Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account

ADW Cleaner Showing 'Threats' It Can't Delete. Help!

ADW cleaner 07171AC2-0D2A-427d-BCE5-B6C2D 740F530B-DDF1-4488-8868-BA63A

  • Please log in to reply

Waste of Space

Waste of Space


  • Member
  • PipPip
  • 77 posts

Hi and thanks for providing this amazing voluntary service, O awesome geeks.


My PC (running Windows 7) has ADW Cleaner on it, plus Spyware Blaster and Malwarebytes Anti-Malware Premium.  I update/check for updates/run these three first thing every morning.  I also have AVG, which I update each day but only run every two days.


This morning when I ran ADW Cleaner, it picked up two so-called threats under the 'Services' heading.  I instructed ADW to clean them out, but when the PC restarted it displayed the following report:


[!] Service not deleted: {07171AC2-0D2A-427d-BCE5-B6C2D6C7058B}

[!] Service not deleted: {740F530B-DDF1-4488-8868-BA63A715455B}


I ran ADW Cleaner again immediately, but with the same result.


I then ran Malwarebytes Anti-Malware and AVG, but neither of them picked up on any junk at all, saying that my PC had 0 threats.


At this stage, nothing weird is discernible on my PC  -  no pop-ups, no strange default homepage, no unwanted toolbars, nothing.  But understandably I'm still really worried.  What exactly are these two things that've shown up on my PC?  Are they harmful?


In the past 24 hours, I've not visited any dodgy websites or opened any wrong-looking emails, nor downloaded anything inadvisable.  All my Web activity was on mainstream websites.  I haven't even visited a quiz website or a song lyrics website, which I know sometimes put stuff on your PC. So how come this junk is showing up now on my ADW Cleaner scan? Why can't ADW Cleaner get rid of it and why can't Malwarebytes Anti-Malware or AVG even see it?  I'm baffled and very concerned.

Many, many thanks for your help, comrades.

  • 0




    Trusted Helper

  • Malware Removal
  • 8,107 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)

Everything gets download to the desktop and tools are "Run as administrator."

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

  • 0

Waste of Space

Waste of Space


  • Topic Starter
  • Member
  • PipPip
  • 77 posts

zep516, many thanks for your response.  Greatly appreciated.


Now here's the bizarre thing.  This morning when I ran my customary breakfast-time scans/updates, ADW Cleaner didn't pick up on either of the two threats which it drew my attention to yesterday morning.  I ran ADW Cleaner again immediately, but with exactly the same result.  As previously, neither MBAM nor AVG could find anything amiss either.


None of this makes a scrap of sense to me, especially with there having been no update to ADW Cleaner overnight.


Obviously I'm glad that nothing showed up on the scan and I'm hoping it means that the two 'threats' discovered yesterday were nothing of the sort, just the result of some kind of glitch on ADW Cleaner.  But maybe in adopting that attitude I'm living in a fool's paradise. 


So I've not yet tried downloading FRST and I'm hoping I don't need to now.  What do you reckon, amigo?


Many thanks.

  • 0



    Trusted Helper

  • Malware Removal
  • 8,107 posts

We have come this far,

Lets review the log reports FRST.txt and Additions.txt at least.

Joe :)
  • 0



    Trusted Helper

  • Malware Removal
  • 8,107 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

Waste of Space

Waste of Space


  • Topic Starter
  • Member
  • PipPip
  • 77 posts

Zep516 (Joe)


Hearty apologies for my delay in responding.  A major family crisis intervened, like.


I've followed your advice to the letter and am pasting the two FRST reports below. (I didn't however run the 'optional scan' covering 'List BCD', 'Drivers MD5', 'shortcut.txt', 'Addition.txt' and '90 days files'.  If they're vital, I'm happy to run again.)  Enormous thanks for taking the time to run your eyeballs over all this stuff.





Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-09-2016

Ran by Home (administrator) on HOME-PC (18-09-2016 07:33:01)

Running from C:\Users\Home\Desktop

Loaded Profiles: Home (Available Profiles: Home)

Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: Chrome)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/


==================== Processes (Whitelisted) =================


(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)


(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe

(Intel Corporation) C:\Windows\System32\igfxtray.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

(Intel Corporation) C:\Windows\System32\igfxsrvc.exe

(Spotify Ltd) C:\Users\Home\AppData\Roaming\Spotify\SpotifyWebHelper.exe

(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe

(Microsoft Corporation) C:\Windows\System32\rundll32.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe

(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe



==================== Registry (Whitelisted) ===========================


(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)


HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13876952 2015-04-13] (Realtek Semiconductor)

HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)

HKLM-x32\...\Run: [] => [X]

HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2631120 2016-07-28] (Malwarebytes Corporation)

HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [6718224 2016-08-26] (AVG Technologies CZ, s.r.o.)

HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [204560 2016-09-07] (AVG Technologies CZ, s.r.o.)

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\Run: [Spotify Web Helper] => C:\Users\Home\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1553520 2016-06-30] (Spotify Ltd)

HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd)

HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\MountPoints2: {165b3c49-78e8-11e4-959f-806e6f6e6963} - E:\RunMe.exe

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-08-15]

ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe (McAfee, Inc.)

Startup: C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1510 series.lnk [2016-09-18]

ShortcutTarget: Monitor Ink Alerts - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

GroupPolicy: Restriction - Chrome <======= ATTENTION

CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION


==================== Internet (Whitelisted) ====================


(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)


Hosts:     mssplus.mcafee.com

Tcpip\Parameters: [DhcpNameServer]

Tcpip\..\Interfaces\{740F530B-DDF1-4488-8868-BA63A715455B}: [DhcpNameServer]


Internet Explorer:


SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2013-04-16] (Belarc, Inc.)




FF Plugin: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)




CHR Profile: C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default [2016-09-18]

CHR Extension: (Google Slides) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-06]

CHR Extension: (Google Docs) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-06]

CHR Extension: (Google Drive) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]

CHR Extension: (YouTube) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]

CHR Extension: (Google Search) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]

CHR Extension: (Google Sheets) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-06]

CHR Extension: (AdBlock) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-09-17]

CHR Extension: (Chrome Web Store Payments) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-03]

CHR Extension: (Gmail) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-06]

CHR Extension: (Chrome Media Router) - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-18]


==================== Services (Whitelisted) ========================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [674552 2016-08-26] (AVG Technologies CZ, s.r.o.)

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5285344 2016-08-26] (AVG Technologies CZ, s.r.o.)

R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1097488 2016-09-07] (AVG Technologies CZ, s.r.o.)

R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [760024 2016-08-26] (AVG Technologies CZ, s.r.o.)

R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [750032 2016-07-28] (Malwarebytes Corporation)

S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)

S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)

S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe [327944 2016-07-19] (McAfee, Inc.)

R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [294104 2015-04-10] (Realtek Semiconductor)

S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)


===================== Drivers (Whitelisted) ==========================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)

R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [310016 2016-08-23] (AVG Technologies CZ, s.r.o.)

R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [272640 2016-07-27] (AVG Technologies CZ, s.r.o.)

R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [260352 2016-06-01] (AVG Technologies CZ, s.r.o.)

R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)

R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [262400 2016-08-02] (AVG Technologies CZ, s.r.o.)

R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)

R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [299264 2016-07-27] (AVG Technologies CZ, s.r.o.)

R0 Avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.)

S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)

R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [74984 2016-07-28] ()

R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)

S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-09-16] (Malwarebytes)

S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)

S3 USBET; C:\Windows\System32\DRIVERS\ETdrv.sys [6423936 2013-02-04] (Etron)

U4 Avgfwfd; system32\DRIVERS\avgfwd6a.sys [X]


==================== NetSvcs (Whitelisted) ===================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)



==================== One Month Created files and folders ========


(If an entry is included in the fixlist, the file/folder will be moved.)


2099-11-02 00:08 - 2015-04-06 09:52 - 00524288 ___SH C:\Users\Home\ntuser.dat{c6c2e5f8-9722-14dc-b99e-0018716c3889}.TMContainer00000000000000000002.regtrans-ms

2099-11-02 00:08 - 2015-04-06 09:52 - 00524288 ___SH C:\Users\Home\ntuser.dat{c6c2e5f8-9722-14dc-b99e-0018716c3889}.TMContainer00000000000000000001.regtrans-ms

2099-11-02 00:08 - 2015-04-06 09:52 - 00065536 ___SH C:\Users\Home\ntuser.dat{c6c2e5f8-9722-14dc-b99e-0018716c3889}.TM.blf

2016-09-18 07:33 - 2016-09-18 07:33 - 00011639 _____ C:\Users\Home\Desktop\FRST.txt

2016-09-18 07:31 - 2016-09-18 07:33 - 00000000 ____D C:\FRST

2016-09-18 07:26 - 2016-09-18 07:26 - 02399232 _____ (Farbar) C:\Users\Home\Desktop\FRST64.exe

2016-09-18 07:05 - 2016-09-18 07:05 - 00000984 _____ C:\Users\Public\Desktop\AVG.lnk

2016-09-18 07:05 - 2016-09-18 07:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen

2016-09-18 07:02 - 2016-09-18 07:02 - 03143504 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Home\Downloads\AVG_Protection_Free_1606.exe

2016-09-16 07:16 - 2016-09-16 07:16 - 03861056 _____ C:\Users\Home\Desktop\adwcleaner_6.020.exe

2016-09-05 16:15 - 2016-09-05 16:15 - 00127996 _____ C:\Users\Home\Downloads\Listing_Details2016-09-05-17-14.pdf

2016-08-31 07:42 - 2016-08-31 07:43 - 54287072 _____ (Microsoft Corporation) C:\Users\Home\Desktop\Windows-KB890830-x64-V5.39.exe

2016-08-30 08:34 - 2016-08-30 08:34 - 00009904 ____N C:\bootsqm.dat

2016-08-23 16:31 - 2016-08-23 16:31 - 00310016 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys


==================== One Month Modified files and folders ========


(If an entry is included in the fixlist, the file/folder will be moved.)


2099-11-02 00:02 - 2014-12-01 10:33 - 00000000 ____D C:\Users\Home\AppData\Local\Microsoft Games

2016-09-18 07:31 - 2009-07-14 05:45 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2016-09-18 07:31 - 2009-07-14 05:45 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2016-09-18 07:19 - 2014-12-01 09:28 - 00000000 ____D C:\ProgramData\MFAData

2016-09-18 07:17 - 2015-04-06 10:35 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2016-09-18 07:17 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT

2016-09-18 07:14 - 2015-06-28 10:12 - 00000000 ____D C:\Program Files\Common Files\AV

2016-09-18 07:14 - 2015-04-29 07:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG

2016-09-18 07:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf

2016-09-18 07:05 - 2015-08-15 06:44 - 00000000 ____D C:\Users\Home\AppData\Local\AvgSetupLog

2016-09-18 07:05 - 2015-08-15 06:44 - 00000000 ____D C:\ProgramData\Avg

2016-09-18 07:05 - 2014-12-01 09:30 - 00000000 ____D C:\Program Files (x86)\AVG

2016-09-17 20:48 - 2015-04-06 10:35 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2016-09-17 19:28 - 2015-08-07 06:56 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit

2016-09-17 07:53 - 2015-04-06 10:36 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

2016-09-17 07:53 - 2015-04-06 10:36 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2016-09-17 07:26 - 2016-07-12 19:16 - 00000000 ____D C:\Users\Home\Documents\Architectural Insides and Outsides

2016-09-16 07:22 - 2016-04-18 18:18 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

2016-09-16 07:21 - 2015-05-02 09:26 - 00000000 ____D C:\AdwCleaner

2016-09-16 07:15 - 2014-12-01 09:56 - 00000000 ____D C:\ProgramData\TEMP

2016-09-16 07:14 - 2015-07-18 04:54 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster

2016-09-14 16:35 - 2015-06-14 09:29 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task

2016-09-14 08:32 - 2015-05-02 13:49 - 00000000 ____D C:\Users\Home\Documents\Primus eBills

2016-09-12 16:24 - 2016-02-20 11:21 - 00000000 ____D C:\Users\Home\Documents\Miller Parris etc

2016-09-11 19:18 - 2015-05-02 16:55 - 00000000 ____D C:\Users\Home\AppData\Local\Spotify

2016-09-11 19:18 - 2015-05-02 16:54 - 00000000 ____D C:\Users\Home\AppData\Roaming\Spotify

2016-09-10 08:38 - 2015-04-06 12:47 - 147640136 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe

2016-09-05 06:57 - 2009-07-14 06:08 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2016-09-04 21:10 - 2015-04-29 06:45 - 00000000 ____D C:\Users\Home\AppData\Roaming\vlc

2016-09-04 19:01 - 2015-07-23 19:30 - 00000000 ____D C:\Users\Home\AppData\Roaming\dvdcss


==================== Files in the root of some directories =======


2015-05-11 08:44 - 2015-05-11 08:44 - 0000057 _____ () C:\ProgramData\Ament.ini


Some files in TEMP:















==================== Bamital & volsnap =================


(There is no automatic fix for files that do not pass verification.)


C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed



LastRegBack: 2016-08-10 08:13


==================== End of FRST.txt ============================





Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-09-2016

Ran by Home (18-09-2016 07:34:26)

Running from C:\Users\Home\Desktop

Windows 7 Home Premium Service Pack 1 (X64) (2014-11-30 23:31:31)

Boot Mode: Normal




==================== Accounts: =============================


Administrator (S-1-5-21-2588259368-3398593882-3987161955-500 - Administrator - Disabled)

Guest (S-1-5-21-2588259368-3398593882-3987161955-501 - Limited - Disabled)

Home (S-1-5-21-2588259368-3398593882-3987161955-1000 - Administrator - Enabled) => C:\Users\Home

HomeGroupUser$ (S-1-5-21-2588259368-3398593882-3987161955-1002 - Limited - Enabled)

Malcolm_Richardson (S-1-5-21-2588259368-3398593882-3987161955-1003 - Administrator - Enabled)


==================== Security Center ========================


(If an entry is included in the fixlist, it will be removed.)


AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}

AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}


==================== Installed Programs ======================


(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)


Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)

AVG (HKLM\...\AvgZen) (Version: - AVG Technologies)

AVG (Version: 16.111.7797 - AVG Technologies) Hidden

AVG 2016 (Version: 16.0.4656 - AVG Technologies) Hidden

AVG Protection (HKLM\...\AVG) (Version: 2016.111.7797 - AVG Technologies)

AVG Zen (Version: 1.91.11 - AVG Technologies) Hidden

Belarc Advisor 8.4 (HKLM-x32\...\Belarc Advisor) (Version: - Belarc Inc.)

CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform)

FMW 1 (Version: 1.123.1 - AVG Technologies) Hidden

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 53.0.2785.116 - Google Inc.)

Google Update Helper (x32 Version: - Google Inc.) Hidden

HP Deskjet 1510 series Basic Device Software (HKLM\...\{C9064E5C-D5AB-4EEB-86A6-50756901038A}) (Version: 32.0.1180.44630 - Hewlett-Packard Co.)

HP Deskjet 1510 series Help (HKLM-x32\...\{2E25FCEB-EFCB-4696-AA01-D3CBAC721831}) (Version: 30.0.0 - Hewlett Packard)

HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: - Hewlett-Packard)

HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: - HP)

HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: - Hewlett-Packard)

HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden

Edited by Waste of Space, 19 September 2016 - 01:43 AM.

  • 0



    Trusted Helper

  • Malware Removal
  • 8,107 posts

Please re-post the additions.txt log report.
  • 0

Waste of Space

Waste of Space


  • Topic Starter
  • Member
  • PipPip
  • 77 posts

Right, yes, some of that Addition report appears to have gone missing in my last post, doesn't it?  Let's try again.  My thanks to you for bringing your brain to bear on it.



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-09-2016
Ran by Home (18-09-2016 07:34:26)
Running from C:\Users\Home\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2014-11-30 23:31:31)
Boot Mode: Normal
==================== Accounts: =============================
Administrator (S-1-5-21-2588259368-3398593882-3987161955-500 - Administrator - Disabled)
Guest (S-1-5-21-2588259368-3398593882-3987161955-501 - Limited - Disabled)
Home (S-1-5-21-2588259368-3398593882-3987161955-1000 - Administrator - Enabled) => C:\Users\Home
HomeGroupUser$ (S-1-5-21-2588259368-3398593882-3987161955-1002 - Limited - Enabled)
Malcolm_Richardson (S-1-5-21-2588259368-3398593882-3987161955-1003 - Administrator - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
AVG (HKLM\...\AvgZen) (Version: - AVG Technologies)
AVG (Version: 16.111.7797 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4656 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.111.7797 - AVG Technologies)
AVG Zen (Version: 1.91.11 - AVG Technologies) Hidden
Belarc Advisor 8.4 (HKLM-x32\...\Belarc Advisor) (Version: - Belarc Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform)
FMW 1 (Version: 1.123.1 - AVG Technologies) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 53.0.2785.116 - Google Inc.)
Google Update Helper (x32 Version: - Google Inc.) Hidden
HP Deskjet 1510 series Basic Device Software (HKLM\...\{C9064E5C-D5AB-4EEB-86A6-50756901038A}) (Version: 32.0.1180.44630 - Hewlett-Packard Co.)
HP Deskjet 1510 series Help (HKLM-x32\...\{2E25FCEB-EFCB-4696-AA01-D3CBAC721831}) (Version: 30.0.0 - Hewlett Packard)
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: - Hewlett-Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation)
Malwarebytes Anti-Exploit version (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: - Malwarebytes)
Malwarebytes Anti-Malware version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.376.2 - McAfee, Inc.)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Product Improvement Study for HP Deskjet 1510 series (HKLM\...\{EC27E742-EB04-4A2C-BA64-20271929528A}) (Version: 32.0.1180.44630 - Hewlett-Packard Co.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Spotify (HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\Spotify) (Version: - Spotify AB)
SpywareBlaster 5.5 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
The Complete Theory Test V14/1 (Update 6.1) (HKLM-x32\...\{C8A53C9C-185D-46E0-8F63-1E6AE4140674}_is1) (Version: 18.0 - Imagitech Ltd.)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Webcam Videocap (HKLM-x32\...\{ED1674F5-5165-49BF-B546-AE5343111540}) (Version: - ETRON)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0BFECD64-464B-4FDF-8D3E-98D10576FD7D} - System32\Tasks\0715avUpdateInfo => C:\ProgramData\Avg_Update_0715av\0715av_AVG-Secure-Search-Update.exe
Task: {43654E2F-519D-4AD2-BF48-7BD902E39559} - System32\Tasks\HP AR Program Upload - 266169d4c15d42d98792b69faaad09be883dac1ca9ac47ffb31a810d10c5c602 => C:\Program Files\HP\HP Deskjet 1510 series\bin\HPRewards.exe [2013-08-13] (TODO: <Company name>)
Task: {5346CDAE-5D3E-47E4-B9D2-1F20D0D8060F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-06] (Google Inc.)
Task: {57F886DD-0CD0-4D95-ADC6-756BAD8B20C7} - System32\Tasks\HP AR Program Upload - ed225ec28faa4de69aa38a7e71c12cf8fbd59866eac840578c7dc320e8048fd7 => C:\Program Files\HP\HP Deskjet 1510 series\bin\HPRewards.exe [2013-08-13] (TODO: <Company name>)
Task: {5C2F98BA-6F03-43DB-B5F5-B5A1B3B32F4D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-06] (Google Inc.)
Task: {712F7E10-29FD-4F02-8024-D9D006EBDC84} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-07-17] (Piriform Ltd)
Task: {758E6F9E-1A23-487C-8504-742D9F7A50C6} - System32\Tasks\HP AR Program Upload - f35b06af1f374e60a3ad414eb5c3d41a032fd27133d3434f9bd8aff3d42a6c4f => C:\Program Files\HP\HP Deskjet 1510 series\bin\HPRewards.exe [2013-08-13] (TODO: <Company name>)
Task: {B3CD23D6-9B82-47F4-8F5E-B213D1251910} - System32\Tasks\HPCustParticipation HP Deskjet 1510 series => C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPCustPartic.exe [2013-08-13] (Hewlett-Packard Co.)
Task: {C0BF4809-7141-490E-9E43-7F5650410CAE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-08] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\0715avUpdateInfo.job => C:\ProgramData\Avg_Update_0715av\0715av_AVG-Secure-Search-Update.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2015-10-27 08:46 - 2016-04-07 18:52 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\1001movie.com -> 1001movie.com
There are 6091 more sites.
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2016-08-15 09:33 - 00000869 ____A C:\Windows\system32\Drivers\etc\hosts mssplus.mcafee.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Home\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{91582C4B-FF78-4304-9353-82382426A9B7}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{7D324CCA-A9AE-4FA6-BE76-DC9C52F85625}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{D324E971-28F4-4AEC-A6FE-F8348E64DEBF}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{0C4C3AA0-2E79-480C-A36F-1EB22B74B829}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{F80683F8-8B4E-41A9-BA47-5ED1BBA63A89}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{057B838A-CBDE-4FEC-9424-28564464878E}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{B6131709-9C92-46EF-8873-05AA84527A0B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{FE14C52B-B307-44A5-8305-0877E29A286E}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [TCP Query User{3A02E090-352B-4401-88A4-542C954253E2}C:\users\home\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\home\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{54A01565-46AF-45C3-A7B1-608464600528}C:\users\home\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\home\appdata\roaming\spotify\spotify.exe
FirewallRules: [{FD9E55CB-621C-4310-9933-F702B56FBF57}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\USBSetup.exe
FirewallRules: [{3001989F-AC38-4230-BC46-1DF7A56E9AB1}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{3D6C740C-368E-479A-B484-D0827DD91718}] => (Allow) C:\Users\Home\AppData\Local\Temp\7zS04FE\HPDiagnosticCoreUI.exe
FirewallRules: [{ED9974F9-C96C-42DE-8B42-D7310677512A}] => (Allow) C:\Users\Home\AppData\Local\Temp\7zS04FE\HPDiagnosticCoreUI.exe
FirewallRules: [{1BE16BA5-0406-45E0-AC61-D452984970FD}] => (Allow) C:\Users\Home\AppData\Local\Temp\7zS7EC1\HPDiagnosticCoreUI.exe
FirewallRules: [{0A7756BE-9C8F-4206-9C6E-4737F2B4CE89}] => (Allow) C:\Users\Home\AppData\Local\Temp\7zS7EC1\HPDiagnosticCoreUI.exe
FirewallRules: [{6A4A8261-C727-4D6E-B399-F06DF0E4FFB1}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{4D43F22D-30B6-4002-9481-3372D9A95E03}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{6BFDCED0-68E2-4362-92B6-6E689B668555}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{1EC82F80-A0C5-4349-AF33-4E8F3A6DFD1E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{BD65C8F9-158E-4110-B712-5678C8D75502}] => (Allow) C:\Users\Home\AppData\Local\Temp\7zS7F43\HPDiagnosticCoreUI.exe
FirewallRules: [{06945B05-D32E-4B23-840D-2F5CBFB66D02}] => (Allow) C:\Users\Home\AppData\Local\Temp\7zS7F43\HPDiagnosticCoreUI.exe
FirewallRules: [{79F1A065-DE42-4FC5-A9C9-DD40DB34BD0E}] => (Allow) C:\Users\Home\AppData\Local\Temp\7zS7F98\HPDiagnosticCoreUI.exe
FirewallRules: [{4C2E681B-025E-46F9-9135-772609516805}] => (Allow) C:\Users\Home\AppData\Local\Temp\7zS7F98\HPDiagnosticCoreUI.exe
FirewallRules: [{291F5196-C787-4871-A693-E558DD01C4EF}] => (Allow) C:\Users\Home\AppData\Local\Temp\7zS0481\HPDiagnosticCoreUI.exe
FirewallRules: [{22C478D7-9E54-4617-904B-D24E10774339}] => (Allow) C:\Users\Home\AppData\Local\Temp\7zS0481\HPDiagnosticCoreUI.exe
FirewallRules: [{3579199A-9AE1-415D-B224-47F9B0F651B8}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{006061EC-E8D6-4E5B-8140-BE874B1451E1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{629DCBF5-9F5D-40B4-A462-81E373FDDDD6}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{21C32A74-C118-4566-B1B8-1668C99A73E4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{0AA7EA2C-2C91-4BD7-BE7E-B30659764A63}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{90DED8EA-2DA6-484C-9FED-D29C807DA851}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{50E3EBD3-8E0E-48DA-982B-6F04ABA84A0E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
==================== Faulty Device Manager Devices =============
Name: PS/2 Compatible Mouse
Description: PS/2 Compatible Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
Error: (09/18/2016 07:18:41 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (09/18/2016 06:58:49 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (09/17/2016 07:26:31 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (09/17/2016 06:57:13 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (09/16/2016 04:20:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (09/16/2016 01:03:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (09/16/2016 07:14:33 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (09/15/2016 12:14:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (09/15/2016 07:46:22 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (09/14/2016 07:44:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
System errors:
Error: (09/11/2016 12:21:11 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (09/11/2016 12:21:11 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (08/19/2016 07:05:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Modules Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
Error: (08/19/2016 07:05:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Software Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
Error: (08/19/2016 07:05:33 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
Error: (08/19/2016 07:05:33 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
Error: (08/19/2016 07:05:32 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Malwarebytes Anti-Exploit Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
Error: (08/19/2016 07:05:31 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The AVG Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
Error: (08/19/2016 07:05:31 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Adobe Acrobat Update Service service terminated unexpectedly.  It has done this 1 time(s).
Error: (08/19/2016 07:05:31 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
==================== Memory info =========================== 
Processor: Intel® Pentium® 4 CPU 3.00GHz
Percentage of memory in use: 66%
Total physical RAM: 3063.43 MB
Available physical RAM: 1033.79 MB
Total Virtual: 6125.04 MB
Available Virtual: 4175.74 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:78.14 GB) (Free:34.16 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Data) (Fixed) (Total:154.69 GB) (Free:154.59 GB) NTFS
Drive e: (The Complete Theory Test) (CDROM) (Total:5.06 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.8 GB) (Disk ID: EA1AA9C7)
Partition 1: (Active) - (Size=78.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=154.7 GB) - (Type=OF Extended)
==================== End of Addition.txt ============================

  • 0



    Trusted Helper

  • Malware Removal
  • 8,107 posts
Download the enclosed =>Attached File  fixlist.txt   1.45KB   193 downloads Save it in the location FRST64 is. (Desktop) Run FRST and click on the Fix button. Wait until finished.

The tool will make a log in the location FRST is,(Desktop) CALLED (Fixlog.txt). Please post it to your reply.
  • 0

Waste of Space

Waste of Space


  • Topic Starter
  • Member
  • PipPip
  • 77 posts

Hmmm, well, I'm not 100% certain I understood all the instructions (especially about saving your downloadable file in a location called FRST64 is. (Desktop)), but I seem nevertheless to have emerged from the process with a document called Fixlog.txt which simply stored itself on my desktop as a standalone file.  I'm hoping to god it makes sense to you, because it's quite possible I haven't actually done what you axed me to do.  Please run an eyeball over it and see what you think.  My large thanks for your on-going help, Joe.




Fix result of Farbar Recovery Scan Tool (x64) Version: 18-09-2016

Ran by Home (20-09-2016 07:05:10) Run:1
Running from C:\Users\Home\Desktop
Loaded Profiles: Home (Available Profiles: Home)
Boot Mode: Normal
fixlist content:
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\MountPoints2: {165b3c49-78e8-11e4-959f-806e6f6e6963} - E:\RunMe.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
U4 Avgfwfd; system32\DRIVERS\avgfwd6a.sys [X]
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
Processes closed successfully.
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{165b3c49-78e8-11e4-959f-806e6f6e6963}" => key removed successfully
HKCR\CLSID\{165b3c49-78e8-11e4-959f-806e6f6e6963} => key not found. 
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. 
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
Avgfwfd => service could not remove
C:\Users\Home\AppData\Local\Temp\avguirn_081692346769.exe => moved successfully
C:\Users\Home\AppData\Local\Temp\avguirn_081778736183.exe => moved successfully
C:\Users\Home\AppData\Local\Temp\avguirn_082048732973.exe => moved successfully
C:\Users\Home\AppData\Local\Temp\avguirn_082124867046.exe => moved successfully
C:\Users\Home\AppData\Local\Temp\avguirn_08230171427.exe => moved successfully
C:\Users\Home\AppData\Local\Temp\avguirn_08529085845.exe => moved successfully
C:\Users\Home\AppData\Local\Temp\avguirn_08699622339.exe => moved successfully
C:\Users\Home\AppData\Local\Temp\avguirn_08798282415.exe => moved successfully
C:\Users\Home\AppData\Local\Temp\avguirn_08815743683.exe => moved successfully
C:\Users\Home\AppData\Local\Temp\HPPSdr.exe => moved successfully
C:\Users\Home\AppData\Local\Temp\Quarantine.exe => moved successfully
C:\ProgramData\TEMP => ":5C321E34" ADS removed successfully.
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
0 out of 0 jobs canceled.
========= End of CMD: =========
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
========= RemoveProxy: =========
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
========= End of RemoveProxy: =========
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 63770974 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 242952338 B
Edge => 0 B
Chrome => 931132175 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 66356 B
systemprofile32 => 67230 B
LocalService => 66228 B
NetworkService => 66228 B
Home => 320465816 B
RecycleBin => 0 B
EmptyTemp: => 1.5 GB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 07:07:09 ====

  • 0




    Trusted Helper

  • Malware Removal
  • 8,107 posts
Those are correct instructions

Can you run adwCleaner again and post the log c1.txt
  • 0

Waste of Space

Waste of Space


  • Topic Starter
  • Member
  • PipPip
  • 77 posts

Okay, we've hit a problem. For some reason that's beyond my understanding, I'm unable to to copy and paste the log from ADW Cleaner.


If I select the text of the log, I can click on 'Copy' and it appears to be working  -  but when I go to paste it onto Geekstogo, a dialogue box appears, containing the message 'Because of your browser security settings, the editor is not able to access your clipboard data directly. You are required to paste it again in this window.  Please paste inside the following box using the keyboard (Ctrl/Cmd+V) and hit OK.'   But even going via that route, it still won't paste.  (I can't even paste it onto a Word document.  The 'paste' function is greyed out.)


Yikes. Why on earth would my browser security settings suddenly stop me copying and pasting, especially when they let me paste the FRST logs?


Technology, eh?  Don'tcha just love it?


I'm kinda hoping you might understand what's going on.....  (Thanks.)

Edited by Waste of Space, 21 September 2016 - 02:17 AM.

  • 0



    Trusted Helper

  • Malware Removal
  • 8,107 posts
What's the log say is it still having problem with those services ?

I'd reboot the computer and try again, or just let me know how the log looks as long as it deleted junk or found nothing we are ok.

There have been issues with the forum this week about pasting logs in.
  • 0

Waste of Space

Waste of Space


  • Topic Starter
  • Member
  • PipPip
  • 77 posts

The ADW Cleaner log appears to give me a clean bill of health  -  no malicious or infected anything.  Likewise MBAM and AVG.  Looking good.


Enormous and sincere thanks for your help, zep516.  I genuinely appreciate your taking the time to focus on my concerns.


(Now if only I knew why my PC has stopped being able to download Windows updates.  But I'll save that one for another day and another thread.)

  • 0



    Trusted Helper

  • Malware Removal
  • 8,107 posts
Can you describe the windows up date issue. Are there ant errors ?
  • 0

Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP