TechSpot

Ads all over Firefox browser

By Guymarshall
Apr 16, 2015
  1. Hello, AVG[​IMG] detected a threat and I opted to "remove", AVG informed me it had done so but after this my browser has ads all over and links on a page open new pages from advertisers - very intense and intrusive can you help? I have followed instructions on your site, results from Farbar scan included.

    FRST
    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 04
    Ran by guy (administrator) on GUY-PC on 16-04-2015 16:27:32
    Running from C:\Users\guy\Desktop
    Loaded Profiles: guy (Available profiles: guy)
    Platform: Windows 7 Home Premium (X64) OS Language: English (United States)
    Internet Explorer Version 8 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (AVG Technologies[​IMG] CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Acer[​IMG] Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
    (Seagate) C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
    (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
    (Acer Incorporated) C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe
    (TODO: <Company name>) C:\Program Files (x86)\STab\ProtectService.exe
    (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
    (SearchProtect) C:\Program Files (x86)\STab\CmdShell.exe
    (TODO: <Company name>) C:\Program Files (x86)\STab\HPNotify.exe
    (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
    (AVG[​IMG] Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgscanx.exe
    (McAfee, Inc.) C:\Program Files\McAfee Security Scan[​IMG]\3.8.150\SSScheduler.exe
    (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
    () C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe
    (AVG Technologies[​IMG] CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
    (Seagate) C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (Acer[​IMG]) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
    (Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
    (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
    (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
    (Seagate) C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
    (Acronis) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
    (CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\EpmNews.exe
    () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\TrayTipAgentE.exe
    (Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
    (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
    (Forte Internet Software Inc.) E:\Agent\agent.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
    (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry[​IMG] item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [823840 2009-09-30] (Acer Incorporated)
    HKLM\...\Run: [Seagate Scheduler2 Service] => C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe [400376 2013-10-30] (Seagate)
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe [262912 2009-08-21] (NewTech Infosystems, Inc.)
    HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1094736 2009-11-02] (Dritek System Inc.)
    HKLM-x32\...\Run: [DiscWizardMonitor.exe] => C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe [6382504 2013-10-30] (Seagate)
    HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1103424 2013-01-10] (Acronis)
    HKLM-x32\...\Run: [EaseUS EPM tray] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\EpmNews.exe [2086568 2014-03-06] (CHENGDU YIWO Tech Development Co., Ltd)
    HKLM-x32\...\Run: [EaseUS EPM Tray Agent] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\TrayTipAgentE.exe [254024 2014-02-13] ()
    HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [137352 2014-08-13] (Check Point Software Technologies Ltd.)
    HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3723728 2015-03-25] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.)
    HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.)
    HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\...\MountPoints2: {c4642e48-4df4-11e4-a84e-806e6f6e6963} - D:\autorun.exe
    HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> c:\windows\system32\PACKAR~1.SCR [413696 2009-01-22] (Acer)
    HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-10-28] (Microsoft Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.v9.com/web/?type=ds&t...6JD2ZB03737&I=psd&t=34bcb47fb&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.v9.com/web/?type=ds&t...6JD2ZB03737&I=psd&t=34bcb47fb&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.v9.com/web/?type=ds&t...6JD2ZB03737&I=psd&t=34bcb47fb&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.v9.com/web/?type=ds&t...6JD2ZB03737&I=psd&t=34bcb47fb&q={searchTerms}
    HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?source...nputEncoding}&oe={outputEncoding}&rlz=1I7ACPW
    SearchScopes: HKU\S-1-5-21-1673714354-1666257763-1680629560-1000 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?source...ding}&oe={outputEncoding}&rlz=1I7ACPW_enGB609
    SearchScopes: HKU\S-1-5-21-1673714354-1666257763-1680629560-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?source...ding}&oe={outputEncoding}&rlz=1I7ACPW_enGB609
    BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
    BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
    BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated)
    BHO-x32: Zonealarm Helper Object -> {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} -> C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.29.17\bh\zonealarm.dll [2014-02-26] (Check Point Software Technologies LTD)
    BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
    BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
    BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
    Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
    Toolbar: HKLM-x32 - ZoneAlarm Security Toolbar - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.29.17\zonealarmTlbr.dll [2014-02-26] (Check Point Software Technologies LTD)
    Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
    Toolbar: HKU\S-1-5-21-1673714354-1666257763-1680629560-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    Toolbar: HKU\S-1-5-21-1673714354-1666257763-1680629560-1000 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
    Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
    Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
    Tcpip\Parameters: [DhcpNameServer] 194.168.4.100 194.168.8.100

    FireFox:
    ========
    FF ProfilePath: C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
    FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
    FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2014-11-10] (globalUpdate)
    FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2014-11-10] (globalUpdate)
    FF user.js: detected! => C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\user.js [2015-04-16]
    FF Extension: No Name - C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\Extensions\OFcPuP@gmail.com [2015-04-02]
    FF HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
    FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]

    Chrome:
    =======
    CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3416016 2015-03-25] (AVG Technologies CZ, s.r.o.)
    R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [309232 2015-03-25] (AVG Technologies CZ, s.r.o.)
    R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [844320 2009-09-30] (Acer Incorporated)
    S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2014-10-07] (Macrovision Europe Ltd.) [File not signed]
    S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-11-10] () [File not signed] <==== ATTENTION
    S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-11-10] () [File not signed] <==== ATTENTION
    R2 Greg_Service; C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe [1150496 2009-08-28] (Acer Incorporated)
    R2 IHProtect Service; C:\Program Files (x86)\STab\ProtectService.exe [158864 2014-11-10] (TODO: <Company name>)
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
    R2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [62720 2009-08-21] (NewTech Infosystems, Inc.)
    R2 OberonGameConsoleService; C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe [44312 2009-08-29] ()
    R2 Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [240160 2009-07-04] (Acer)
    R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [3596752 2014-08-13] (Check Point Software Technologies Ltd.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
    R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [96272 2014-08-13] (Check Point Software Technologies, Ltd.)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [281056 2015-03-25] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [203544 2014-11-18] (AVG Technologies CZ, s.r.o.)
    R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
    R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [341472 2015-02-03] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [133088 2015-02-05] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
    R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [284128 2015-02-25] (AVG Technologies CZ, s.r.o.)
    R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [1442816 2009-03-24] (C-Media Inc)
    S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] () [File not signed]
    S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [13896 2013-03-07] () [File not signed]
    S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] () [File not signed]
    S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () [File not signed]
    R3 RDID1115; C:\Windows\System32\Drivers\rdwm1115.sys [81920 2010-09-17] (Roland Corporation)
    R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2014-10-22] (Acronis International GmbH)
    R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [183224 2014-10-22] (Acronis)
    R0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [117024 2014-10-22] (Acronis International GmbH)
    R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [450456 2014-08-13] (Check Point Software Technologies Ltd.)
    S3 k57nd60a; system32\DRIVERS\k57nd60a.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-04-16 16:27 - 2015-04-16 16:28 - 00017984 _____ () C:\Users\guy\Desktop\FRST.txt
    2015-04-16 16:27 - 2015-04-16 16:27 - 00000000 ____D () C:\FRST
    2015-04-16 16:25 - 2015-04-16 16:25 - 02097664 _____ (Farbar) C:\Users\guy\Desktop\FRST64.exe
    2015-04-16 16:21 - 2015-04-16 16:21 - 05481336 _____ (Avast Software s.r.o.) C:\Users\guy\Downloads\avast_free_antivirus_setup_online_cnet.exe
    2015-04-13 18:15 - 2015-04-13 18:15 - 00243320 _____ () C:\Users\guy\Downloads\Firefox Setup Stub 37.0.1.exe
    2015-04-13 18:15 - 2015-04-13 18:15 - 00001169 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    2015-04-13 18:15 - 2015-04-13 18:15 - 00001157 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
    2015-04-13 18:15 - 2015-04-13 18:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    2015-04-08 17:10 - 2015-04-08 17:10 - 00000000 ____D () C:\Users\guy\Documents\VideoPad Projects
    2015-04-08 15:56 - 2015-04-08 17:46 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
    2015-04-08 15:56 - 2015-04-08 17:19 - 00000000 ____D () C:\Users\guy\AppData\Roaming\NCH Software
    2015-04-08 15:56 - 2015-04-08 15:56 - 00001296 _____ () C:\Users\Public\Desktop\NCH Suite.lnk
    2015-04-08 15:56 - 2015-04-08 15:56 - 00001156 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
    2015-04-08 15:56 - 2015-04-08 15:56 - 00001144 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
    2015-04-08 15:56 - 2015-04-08 15:56 - 00000000 ____D () C:\ProgramData\NCH Software
    2015-04-08 15:56 - 2015-04-08 15:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
    2015-04-08 15:56 - 2015-04-08 15:56 - 00000000 ____D () C:\Program Files (x86)\NCH Software
    2015-04-08 15:54 - 2015-04-08 15:54 - 04910136 _____ (NCH Software) C:\Users\guy\Downloads\vpsetup.exe
    2015-04-08 13:26 - 2015-04-09 00:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
    2015-04-02 14:41 - 2015-04-16 15:41 - 00001304 _____ () C:\Windows\Tasks\sup_games_notification_service.job
    2015-04-02 14:41 - 2015-04-16 14:53 - 00000666 _____ () C:\Windows\Tasks\sup_games_updating_service.job
    2015-04-02 14:41 - 2015-04-06 21:55 - 00000902 _____ () C:\Windows\Tasks\QW6j3Ibuk3BnMptEc.job
    2015-04-02 14:41 - 2015-04-02 14:41 - 00004318 _____ () C:\Windows\System32\Tasks\sup_games_notification_service
    2015-04-02 14:41 - 2015-04-02 14:41 - 00003682 _____ () C:\Windows\System32\Tasks\sup_games_updating_service
    2015-04-02 14:41 - 2015-04-02 14:41 - 00003022 _____ () C:\Windows\System32\Tasks\QW6j3Ibuk3BnMptEc
    2015-04-02 14:41 - 2015-04-02 14:41 - 00000000 ____D () C:\Program Files (x86)\sup games
    2015-04-02 11:31 - 2015-04-02 11:33 - 00000000 ___HD () C:\ProgramData\CanonIJMIG
    2015-04-02 11:27 - 2015-04-02 11:30 - 00000000 ___HD () C:\ProgramData\CanonIJScan
    2015-03-25 11:21 - 2015-03-25 11:21 - 00281056 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-04-16 16:26 - 2014-10-07 08:41 - 01212252 _____ () C:\Windows\WindowsUpdate.log
    2015-04-16 16:02 - 2014-11-11 23:49 - 00000000 ___HD () C:\Users\guy\Documents\Attachments
    2015-04-16 15:54 - 2009-07-14 05:45 - 00026992 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-04-16 15:54 - 2009-07-14 05:45 - 00026992 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-04-16 15:44 - 2014-10-12 13:54 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-04-16 15:36 - 2014-11-10 15:36 - 00005496 _____ () C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-6.job
    2015-04-16 14:58 - 2010-10-15 19:04 - 00000000 ____D () C:\ProgramData\MFAData
    2015-04-16 14:53 - 2014-11-10 15:37 - 00004472 _____ () C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-4.job
    2015-04-16 14:53 - 2014-11-10 15:37 - 00003090 _____ () C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-1.job
    2015-04-16 14:53 - 2014-11-10 15:37 - 00002424 _____ () C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-5_user.job
    2015-04-16 14:53 - 2014-11-10 15:37 - 00002424 _____ () C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-5.job
    2015-04-16 14:53 - 2014-11-10 15:37 - 00002088 _____ () C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-2.job
    2015-04-16 14:53 - 2014-11-10 15:36 - 00005160 _____ () C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-7.job
    2015-04-16 14:53 - 2014-11-10 15:36 - 00004818 _____ () C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-11.job
    2015-04-16 14:53 - 2014-11-10 15:36 - 00000936 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
    2015-04-16 14:53 - 2014-10-11 18:53 - 00000000 ____D () C:\ProgramData\NVIDIA
    2015-04-16 14:53 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2015-04-16 14:53 - 2009-07-14 05:51 - 00053581 _____ () C:\Windows\setupact.log
    2015-04-15 12:44 - 2014-10-12 13:54 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-04-15 12:44 - 2014-10-12 13:54 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-04-15 12:44 - 2014-10-12 13:54 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2015-04-15 10:05 - 2014-11-10 21:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2015-04-08 14:41 - 2014-11-10 15:36 - 00000940 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
    2015-04-07 00:59 - 2014-11-10 15:36 - 00000000 ____D () C:\Program Files (x86)\e8dd412c-2343-4a8c-b721-2345b83b3e2c
    2015-04-07 00:42 - 2014-11-10 21:40 - 00000000 ____D () C:\Users\guy\AppData\Local\Avg2015
    2015-04-02 14:41 - 2014-11-10 21:42 - 00000000 ____D () C:\ProgramData\AVG2015
    2015-04-02 11:30 - 2014-11-16 17:08 - 00000000 ____D () C:\Users\guy\AppData\Roaming\Canon
    2015-04-01 14:30 - 2014-11-10 21:42 - 00000977 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
    2015-04-01 14:30 - 2013-12-11 17:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    2015-03-29 23:25 - 2009-07-14 06:13 - 00726316 _____ () C:\Windows\system32\PerfStringBackup.INI
    2015-03-28 23:38 - 2014-10-12 23:08 - 00001225 _____ () C:\Users\guy\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
    2015-03-28 23:38 - 2014-10-12 23:08 - 00001201 _____ () C:\Users\Public\Desktop\GOM Player.lnk

    ==================== Files in the root of some directories =======

    2009-10-30 05:25 - 2008-06-11 16:12 - 0776614 _____ () C:\Program Files (x86)\Common Files\packardbell.ico
    2009-10-30 05:26 - 2009-08-24 13:06 - 0131368 _____ () C:\ProgramData\FullRemove.exe
    2010-09-12 15:40 - 2014-05-03 11:20 - 0000020 ____H () C:\ProgramData\PKP_DLec.DAT

    Some content of TEMP:
    ====================
    C:\Users\guy\AppData\Local\Temp\917b0b87-3358-4e79-93de-3dfc2fc99ed0.exe
    C:\Users\guy\AppData\Local\Temp\AVG-AntiVirus-Free-2014201505315.exe
    C:\Users\guy\AppData\Local\Temp\DseShExt-x64.dll
    C:\Users\guy\AppData\Local\Temp\DseShExt-x86.dll
    C:\Users\guy\AppData\Local\Temp\ExPromo.exe
    C:\Users\guy\AppData\Local\Temp\MSETUP4.EXE
    C:\Users\guy\AppData\Local\Temp\SDShelEx-win32.dll
    C:\Users\guy\AppData\Local\Temp\SDShelEx-x64.dll
    C:\Users\guy\AppData\Local\Temp\wmfdist.exe


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-04-15 13:12

    ==================== End Of Log ============================
     
  2. Guymarshall

    Guymarshall TS Rookie Topic Starter

    ......and the Addition log

    Addition

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-04-2015 04
    Ran by guy at 2015-04-16 16:28:28
    Running from C:\Users\guy\Desktop
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: AVG AntiVirus Free[​IMG] Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
    FW: ZoneAlarm Free Firewall[​IMG] Firewall (Enabled) {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}

    ==================== Installed Programs ======================

    (Only the adware programs[​IMG] with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
    Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
    Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
    Adobe Photoshop Elements 7.0 (HKLM-x32\...\Adobe Photoshop Elements 7) (Version: 7.0.1 - Adobe Systems Incorporated)
    Adobe Reader 9.1 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.1.0 - Adobe Systems Incorporated)
    Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
    Alice Greenfingers (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}) (Version: - Oberon Media)
    Amazonia (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}) (Version: - Oberon Media)
    AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5863 - AVG Technologies)
    AVG 2015 (Version: 15.0.4331 - AVG Technologies) Hidden
    AVG 2015 (Version: 15.0.5863 - AVG Technologies) Hidden
    Backup Manager Basic (x32 Version: 2.0.0.22 - NewTech Infosystems) Hidden
    Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.5.0.0 - Canon Inc.)
    Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - ‪Canon Inc.‬)
    Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.0 - Canon Inc.)
    Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - ‪Canon Inc.‬)
    Canon MG4200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG4200_series) (Version: 1.01 - Canon Inc.)
    Canon MG4200 series On-screen Manual (HKLM-x32\...\Canon MG4200 series On-screen Manual) (Version: 7.5.0 - Canon Inc.)
    Canon MG4200 series User Registration (HKLM-x32\...\Canon MG4200 series User Registration) (Version: - Canon Inc.‎)
    Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 1.1.2 - Canon Inc.)
    Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 1.0.1 - Canon Inc.)
    Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.)
    Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.0.0 - Canon Inc.)
    Chicken Invaders 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}) (Version: - Oberon Media)
    Dairy Dash (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}) (Version: - Oberon Media)
    Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
    EaseUS Partition Master 10.1 (HKLM-x32\...\EaseUS Partition Master_is1) (Version: - EaseUS)
    EnterDigital (HKLM\...\EnterDigital) (Version: 2014.11.10.162145 - EnterDigital) <==== ATTENTION
    Farm Frenzy 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}) (Version: - Oberon Media)
    FastImageResizer (remove only) (HKLM-x32\...\FastImageResizer) (Version: - )
    Firefox Packages (HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\...\Firefox Packages) (Version: - ) <==== ATTENTION
    First Class Flurry (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115208410}) (Version: - Oberon Media)
    Forté Agent (HKLM-x32\...\Forte Agent) (Version: 7.00 - Forté Internet Software, Inc.)
    GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.69.5227 - Gretech Corporation)
    Granny In Paradise (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}) (Version: - Oberon Media)
    Heroes of Hellas (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}) (Version: - Oberon Media)
    Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3002 - Packard Bell)
    ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
    Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
    Launch Manager (HKLM-x32\...\LManager) (Version: 3.0.04 - Packard Bell)
    McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
    Merriam Websters Spell Jam (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}) (Version: - Oberon Media)
    Metaboli (HKLM-x32\...\Metaboli) (Version: 1.00.0006 - Packard Bell)
    Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
    Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Mozilla Firefox 37.0.1 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 37.0.1 (x86 en-GB)) (Version: 37.0.1 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 37.0.1 - Mozilla)
    Mozilla Thunderbird 31.6.0 (x86 en-GB) (HKLM-x32\...\Mozilla Thunderbird 31.6.0 (x86 en-GB)) (Version: 31.6.0 - Mozilla)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    Nero 9 Essentials (HKLM-x32\...\{a4584eb1-2889-4dcf-abed-da4f9f6996a3}) (Version: - Nero AG)
    NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.9 - NVIDIA Corporation)
    NVIDIA Stereoscopic 3D Driver (HKLM-x32\...\NVIDIAStereo) (Version: 7.16.11.9107 - NVIDIA Corporation)
    OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
    Packard Bell GameZone Console (HKLM-x32\...\{117E3AE2-10D1-41C1-9FA6-F4C382F767A8}_is1) (Version: 5.1.2.5 - Oberon Media, Inc.)
    Packard Bell InfoCentre (HKLM-x32\...\Packard Bell InfoCentre) (Version: 3.02.3000 - Packard Bell)
    Packard Bell MyBackup (HKLM-x32\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.22 - NewTech Infosystems)
    Packard Bell Power Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.05.3004 - Packard Bell)
    Packard Bell Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Packard Bell)
    Packard Bell Registration (HKLM-x32\...\Packard Bell Registration) (Version: 1.02.3006 - Packard Bell)
    Packard Bell Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.01.3017 - Packard Bell)
    PackardBell ScreenSaver (HKLM-x32\...\PackardBell Screensaver) (Version: 1.0.1.0302 - PackardBell)
    QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements)
    Radio Canyon (HKLM-x32\...\Radio Canyon) (Version: 1.35.9.29 - Radio Canyon) <==== ATTENTION!
    Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30104 - Realtek Semiconductor Corp.)
    Seagate DiscWizard (HKLM-x32\...\{AC5BFE42-B72A-467C-B9B2-8BF77C6D4D70}) (Version: 16.0.5840 - Seagate)
    Steinberg Cubase SX v2.2.0.35 (HKLM-x32\...\Steinberg Cubase SX v2.2.0.35) (Version: - )
    Theorica Divx ;-) Codecs (remove only) (HKLM-x32\...\Theorica Divx ;-) Codecs) (Version: 3.0 - )
    UM-ONE Driver (HKLM\...\RolandRDID0115) (Version: - Roland Corporation)
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 4.00 - NCH Software)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Welcome Center (HKLM-x32\...\Packard Bell Welcome Center) (Version: 1.00.3009 - Packard Bell)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
    Windows Live Sign-in Assistant (HKLM-x32\...\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
    Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
    Windows Live Upload Tool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
    WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - )
    ZoneAlarm Firewall (x32 Version: 13.3.209.000 - Check Point Software Technologies Ltd.) Hidden
    ZoneAlarm Free Firewall (HKLM-x32\...\ZoneAlarm Free Firewall) (Version: 13.3.209.000 - Check Point)
    ZoneAlarm Security (x32 Version: 13.3.209.000 - Check Point Software Technologies Ltd.) Hidden
    ZoneAlarm Security Toolbar (HKLM-x32\...\zonealarm) (Version: 1.8.29.17 - Check Point Software Technologies LTD)
    ZoneAlarm Security Toolbar (HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\...\zonealarm) (Version: 1.8.29.17 - Check Point Software Technologies LTD)

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


    ==================== Restore Points =========================

    15-04-2015 13:18:57 Scheduled Checkpoint

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {06D8C6C3-AE71-4C8C-9760-FE2DE1D38AF6} - System32\Tasks\ASP => C:\Program Files (x86)\Tuneup Pro\systweakasp.exe
    Task: {0C2AD34D-A35B-4C33-AB59-7509528FDC45} - System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-5 => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-5.exe <==== ATTENTION
    Task: {22F4460E-F68B-480D-A787-586F5FF9EA0A} - System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-11 => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-11.exe <==== ATTENTION
    Task: {492C6CF5-773E-446F-8A4D-A0FC43CE591B} - System32\Tasks\sup_games_notification_service => C:\Program Files (x86)\sup games\sup_games_notification_service.exe <==== ATTENTION
    Task: {4F375027-D1D2-4F4D-8D92-5077BAD11C17} - System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-6 => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-6.exe <==== ATTENTION
    Task: {5713DF5F-54FC-432D-A647-C51C80345AA3} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-11-10] () <==== ATTENTION
    Task: {5ABE39ED-2BBB-4FFA-BF72-5D4BF6EAFDD3} - System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-4 => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-4.exe <==== ATTENTION
    Task: {5D192FEF-1FE0-4CBF-B220-5B3C93532C73} - System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-5_user => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-5.exe <==== ATTENTION
    Task: {64E8BB91-F3B2-4BC0-99F1-DA7C631AAEB8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
    Task: {752CB585-8E11-4F4F-8045-BA87E22A39FB} - System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-2 => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-2.exe <==== ATTENTION
    Task: {7F657E54-BBBD-4B6F-A2A2-DBDDA3D8B3C2} - System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-7 => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-7.exe <==== ATTENTION
    Task: {A6864D0B-DA88-496A-9C0F-9E29971BDB9F} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-11-10] () <==== ATTENTION
    Task: {A9D902F8-F4CA-47A1-A5C0-1637316EDCDD} - System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-1 => C:\Program Files (x86)\Radio Canyon\Radio Canyon-codedownloader.exe <==== ATTENTION
    Task: {F83C439D-ED55-4A35-9F7A-4DFD2D8D59C1} - System32\Tasks\sup_games_updating_service => C:\Program Files (x86)\sup games\sup_games_updating_service.exe <==== ATTENTION
    Task: {FA9A574B-38A8-45FE-9626-9AF4FF1211C2} - System32\Tasks\QW6j3Ibuk3BnMptEc => C:\Users\guy\AppData\Roaming\QW6j3Ibuk3BnMptEc.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-1.job => C:\Program Files (x86)\Radio Canyon\Radio Canyon-codedownloader.exe <==== ATTENTION
    Task: C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-11.job => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-11.exe <==== ATTENTION
    Task: C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-2.job => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-2.exe <==== ATTENTION
    Task: C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-4.job => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-4.exe <==== ATTENTION
    Task: C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-5.job => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-5.exe <==== ATTENTION
    Task: C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-5_user.job => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-5.exe <==== ATTENTION
    Task: C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-6.job => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-6.exe <==== ATTENTION
    Task: C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-7.job => C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e-7.exe <==== ATTENTION
    Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
    Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
    Task: C:\Windows\Tasks\QW6j3Ibuk3BnMptEc.job => C:\Users\guy\AppData\Roaming\QW6j3Ibuk3BnMptEc.exe <==== ATTENTION
    Task: C:\Windows\Tasks\sup_games_notification_service.job => C:\Program Files (x86)\sup games\sup_games_notification_service.exeå/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='sup games' /appid='73143' /srcid='2913' /bic='b22ee001b9b21b480b1aad83d10931d4' /verifier='cf43ff5082968a0c49707a78d6c6e3d6' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif <==== ATTENTION
    Task: C:\Windows\Tasks\sup_games_updating_service.job => C:\Program Files (x86)\sup games\sup_games_updating_service.exeª /campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=sup_games_updating_service /funurl=http:/stats.buildomserv.com <==== ATTENTION

    ==================== Loaded Modules (whitelisted) ==============

    2009-10-30 05:33 - 2009-08-29 01:05 - 00044312 _____ () C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe
    2014-11-10 15:29 - 2014-02-13 16:37 - 00254024 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\TrayTipAgentE.exe
    2009-02-03 01:33 - 2009-02-03 01:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
    2008-09-29 01:55 - 2008-09-29 01:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\ACE.dll
    2014-11-10 15:29 - 2014-02-13 16:27 - 00222792 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\traynet.dll
    2014-11-10 15:29 - 2014-02-13 16:27 - 00275528 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\libcurl.dll
    2014-11-10 15:29 - 2014-02-13 16:27 - 00113166 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\zlib1.dll
    2014-11-10 15:29 - 2014-02-13 16:27 - 00249928 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\uexper.dll
    2015-04-08 13:26 - 2015-04-08 13:26 - 03348592 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
    2015-04-08 13:26 - 2015-04-08 13:26 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
    2015-04-08 13:26 - 2015-04-08 13:26 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
    2015-04-15 12:44 - 2015-04-15 12:44 - 16863920 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

    AlternateDataStreams: C:\ProgramData\Temp:0B9176C0
    AlternateDataStreams: C:\ProgramData\Temp:93DE1838
    AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE

    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"

    ==================== EXE Association (whitelisted) ===============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\guy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 194.168.4.100 - 194.168.8.100

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== Accounts: =============================

    Administrator (S-1-5-21-1673714354-1666257763-1680629560-500 - Administrator - Disabled)
    Guest (S-1-5-21-1673714354-1666257763-1680629560-501 - Limited - Disabled)
    guy (S-1-5-21-1673714354-1666257763-1680629560-1000 - Administrator - Enabled) => C:\Users\guy

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (04/16/2015 04:26:33 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1256) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/16/2015 04:26:33 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1256) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/16/2015 04:26:33 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1256) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/16/2015 04:26:33 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1256) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/16/2015 03:56:33 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1256) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/16/2015 03:56:33 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1256) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/16/2015 03:56:33 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1256) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/16/2015 03:56:33 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1256) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/16/2015 03:26:33 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1256) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/16/2015 03:26:33 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1256) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.


    System errors:
    =============
    Error: (04/15/2015 01:53:00 PM) (Source: Service Control Manager) (EventID: 7016) (User: )
    Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

    Error: (04/15/2015 10:16:17 AM) (Source: DCOM) (EventID: 10010) (User: )
    Description: {ED1D0FDF-4414-470A-A56D-CFB68623FC58}

    Error: (04/13/2015 06:34:20 PM) (Source: Service Control Manager) (EventID: 7016) (User: )
    Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

    Error: (04/13/2015 02:25:58 PM) (Source: Service Control Manager) (EventID: 7016) (User: )
    Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

    Error: (04/11/2015 11:41:15 AM) (Source: Service Control Manager) (EventID: 7016) (User: )
    Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

    Error: (04/09/2015 01:22:00 AM) (Source: Service Control Manager) (EventID: 7016) (User: )
    Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

    Error: (04/09/2015 00:59:23 AM) (Source: volsnap) (EventID: 36) (User: )
    Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.

    Error: (04/08/2015 06:56:11 PM) (Source: Service Control Manager) (EventID: 7016) (User: )
    Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

    Error: (04/07/2015 01:15:38 AM) (Source: Service Control Manager) (EventID: 7016) (User: )
    Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

    Error: (04/06/2015 10:28:35 PM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 22:26:38 on ‎06/‎04/‎2015 was unexpected.


    Microsoft Office Sessions:
    =========================

    CodeIntegrity Errors:
    ===================================
    Date: 2015-04-08 14:43:37.097
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume6\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPI64.dll because the set of per-page image hashes could not be found on the system.

    Date: 2014-11-15 17:40:08.771
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume11\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPI64.dll because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    Processor: AMD Athlon(tm) II X4 640 Processor
    Percentage of memory in use: 49%
    Total physical RAM: 4095.3 MB
    Available physical RAM: 2070.99 MB
    Total Pagefile: 8188.75 MB
    Available Pagefile: 5794.49 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.82 MB

    ==================== Drives ================================

    Drive c: (system) (Fixed) (Total:302.7 GB) (Free:42.64 GB) NTFS
    Drive e: (New 2) (Fixed) (Total:302.95 GB) (Free:297.89 GB) NTFS
    Drive f: (New 3) (Fixed) (Total:314.04 GB) (Free:312.15 GB) NTFS
    Drive r: (Old hD 1) (Fixed) (Total:307.62 GB) (Free:222.47 GB) NTFS
    Drive s: (Old HD2) (Fixed) (Total:307.62 GB) (Free:292.67 GB) NTFS
    Drive t: (Old HD 3) (Fixed) (Total:316.27 GB) (Free:215.27 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 220A2209)
    Partition 1: (Active) - (Size=307.6 GB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=623.9 GB) - (Type=OF Extended)

    ========================================================
    Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 6F23EF61)
    Partition 1: (Not Active) - (Size=11.7 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=302.7 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=617 GB) - (Type=OF Extended)

    ==================== End Of Log ============================
     
  3. Broni

    Broni Malware Annihilator Posts: 52,890   +344

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    =====================================

    [​IMG] Uninstall:

    EnterDigital
    Firefox Packages
    Radio Canyon


    [​IMG] Download RogueKiller from one of the following links and save it to your Desktop:

    Link 1
    Link 2

    • Close all the running programs
    • Windows Vista/7/8 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    [​IMG] Please download Malwarebytes Anti-Malware (MBAM) to your desktop.
    NOTE. If you already have MBAM 2.0 installed scroll down.

    • Double-click mbam-setup-2.0.0.1000.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
      • Launch Malwarebytes Anti-Malware
      • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
    • Click Finish.
    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.


    If you already have MBAM 2.0 installed:

    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.

    How to get logs:
    (Export log to save as txt)


    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Export'.
    • Click 'Text file (*.txt)'
    • In the Save File dialog box which appears, click on Desktop.
    • In the File name: box type a name for your scan log.
    • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
    • Click Ok
    • Attach that saved log to your next reply.


    (Copy to clipboard for pasting into forum replies or tickets)

    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Copy to Clipboard'
    • Paste the contents of the clipboard into your reply.

    [​IMG] Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Scan button.
    • When the scan has finished click on Clean button.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
     
  4. Guymarshall

    Guymarshall TS Rookie Topic Starter

    Hello Broni, thanks for this - I have just been through your 5 step program to recovery and all has gone smoothly. Now sending you the various logs.

    MBAM

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 18/04/2015
    Scan Time: 23:13:44
    Logfile: MBAM log 1.txt
    Administrator: Yes

    Version: 2.01.4.1018
    Malware Database: v2015.04.18.04
    Rootkit Database: v2015.03.31.01
    License: Trial
    Malware Protection: Enabled
    Malicious Website Protection: Enabled
    Self-protection: Disabled

    OS: Windows 7
    CPU: x64
    File System: NTFS
    User: guy

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 338543
    Time Elapsed: 9 min, 30 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 1
    PUP.Optional.IHProtect.A, C:\Program Files (x86)\STab\ProtectService.exe, 2168, Delete-on-Reboot, [6d9fdf8f2a603afc474d07c77093f30d]

    Modules: 0
    (No malicious items detected)

    Registry Keys: 103
    PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, Quarantined, [fd0f6509375396a007744f29fe05ee12],
    PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, Quarantined, [fd0f6509375396a007744f29fe05ee12],
    PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, Quarantined, [fd0f6509375396a007744f29fe05ee12],
    PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{91b8f7a9-1558-40b3-b1e9-824ae5a2089f}, Quarantined, [4cc0b3bbd7b3c86ed0e545f7d330d32d],
    PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{09e31fda-3893-4c78-9562-7b8df8f5f47c}, Quarantined, [4cc0b3bbd7b3c86ed0e545f7d330d32d],
    PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C69A48F3-9357-40E4-9C73-9B3A8E23A128}, Quarantined, [4cc0b3bbd7b3c86ed0e545f7d330d32d],
    PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C69A48F3-9357-40E4-9C73-9B3A8E23A128}, Quarantined, [4cc0b3bbd7b3c86ed0e545f7d330d32d],
    PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C69A48F3-9357-40E4-9C73-9B3A8E23A128}, Quarantined, [4cc0b3bbd7b3c86ed0e545f7d330d32d],
    PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{09e31fda-3893-4c78-9562-7b8df8f5f47c}, Quarantined, [4cc0b3bbd7b3c86ed0e545f7d330d32d],
    PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{09e31fda-3893-4c78-9562-7b8df8f5f47c}, Quarantined, [4cc0b3bbd7b3c86ed0e545f7d330d32d],
    PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{91B8F7A9-1558-40B3-B1E9-824AE5A2089F}, Quarantined, [4cc0b3bbd7b3c86ed0e545f7d330d32d],
    PUP.Optional.EnterDigital.A, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{91B8F7A9-1558-40B3-B1E9-824AE5A2089F}, Quarantined, [4cc0b3bbd7b3c86ed0e545f7d330d32d],
    PUP.Optional.EnterDigital.A, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{91B8F7A9-1558-40B3-B1E9-824AE5A2089F}, Quarantined, [4cc0b3bbd7b3c86ed0e545f7d330d32d],
    PUP.Optional.ModGoog, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [37d5cf9fa9e1b581b0d4014535cd847c],
    PUP.Optional.ModGoog, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [37d5cf9fa9e1b581b0d4014535cd847c],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [4fbddd91fb8f80b60cf64e051fe6d62a],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickProcessLauncherMachine, Quarantined, [ec20afbfd9b1280e818196bd887d6f91],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickProcessLauncherMachine.1.0, Quarantined, [f814f678414947ef27db2d26ef16c23e],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoCreateAsync, Quarantined, [66a6a6c8a9e16dc9986b470cbe4724dc],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoCreateAsync.1.0, Quarantined, [60ac3c322763be78a85b71e24bba51af],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass, Quarantined, [c84483ebb7d349ed51b290c371945fa1],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass.1, Quarantined, [9e6e0866216969cd16ed67ec966f9868],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreMachineClass, Quarantined, [fc107df158329b9ba75cb59eb45111ef],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreMachineClass.1, Quarantined, [010b630b1674fb3bb54e56fdce374ab6],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CredentialDialogMachine, Quarantined, [f51795d991f95adc9370e07346bf718f],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CredentialDialogMachine.1.0, Quarantined, [ff0d511d4d3df343f90ac39060a5926e],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine, Quarantined, [f616e5896624e254897a1c376c99a55b],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [5eae5717b1d9c373b152bb987f868878],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback, Quarantined, [7d8f3737c3c7a591c142252ef80d738d],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [23e993db781244f2ed16371c22e37b85],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, Quarantined, [ed1f73fb0387e155af54db78fa0baa56],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [37d55e103d4d16208182d18257ae8c74],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.ProcessLauncher, Quarantined, [c7452549ff8baa8cdc27dc7710f58878],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.ProcessLauncher.1.0, Quarantined, [f81498d694f6f64055ae5cf79d685da3],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService, Quarantined, [1deffa744d3db086ca39e073be4708f8],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, Quarantined, [ad5fbdb10e7c36005ea551027a8bf808],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachine, Quarantined, [14f82e4074160c2adf245bf89e678f71],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachine.1.0, Quarantined, [8389036bc5c56cca996ab79c2bda3ec2],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback, Quarantined, [5cb088e67f0b300609faf45f6c995aa6],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback.1.0, Quarantined, [8785145a55350b2b53b084cfa85d817f],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc, Quarantined, [9f6d7feffd8d2d098c771043996cf20e],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, Quarantined, [39d3dd914a4022146f94b79c7b8a50b0],
    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\13641, Quarantined, [cd3f45292e5c1b1bd6167b8631d336ca],
    PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, Quarantined, [a9631f4f9eecef47d1c4f7d71ce77c84],
    PUP.Optional.RadioCanyon.A, HKLM\SOFTWARE\WOW6432NODE\Radio Canyon, Quarantined, [dc30cba3c6c455e1e2a5ad9b5da89d63],
    PUP.Optional.RadioCanyon.A, HKLM\SOFTWARE\WOW6432NODE\Radio Canyon-nv, Quarantined, [4ebe05692b5f66d042453c0cd62f01ff],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [29e375f9deac42f4ec16ada6e81dfc04],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickProcessLauncherMachine, Quarantined, [1bf14f1f256568ce61a18bc8e3223cc4],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickProcessLauncherMachine.1.0, Quarantined, [06065d1165258bab020059faac593ec2],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoCreateAsync, Quarantined, [3ece422c701a1f1758ab084b5fa69967],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoCreateAsync.1.0, Quarantined, [3dcf8ae477133402d03370e3c3426b95],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreClass, Quarantined, [49c33c32d1b9171f1ae9bd96da2b44bc],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreClass.1, Quarantined, [f11b2e400e7cb4824ab9e56e1ee7b34d],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreMachineClass, Quarantined, [c844234b9eeca294a75cf85b61a434cc],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreMachineClass.1, Quarantined, [46c60d61206a78bee22182d1c441837d],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CredentialDialogMachine, Quarantined, [c04c0965e1a9231360a3be9529dcf50b],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CredentialDialogMachine.1.0, Quarantined, [25e7353978127abcc53e381bda2b916f],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine, Quarantined, [ae5e86e8731781b58c7793c06d98718f],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [09036c0245456bcb9370480b6a9b2dd3],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback, Quarantined, [f5170c6237534aec40c3f3600401f907],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [a7654d21791140f60ff478dbb451b54b],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, Quarantined, [d834e787e0aab58149ba75dee2234bb5],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [9b715a1465251620fb083221b055d22e],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.ProcessLauncher, Quarantined, [59b391dd19710b2b16ed0c47d332ae52],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.ProcessLauncher.1.0, Quarantined, [739936381971d066649f0a49759059a7],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3COMClassService, Quarantined, [83892a447a10a492937068ebdd282ed2],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, Quarantined, [e72577f771190135f40f90c356af4cb4],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachine, Quarantined, [68a4bcb29af014224db6aaa9c243c43c],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachine.1.0, Quarantined, [37d5e48a593152e4c63d2c276f966799],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback, Quarantined, [0ffd2648c6c420164db697bc937238c8],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback.1.0, Quarantined, [b25a115d5f2b67cf35ce78db44c159a7],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebSvc, Quarantined, [9b719bd32e5c8bab3fc493c034d13dc3],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, Quarantined, [000cea8479110135fc0766eddd28df21],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, Quarantined, [64a8115dd8b2cb6bb870feec24df41bf],
    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\13641, Quarantined, [fe0efe70becc2f0764880ef3976df10f],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, Quarantined, [8d7f8ce2c7c37fb742fae95c8580817f],
    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, Quarantined, [8587a2ccdeacfe3899a4301548bd17e9],
    PUP.Optional.V9.A, HKLM\SOFTWARE\WOW6432NODE\V9SOFTWARE\v9hp, Quarantined, [62aa87e75337e45241d43ad04bb98a76],
    PUP.Optional.IHProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IHProtect Service, Quarantined, [6d9fdf8f2a603afc474d07c77093f30d],
    PUP.Optional.RadioCanyon.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Radio Canyon, Quarantined, [33d947270882a591fe8b52f65aab0ef2],
    PUP.Optional.CrossRider.A, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [d03cb9b54743d561fc99ee493bcaa858],
    PUP.Optional.RadioCanyon.A, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\APPDATALOW\SOFTWARE\Radio Canyon, Quarantined, [0606f17dcfbb1d19a8e1a3a561a4d22e],
    PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, Quarantined, [89837df1e8a2da5c332b6759c14256aa],
    PUP.Optional.InstallCore.A, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [7399610d563448eebbf3e22b857fff01],
    PUP.Optional.InstallCore.A, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\INSTALLCORE, Quarantined, [51bb1e50a9e1cd69126e64bf0afb58a8],
    PUP.Optional.CrossRider.A, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\13641, Quarantined, [3ece610df496082e5df25e81ae556a96],
    PUP.Optional.CrossRider.A, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Radio Canyon, Quarantined, [b854a6c8cac073c3977ca73ca65d60a0],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\globalUpdate.OneClickCtrl.10, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.Update3WebControl.4, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\globalUpdate.Update3WebControl.4, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],

    Registry Values: 4
    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [64a8115dd8b2cb6bb870feec24df41bf]
    PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATEDEV|AuCheckPeriodMs, 21600000, Quarantined, [51bb8de1bad0aa8cf4d19b24f80bcb35]
    PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, Firefox, Quarantined, [89837df1e8a2da5c332b6759c14256aa]
    PUP.Optional.InstallCore.A, HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\INSTALLCORE|tb, 0Z1B1L2Z1S, Quarantined, [51bb1e50a9e1cd69126e64bf0afb58a8]

    Registry Data: 4
    PUP.Optional.V9.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://search.v9.com/web/?type=ds&t...6JD2ZB03737&I=psd&t=34bcb47fb&q={searchTerms}, Good: (www.google.com), Bad: (http://search.v9.com/web/?type=ds&t...),Replaced,[98742a448406e254a358ed0934d1be42]
    PUP.Optional.V9.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://search.v9.com/web/?type=ds&t...6JD2ZB03737&I=psd&t=34bcb47fb&q={searchTerms}, Good: (www.google.com), Bad: (http://search.v9.com/web/?type=ds&t...),Replaced,[48c41757cdbd8caa5d9e45b10cf944bc]
    PUP.Optional.V9.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://search.v9.com/web/?type=ds&t...6JD2ZB03737&I=psd&t=34bcb47fb&q={searchTerms}, Good: (www.google.com), Bad: (http://search.v9.com/web/?type=ds&t...),Replaced,[c24aeb83414931057f7c6591a85df709]
    PUP.Optional.V9.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://search.v9.com/web/?type=ds&t...6JD2ZB03737&I=psd&t=34bcb47fb&q={searchTerms}, Good: (www.google.com), Bad: (http://search.v9.com/web/?type=ds&t...),Replaced,[44c8b3bbed9db18548b3cb2ba95c926e]

    Folders: 25
    PUP.Optional.OpenCandy, C:\Users\guy\AppData\Roaming\OpenCandy, Delete-on-Reboot, [2be1630bee9c0d29406b7d0fcb3804fc],
    PUP.Optional.OpenCandy, C:\Users\guy\AppData\Roaming\OpenCandy\47CD773615C046E6884327E1D22E2C58, Quarantined, [2be1630bee9c0d29406b7d0fcb3804fc],
    PUP.Optional.OpenCandy, C:\Users\guy\AppData\Roaming\OpenCandy\9297761703F34D7EBFA160FD8D0F3F22, Quarantined, [2be1630bee9c0d29406b7d0fcb3804fc],
    PUP.Optional.OpenCandy, C:\Users\guy\AppData\Roaming\OpenCandy\D8FABC691B54453487793E541752C4DF, Quarantined, [2be1630bee9c0d29406b7d0fcb3804fc],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, Delete-on-Reboot, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, Delete-on-Reboot, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download\{DF43BBA7-FA5E-49AA-85B8-CD01727E5373}, Delete-on-Reboot, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download\{DF43BBA7-FA5E-49AA-85B8-CD01727E5373}\1.3.25.27, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, Delete-on-Reboot, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{9C774238-80B0-4CB6-918A-DAB2098FCCF6}, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.A, C:\Users\guy\AppData\Local\Temp\comh.167741, Quarantined, [a16b214d8505350190045f42b053f808],
    PUP.Optional.RadioCanyon.A, C:\Users\guy\AppData\LocalLow\Radio Canyon, Quarantined, [729ae5896c1e52e4f5e4e8c447bc0ef2],
    PUP.Optional.RadioCanyon.A, C:\Program Files (x86)\Radio Canyon, Quarantined, [b05c224cf9911422706bbaf2f211639d],
    PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, Delete-on-Reboot, [927a5b136c1e6bcbd557368030d36a96],
    PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, Quarantined, [927a5b136c1e6bcbd557368030d36a96],
    PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital, Quarantined, [0705a5c9a8e2d95d7e527349af54df21],
    PUP.Optional.EnterDigital.A, C:\Users\guy\AppData\Local\Temp\EnterDigital, Quarantined, [15f789e5f5956dc9d9f8fdbfa95a46ba],
    PUP.Optional.SupGames.A, C:\Program Files (x86)\sup games, Quarantined, [a7658ce22565ac8afb63922b06fd956b],
    PUP.Optional.SupGames.A, C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\extensions\OFcPuP@gmail.com, Delete-on-Reboot, [e02c18563a50979f96e86cd0ad597090],
    PUP.Optional.SupGames.A, C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\extensions\OFcPuP@gmail.com\chrome, Delete-on-Reboot, [e02c18563a50979f96e86cd0ad597090],
    PUP.Optional.SupGames.A, C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\extensions\OFcPuP@gmail.com\chrome\content, Quarantined, [e02c18563a50979f96e86cd0ad597090],
    PUP.Optional.SupGames.A, C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\extensions\OFcPuP@gmail.com\defaults, Delete-on-Reboot, [e02c18563a50979f96e86cd0ad597090],
    PUP.Optional.SupGames.A, C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\extensions\OFcPuP@gmail.com\defaults\preferences, Quarantined, [e02c18563a50979f96e86cd0ad597090],

    Files: 72
    PUP.Optional.OpenCandy.A, C:\Users\guy\AppData\Roaming\OpenCandy\9297761703F34D7EBFA160FD8D0F3F22\dm.exe, Quarantined, [c84469052862c472090b5bf5ec1556aa],
    PUP.Optional.OpenCandy.A, C:\Users\guy\AppData\Roaming\OpenCandy\D8FABC691B54453487793E541752C4DF\dm.exe, Quarantined, [c943aec0e7a36ec822f268e83cc5a15f],
    PUP.Optional.InstallCore.SID.A, C:\Users\guy\AppData\Local\Temp\YtWDwKlA.exe.part, Quarantined, [ab61432b424872c4abe3f14ad333748c],
    PUP.Optional.InstallCore, C:\Users\guy\AppData\Local\Temp\215203.Uninstall\uninstaller.exe, Quarantined, [de2ec5a9dfabe155cbb92b2919e939c7],
    PUP.Optional.Bundle, C:\Users\guy\AppData\Local\Temp\is667172802\21F89854_stp\Oct28_cor_v9.exe, Quarantined, [64a8046a7a1038fe3a067969699ca15f],
    PUP.Optional.InstallCore, C:\Users\guy\AppData\Local\Temp\is667172802\5D4B7A38_stp\uninstaller.exe, Quarantined, [b359610d583261d595effc58dd25827e],
    PUP.Optional.ModGoog, C:\Users\guy\AppData\Local\Temp\comh.167741\GoogleCrashHandler.exe, Quarantined, [a26aa4ca9ded6cca0b79a89e778b4fb1],
    PUP.Optional.ModGoog, C:\Users\guy\AppData\Local\Temp\comh.167741\GoogleUpdate.exe, Quarantined, [37d5cf9fa9e1b581b0d4014535cd847c],
    PUP.Optional.ModGoog, C:\Users\guy\AppData\Local\Temp\comh.167741\GoogleUpdateBroker.exe, Quarantined, [f01c27471d6d5cdaadd761e5bf43649c],
    PUP.Optional.ModGoog, C:\Users\guy\AppData\Local\Temp\comh.167741\GoogleUpdateOnDemand.exe, Quarantined, [eb210767dbaf78be92f2d76f986ae917],
    PUP.Optional.ModGoog, C:\Users\guy\AppData\Local\Temp\comh.167741\goopdate.dll, Quarantined, [0309294575153df98cf869dddd25cc34],
    PUP.Optional.ModGoog, C:\Users\guy\AppData\Local\Temp\comh.167741\goopdateres_en.dll, Quarantined, [34d89fcf2961cb6b1e66390daa581ae6],
    PUP.Optional.ModGoog, C:\Users\guy\AppData\Local\Temp\comh.167741\npGoogleUpdate4.dll, Quarantined, [30dc5717ec9e90a6156f81c5af53c739],
    PUP.Optional.ModGoog, C:\Users\guy\AppData\Local\Temp\comh.167741\psmachine.dll, Quarantined, [e527aac4197181b5e2a277cf53afb24e],
    PUP.Optional.ModGoog, C:\Users\guy\AppData\Local\Temp\comh.167741\psuser.dll, Quarantined, [060672fc5f2b2b0be59f67df61a1cc34],
    PUP.Optional.OpenCandy, C:\Users\guy\Downloads\GOMPLAYERENSETUP.EXE, Quarantined, [1def016d5634d660aebedc4b47bf22de],
    PUP.Optional.Updating.A, C:\Windows\System32\Tasks\sup_games_updating_service, Quarantined, [020a115d07838bab6666dae46e95619f],
    PUP.Optional.Updating.A, C:\Windows\Tasks\sup_games_updating_service.job, Quarantined, [0ffda2cc98f26bcb0dc0744adb283fc1],
    PUP.Optional.Notification.A, C:\Windows\Tasks\sup_games_notification_service.job, Quarantined, [53b998d6355555e1c530655916edfb05],
    PUP.Optional.Notification.A, C:\Windows\System32\Tasks\sup_games_notification_service, Quarantined, [04085519602a54e2ca2c4d714cb7d22e],
    PUP.Optional.RegCleanerPro, C:\Windows\System32\Tasks\ASP, Quarantined, [9b71640af5951d19f168677e4fb48b75],
    PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-1, Quarantined, [46c6531b652530065ec502e8b350738d],
    PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-11, Quarantined, [4ac2f47ac6c4b28477ac7b6f21e29e62],
    PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-2, Quarantined, [2fdd630bf39753e34ed5509a09fa26da],
    PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-4, Quarantined, [d636b1bd1575f93d081b30ba8182be42],
    PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-5, Quarantined, [2ce0a7c75f2b0c2a34efd01ab94a619f],
    PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-5_user, Quarantined, [53b9b7b75238b0860b18ae3ce51e6c94],
    PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-6, Quarantined, [ee1e85e97c0ee74f8f948664e023a25e],
    PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-7, Quarantined, [f715d29c9eec56e0cb58707aa360a858],
    PUP.Optional.CrossRider.T, C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-1.job, Quarantined, [e824e08e7a10bd792411db68d82d4fb1],
    PUP.Optional.CrossRider.T, C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-11.job, Quarantined, [907c92dce7a34de98ca91e2546bf37c9],
    PUP.Optional.CrossRider.T, C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-2.job, Quarantined, [20ecdc92f892f1450d28fa491ce904fc],
    PUP.Optional.CrossRider.T, C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-4.job, Quarantined, [9a72ee80e4a694a2d362e45fa65f659b],
    PUP.Optional.CrossRider.T, C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-5.job, Quarantined, [947870fed5b5a78f0d288ab9ac59bc44],
    PUP.Optional.CrossRider.T, C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-5_user.job, Quarantined, [d6362e4098f2a59146ef063d57aee020],
    PUP.Optional.CrossRider.T, C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-6.job, Quarantined, [e824cba35931af87a98cb98a679e738d],
    PUP.Optional.CrossRider.T, C:\Windows\Tasks\febf2629-a25f-4a27-ac94-36a8dc593e5e-7.job, Quarantined, [5daf83eb8bffb18554e1c08345c0a55b],
    PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, Quarantined, [8c809cd2e7a3cf671b2965defb0a6898],
    PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, Quarantined, [24e8a1cdc1c9be78c77ed370c5407d83],
    PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, Quarantined, [8785115dcac0a492bb8be261867f9070],
    PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, Quarantined, [33d95b13a2e862d4b88f1231a95cfb05],
    PUP.Optional.IHProtect.A, C:\Program Files (x86)\STab\ProtectService.exe, Delete-on-Reboot, [6d9fdf8f2a603afc474d07c77093f30d],
    PUP.Optional.OpenCandy, C:\Users\guy\AppData\Roaming\OpenCandy\47CD773615C046E6884327E1D22E2C58\Opera_NI_stable.exe, Quarantined, [2be1630bee9c0d29406b7d0fcb3804fc],
    PUP.Optional.OpenCandy, C:\Users\guy\AppData\Roaming\OpenCandy\9297761703F34D7EBFA160FD8D0F3F22\TuneUpUtilities_UK_Exp2.exe, Quarantined, [2be1630bee9c0d29406b7d0fcb3804fc],
    PUP.Optional.OpenCandy, C:\Users\guy\AppData\Roaming\OpenCandy\D8FABC691B54453487793E541752C4DF\setupSt_p1v5.exe, Quarantined, [2be1630bee9c0d29406b7d0fcb3804fc],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll, Quarantined, [de2e6b035d2da096dd9effa2bc478a76],
    PUP.Optional.GlobalUpdate.A, C:\Users\guy\AppData\Local\Temp\comh.167741\GoogleUpdateHelper.msi, Quarantined, [a16b214d8505350190045f42b053f808],
    PUP.Optional.RadioCanyon.A, C:\Users\guy\AppData\LocalLow\Radio Canyon\DTFProxyToServerSect_b71c6c330e74701318a6f0adb73eaa5ae0060804_p620.dat, Quarantined, [729ae5896c1e52e4f5e4e8c447bc0ef2],
    PUP.Optional.RadioCanyon.A, C:\Program Files (x86)\Radio Canyon\1293297481.mxaddon, Quarantined, [b05c224cf9911422706bbaf2f211639d],
    PUP.Optional.RadioCanyon.A, C:\Program Files (x86)\Radio Canyon\background.html, Quarantined, [b05c224cf9911422706bbaf2f211639d],
    PUP.Optional.RadioCanyon.A, C:\Program Files (x86)\Radio Canyon\bd6add61-2518-46ac-9596-fa09cbd04ef8.crx, Quarantined, [b05c224cf9911422706bbaf2f211639d],
    PUP.Optional.RadioCanyon.A, C:\Program Files (x86)\Radio Canyon\bgNova.html, Quarantined, [b05c224cf9911422706bbaf2f211639d],
    PUP.Optional.RadioCanyon.A, C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e.crx, Quarantined, [b05c224cf9911422706bbaf2f211639d],
    PUP.Optional.RadioCanyon.A, C:\Program Files (x86)\Radio Canyon\febf2629-a25f-4a27-ac94-36a8dc593e5e.xpi, Quarantined, [b05c224cf9911422706bbaf2f211639d],
    PUP.Optional.RadioCanyon.A, C:\Program Files (x86)\Radio Canyon\Radio Canyon.ico, Quarantined, [b05c224cf9911422706bbaf2f211639d],
    PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update\conf, Quarantined, [927a5b136c1e6bcbd557368030d36a96],
    PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\7za.exe, Quarantined, [0705a5c9a8e2d95d7e527349af54df21],
    PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\EnterDigital.ico, Quarantined, [0705a5c9a8e2d95d7e527349af54df21],
    PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\updateEnterDigital.InstallState, Quarantined, [0705a5c9a8e2d95d7e527349af54df21],
    PUP.Optional.SupGames.A, C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\extensions\OFcPuP@gmail.com\chrome.manifest, Quarantined, [e02c18563a50979f96e86cd0ad597090],
    PUP.Optional.SupGames.A, C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\extensions\OFcPuP@gmail.com\install.rdf, Quarantined, [e02c18563a50979f96e86cd0ad597090],
    PUP.Optional.SupGames.A, C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\extensions\OFcPuP@gmail.com\chrome\content\browser.xul, Quarantined, [e02c18563a50979f96e86cd0ad597090],
    PUP.Optional.SupGames.A, C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\extensions\OFcPuP@gmail.com\chrome\content\main.js, Quarantined, [e02c18563a50979f96e86cd0ad597090],

    Physical Sectors: 0
    (No malicious items detected)


    (end)
     

    Attached Files:

  5. Guymarshall

    Guymarshall TS Rookie Topic Starter

    ... and Rogue Killer

    RogueKiller V10.5.10.0 [Apr 14 2015] by Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : http://forum.adlice.com
    Website : http://www.adlice.com/softwares/roguekiller/
    Blog : http://www.adlice.com

    Operating System : Windows 7 (6.1.7600 ) 64 bits version
    Started in : Normal mode
    User : guy [Administrator]
    Started from : C:\Users\guy\Desktop\RogueKiller.exe
    Mode : Delete -- Date : 04/18/2015 23:06:55

    ¤¤¤ Processes : 0 ¤¤¤

    ¤¤¤ Registry : 14 ¤¤¤
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} -> Not selected
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} -> Not selected
    [PUM.SearchPage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.v9.com/web/?type=ds&t...6JD2ZB03737&I=psd&t=34bcb47fb&q={searchTerms} -> Not selected
    [PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.v9.com/web/?type=ds&t...6JD2ZB03737&I=psd&t=34bcb47fb&q={searchTerms} -> Not selected
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 194.168.4.100 194.168.8.100 [UNITED KINGDOM (GB)][UNITED KINGDOM (GB)] -> Not selected
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 194.168.4.100 194.168.8.100 [UNITED KINGDOM (GB)][UNITED KINGDOM (GB)] -> Not selected
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 194.168.4.100 194.168.8.100 [UNITED KINGDOM (GB)][UNITED KINGDOM (GB)] -> Not selected
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{F090ACF2-2A10-464A-920D-6395873AA4E6} | DhcpNameServer : 194.168.4.100 194.168.8.100 [UNITED KINGDOM (GB)][UNITED KINGDOM (GB)] -> Not selected
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{F090ACF2-2A10-464A-920D-6395873AA4E6} | DhcpNameServer : 194.168.4.100 194.168.8.100 [UNITED KINGDOM (GB)][UNITED KINGDOM (GB)] -> Not selected
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{F090ACF2-2A10-464A-920D-6395873AA4E6} | DhcpNameServer : 194.168.4.100 194.168.8.100 [UNITED KINGDOM (GB)][UNITED KINGDOM (GB)] -> Not selected
    [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Not selected
    [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Not selected
    [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Not selected
    [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Not selected

    ¤¤¤ Tasks : 0 ¤¤¤

    ¤¤¤ Files : 0 ¤¤¤

    ¤¤¤ Hosts File : 0 ¤¤¤

    ¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ MBR Check : ¤¤¤
    +++++ PhysicalDrive0: +++++
    --- User ---
    [MBR] fc787b9d7d264279fe8511bf3af62390
    [BSP] c98760a201ec12c568c80400410b26dd : Windows XP MBR Code
    Partition table:
    User = LL1 ... OK
    User = LL2 ... OK

    +++++ PhysicalDrive1: +++++
    --- User ---
    [MBR] 69b7af525275156391a46f4aee9df87e
    [BSP] e65693e98266560cd9a3c59f3f9e91d4 : HP MBR Code
    Partition table:
    User = LL1 ... OK
    User = LL2 ... OK


    ============================================
    RKreport_SCN_04182015_230534.log
     
  6. Guymarshall

    Guymarshall TS Rookie Topic Starter

    ... and ADW + JRT

    # AdwCleaner v4.201 - Logfile created 18/04/2015 at 23:46:59
    # Updated 08/04/2015 by Xplode
    # Database : 2015-04-18.3 [Server]
    # Operating system : Windows 7 Home Premium (x64)
    # Username : guy - GUY-PC
    # Running from : C:\Users\guy\Desktop\adwcleaner_4.201.exe
    # Option : Cleaning

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    [!] Folder Deleted : C:\ProgramData\Partner
    [!] Folder Deleted : C:\ProgramData\MailUpdate
    [!] Folder Deleted : C:\Program Files (x86)\globalUpdate
    [!] Folder Deleted : C:\Program Files (x86)\Check Point Software Technologies LTD
    [!] Folder Deleted : C:\Program Files (x86)\STab
    [!] Folder Deleted : C:\Users\guy\AppData\Local\globalUpdate
    [!] Folder Deleted : C:\Users\guy\AppData\LocalLow\Check Point Software Technologies LTD
    [!] Folder Deleted : C:\Users\guy\AppData\Roaming\Systweak
    [!] Folder Deleted : C:\Users\guy\AppData\Roaming\MailUpdate
    [!] Folder Deleted : C:\Users\guy\AppData\Roaming\Check Point Software Technologies LTD
    File Deleted : C:\Windows\System32\roboot64.exe
    File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\v9.xml
    File Deleted : C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\user.js

    ***** [ Scheduled tasks ] *****

    Task Deleted : ASP

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
    Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool
    Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
    Key Deleted : HKLM\SOFTWARE\bb0a1f47-2cd8-43fc-8ebc-6eac68c5fbc6
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{987D9269-F8A1-408F-BF62-4397D2F5363E}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0722BEB-FDA1-4AA1-A2A8-15A74A5B3F70}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F1963E76-845B-474C-8C7F-D69A96D8AA34}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611081104}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622082204}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655085504}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666086604}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E00DE9B9-B128-4C39-B732-B5D85013FA48}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644084404}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611081104}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110611081104}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}]
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611081104}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622082204}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655085504}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666086604}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
    Key Deleted : HKCU\Software\GlobalUpdate
    Key Deleted : HKCU\Software\InstalledBrowserExtensions
    Key Deleted : HKCU\Software\Softonic
    Key Deleted : HKCU\Software\systweak
    Key Deleted : HKCU\Software\Tune
    Key Deleted : HKCU\Software\EnterDigital
    Key Deleted : HKLM\SOFTWARE\GlobalUpdate
    Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
    Key Deleted : HKLM\SOFTWARE\SupDp
    Key Deleted : HKLM\SOFTWARE\systweak
    Key Deleted : HKLM\SOFTWARE\Tune
    Key Deleted : HKLM\SOFTWARE\V9Software
    Key Deleted : HKLM\SOFTWARE\EnterDigital
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
    Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions

    ***** [ Web browsers ] *****

    -\\ Internet Explorer v8.0.7600.16385

    Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
    Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
    Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
    Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
    Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
    Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
    Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

    -\\ Mozilla Firefox v37.0.1 (x86 en-GB)

    [pd6b8t9h.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.v9.com/?type=hppp&ts=1415651552&from=cor&uid=SAMSUNGXHD103SJ_S246JD2ZB03737&I=psd&t=34bcb48c5 /verysilent /hideuninstall");

    -\\ Google Chrome v


    *************************

    AdwCleaner[R0].txt - [10598 bytes] - [18/04/2015 23:44:12]
    AdwCleaner[S0].txt - [9364 bytes] - [18/04/2015 23:46:59]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9423 bytes] ##########


    JRT

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.5.8 (04.17.2015:1)
    OS: Windows 7 Home Premium x64
    Ran by guy on 18/04/2015 at 23:54:27.82
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Tasks



    ~~~ Registry Values



    ~~~ Registry Keys



    ~~~ Files



    ~~~ Folders





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 18/04/2015 at 23:59:45.85
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


    How's it looking? and thanks again.

    Guy
     
  7. Broni

    Broni Malware Annihilator Posts: 52,890   +344

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Very Important! Temporarily disable your anti-virus and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
      If the connection is not there use restore point you created prior to running Combofix.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error Illegal operation attempted on a registery key that has been marked for deletion, restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Windows Vista, 7 or 8 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
     
  8. Guymarshall

    Guymarshall TS Rookie Topic Starter

    Thanks Broni, again, no problems running Combofix - log below..

    ComboFix 15-04-19.01 - guy 22/04/2015 9:17.1.4 - x64
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.4095.2230 [GMT 1:00]
    Running from: c:\users\guy\Desktop\ComboFix.exe
    AV: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
    FW: ZoneAlarm Free Firewall Firewall *Enabled* {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
    SP: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\program files (x86)\Common Files\packardbell.ico
    c:\users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\EnterDigital_iels
    .
    .
    ((((((((((((((((((((((((( Files Created from 2015-03-22 to 2015-04-22 )))))))))))))))))))))))))))))))
    .
    .
    2015-04-22 08:24 . 2015-04-22 08:24 -------- d-----w- c:\users\Default\AppData\Local\temp
    2015-04-18 22:54 . 2015-04-18 22:54 -------- d-----w- C:\RegBackup
    2015-04-18 22:43 . 2015-04-18 22:47 -------- d-----w- C:\AdwCleaner
    2015-04-18 22:12 . 2015-04-21 17:24 136408 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
    2015-04-18 22:11 . 2015-04-18 22:11 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
    2015-04-18 22:11 . 2015-04-18 22:11 -------- d-----w- c:\programdata\Malwarebytes
    2015-04-18 22:11 . 2015-03-17 05:15 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
    2015-04-18 22:11 . 2015-03-17 05:15 107736 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
    2015-04-18 22:11 . 2015-03-17 05:15 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
    2015-04-18 22:01 . 2015-04-18 22:01 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
    2015-04-18 22:00 . 2015-04-18 22:10 -------- d-----w- c:\programdata\RogueKiller
    2015-04-16 15:27 . 2015-04-16 15:28 -------- d-----w- C:\FRST
    2015-04-08 14:56 . 2015-04-08 16:19 -------- d-----w- c:\users\guy\AppData\Roaming\NCH Software
    2015-04-08 14:56 . 2015-04-08 14:56 -------- d-----w- c:\program files (x86)\NCH Software
    2015-04-08 14:56 . 2015-04-08 14:56 -------- d-----w- c:\programdata\NCH Software
    2015-04-08 12:26 . 2015-04-08 23:03 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
    2015-04-02 10:31 . 2015-04-02 10:33 -------- d--h--w- c:\programdata\CanonIJMIG
    2015-04-02 10:27 . 2015-04-02 10:30 -------- d--h--w- c:\programdata\CanonIJScan
    2015-03-25 10:21 . 2015-03-25 10:21 281056 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2015-04-15 11:44 . 2014-10-12 12:54 778416 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2015-04-15 11:44 . 2014-10-12 12:54 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2015-02-25 17:37 . 2015-02-25 17:37 284128 ----a-w- c:\windows\system32\drivers\avgtdia.sys
    2015-02-05 10:27 . 2015-02-05 10:27 133088 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
    2015-02-03 10:47 . 2015-02-03 10:47 341472 ----a-w- c:\windows\system32\drivers\avgloga.sys
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
    "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" [2009-08-21 262912]
    "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-11-01 1094736]
    "DiscWizardMonitor.exe"="c:\program files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe" [2013-10-30 6382504]
    "AcronisTibMounterMonitor"="c:\program files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe" [2013-01-10 1103424]
    "EaseUS EPM tray"="c:\program files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\EpmNews.exe" [2014-03-06 2086568]
    "EaseUS EPM Tray Agent"="c:\program files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\TrayTipAgentE.exe" [2014-02-13 254024]
    "ZoneAlarm"="c:\program files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2014-08-13 137352]
    "AVG_UI"="c:\program files (x86)\AVG\AVG2015\avgui.exe" [2015-03-25 3723728]
    "CanonQuickMenu"="c:\program files (x86)\Canon\Quick Menu\CNQMMAIN.EXE" [2012-04-03 1273448]
    "IJNetworkScannerSelectorEX"="c:\program files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2012-03-26 449168]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.150\SSScheduler.exe [2014-4-9 332016]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    "EnableLinkedConnections"= 1 (0x1)
    .
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2015\avgidsagent.exe;c:\program files (x86)\AVG\AVG2015\avgidsagent.exe [x]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
    R3 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [x]
    R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys;c:\windows\SYSNATIVE\epmntdrv.sys [x]
    R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys;c:\windows\SYSNATIVE\EuGdiDrv.sys [x]
    R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
    R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe [x]
    R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
    R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
    R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
    R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
    R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
    S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
    S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
    S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
    S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
    S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys;c:\windows\SYSNATIVE\DRIVERS\fltsrv.sys [x]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
    S0 tib;Acronis TIB Manager;c:\windows\system32\DRIVERS\tib.sys;c:\windows\SYSNATIVE\DRIVERS\tib.sys [x]
    S0 tib_mounter;Acronis TIB Mounter;c:\windows\system32\DRIVERS\tib_mounter.sys;c:\windows\SYSNATIVE\DRIVERS\tib_mounter.sys [x]
    S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys;c:\windows\SYSNATIVE\DRIVERS\vididr.sys [x]
    S0 vidsflt;Acronis Disk Storage Filter;c:\windows\system32\DRIVERS\vidsflt.sys;c:\windows\SYSNATIVE\DRIVERS\vidsflt.sys [x]
    S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
    S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
    S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
    S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
    S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2015\avgwdsvc.exe;c:\program files (x86)\AVG\AVG2015\avgwdsvc.exe [x]
    S2 ePowerSvc;Acer ePower Service;c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe;c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [x]
    S2 Greg_Service;GRegService;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe [x]
    S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
    S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [x]
    S2 OberonGameConsoleService;Oberon Media Game Console service;c:\program files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe;c:\program files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe [x]
    S2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [x]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
    S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [x]
    S2 ZAPrivacyService;ZoneAlarm Privacy Service;c:\program files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe;c:\program files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [x]
    S3 cmudaxp;ASUS Xonar DS Audio Interface;c:\windows\system32\drivers\cmudaxp.sys;c:\windows\SYSNATIVE\drivers\cmudaxp.sys [x]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
    S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
    S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
    S3 RDID1115;UM-ONE;c:\windows\system32\Drivers\rdwm1115.sys;c:\windows\SYSNATIVE\Drivers\rdwm1115.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - MBAMSWISSARMY
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2015-04-22 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-12 11:44]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Acer ePower Management"="c:\program files\Packard Bell\Packard Bell Power Management\ePowerTray.exe" [2009-09-30 823840]
    "Seagate Scheduler2 Service"="c:\program files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe" [2013-10-30 400376]
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com
    uLocal Page = c:\windows\system32\blank.htm
    mDefault_Search_URL = www.google.com
    mDefault_Page_URL = hxxp://www.google.com
    mStart Page = hxxp://www.google.com
    mLocal Page = c:\windows\SysWOW64\blank.htm
    mSearch Page = www.google.com
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
    TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
    FF - ProfilePath - c:\users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default\
    FF - prefs.js: browser.search.selectedEngine - v9
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
    Toolbar-Locked - (no file)
    AddRemove-Free FLV Converter - c:\program files (x86)\Free FLV Converter\uninstall.exe
    AddRemove-zonealarm - c:\users\guy\AppData\Roaming\Check Point Software Technologies LTD\zonealarm\1.8.29.17\uninstall.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_169_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_169_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker6"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_169_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_169_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_169.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.17"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_169.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_169.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_169.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker6"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2015-04-22 09:26:43
    ComboFix-quarantined-files.txt 2015-04-22 08:26
    .
    Pre-Run: 46,539,804,672 bytes free
    Post-Run: 47,382,196,224 bytes free
    .
    - - End Of File - - 2DF7DDE7BA8EEA6F346083CEAB3FC44A
    8F558EB6672622401DA993E1E865C861
     
  9. Broni

    Broni Malware Annihilator Posts: 52,890   +344

    Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.

    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Make sure you checkmark Addition.txt box.
    • Press Scan button.
    • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.
     
  10. Guymarshall

    Guymarshall TS Rookie Topic Starter

    Thanks, logs from FRST below....

    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2015 01
    Ran by guy (administrator) on GUY-PC on 23-04-2015 14:53:04
    Running from C:\Users\guy\Desktop
    Loaded Profiles: guy (Available profiles: guy)
    Platform: Windows 7 Home Premium (X64) OS Language: English (United States)
    Internet Explorer Version 8 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
    (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
    (Seagate) C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
    (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
    (Acer Incorporated) C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgscanx.exe
    (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
    (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    () C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
    (Seagate) C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (Acer) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
    (Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
    (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
    (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
    (Seagate) C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
    (Acronis) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
    (CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\EpmNews.exe
    () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\TrayTipAgentE.exe
    (Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
    (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [823840 2009-09-30] (Acer Incorporated)
    HKLM\...\Run: [Seagate Scheduler2 Service] => C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe [400376 2013-10-30] (Seagate)
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe [262912 2009-08-21] (NewTech Infosystems, Inc.)
    HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1094736 2009-11-02] (Dritek System Inc.)
    HKLM-x32\...\Run: [DiscWizardMonitor.exe] => C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe [6382504 2013-10-30] (Seagate)
    HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1103424 2013-01-10] (Acronis)
    HKLM-x32\...\Run: [EaseUS EPM tray] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\EpmNews.exe [2086568 2014-03-06] (CHENGDU YIWO Tech Development Co., Ltd)
    HKLM-x32\...\Run: [EaseUS EPM Tray Agent] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\TrayTipAgentE.exe [254024 2014-02-13] ()
    HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [137352 2014-08-13] (Check Point Software Technologies Ltd.)
    HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3723728 2015-03-25] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.)
    HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.)
    HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> c:\windows\system32\PACKAR~1.SCR [413696 2009-01-22] (Acer)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-02-09]
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
    HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?source...nputEncoding}&oe={outputEncoding}&rlz=1I7ACPW
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-1673714354-1666257763-1680629560-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?source...ding}&oe={outputEncoding}&rlz=1I7ACPW_enGB609
    BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
    BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
    BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated)
    BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
    BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
    BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
    Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
    Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
    Toolbar: HKU\S-1-5-21-1673714354-1666257763-1680629560-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    Toolbar: HKU\S-1-5-21-1673714354-1666257763-1680629560-1000 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
    Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
    Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
    Tcpip\Parameters: [DhcpNameServer] 194.168.4.100 194.168.8.100

    FireFox:
    ========
    FF ProfilePath: C:\Users\guy\AppData\Roaming\Mozilla\Firefox\Profiles\pd6b8t9h.default
    FF SelectedSearchEngine: v9
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
    FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
    FF HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
    FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3416016 2015-03-25] (AVG Technologies CZ, s.r.o.)
    R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [309232 2015-03-25] (AVG Technologies CZ, s.r.o.)
    R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [844320 2009-09-30] (Acer Incorporated)
    S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2014-10-07] (Macrovision Europe Ltd.) [File not signed]
    R2 Greg_Service; C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe [1150496 2009-08-28] (Acer Incorporated)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
    R2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [62720 2009-08-21] (NewTech Infosystems, Inc.)
    R2 OberonGameConsoleService; C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe [44312 2009-08-29] ()
    R2 Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [240160 2009-07-04] (Acer)
    R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [3596752 2014-08-13] (Check Point Software Technologies Ltd.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
    R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [96272 2014-08-13] (Check Point Software Technologies, Ltd.)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [281056 2015-03-25] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [203544 2014-11-18] (AVG Technologies CZ, s.r.o.)
    R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
    R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [341472 2015-02-03] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [133088 2015-02-05] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
    R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [284128 2015-02-25] (AVG Technologies CZ, s.r.o.)
    R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [1442816 2009-03-24] (C-Media Inc)
    S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] () [File not signed]
    S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [13896 2013-03-07] () [File not signed]
    S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] () [File not signed]
    S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () [File not signed]
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-04-23] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
    R3 RDID1115; C:\Windows\System32\Drivers\rdwm1115.sys [81920 2010-09-17] (Roland Corporation)
    R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2014-10-22] (Acronis International GmbH)
    R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [183224 2014-10-22] (Acronis)
    U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-04-18] ()
    R0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [117024 2014-10-22] (Acronis International GmbH)
    R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [450456 2014-08-13] (Check Point Software Technologies Ltd.)
    S3 catchme; \??\C:\ComboFix\catchme.sys [X]
    S3 k57nd60a; system32\DRIVERS\k57nd60a.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-04-23 14:52 - 2015-04-23 14:52 - 00000000 ____D () C:\Users\guy\Desktop\FRST-OlderVersion
    2015-04-22 09:26 - 2015-04-22 09:26 - 00017898 _____ () C:\Users\guy\Desktop\ComboFix.txt
    2015-04-22 09:16 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
    2015-04-22 09:16 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
    2015-04-22 09:16 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
    2015-04-22 09:16 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
    2015-04-22 09:16 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
    2015-04-22 09:16 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
    2015-04-22 09:16 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
    2015-04-22 09:16 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
    2015-04-22 09:15 - 2015-04-22 09:26 - 00000000 ____D () C:\Qoobox
    2015-04-22 09:15 - 2015-04-22 09:25 - 00000000 ____D () C:\Windows\erdnt
    2015-04-22 09:09 - 2015-04-22 09:09 - 05619466 ____R (Swearware) C:\Users\guy\Desktop\ComboFix.exe
    2015-04-19 03:09 - 2015-04-19 03:09 - 00000359 _____ () C:\Users\guy\Desktop\Recycle Bin - Shortcut.lnk
    2015-04-18 23:59 - 2015-04-18 23:59 - 00000598 _____ () C:\Users\guy\Desktop\JRT.txt
    2015-04-18 23:54 - 2015-04-18 23:54 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-GUY-PC-Windows-7-Home-Premium-(64-bit).dat
    2015-04-18 23:54 - 2015-04-18 23:54 - 00000000 ____D () C:\RegBackup
    2015-04-18 23:52 - 2015-04-18 23:53 - 02686254 _____ (Thisisu) C:\Users\guy\Desktop\JRT.exe
    2015-04-18 23:49 - 2015-04-18 23:49 - 00009535 _____ () C:\Users\guy\Desktop\AdwCleaner[S0].txt
    2015-04-18 23:43 - 2015-04-18 23:47 - 00000000 ____D () C:\AdwCleaner
    2015-04-18 23:35 - 2015-04-18 23:35 - 02217984 _____ () C:\Users\guy\Desktop\adwcleaner_4.201.exe
    2015-04-18 23:12 - 2015-04-23 13:59 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-04-18 23:11 - 2015-04-22 16:39 - 00001112 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-04-18 23:11 - 2015-04-22 16:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-04-18 23:11 - 2015-04-22 16:39 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-04-18 23:11 - 2015-04-18 23:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2015-04-18 23:11 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2015-04-18 23:11 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2015-04-18 23:11 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2015-04-18 23:09 - 2015-04-18 23:09 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\guy\Desktop\mbam-setup-2.1.4.1018.exe
    2015-04-18 23:08 - 2015-04-18 23:08 - 00003987 _____ () C:\Users\guy\Desktop\RKreport_DEL_04182015_230655.log
    2015-04-18 23:01 - 2015-04-18 23:01 - 00035064 _____ () C:\Windows\system32\Drivers\TrueSight.sys
    2015-04-18 23:00 - 2015-04-18 23:10 - 00000000 ____D () C:\ProgramData\RogueKiller
    2015-04-18 22:55 - 2015-04-18 22:55 - 16866392 _____ () C:\Users\guy\Desktop\RogueKiller.exe
    2015-04-16 16:28 - 2015-04-16 16:29 - 00027421 _____ () C:\Users\guy\Desktop\Addition.txt
    2015-04-16 16:27 - 2015-04-23 14:53 - 00016524 _____ () C:\Users\guy\Desktop\FRST.txt
    2015-04-16 16:27 - 2015-04-23 14:53 - 00000000 ____D () C:\FRST
    2015-04-16 16:25 - 2015-04-23 14:52 - 02099712 _____ (Farbar) C:\Users\guy\Desktop\FRST64.exe
    2015-04-16 16:21 - 2015-04-16 16:21 - 05481336 _____ (Avast Software s.r.o.) C:\Users\guy\Downloads\avast_free_antivirus_setup_online_cnet.exe
    2015-04-13 18:15 - 2015-04-13 18:15 - 00243320 _____ () C:\Users\guy\Downloads\Firefox Setup Stub 37.0.1.exe
    2015-04-13 18:15 - 2015-04-13 18:15 - 00001169 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    2015-04-13 18:15 - 2015-04-13 18:15 - 00001157 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
    2015-04-13 18:15 - 2015-04-13 18:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    2015-04-08 17:10 - 2015-04-08 17:10 - 00000000 ____D () C:\Users\guy\Documents\VideoPad Projects
    2015-04-08 15:56 - 2015-04-08 17:46 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
    2015-04-08 15:56 - 2015-04-08 17:19 - 00000000 ____D () C:\Users\guy\AppData\Roaming\NCH Software
    2015-04-08 15:56 - 2015-04-08 15:56 - 00001296 _____ () C:\Users\Public\Desktop\NCH Suite.lnk
    2015-04-08 15:56 - 2015-04-08 15:56 - 00001156 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
    2015-04-08 15:56 - 2015-04-08 15:56 - 00001144 _____ () C:\Users\Public\Desktop\VideoPad Video Editor.lnk
    2015-04-08 15:56 - 2015-04-08 15:56 - 00000000 ____D () C:\ProgramData\NCH Software
    2015-04-08 15:56 - 2015-04-08 15:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
    2015-04-08 15:56 - 2015-04-08 15:56 - 00000000 ____D () C:\Program Files (x86)\NCH Software
    2015-04-08 15:54 - 2015-04-08 15:54 - 04910136 _____ (NCH Software) C:\Users\guy\Downloads\vpsetup.exe
    2015-04-08 13:26 - 2015-04-09 00:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
    2015-04-02 11:31 - 2015-04-02 11:33 - 00000000 ___HD () C:\ProgramData\CanonIJMIG
    2015-04-02 11:27 - 2015-04-02 11:30 - 00000000 ___HD () C:\ProgramData\CanonIJScan
    2015-03-25 11:21 - 2015-03-25 11:21 - 00281056 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-04-23 14:44 - 2014-10-12 13:54 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-04-23 14:31 - 2014-10-07 08:41 - 01340962 _____ () C:\Windows\WindowsUpdate.log
    2015-04-23 14:06 - 2009-07-14 05:45 - 00026992 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-04-23 14:06 - 2009-07-14 05:45 - 00026992 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-04-23 14:03 - 2010-10-15 19:04 - 00000000 ____D () C:\ProgramData\MFAData
    2015-04-23 13:58 - 2014-10-11 18:53 - 00000000 ____D () C:\ProgramData\NVIDIA
    2015-04-23 13:58 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2015-04-23 13:58 - 2009-07-14 05:51 - 00054029 _____ () C:\Windows\setupact.log
    2015-04-22 16:38 - 2009-10-30 02:08 - 00219104 _____ () C:\Windows\PFRO.log
    2015-04-22 12:47 - 2014-11-11 23:49 - 00000000 ___HD () C:\Users\guy\Documents\Attachments
    2015-04-22 09:26 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
    2015-04-22 09:24 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
    2015-04-18 23:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Vss
    2015-04-15 12:44 - 2014-10-12 13:54 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-04-15 12:44 - 2014-10-12 13:54 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-04-15 12:44 - 2014-10-12 13:54 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2015-04-15 10:05 - 2014-11-10 21:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2015-04-07 00:59 - 2014-11-10 15:36 - 00000000 ____D () C:\Program Files (x86)\e8dd412c-2343-4a8c-b721-2345b83b3e2c
    2015-04-07 00:42 - 2014-11-10 21:40 - 00000000 ____D () C:\Users\guy\AppData\Local\Avg2015
    2015-04-02 14:41 - 2014-11-10 21:42 - 00000000 ____D () C:\ProgramData\AVG2015
    2015-04-02 11:30 - 2014-11-16 17:08 - 00000000 ____D () C:\Users\guy\AppData\Roaming\Canon
    2015-04-01 14:30 - 2014-11-10 21:42 - 00000977 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
    2015-04-01 14:30 - 2013-12-11 17:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    2015-03-29 23:25 - 2009-07-14 06:13 - 00726316 _____ () C:\Windows\system32\PerfStringBackup.INI
    2015-03-28 23:38 - 2014-10-12 23:08 - 00001225 _____ () C:\Users\guy\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
    2015-03-28 23:38 - 2014-10-12 23:08 - 00001201 _____ () C:\Users\Public\Desktop\GOM Player.lnk

    ==================== Files in the root of some directories =======

    2009-10-30 05:26 - 2009-08-24 13:06 - 0131368 _____ () C:\ProgramData\FullRemove.exe
    2010-09-12 15:40 - 2014-05-03 11:20 - 0000020 ____H () C:\ProgramData\PKP_DLec.DAT

    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-04-15 13:12

    ==================== End Of Log ============================
     
  11. Guymarshall

    Guymarshall TS Rookie Topic Starter

    And "addition" ...

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2015 01
    Ran by guy at 2015-04-23 14:53:43
    Running from C:\Users\guy\Desktop
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
    FW: ZoneAlarm Free Firewall Firewall (Enabled) {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
    Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
    Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
    Adobe Photoshop Elements 7.0 (HKLM-x32\...\Adobe Photoshop Elements 7) (Version: 7.0.1 - Adobe Systems Incorporated)
    Adobe Reader 9.1 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.1.0 - Adobe Systems Incorporated)
    Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
    Alice Greenfingers (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}) (Version: - Oberon Media)
    Amazonia (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}) (Version: - Oberon Media)
    AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5863 - AVG Technologies)
    AVG 2015 (Version: 15.0.4334 - AVG Technologies) Hidden
    AVG 2015 (Version: 15.0.5863 - AVG Technologies) Hidden
    Backup Manager Basic (x32 Version: 2.0.0.22 - NewTech Infosystems) Hidden
    Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.5.0.0 - Canon Inc.)
    Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - ‪Canon Inc.‬)
    Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.0 - Canon Inc.)
    Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - ‪Canon Inc.‬)
    Canon MG4200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG4200_series) (Version: 1.01 - Canon Inc.)
    Canon MG4200 series On-screen Manual (HKLM-x32\...\Canon MG4200 series On-screen Manual) (Version: 7.5.0 - Canon Inc.)
    Canon MG4200 series User Registration (HKLM-x32\...\Canon MG4200 series User Registration) (Version: - Canon Inc.‎)
    Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 1.1.2 - Canon Inc.)
    Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 1.0.1 - Canon Inc.)
    Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.)
    Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.0.0 - Canon Inc.)
    Chicken Invaders 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}) (Version: - Oberon Media)
    Dairy Dash (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}) (Version: - Oberon Media)
    Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
    EaseUS Partition Master 10.1 (HKLM-x32\...\EaseUS Partition Master_is1) (Version: - EaseUS)
    Farm Frenzy 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}) (Version: - Oberon Media)
    FastImageResizer (remove only) (HKLM-x32\...\FastImageResizer) (Version: - )
    First Class Flurry (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115208410}) (Version: - Oberon Media)
    Forté Agent (HKLM-x32\...\Forte Agent) (Version: 7.00 - Forté Internet Software, Inc.)
    GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.69.5227 - Gretech Corporation)
    Granny In Paradise (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}) (Version: - Oberon Media)
    Heroes of Hellas (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}) (Version: - Oberon Media)
    Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3002 - Packard Bell)
    ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
    Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
    Launch Manager (HKLM-x32\...\LManager) (Version: 3.0.04 - Packard Bell)
    Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
    McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
    Merriam Websters Spell Jam (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}) (Version: - Oberon Media)
    Metaboli (HKLM-x32\...\Metaboli) (Version: 1.00.0006 - Packard Bell)
    Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
    Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Mozilla Firefox 37.0.1 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 37.0.1 (x86 en-GB)) (Version: 37.0.1 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 37.0.1 - Mozilla)
    Mozilla Thunderbird 31.6.0 (x86 en-GB) (HKLM-x32\...\Mozilla Thunderbird 31.6.0 (x86 en-GB)) (Version: 31.6.0 - Mozilla)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    Nero 9 Essentials (HKLM-x32\...\{a4584eb1-2889-4dcf-abed-da4f9f6996a3}) (Version: - Nero AG)
    NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.9 - NVIDIA Corporation)
    NVIDIA Stereoscopic 3D Driver (HKLM-x32\...\NVIDIAStereo) (Version: 7.16.11.9107 - NVIDIA Corporation)
    OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
    Packard Bell GameZone Console (HKLM-x32\...\{117E3AE2-10D1-41C1-9FA6-F4C382F767A8}_is1) (Version: 5.1.2.5 - Oberon Media, Inc.)
    Packard Bell InfoCentre (HKLM-x32\...\Packard Bell InfoCentre) (Version: 3.02.3000 - Packard Bell)
    Packard Bell MyBackup (HKLM-x32\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.22 - NewTech Infosystems)
    Packard Bell Power Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.05.3004 - Packard Bell)
    Packard Bell Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Packard Bell)
    Packard Bell Registration (HKLM-x32\...\Packard Bell Registration) (Version: 1.02.3006 - Packard Bell)
    PackardBell ScreenSaver (HKLM-x32\...\PackardBell Screensaver) (Version: 1.0.1.0302 - PackardBell)
    QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements)
    Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30104 - Realtek Semiconductor Corp.)
    Seagate DiscWizard (HKLM-x32\...\{AC5BFE42-B72A-467C-B9B2-8BF77C6D4D70}) (Version: 16.0.5840 - Seagate)
    Steinberg Cubase SX v2.2.0.35 (HKLM-x32\...\Steinberg Cubase SX v2.2.0.35) (Version: - )
    Theorica Divx ;-) Codecs (remove only) (HKLM-x32\...\Theorica Divx ;-) Codecs) (Version: 3.0 - )
    UM-ONE Driver (HKLM\...\RolandRDID0115) (Version: - Roland Corporation)
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 4.00 - NCH Software)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Welcome Center (HKLM-x32\...\Packard Bell Welcome Center) (Version: 1.00.3009 - Packard Bell)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
    Windows Live Sign-in Assistant (HKLM-x32\...\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
    Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
    Windows Live Upload Tool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
    WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - )
    ZoneAlarm Firewall (x32 Version: 13.3.209.000 - Check Point Software Technologies Ltd.) Hidden
    ZoneAlarm Free Firewall (HKLM-x32\...\ZoneAlarm Free Firewall) (Version: 13.3.209.000 - Check Point)
    ZoneAlarm Security (x32 Version: 13.3.209.000 - Check Point Software Technologies Ltd.) Hidden
    ZoneAlarm Security Toolbar (HKLM-x32\...\zonealarm) (Version: 1.8.29.17 - Check Point Software Technologies LTD)

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


    ==================== Restore Points =========================


    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 03:34 - 2015-04-22 09:24 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
    127.0.0.1 localhost

    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {64E8BB91-F3B2-4BC0-99F1-DA7C631AAEB8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    ==================== Loaded Modules (whitelisted) ==============

    2009-10-30 05:33 - 2009-08-29 01:05 - 00044312 _____ () C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe
    2014-11-10 15:29 - 2014-02-13 16:37 - 00254024 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\TrayTipAgentE.exe
    2009-02-03 01:33 - 2009-02-03 01:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
    2008-09-29 01:55 - 2008-09-29 01:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\ACE.dll
    2014-11-10 15:29 - 2014-02-13 16:27 - 00222792 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\traynet.dll
    2014-11-10 15:29 - 2014-02-13 16:27 - 00275528 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\libcurl.dll
    2014-11-10 15:29 - 2014-02-13 16:27 - 00113166 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\zlib1.dll
    2014-11-10 15:29 - 2014-02-13 16:27 - 00249928 _____ () C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\TrayPopupE\uexper.dll
    2015-04-08 13:26 - 2015-04-08 13:26 - 03348592 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
    2015-04-08 13:26 - 2015-04-08 13:26 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
    2015-04-08 13:26 - 2015-04-08 13:26 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

    AlternateDataStreams: C:\ProgramData\Temp:0B9176C0
    AlternateDataStreams: C:\ProgramData\Temp:93DE1838
    AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE

    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"

    ==================== EXE Association (whitelisted) ===============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, the associated entry will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\guy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 194.168.4.100 - 194.168.8.100

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== Accounts: =============================

    Administrator (S-1-5-21-1673714354-1666257763-1680629560-500 - Administrator - Disabled)
    Guest (S-1-5-21-1673714354-1666257763-1680629560-501 - Limited - Disabled)
    guy (S-1-5-21-1673714354-1666257763-1680629560-1000 - Administrator - Enabled) => C:\Users\guy

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (04/23/2015 02:51:12 PM) (Source: SideBySide) (EventID: 35) (User: )
    Description: Activation context generation failed for "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1".Error in manifest or policy file "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" on line WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
    Component identity found in manifest does not match the identity of the component requested.
    Reference is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
    Definition is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/23/2015 02:36:47 PM) (Source: SideBySide) (EventID: 35) (User: )
    Description: Activation context generation failed for "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1".Error in manifest or policy file "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" on line WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
    Component identity found in manifest does not match the identity of the component requested.
    Reference is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
    Definition is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/23/2015 02:33:36 PM) (Source: SideBySide) (EventID: 63) (User: )
    Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
    The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

    Error: (04/23/2015 02:31:54 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1272) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/23/2015 02:31:54 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1272) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/23/2015 02:31:54 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1272) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/23/2015 02:31:54 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1272) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/23/2015 02:01:56 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1272) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/23/2015 02:01:56 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1272) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.

    Error: (04/23/2015 02:01:56 PM) (Source: ESENT) (EventID: 412) (User: )
    Description: wuaueng.dll (1272) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546.


    System errors:
    =============
    Error: (04/23/2015 02:45:06 PM) (Source: volsnap) (EventID: 36) (User: )
    Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.

    Error: (04/22/2015 06:17:02 PM) (Source: Service Control Manager) (EventID: 7016) (User: )
    Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

    Error: (04/22/2015 02:29:18 PM) (Source: Service Control Manager) (EventID: 7016) (User: )
    Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

    Error: (04/22/2015 09:24:19 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (04/22/2015 09:23:39 AM) (Source: Application Popup) (EventID: 1060) (User: )
    Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

    Error: (04/22/2015 09:21:02 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (04/21/2015 11:18:46 AM) (Source: Service Control Manager) (EventID: 7016) (User: )
    Description: The NVIDIA Display Driver Service service has reported an invalid current state 32.

    Error: (04/18/2015 11:55:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Software Protection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

    Error: (04/18/2015 11:55:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

    Error: (04/18/2015 11:55:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The ZoneAlarm Privacy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.


    Microsoft Office Sessions:
    =========================

    CodeIntegrity Errors:
    ===================================
    Date: 2015-04-22 09:23:39.694
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume6\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-04-22 09:23:39.683
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume6\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-04-08 14:43:37.097
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume6\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPI64.dll because the set of per-page image hashes could not be found on the system.

    Date: 2014-11-15 17:40:08.771
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume11\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPI64.dll because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    Processor: AMD Athlon(tm) II X4 640 Processor
    Percentage of memory in use: 41%
    Total physical RAM: 4095.3 MB
    Available physical RAM: 2411.87 MB
    Total Pagefile: 8188.75 MB
    Available Pagefile: 6150.49 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.83 MB

    ==================== Drives ================================

    Drive c: (system) (Fixed) (Total:302.7 GB) (Free:45.02 GB) NTFS
    Drive e: (New 2) (Fixed) (Total:302.95 GB) (Free:297.89 GB) NTFS
    Drive f: (New 3) (Fixed) (Total:314.04 GB) (Free:312.15 GB) NTFS
    Drive r: (Old hD 1) (Fixed) (Total:307.62 GB) (Free:222.47 GB) NTFS
    Drive s: (Old HD2) (Fixed) (Total:307.62 GB) (Free:292.67 GB) NTFS
    Drive t: (Old HD 3) (Fixed) (Total:316.27 GB) (Free:215.27 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 220A2209)
    Partition 1: (Active) - (Size=307.6 GB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=623.9 GB) - (Type=OF Extended)

    ========================================================
    Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 6F23EF61)
    Partition 1: (Not Active) - (Size=11.7 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=302.7 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=617 GB) - (Type=OF Extended)

    ==================== End Of Log ============================
     
  12. Broni

    Broni Malware Annihilator Posts: 52,890   +344

    [​IMG] Uninstall McAfee Security Scan, typical foistware.

    [​IMG]
    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
     

    Attached Files:

  13. Guymarshall

    Guymarshall TS Rookie Topic Starter

    Thanks once again, OK, done that - didn't mention before that the browser seems free of unwanted / expected ads.

    fixlog below:

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 27-04-2015
    Ran by guy at 2015-04-27 12:32:04 Run:1
    Running from C:\Users\guy\Desktop
    Loaded Profiles: guy & (Available profiles: guy)
    Boot Mode: Normal
    ==============================================

    Content of fixlist:
    *****************
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
    Toolbar: HKU\S-1-5-21-1673714354-1666257763-1680629560-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    FF SelectedSearchEngine: v9
    S3 catchme; \??\C:\ComboFix\catchme.sys [X]
    S3 k57nd60a; system32\DRIVERS\k57nd60a.sys [X]
    2009-10-30 05:26 - 2009-08-24 13:06 - 0131368 _____ () C:\ProgramData\FullRemove.exe
    2010-09-12 15:40 - 2014-05-03 11:20 - 0000020 ____H () C:\ProgramData\PKP_DLec.DAT
    AlternateDataStreams: C:\ProgramData\Temp:0B9176C0
    AlternateDataStreams: C:\ProgramData\Temp:93DE1838
    AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE

    *****************

    "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
    "HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
    "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}" => Key deleted successfully.
    HKCR\Wow6432Node\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key not found.
    HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully.
    HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
    Firefox SelectedSearchEngine deleted successfully.
    catchme => Service deleted successfully.
    k57nd60a => Service deleted successfully.
    C:\ProgramData\FullRemove.exe => Moved successfully.
    C:\ProgramData\PKP_DLec.DAT => Moved successfully.
    C:\ProgramData\Temp => ":0B9176C0" ADS removed successfully.
    C:\ProgramData\Temp => ":93DE1838" ADS removed successfully.
    C:\ProgramData\Temp => ":ABE89FFE" ADS removed successfully.

    ==== End of Fixlog 12:32:05 ====
     
  14. Broni

    Broni Malware Annihilator Posts: 52,890   +344

    Good news :)

    Last scans...

    [​IMG] Download Security Check from here or here and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
    NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


    [​IMG] Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
      • Other Services
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    [​IMG] Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    [​IMG] Download Sophos Free Virus Removal Tool and save it to your desktop.
    • Double click the icon and select Run
    • Click Next
    • Select I accept the terms in this license agreement, then click Next twice
    • Click Install
    • Click Finish to launch the program
    • Once the virus database has been updated click Start Scanning
    • If any threats are found click Details, then View log file... (bottom left hand corner)
    • Copy and paste the results in your reply
    • Close the Notepad document, close the Threat Details screen, then click Start cleanup
    • Click Exit to close the program
     
  15. Guymarshall

    Guymarshall TS Rookie Topic Starter

    Thanks, latest logs to follow - all looking good

    Results of screen317's Security Check version 1.00
    Windows 7 x64 (UAC is enabled)
    Out of date service pack!!
    ``````````````Antivirus/Firewall Check:``````````````

    Windows Firewall Disabled!
    AVG AntiVirus Free Edition 2015
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Adobe Flash Player 17.0.0.169
    Adobe Reader 9 Adobe Reader out of Date!
    Mozilla Firefox (37.0.2)
    Mozilla Thunderbird (31.6.0)
    ````````Process Check: objlist.exe by Laurent````````
    Malwarebytes Anti-Malware mbamservice.exe
    Malwarebytes Anti-Malware mbam.exe
    AVG avgwdsvc.exe
    Malwarebytes Anti-Malware mbamscheduler.exe
    CheckPoint ZoneAlarm vsmon.exe
    CheckPoint ZoneAlarm ZaPrivacyService.exe
    CheckPoint ZoneAlarm zatray.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 1%
    ````````````````````End of Log``````````````````````

    and..

    Farbar Service Scanner Version: 17-01-2015
    Ran by guy (administrator) on 30-04-2015 at 16:35:01
    Running from "C:\Users\guy\Desktop"
    Microsoft Windows 7 Home Premium (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Attempt to access Google IP returned error. Google IP is unreachable
    Google.com is accessible.
    Attempt to access Yahoo.com returned error: Yahoo.com is unreachable


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall"=DWORD:0


    System Restore:
    ============

    System Restore Policy:
    ========================


    Action Center:
    ============


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============
    WinDefend Service is not running. Checking service configuration:
    The start type of WinDefend service is set to Demand. The default start type is Auto.
    The ImagePath of WinDefend service is OK.
    The ServiceDll of WinDefend service is OK.


    Windows Defender Disabled Policy:
    ==========================
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware"=DWORD:1


    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => File is digitally signed
    C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
    C:\Windows\System32\dhcpcore.dll => File is digitally signed
    C:\Windows\System32\drivers\afd.sys => File is digitally signed
    C:\Windows\System32\drivers\tdx.sys => File is digitally signed
    C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
    C:\Windows\System32\dnsrslvr.dll => File is digitally signed
    C:\Windows\System32\mpssvc.dll => File is digitally signed
    C:\Windows\System32\bfe.dll => File is digitally signed
    C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
    C:\Windows\System32\SDRSVC.dll => File is digitally signed
    C:\Windows\System32\vssvc.exe => File is digitally signed
    C:\Windows\System32\wscsvc.dll => File is digitally signed
    C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
    C:\Windows\System32\wuaueng.dll => File is digitally signed
    C:\Windows\System32\qmgr.dll => File is digitally signed
    C:\Windows\System32\es.dll => File is digitally signed
    C:\Windows\System32\cryptsvc.dll => File is digitally signed
    C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
    C:\Windows\System32\ipnathlp.dll => File is digitally signed
    C:\Windows\System32\iphlpsvc.dll => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed


    **** End of log ****

    finally....

    2015-04-30 15:45:03.864 Sophos Virus Removal Tool version 2.5.4
    2015-04-30 15:45:03.864 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

    2015-04-30 15:45:03.864 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

    2015-04-30 15:45:03.864 Windows version 6.1 SP 0.0 build 7600 SM=0x300 PT=0x1 WOW64
    2015-04-30 15:45:03.865 Checking for updates...
    2015-04-30 15:45:14.562 Option all = no
    2015-04-30 15:45:14.562 Option recurse = yes
    2015-04-30 15:45:14.562 Option archive = no
    2015-04-30 15:45:14.562 Option service = yes
    2015-04-30 15:45:14.562 Option confirm = yes
    2015-04-30 15:45:14.562 Option sxl = yes
    2015-04-30 15:45:14.563 Option max-data-age = 35
    2015-04-30 15:45:14.563 Option EnableSafeClean = yes
    2015-04-30 15:45:16.901 Option vdl-logging = yes
    2015-04-30 15:45:16.931 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
    2015-04-30 15:45:16.931 Machine ID: 8fef7cfffd6247a2b6c0893218a6ecd1
    2015-04-30 15:45:16.984 Component SVRTcli.exe version 2.5.4
    2015-04-30 15:45:16.984 Component control.dll version 2.5.4
    2015-04-30 15:45:16.984 Component SVRTservice.exe version 2.5.4
    2015-04-30 15:45:16.984 Component engine\osdp.dll version 1.44.1.2200
    2015-04-30 15:45:16.986 Component engine\veex.dll version 3.60.0.2200
    2015-04-30 15:45:16.986 Component engine\savi.dll version 8.1.7.2200
    2015-04-30 15:45:17.004 Component rkdisk.dll version 1.5.30.0
    2015-04-30 15:45:17.004 Version info: Product version 2.5.4
    2015-04-30 15:45:17.004 Version info: Detection engine 3.60.0
    2015-04-30 15:45:17.004 Version info: Detection data 5.13
    2015-04-30 15:45:17.006 Version info: Build date 31/03/2015
    2015-04-30 15:45:17.006 Version info: Data files added 337
    2015-04-30 15:45:17.006 Version info: Last successful update (not yet updated)
    2015-04-30 15:45:18.198 Update progress: proxy server not available
    2015-04-30 15:45:55.354 Downloading updates...
    2015-04-30 15:45:55.371 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
    2015-04-30 15:45:55.371 Update progress: [I49502] Found supplement SAVIW32 LATEST
    2015-04-30 15:45:55.371 Update progress: [I49502] Found supplement IDE514 LATEST
    2015-04-30 15:45:55.371 Update progress: [I49502] Found supplement IDE515 LATEST
    2015-04-30 15:45:55.371 Update progress: [I49502] Found supplement IDE516 LATEST
    2015-04-30 15:45:55.371 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
    2015-04-30 15:45:55.371 Update progress: [I19463] Syncing product SAVIW32 53
    2015-04-30 15:45:57.282 Update progress: [I19463] Syncing product IDE514 161
    2015-04-30 15:46:03.099 Update progress: [I19463] Syncing product IDE515 171
    2015-04-30 15:46:03.099 Update progress: [I19463] Syncing product IDE516 16
    2015-04-30 15:46:05.048 Installing updates...
    2015-04-30 15:46:05.650 Error level 1
    2015-04-30 15:46:21.944 Update successful
    2015-04-30 15:46:37.942 Option all = no
    2015-04-30 15:46:37.942 Option recurse = yes
    2015-04-30 15:46:37.942 Option archive = no
    2015-04-30 15:46:37.942 Option service = yes
    2015-04-30 15:46:37.942 Option confirm = yes
    2015-04-30 15:46:37.942 Option sxl = yes
    2015-04-30 15:46:37.943 Option max-data-age = 35
    2015-04-30 15:46:37.943 Option EnableSafeClean = yes
    2015-04-30 15:46:37.993 Option vdl-logging = yes
    2015-04-30 15:46:37.998 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
    2015-04-30 15:46:37.998 Machine ID: 8fef7cfffd6247a2b6c0893218a6ecd1
    2015-04-30 15:46:37.999 Component SVRTcli.exe version 2.5.4
    2015-04-30 15:46:37.999 Component control.dll version 2.5.4
    2015-04-30 15:46:37.999 Component SVRTservice.exe version 2.5.4
    2015-04-30 15:46:37.999 Component engine\osdp.dll version 1.44.1.2200
    2015-04-30 15:46:38.001 Component engine\veex.dll version 3.60.0.2200
    2015-04-30 15:46:38.001 Component engine\savi.dll version 8.1.7.2200
    2015-04-30 15:46:38.001 Component rkdisk.dll version 1.5.30.0
    2015-04-30 15:46:38.001 Version info: Product version 2.5.4
    2015-04-30 15:46:38.002 Version info: Detection engine 3.60.0
    2015-04-30 15:46:38.002 Version info: Detection data 5.13G
    2015-04-30 15:46:38.002 Version info: Build date 31/03/2015
    2015-04-30 15:46:38.002 Version info: Data files added 343
    2015-04-30 15:46:38.002 Version info: Last successful update 30/04/2015 16:46:21

    2015-04-30 16:26:53.247 Could not open C:\hiberfil.sys
    2015-04-30 16:27:16.942 Could not open C:\pagefile.sys
    2015-04-30 16:34:26.329 >>> Virus 'Mal/FakeAvCn-B' found in file C:\ProgramData\hHm24500kIaCi24500\hHm24500kIaCi24500
    2015-04-30 16:34:26.329 >>> Virus 'Mal/FakeAvCn-B' found in file HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-04-30 16:34:26.329 >>> Virus 'Mal/FakeAvCn-B' found in file HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-04-30 16:34:26.330 >>> Virus 'Mal/FakeAvCn-B' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-04-30 16:35:16.135 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-04-30 16:35:16.136 Could not open C:\System Volume Information\{39072dbb-ef4f-11e4-8190-d027880bcaa8}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-04-30 16:35:16.137 Could not open C:\System Volume Information\{45364b3a-ecd0-11e4-b4c5-d027880bcaa8}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-04-30 16:41:19.811 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
    2015-04-30 16:41:19.813 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
    2015-04-30 16:41:23.509 Could not open C:\Windows\System32\config\RegBack\DEFAULT
    2015-04-30 16:41:23.510 Could not open C:\Windows\System32\config\RegBack\SAM
    2015-04-30 16:41:23.512 Could not open C:\Windows\System32\config\RegBack\SECURITY
    2015-04-30 16:41:23.513 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
    2015-04-30 16:41:23.514 Could not open C:\Windows\System32\config\RegBack\SYSTEM
    2015-04-30 16:54:41.110 >>> Virus 'Mal/Behav-413' found in file T:\Software_zips\Sibelius 2\crack\crack.exe
    2015-04-30 16:54:41.111 >>> Virus 'Mal/Behav-413' found in file HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-04-30 16:54:41.111 >>> Virus 'Mal/Behav-413' found in file HKU\S-1-5-21-1673714354-1666257763-1680629560-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-04-30 16:54:41.111 >>> Virus 'Mal/Behav-413' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-04-30 16:54:49.901 The following items will be cleaned up:
    2015-04-30 16:54:49.903 Mal/FakeAvCn-B
    2015-04-30 16:54:49.903 Mal/Behav-413
     
  16. Broni

    Broni Malware Annihilator Posts: 52,890   +344

    [​IMG] Update Adobe Reader

    You can download it from http://www.adobe.com/products/acrobat/readstep2.html
    After installing the latest Adobe Reader, uninstall all previous versions (if present).
    Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

    [​IMG] Your Windows firewall seems to be disabled.
    Any reason for it? It's not safe.

    [​IMG] Your Windows updates are not current. Service Pack 1, for instance, is not installed.
    Why?
     
  17. Guymarshall

    Guymarshall TS Rookie Topic Starter

    Thanks

    OK, I have enabled Windows firewall - I wasn't sure whether it was useful or necessary to have Zone Alarm and Windows firewall. It seems I can't update Windows, "Windows Update" in control panel seems to be disabled. When I click "check for updates" a dialog box tells me "...the service is not running... may need to restart...". Restarting doesn't change this. This reminds me; I tried to set a restore point some weeks ago and was unable to do this either. Can you advise?

    Slightly worringly, on the Techspot website occasional words have become links ("AVG" and "the registry" for example) - bold blue text followed by a green circle having a short line emerging at 1 o'clock - and there are intermitent random popup ads..... this was how my original issues first appeared.

    Guy
     
  18. Broni

    Broni Malware Annihilator Posts: 52,890   +344

    I'm sorry. My mistake. I didn't notice you have ZA firewall there.
    Please disable Windows firewall.

    As for Windows updates...what is the EXACT error message?
     
  19. Guymarshall

    Guymarshall TS Rookie Topic Starter

    No problem, as for windows update: this is where I am - control panel/system and security/windows update - the graphic that I see is the red shield containing a white cross alongside text "always install the leatest updates to enhance your computer's security and performance" there is a button labelled "check for updates" - when I click the button a dialog appears "Windows Update cannot currently check for update, because the service is not running. You may need to restart your computer." ...and a button for "OK". Restarting changes nothing.

    upload_2015-5-2_12-11-22.png
     
  20. Broni

    Broni Malware Annihilator Posts: 52,890   +344

  21. Guymarshall

    Guymarshall TS Rookie Topic Starter

    Thanks Broni, tried that but nothing has changed apart from Windows Explorer is now a little flaky.

    Guy
     
  22. Broni

    Broni Malware Annihilator Posts: 52,890   +344

  23. Broni

    Broni Malware Annihilator Posts: 52,890   +344

    Still with me?
     
  24. Broni

    Broni Malware Annihilator Posts: 52,890   +344

    This topic is marked as abandoned and closed due to inactivity.

    This member will NOT be eligible to receive any more help in malware removal forum.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...