07-20 20:42 - 2014-07-20 20:42 - 00602112 _____ (OldTimer Tools) C:\Users\Nancy\Downloads\OTL (1).exe
2014-07-20 19:21 - 2012-03-03 17:10 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000Core.job
2014-07-20 17:25 - 2012-08-25 13:08 - 00000856 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2222092012-326958857-3758879047-1000Core.job
2014-07-20 15:58 - 2014-07-20 15:58 - 00000000 ____D () C:\Users\Nancy\Downloads\New folder
2014-07-20 15:55 - 2014-07-20 15:55 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-20 15:55 - 2014-07-20 15:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-20 15:55 - 2014-07-20 15:55 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-20 15:55 - 2014-07-20 15:55 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-20 15:12 - 2014-07-20 15:12 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Nancy\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-07-20 15:12 - 2014-07-20 15:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Nancy\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-20 15:05 - 2014-07-19 16:49 - 00075260 _____ () C:\Users\Nancy\Downloads\Extras.Txt
2014-07-20 07:45 - 2014-07-20 07:45 - 00000000 ____D () C:\_OTL
2014-07-20 07:40 - 2012-11-01 16:55 - 00000000 ____D () C:\Users\Nancy\Downloads\angels
2014-07-19 19:59 - 2014-07-19 19:58 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{F8404204-7BA7-4F64-AEBC-CE551CA1F707}
2014-07-19 16:36 - 2014-07-19 16:36 - 00602112 _____ (OldTimer Tools) C:\Users\Nancy\Downloads\OTL.exe
2014-07-19 07:58 - 2014-07-19 07:57 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{3E5A0AD6-99F2-407C-B1A9-54C106B9993B}
2014-07-18 19:57 - 2014-07-18 19:57 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{021E84F5-B9E5-41C8-8897-05D8FB2D5A39}
2014-07-18 14:31 - 2012-08-25 13:10 - 00002328 _____ () C:\Users\Nancy\Desktop\Google Chrome.lnk
2014-07-18 08:23 - 2012-11-01 17:05 - 00000000 ____D () C:\Users\Nancy\Downloads\animals
2014-07-18 07:57 - 2014-07-18 07:56 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{1BFE49DB-DE26-443E-AA78-88A99AEAD380}
2014-07-17 23:51 - 2012-06-11 10:09 - 00000000 ____D () C:\Users\Nancy\Downloads\Birds
2014-07-17 19:56 - 2014-07-17 19:56 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{06E5E672-B0E5-476D-A619-41E4DA0F03ED}
2014-07-17 07:55 - 2014-07-17 07:55 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{70497B6D-7C38-46C1-9453-91EEC9119FF9}
2014-07-16 19:55 - 2014-07-16 19:54 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{14D48415-6278-48DF-A604-1B12AFFB5750}
2014-07-16 12:17 - 2014-07-16 12:17 - 00103286 _____ () C:\Users\Nancy\Downloads\sketch.eml
2014-07-16 12:17 - 2014-07-16 12:17 - 00103286 _____ () C:\Users\Nancy\Downloads\sketch (1).eml
2014-07-16 07:54 - 2014-07-16 07:54 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{41D2BE0B-D136-449A-8FBB-E87FD47676EB}
2014-07-15 17:52 - 2014-07-15 17:52 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{0CFB824D-E472-40FD-817E-3F3562A5B097}
2014-07-15 05:51 - 2014-07-15 05:51 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{ACAE3AC8-D84F-466D-B951-816A5F1922F2}
2014-07-14 17:47 - 2014-07-14 17:47 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{14635022-2528-49AC-9E21-33846984615D}
2014-07-14 17:45 - 2014-07-14 17:45 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{97BB7E00-D51C-4CAC-8BCB-4302D6455535}
2014-07-14 16:38 - 2014-07-14 16:07 - 00000000 ____D () C:\AdwCleaner
2014-07-14 16:06 - 2014-07-14 16:06 - 01348263 _____ () C:\Users\Nancy\Downloads\adwcleaner_3.215.exe
2014-07-14 07:06 - 2012-11-01 16:54 - 00000000 ____D () C:\Users\Nancy\Downloads\friends and family
2014-07-13 00:48 - 2014-07-13 00:48 - 00000305 _____ () C:\Users\Nancy\Downloads\Kathy Holland Jardone.vcf
2014-07-12 16:34 - 2014-07-12 16:34 - 00000000 __SHD () C:\Users\Nancy\AppData\Local\EmieUserList
2014-07-12 16:34 - 2014-07-12 16:34 - 00000000 __SHD () C:\Users\Nancy\AppData\Local\EmieSiteList
2014-07-12 16:30 - 2014-07-12 16:30 - 05572640 _____ (383 Media, Inc.) C:\Users\Nancy\Downloads\DriverRestore.exe
2014-07-12 13:37 - 2013-09-30 15:03 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-12 12:42 - 2014-07-12 12:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-12 12:42 - 2014-07-12 12:42 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-12 12:42 - 2014-07-12 12:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-12 12:42 - 2011-03-12 10:31 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-12 12:42 - 2011-03-12 10:31 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-12 12:42 - 2010-02-16 01:45 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-11 14:20 - 2014-07-11 14:20 - 00000000 ____D () C:\SUPERDelete
2014-07-11 00:01 - 2012-05-27 15:32 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-07-10 19:09 - 2014-07-10 19:09 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{05E5D35C-7B8D-48C7-B52C-A428539C7A17}
2014-07-10 07:08 - 2014-07-10 07:08 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{CFCE6609-4768-4F01-AC5A-DF77150AADE0}
2014-07-10 06:56 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-07-10 03:24 - 2009-07-14 00:45 - 00343552 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 03:21 - 2014-05-07 03:02 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-10 03:21 - 2009-07-14 03:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-10 03:21 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-10 03:21 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-10 03:04 - 2013-08-14 03:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-10 03:03 - 2010-07-07 00:28 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-09 09:42 - 2012-11-01 17:01 - 00000000 ____D () C:\Users\Nancy\Downloads\design ideas
2014-07-08 14:25 - 2014-07-08 14:24 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{2C9E13A0-9D44-42E0-A81C-A0421C116BCD}
2014-07-08 14:20 - 2009-07-14 01:13 - 00782510 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-03 11:12 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\tracing
2014-06-29 22:09 - 2014-07-09 11:59 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-29 22:04 - 2014-07-09 11:59 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-28 13:36 - 2014-06-28 13:36 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{61570072-25A5-41C3-9FA0-434CE421A929}
2014-06-28 01:35 - 2014-06-28 01:35 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{8B33D582-E07B-4A9A-978D-031A00EEDEBE}
2014-06-27 13:35 - 2014-06-27 13:34 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{2655DFB9-37EC-4295-8355-9C15FB553E24}
2014-06-27 01:34 - 2014-06-27 01:34 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{1EE06C26-D863-40D0-81A2-6B0ABBD5CF8F}
2014-06-26 13:34 - 2014-06-26 13:34 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{58032922-04C9-4A07-B3B0-C4FBE1F2513F}
2014-06-26 00:22 - 2014-06-26 00:21 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{8E973783-C14F-4D92-A06C-EEC1049AB08D}
2014-06-25 12:21 - 2014-06-25 12:20 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{9E418645-FB8F-4EEE-B2C4-3D0780B7E2CA}
2014-06-25 00:20 - 2014-06-25 00:20 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{82157E21-23DA-4BED-89F4-0A87F6CEF6AB}
2014-06-24 12:20 - 2014-06-24 12:20 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{56F5B925-9031-49FC-9C27-53D8D2E7EAC4}
2014-06-24 00:20 - 2014-06-24 00:20 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{5C66800E-287F-410A-B550-FF0ADF215D6A}
2014-06-23 12:20 - 2014-06-23 12:20 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{B3492C91-A5BF-4F2D-BA5E-653E9159B260}
2014-06-23 00:20 - 2014-06-23 00:19 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{60CFDA94-5449-4C51-A38A-B91496470C36}
2014-06-22 20:06 - 2012-11-01 17:16 - 00000000 ____D () C:\Users\Nancy\Downloads\artwork
2014-06-22 12:19 - 2014-06-22 12:19 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{8118CE06-E440-438F-B652-6B0A08A3517C}
2014-06-22 00:18 - 2014-06-22 00:18 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{36B38102-EA43-4F00-B8B9-A2222F43886E}
2014-06-21 12:17 - 2014-06-21 12:17 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{BE4B2671-1567-4FE6-B356-CF3FCA2377C9}
2014-06-21 00:17 - 2014-06-21 00:17 - 00000000 ____D () C:\Users\Nancy\AppData\Local\{D5BDC102-3DA9-4E64-9CC6-945D5D4AD178}
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-07-18 09:24
 
==================== End Of Log ============================

  • 0

#24
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,107 posts
Hello,

Not sure why you got the windows error. Don't take any action on it.

I have also noticed in your log file you are using FrostWire P2P program. We at Geeks to go ! Recommend removing these type of programs, they are a known cause of Malware infections. When you use file sharing programs like this you can never be sure of the file content and you are put at a much greater risk for infection. I strongly recommend you remove this program


Programs to uninstall,

1-FrostWire 4.20.7 (HKLM-x32\...\FrostWire) (Version: 4.20.7.0 - FrostWire, LLC)
2-Java 6 Update 17 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416017FF}) (Version: 6.0.170 - Sun Microsystems, Inc.)
3-Java 6 Update 24 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216017FF}) (Version: 6.0.240 - Sun Microsystems, Inc.)
4-Uniblue RegistryBooster (HKLM-x32\...\Uniblue RegistryBooster) (Version: 6.0.3.6 - Uniblue Systems Ltd)

Never use a registry cleaner (Uniblue RegistryBooster,) they cause more harm then good, After all a broken registry is a broken windows.

Next this how we fix files using FRST it's a bit different but easy, take your time.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
 
Task: {02EF7E7B-96C0-4CF3-8DA7-7D836368CFE0} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-2 No Task File <==== ATTENTION
Task: {167FD5F9-ED52-4F19-81C0-992D6694CB80} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-11 No Task File <==== ATTENTION
Task: {2D55DE8F-EBA1-4BF0-86F1-68F8CC00D9FC} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-1 No Task File <==== ATTENTION
Task: {33F3198A-79CD-432E-83F7-0DD523100D6F} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5 No Task File <==== ATTENTION
Task: {35E068A5-EF12-4CCF-AF69-06D26224748A} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5_user No Task File <==== ATTENTION
Task: {39E72AE9-56D2-4D6F-93E8-57909D358A13} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-5 No Task File <==== ATTENTION
Task: {3C574D08-097B-4195-913A-E91400C9ED4A} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-7 No Task File <==== ATTENTION
Task: {4FF36279-443C-42D4-A89D-CD1ED628E655} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-3 No Task File <==== ATTENTION
Task: {594D6170-8FFB-45A5-8C5B-507758ABFFEB} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-6 No Task File <==== ATTENTION
Task: {5B735B94-5300-49F2-8FAE-2355CED34055} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-6 No Task File <==== ATTENTION
Task: {8B63B624-2F11-4055-9D9F-2D3FD2D0D056} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-1 No Task File <==== ATTENTION
Task: {8C2119A0-B8D9-4487-B7A1-FF11DA0FEB86} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-2 No Task File <==== ATTENTION
Task: {9258B12E-CFC6-419A-AB33-502138E1FBA1} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-11 No Task File <==== ATTENTION
Task: {B03D89AB-A11A-48B1-AA0C-5D3A4547B2ED} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-4 No Task File <==== ATTENTION
Task: {BE488F3A-FE68-4BC8-84C4-E50F87C6EF33} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {C465AABE-7608-46C1-85EE-E08C86163BE4} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-5_user No Task File <==== ATTENTION
Task: {C73A4C15-AB17-4B36-A163-8AA95CEA54BB} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-4 No Task File <==== ATTENTION
Task: {D51911E5-B483-4A41-97A4-BCC1670C6F1F} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-7 No Task File <==== ATTENTION
Task: {E1B656EF-78FD-433A-8D3A-B107378DE346} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-3 No Task File <==== ATTENTION
Task: {EEE0B926-AE48-4983-BDE1-A800825EF9AE} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {362D6CA0-1BEE-4DE3-801D-5449DF0F4585} - System32\Tasks\RegistryBooster => C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe
Task: {55770699-0D06-4AA1-A5D3-71B2053E840A} - System32\Tasks\ASC4_AutoCare => C:\Program Files (x86)\IObit\Advanced SystemCare 4\AutoCare.exe
Task: {59B173CD-503E-4B5B-B62B-C7756F9C9479} - System32\Tasks\ASC4_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe
Task: C:\Windows\Tasks\RegistryBooster.job => C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe
1-Click Format and ensure Wordwrap is unchecked.
2-Save as Fixlist.txt to your Desktop (Must be in this location)
3-Run FRST/FRST64 and press the Fix button just once and wait.
4-If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

Thanks
Joe :)
  • 0

#25
saoirse

saoirse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-07-2014
Ran by Nancy at 2014-07-21 19:40:40 Run:1
Running from C:\Users\Nancy\Desktop
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
Task: {02EF7E7B-96C0-4CF3-8DA7-7D836368CFE0} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-2 No Task File <==== ATTENTION
Task: {167FD5F9-ED52-4F19-81C0-992D6694CB80} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-11 No Task File <==== ATTENTION
Task: {2D55DE8F-EBA1-4BF0-86F1-68F8CC00D9FC} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-1 No Task File <==== ATTENTION
Task: {33F3198A-79CD-432E-83F7-0DD523100D6F} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5 No Task File <==== ATTENTION
Task: {35E068A5-EF12-4CCF-AF69-06D26224748A} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5_user No Task File <==== ATTENTION
Task: {39E72AE9-56D2-4D6F-93E8-57909D358A13} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-5 No Task File <==== ATTENTION
Task: {3C574D08-097B-4195-913A-E91400C9ED4A}
- \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-7 No Task File <==== ATTENTION
Task: {4FF36279-443C-42D4-A89D-CD1ED628E655} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-3 No Task File <==== ATTENTION
Task: {594D6170-8FFB-45A5-8C5B-507758ABFFEB} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-6 No Task File <==== ATTENTION
Task: {5B735B94-5300-49F2-8FAE-2355CED34055} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-6 No Task File <==== ATTENTION
Task: {8B63B624-2F11-4055-9D9F-2D3FD2D0D056} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-1 No Task File <==== ATTENTION
Task: {8C2119A0-B8D9-4487-B7A1-FF11DA0FEB86} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-2 No Task File <==== ATTENTION
Task: {9258B12E-CFC6-419A-AB33-502138E1FBA1} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-11 No Task File <==== ATTENTION
Task: {B03D89AB-A11A-48B1-AA0C-5D3A4547B2ED} - \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-4 No Task File <==== ATTENTION
Task: {BE488F3A-FE68-4BC8-84C4-E50F87C6EF33} - \globalUpdateUpdateTaskMachineUA No
Task File <==== ATTENTION
Task: {C465AABE-7608-46C1-85EE-E08C86163BE4} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-5_user No Task File <==== ATTENTION
ask: {C73A4C15-AB17-4B36-A163-8AA95CEA54BB} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-4 No Task File <==== ATTENTION
Task: {D51911E5-B483-4A41-97A4-BCC1670C6F1F} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-7 No Task File <==== ATTENTION
Task: {E1B656EF-78FD-433A-8D3A-B107378DE346} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-3 No Task File <==== ATTENTION
Task: {EEE0B926-AE48-4983-BDE1-A800825EF9AE} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {362D6CA0-1BEE-4DE3-801D-5449DF0F4585} - System32\Tasks\RegistryBooster => C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe
Task: {55770699-0D06-4AA1-A5D3-71B2053E840A} - System32\Tasks\ASC4_AutoCare => C:\Program Files (x86)\IObit\Advanced SystemCare 4\AutoCare.exe
Task: {59B173CD-503E-4B5B-B62B-C7756F9C9479} -
System32\Tasks\ASC4_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe
Task: C:\Windows\Tasks\RegistryBooster.job => C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe
 
*****************
 
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{02EF7E7B-96C0-4CF3-8DA7-7D836368CFE0}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02EF7E7B-96C0-4CF3-8DA7-7D836368CFE0}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\140ee91b-30c4-45f7-824e-4dcdd2afc6dc-2' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{167FD5F9-ED52-4F19-81C0-992D6694CB80}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{167FD5F9-ED52-4F19-81C0-992D6694CB80}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-11' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2D55DE8F-EBA1-4BF0-86F1-68F8CC00D9FC}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2D55DE8F-EBA1-4BF0-86F1-68F8CC00D9FC}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-1' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{33F3198A-79CD-432E-83F7-0DD523100D6F}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{33F3198A-79CD-432E-83F7-0DD523100D6F}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{35E068A5-EF12-4CCF-AF69-06D26224748A}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{35E068A5-EF12-4CCF-AF69-06D26224748A}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5_user' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{39E72AE9-56D2-4D6F-93E8-57909D358A13}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{39E72AE9-56D2-4D6F-93E8-57909D358A13}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\140ee91b-30c4-45f7-824e-4dcdd2afc6dc-5' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\Task: {3C574D08-097B-4195-913A-E91400C9ED4A}'=> Key not found.
- \2b6328a9-11c8-46e0-8547-2efb3aafcaa4-7 No Task File <==== ATTENTION => Error: No automatic fix found for this entry.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4FF36279-443C-42D4-A89D-CD1ED628E655}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4FF36279-443C-42D4-A89D-CD1ED628E655}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-3' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{594D6170-8FFB-45A5-8C5B-507758ABFFEB}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{594D6170-8FFB-45A5-8C5B-507758ABFFEB}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-6' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5B735B94-5300-49F2-8FAE-2355CED34055}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B735B94-5300-49F2-8FAE-2355CED34055}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\140ee91b-30c4-45f7-824e-4dcdd2afc6dc-6' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8B63B624-2F11-4055-9D9F-2D3FD2D0D056}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B63B624-2F11-4055-9D9F-2D3FD2D0D056}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\140ee91b-30c4-45f7-824e-4dcdd2afc6dc-1' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8C2119A0-B8D9-4487-B7A1-FF11DA0FEB86}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C2119A0-B8D9-4487-B7A1-FF11DA0FEB86}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-2' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9258B12E-CFC6-419A-AB33-502138E1FBA1}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9258B12E-CFC6-419A-AB33-502138E1FBA1}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\140ee91b-30c4-45f7-824e-4dcdd2afc6dc-11' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B03D89AB-A11A-48B1-AA0C-5D3A4547B2ED}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B03D89AB-A11A-48B1-AA0C-5D3A4547B2ED}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-4' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BE488F3A-FE68-4BC8-84C4-E50F87C6EF33}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BE488F3A-FE68-4BC8-84C4-E50F87C6EF33}' => Key deleted successfully.
Task File <==== ATTENTION => Error: No automatic fix found for this entry.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C465AABE-7608-46C1-85EE-E08C86163BE4}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C465AABE-7608-46C1-85EE-E08C86163BE4}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\140ee91b-30c4-45f7-824e-4dcdd2afc6dc-5_user' => Key deleted successfully.
ask: {C73A4C15-AB17-4B36-A163-8AA95CEA54BB} - \140ee91b-30c4-45f7-824e-4dcdd2afc6dc-4 No Task File <==== ATTENTION => Error: No automatic fix found for this entry.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D51911E5-B483-4A41-97A4-BCC1670C6F1F}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D51911E5-B483-4A41-97A4-BCC1670C6F1F}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\140ee91b-30c4-45f7-824e-4dcdd2afc6dc-7' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E1B656EF-78FD-433A-8D3A-B107378DE346}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1B656EF-78FD-433A-8D3A-B107378DE346}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\140ee91b-30c4-45f7-824e-4dcdd2afc6dc-3' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EEE0B926-AE48-4983-BDE1-A800825EF9AE}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EEE0B926-AE48-4983-BDE1-A800825EF9AE}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{362D6CA0-1BEE-4DE3-801D-5449DF0F4585}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{362D6CA0-1BEE-4DE3-801D-5449DF0F4585}' => Key deleted successfully.
C:\Windows\System32\Tasks\RegistryBooster => Moved successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegistryBooster' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{55770699-0D06-4AA1-A5D3-71B2053E840A}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55770699-0D06-4AA1-A5D3-71B2053E840A}' => Key deleted successfully.
C:\Windows\System32\Tasks\ASC4_AutoCare => Moved successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASC4_AutoCare' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\Task: {59B173CD-503E-4B5B-B62B-C7756F9C9479} -'=> Key not found.
System32\Tasks\ASC4_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe => Error: No automatic fix found for this entry.
C:\Windows\Tasks\RegistryBooster.job => Moved successfully.
 
==== End of Fixlog ====

  • 0

Advertisements


#26
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,107 posts
Hello saoirse,

Tell me what malware issues are left, any pop up advertizements, redirects or anything like that.

Thanks
Joe :)
  • 0

#27
saoirse

saoirse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts

Everything seems to be going well...Thank you!

I really appreciate all your help as I was in a bit of a fix!

Do you think I should run disk cleanup or refrag or anything to clean things up a bit more, or just leave well enough alone?

 

Thanks again!

Nancy :-)


  • 0

#28
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,107 posts
I want to review a few things in your logs. Then I'll give instruction on clean up that just means removing the tools we downloaded. I'll get that to you Tomorrow.

Thanks
Joe :)
  • 0

#29
saoirse

saoirse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts

Sounds good, Joe. I'll be waiting. Much appreciation!


  • 0

#30
saoirse

saoirse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts

I am now getting this error message:

 

"Optional update delivery is not working"

 

"To use all Microsoft Windows® features, such as all updates from Windows
Update; get the latest updates; and receive product support, your copy of
Microsoft Windows® must be validated as genuine."

 

Have you ever heard of this?


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP