Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Need help removing nextcoup and pricechopp from extensions
Message
<blockquote data-quote="Steele Duke" data-source="post: 354519" data-attributes="member: 34543"><p>Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-02-2015 01</p><p>Ran by jerry (administrator) on JENNIFER-PC on 26-02-2015 17:01:24</p><p>Running from C:\Users\jerry\Downloads</p><p>Loaded Profiles: jerry (Available profiles: jerry)</p><p>Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)</p><p>Internet Explorer Version 11 (Default browser: Chrome)</p><p>Boot Mode: Normal</p><p>Tutorial for Farbar Recovery Scan Tool: <a href="http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/" target="_blank">http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/</a></p><p></p><p>==================== Processes (Whitelisted) =================</p><p></p><p>(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)</p><p></p><p>(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe</p><p>(Intel Corporation) C:\Windows\System32\hkcmd.exe</p><p>(Intel Corporation) C:\Windows\System32\igfxpers.exe</p><p>(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe</p><p>(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe</p><p>(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe</p><p>(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe</p><p>(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe</p><p>(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe</p><p>(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe</p><p>(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe</p><p>(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe</p><p>(Sun Microsystems, Inc.) C:\Program Files (x86)\Java\jre6\bin\ssvagent.exe</p><p>(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe</p><p>(Microsoft Corporation) C:\Windows\System32\dinotify.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe</p><p>(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe</p><p>(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p>(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe</p><p>(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</p><p></p><p></p><p>==================== Registry (Whitelisted) ==================</p><p></p><p>(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)</p><p></p><p>HKLM\...\Run: [] => [X]</p><p>HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [520760 2010-03-10] (Conexant Systems, Inc.)</p><p>HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] ()</p><p>HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)</p><p>HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)</p><p>HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)</p><p>HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)</p><p>HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2561848 2014-12-10] (Malwarebytes Corporation)</p><p>Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)</p><p>HKU\S-1-5-21-1608575498-428315075-3764911856-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd)</p><p>HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [301568 2013-05-21] (Microsoft Corporation)</p><p>GroupPolicy: Group Policy on Chrome detected <======= ATTENTION</p><p>CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION</p><p></p><p>==================== Internet (Whitelisted) ====================</p><p></p><p>(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)</p><p></p><p>ProxyServer: [S-1-5-21-1608575498-428315075-3764911856-1003] => http=127.0.0.1:57914;https=127.0.0.1:57914</p><p>HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.com" target="_blank">http://www.google.com</a></p><p>HKU\S-1-5-21-1608575498-428315075-3764911856-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.google.com/ig?brand=TSNA&bmod=TSNA" target="_blank">http://www.google.com/ig?brand=TSNA&bmod=TSNA</a></p><p>SearchScopes: HKLM -> DefaultScope {BF47E6B2-ED0A-40C0-A260-69DF9E0FC686} URL = <a href="http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA" target="_blank">http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA</a></p><p>SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = </p><p>SearchScopes: HKLM -> {BF47E6B2-ED0A-40C0-A260-69DF9E0FC686} URL = <a href="http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA" target="_blank">http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA</a></p><p>SearchScopes: HKLM-x32 -> DefaultScope value is missing.</p><p>SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = </p><p>SearchScopes: HKLM-x32 -> {6B3F49F9-BDC7-49E7-8CB7-B5052FFBE44E} URL = <a href="http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA" target="_blank">http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA</a></p><p>SearchScopes: HKU\S-1-5-21-1608575498-428315075-3764911856-1003 -> DefaultScope {6C4FF731-A058-460D-B6C7-8D5C42153056} URL = <a href="https://www.google.com/search?q={searchTerms}" target="_blank">https://www.google.com/search?q={searchTerms}</a></p><p>SearchScopes: HKU\S-1-5-21-1608575498-428315075-3764911856-1003 -> {6C4FF731-A058-460D-B6C7-8D5C42153056} URL = <a href="https://www.google.com/search?q={searchTerms}" target="_blank">https://www.google.com/search?q={searchTerms}</a></p><p>SearchScopes: HKU\S-1-5-21-1608575498-428315075-3764911856-1003 -> {BF47E6B2-ED0A-40C0-A260-69DF9E0FC686} URL = </p><p>SearchScopes: HKU\S-1-5-21-1608575498-428315075-3764911856-1003 -> {EC43DE6D-2551-4562-B52A-3660817F235C} URL = <a href="http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA" target="_blank">http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA</a></p><p>BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)</p><p>BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)</p><p>BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)</p><p>Tcpip\Parameters: [DhcpNameServer] 192.168.43.1</p><p></p><p>FireFox:</p><p>========</p><p>FF Plugin: @microsoft.com/GENUINE -> disabled No File</p><p>FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)</p><p>FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()</p><p>FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)</p><p>FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)</p><p>FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File</p><p>FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)</p><p>FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)</p><p>FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)</p><p>FF Plugin HKU\S-1-5-21-1608575498-428315075-3764911856-1003: @citrixonline.com/appdetectorplugin -> C:\Users\jerry\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)</p><p></p><p>Chrome: </p><p>=======</p><p>CHR HomePage: Default -> hxxp://<a href="http://www.google.com/" target="_blank">www.google.com/</a></p><p>CHR StartupUrls: Default -> "hxxp://google.com/"</p><p>CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google<img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite115" alt=":p" title="Stick out tongue :p" loading="lazy" data-shortname=":p" />ageClassification}{google:searchVersion}{google:sessionToken}{google<img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite115" alt=":p" title="Stick out tongue :p" loading="lazy" data-shortname=":p" />refetchQuery}sugkey={google:suggestAPIKeyParameter}</p><p>CHR Profile: C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default</p><p>CHR Extension: (pricechopp) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\akbhfeplmhgobbfpagoocjhoflolfeel [2014-08-05]</p><p>CHR Extension: (Google Drive) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-04]</p><p>CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-05]</p><p>CHR Extension: (YouTube) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-04]</p><p>CHR Extension: (Google Search) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-04]</p><p>CHR Extension: (Gmail Offline) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2014-09-23]</p><p>CHR Extension: (priciecchop) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhjjeefmnjpgeblclenngnklodenplap [2014-08-05]</p><p>CHR Extension: (NextCoup) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfdjhdenipmoeffffojjehmkefiedeno [2014-08-05]</p><p>CHR Extension: (emails2docs) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\mokbchipfpaaoioeljkgpojddoecnbce [2014-09-23]</p><p>CHR Extension: (Google Wallet) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-04]</p><p>CHR Extension: (Salesforce.com) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooaoeobbhfgkohkegpbidjjnkhjfccao [2014-08-04]</p><p>CHR Extension: (Gmail) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-04]</p><p></p><p>==================== Services (Whitelisted) =================</p><p></p><p>(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)</p><p>R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [555320 2014-12-10] (Malwarebytes Corporation)</p><p>R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)</p><p>R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)</p><p>R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)</p><p>R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)</p><p>S2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [66872 2013-10-31] ()</p><p>S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)</p><p></p><p>==================== Drivers (Whitelisted) ====================</p><p></p><p>(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [63064 2014-12-10] ()</p><p>R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)</p><p>R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-26] (Malwarebytes Corporation)</p><p>R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)</p><p>R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)</p><p>R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)</p><p>S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]</p><p>S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]</p><p></p><p>==================== NetSvcs (Whitelisted) ===================</p><p></p><p>(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)</p><p></p><p></p><p>==================== One Month Created Files and Folders ========</p><p></p><p>(If an entry is included in the fixlist, the file\folder will be moved.)</p><p></p><p>2015-02-26 17:01 - 2015-02-26 17:02 - 00013069 _____ () C:\Users\jerry\Downloads\FRST.txt</p><p>2015-02-26 17:01 - 2015-02-26 17:01 - 00000000 ____D () C:\FRST</p><p>2015-02-26 17:00 - 2015-02-26 17:00 - 02087936 _____ (Farbar) C:\Users\jerry\Downloads\FRST64.exe</p><p>2015-02-26 16:59 - 2015-02-26 16:59 - 01127424 _____ (Farbar) C:\Users\jerry\Downloads\FRST.exe</p><p>2015-02-26 16:47 - 2015-02-26 16:48 - 00000000 ____D () C:\ProgramData\Malwarebytes Anti-Exploit</p><p>2015-02-26 16:47 - 2015-02-26 16:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit</p><p>2015-02-26 16:47 - 2015-02-26 16:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Exploit</p><p>2015-02-26 16:43 - 2015-02-26 16:45 - 02967032 _____ (Malwarebytes ) C:\Users\jerry\Downloads\mbae-setup-1.05.1.1016.exe</p><p>2015-02-26 16:43 - 2015-02-26 16:45 - 00448512 _____ (OldTimer Tools) C:\Users\jerry\Downloads\TFC.exe</p><p>2015-02-26 16:33 - 2015-02-26 16:33 - 00002266 _____ () C:\Users\Public\Desktop\Google Chrome.lnk</p><p>2015-02-26 16:29 - 2015-02-26 16:33 - 00000000 ____D () C:\Program Files (x86)\Google</p><p>2015-02-26 16:28 - 2015-02-26 16:28 - 00000000 ____D () C:\Users\jerry\AppData\Local\Deployment</p><p>2015-02-26 16:28 - 2015-02-26 16:28 - 00000000 ____D () C:\Users\jerry\AppData\Local\Apps\2.0</p><p>2015-02-26 15:53 - 2015-02-26 15:53 - 00010902 _____ () C:\Users\jerry\Documents\cc_20150226_155313.reg</p><p>2015-02-26 15:52 - 2015-02-26 15:53 - 00110586 _____ () C:\Users\jerry\Documents\cc_20150226_155243.reg</p><p>2015-02-26 15:35 - 2015-02-26 15:38 - 05325352 _____ (Piriform Ltd) C:\Users\jerry\Downloads\ccsetup503pro.exe</p><p>2015-02-12 23:16 - 2015-02-26 16:29 - 00003640 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore</p><p>2015-02-12 23:10 - 2015-02-12 23:14 - 00000000 ____D () C:\Users\jerry\AppData\Roaming\Apple Computer</p><p>2015-02-12 23:10 - 2015-02-12 23:10 - 00000000 ____D () C:\Users\jerry\AppData\Local\Apple Computer</p><p>2015-02-12 23:09 - 2015-02-12 23:09 - 00001764 _____ () C:\Users\Public\Desktop\iTunes.lnk</p><p>2015-02-12 23:09 - 2015-02-12 23:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes</p><p>2015-02-12 23:08 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\windows\system32\Drivers\GEARAspiWDM.sys</p><p>2015-02-12 23:06 - 2015-02-12 23:06 - 00000000 ____D () C:\Program Files\iPod</p><p>2015-02-12 23:06 - 2015-02-12 23:06 - 00000000 ____D () C:\Program Files (x86)\iTunes</p><p>2015-02-12 23:05 - 2015-02-12 23:08 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7</p><p>2015-02-12 23:03 - 2015-02-12 23:03 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk</p><p>2015-02-12 23:03 - 2015-02-12 23:03 - 00000000 ____D () C:\windows\System32\Tasks\Apple</p><p>2015-02-12 23:03 - 2015-02-12 23:03 - 00000000 ____D () C:\Users\jerry\AppData\Local\Apple</p><p>2015-02-12 23:02 - 2015-02-12 23:03 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update</p><p>2015-02-12 23:00 - 2015-02-12 23:01 - 00000000 ____D () C:\Program Files\Bonjour</p><p>2015-02-12 23:00 - 2015-02-12 23:01 - 00000000 ____D () C:\Program Files (x86)\Bonjour</p><p>2015-02-12 22:59 - 2015-02-12 23:05 - 00000000 ____D () C:\Program Files\Common Files\Apple</p><p>2015-02-12 22:38 - 2015-02-12 22:40 - 152439600 _____ (Apple Inc.) C:\Users\jerry\Downloads\itunes6464setup.exe</p><p></p><p>==================== One Month Modified Files and Folders =======</p><p></p><p>(If an entry is included in the fixlist, the file\folder will be moved.)</p><p></p><p>2015-02-26 16:57 - 2014-08-05 11:09 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys</p><p>2015-02-26 16:47 - 2013-04-21 18:53 - 00000892 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job</p><p>2015-02-26 16:46 - 2013-03-30 09:55 - 01770429 _____ () C:\windows\WindowsUpdate.log</p><p>2015-02-26 16:34 - 2013-04-21 18:53 - 00000896 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job</p><p>2015-02-26 16:29 - 2013-04-21 18:53 - 00003892 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA</p><p>2015-02-26 15:43 - 2013-04-24 20:09 - 00000000 ____D () C:\Program Files\CCleaner</p><p>2015-02-26 15:41 - 2013-04-24 20:09 - 00002772 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC</p><p>2015-02-26 15:41 - 2013-04-24 20:09 - 00000833 _____ () C:\Users\Public\Desktop\CCleaner.lnk</p><p>2015-02-13 00:47 - 2009-07-13 22:45 - 00018736 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0</p><p>2015-02-13 00:47 - 2009-07-13 22:45 - 00018736 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0</p><p>2015-02-12 23:50 - 2014-08-05 11:09 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk</p><p>2015-02-12 23:50 - 2014-08-05 11:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware</p><p>2015-02-12 23:50 - 2014-08-05 11:08 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware</p><p>2015-02-12 23:41 - 2009-07-13 22:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk</p><p>2015-02-12 22:58 - 2013-11-26 21:36 - 00000000 ____D () C:\ProgramData\Apple</p><p>2015-02-12 22:53 - 2014-09-12 09:39 - 00005617 _____ () C:\windows\system32\lvcoinst.log</p><p>2015-02-12 22:53 - 2014-09-12 09:39 - 00000000 ____D () C:\Program Files\Common Files\logishrd</p><p>2015-02-12 22:50 - 2014-09-12 08:29 - 00000000 ____D () C:\Program Files (x86)\Logitech</p><p>2015-02-12 22:44 - 2009-07-13 23:13 - 00782510 _____ () C:\windows\system32\PerfStringBackup.INI</p><p>2015-02-12 22:36 - 2009-07-13 23:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT</p><p></p><p>==================== Bamital & volsnap Check =================</p><p></p><p>(There is no automatic fix for files that do not pass verification.)</p><p></p><p>C:\Windows\System32\winlogon.exe => File is digitally signed</p><p>C:\Windows\System32\wininit.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\wininit.exe => File is digitally signed</p><p>C:\Windows\explorer.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\explorer.exe => File is digitally signed</p><p>C:\Windows\System32\svchost.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\svchost.exe => File is digitally signed</p><p>C:\Windows\System32\services.exe => File is digitally signed</p><p>C:\Windows\System32\User32.dll => File is digitally signed</p><p>C:\Windows\SysWOW64\User32.dll => File is digitally signed</p><p>C:\Windows\System32\userinit.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\userinit.exe => File is digitally signed</p><p>C:\Windows\System32\rpcss.dll => File is digitally signed</p><p>C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed</p><p></p><p></p><p>LastRegBack: 2015-02-13 00:41</p><p></p><p>==================== End Of Log ============================</p><p></p><p></p><p></p><p>Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-02-2015 01</p><p>Ran by jerry at 2015-02-26 17:02:35</p><p>Running from C:\Users\jerry\Downloads</p><p>Boot Mode: Normal</p><p>==========================================================</p><p></p><p></p><p>==================== Security Center ========================</p><p></p><p>(If an entry is included in the fixlist, it will be removed.)</p><p></p><p>AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}</p><p>AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}</p><p>AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}</p><p></p><p>==================== Installed Programs ======================</p><p></p><p>(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)</p><p></p><p>Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.42.34 - Adobe Systems Incorporated)</p><p>Adobe Reader 9.3 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A93000000001}) (Version: 9.3.0 - Adobe Systems Incorporated)</p><p>Apple Application Support (32-bit) (HKLM-x32\...\{2FE00055-C4F3-4F7A-AEDD-E198D54CF12F}) (Version: 3.1.1 - Apple Inc.)</p><p>Apple Application Support (64-bit) (HKLM\...\{28791292-D18D-42FA-AE66-3D3D20AA8618}) (Version: 3.1.1 - Apple Inc.)</p><p>Apple Mobile Device Support (HKLM\...\{5ED7462B-EF58-4757-B609-53755021EC34}) (Version: 8.1.0.18 - Apple Inc.)</p><p>Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)</p><p>Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.27 - Atheros Communications Inc.)</p><p>Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 5.2 - Atheros)</p><p>Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)</p><p>CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform)</p><p>Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.111.0.64 - Conexant)</p><p>Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.)</p><p>Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden</p><p>Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden</p><p>Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2086 - Intel Corporation)</p><p>Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)</p><p>iTunes (HKLM\...\{7B8D4E8A-EA2B-4A71-BFEB-A4AAAB87C5D0}) (Version: 12.1.0.71 - Apple Inc.)</p><p>Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle)</p><p>Java(TM) 6 Update 17 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216017FF}) (Version: 6.0.170 - Sun Microsystems, Inc.)</p><p>Malwarebytes Anti-Exploit version 1.05.1.1016 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.05.1.1016 - Malwarebytes)</p><p>Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)</p><p>Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)</p><p>Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)</p><p>Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)</p><p>MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)</p><p>MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)</p><p>PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)</p><p>Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.8.1 - Synaptics Incorporated)</p><p></p><p>==================== Custom CLSID (selected items): ==========================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)</p><p></p><p></p><p>==================== Restore Points =========================</p><p></p><p>12-09-2014 16:05:37 Windows Update</p><p>12-09-2014 17:25:51 Installed Webassessor Sentinel Security Shield™ x64</p><p>13-09-2014 02:00:11 Windows Update</p><p>14-09-2014 02:00:12 Windows Update</p><p>23-09-2014 13:31:44 Windows Update</p><p>23-09-2014 13:57:38 Installed AT&T Connect Participant Application v10.7.114.</p><p>23-09-2014 14:07:00 Removed AT&T Connect Participant Application v10.7.114.</p><p>23-09-2014 14:10:03 Removed Bonjour</p><p>23-09-2014 14:12:53 Removed Microsoft Office File Validation Add-In</p><p>23-09-2014 14:13:17 Removed Microsoft PowerPoint Viewer</p><p>23-09-2014 14:15:15 Removed Microsoft Works</p><p>25-09-2014 12:45:57 Windows Update</p><p>23-10-2014 14:52:52 Scheduled Checkpoint</p><p>23-10-2014 14:53:18 Windows Update</p><p>12-02-2015 22:46:10 Removed Webassessor Sentinel Security Shield™ x64</p><p>12-02-2015 23:03:34 Installed iTunes</p><p>26-02-2015 16:11:32 Windows Update</p><p></p><p>==================== Hosts content: ==========================</p><p></p><p>(If needed Hosts: directive could be included in the fixlist to reset Hosts.)</p><p></p><p>2009-07-13 20:34 - 2009-06-10 15:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts</p><p></p><p>==================== Scheduled Tasks (whitelisted) =============</p><p></p><p>(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)</p><p></p><p>Task: {27E0CBD2-1912-421B-8B0D-48CBEB964A2F} - System32\Tasks\{8E77E671-FD11-402A-BB70-1B0DD76E39F3} => pcalua.exe -a C:\Users\jerry\Downloads\Impactor_0.9.14\impactor\installer_x86.exe -d C:\Users\jerry\Downloads\Impactor_0.9.14\impactor</p><p>Task: {502A5686-CC6E-4661-953C-A3BD84C4A245} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION</p><p>Task: {939335F8-FEE1-4F7A-92AC-1AF8BB932045} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-26] (Google Inc.)</p><p>Task: {A2C5E0AA-82B4-4660-A0BF-285A1F418E2B} - System32\Tasks\{2DD3EE5F-22D2-4E9B-86C8-21F05D23691D} => pcalua.exe -a C:\Users\jennifer\Downloads\wlsetup-web.exe -d C:\Users\jennifer\Downloads</p><p>Task: {AE47C330-7824-4137-9889-803BEF5988C1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)</p><p>Task: {D3345348-5D94-4D6E-8D4F-3ED0BA4D362E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-26] (Google Inc.)</p><p>Task: {E9E87C08-088E-4314-B079-0E20FFED6BD0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-02-19] (Piriform Ltd)</p><p>Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe</p><p>Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe</p><p></p><p>==================== Loaded Modules (whitelisted) ==============</p><p></p><p>2015-01-20 22:35 - 2015-01-20 22:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll</p><p>2015-01-20 22:35 - 2015-01-20 22:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll</p><p>2015-02-26 16:33 - 2015-02-17 16:44 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libglesv2.dll</p><p>2015-02-26 16:33 - 2015-02-17 16:44 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libegl.dll</p><p>2015-02-26 16:33 - 2015-02-17 16:44 - 09171272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\pdf.dll</p><p>2015-02-26 16:33 - 2015-02-17 16:44 - 14965064 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\PepperFlash\pepflashplayer.dll</p><p></p><p>==================== Alternate Data Streams (whitelisted) =========</p><p></p><p>(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)</p><p></p><p></p><p>==================== Safe Mode (whitelisted) ===================</p><p></p><p>(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)</p><p></p><p></p><p>==================== EXE Association (whitelisted) ===============</p><p></p><p>(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)</p><p></p><p></p><p>==================== Other Areas ============================</p><p></p><p>(Currently there is no automatic fix for this section.)</p><p></p><p>HKU\S-1-5-21-1608575498-428315075-3764911856-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\jerry\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg</p><p>DNS Servers: 192.168.43.1</p><p></p><p>==================== MSCONFIG/TASK MANAGER disabled items ==</p><p></p><p>(Currently there is no automatic fix for this section.)</p><p></p><p>MSCONFIG\Services: ehRecvr => 3</p><p>MSCONFIG\Services: ehSched => 3</p><p>MSCONFIG\Services: Fax => 3</p><p>MSCONFIG\Services: HomeGroupListener => 3</p><p>MSCONFIG\Services: HomeGroupProvider => 3</p><p>MSCONFIG\Services: iphlpsvc => 2</p><p>MSCONFIG\Services: napagent => 3</p><p>MSCONFIG\Services: SCardSvr => 3</p><p>MSCONFIG\Services: SCPolicySvc => 3</p><p>MSCONFIG\Services: TabletInputService => 3</p><p>MSCONFIG\Services: WMPNetworkSvc => 2</p><p>MSCONFIG\Services: WPCSvc => 3</p><p>MSCONFIG\startupfolder: C:^Users^jerry^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk => C:\windows\pss\Logitech . Product Registration.lnk.Startup</p><p>MSCONFIG\startupreg: LogitechVideoRepair => C:\Program Files (x86)\Logitech\Video\ISStart.exe </p><p>MSCONFIG\startupreg: LogitechVideoTray => C:\Program Files (x86)\Logitech\Video\LogiTray.exe</p><p>MSCONFIG\startupreg: Safer-Surf => C:\Program Files (x86)\ver5Safer-Surf\Safer-Surf.exe</p><p></p><p>==================== Accounts: =============================</p><p></p><p>Administrator (S-1-5-21-1608575498-428315075-3764911856-500 - Administrator - Disabled)</p><p>Guest (S-1-5-21-1608575498-428315075-3764911856-501 - Limited - Disabled)</p><p>HomeGroupUser$ (S-1-5-21-1608575498-428315075-3764911856-1002 - Limited - Enabled)</p><p>jerry (S-1-5-21-1608575498-428315075-3764911856-1003 - Administrator - Enabled) => C:\Users\jerry</p><p></p><p>==================== Faulty Device Manager Devices =============</p><p></p><p>Name: Microsoft Teredo Tunneling Adapter</p><p>Description: Microsoft Teredo Tunneling Adapter</p><p>Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}</p><p>Manufacturer: Microsoft</p><p>Service: tunnel</p><p>Problem: : This device cannot start. (Code10)</p><p>Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.</p><p>On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.</p><p></p><p></p><p>==================== Event log errors: =========================</p><p></p><p>Application errors:</p><p>==================</p><p>Error: (02/26/2015 04:18:36 PM) (Source: SideBySide) (EventID: 33) (User: )</p><p>Description: Activation context generation failed for "37.0.2062.124,language="&#x2a;",type="win32",version="37.0.2062.124"1".</p><p>Dependent Assembly 37.0.2062.124,language="&#x2a;",type="win32",version="37.0.2062.124" could not be found.</p><p>Please use sxstrace.exe for detailed diagnosis.</p><p></p><p>Error: (02/26/2015 04:15:32 PM) (Source: SideBySide) (EventID: 33) (User: )</p><p>Description: Activation context generation failed for "40.0.2214.111,language="&#x2a;",type="win32",version="40.0.2214.111"1".</p><p>Dependent Assembly 40.0.2214.111,language="&#x2a;",type="win32",version="40.0.2214.111" could not be found.</p><p>Please use sxstrace.exe for detailed diagnosis.</p><p></p><p>Error: (02/26/2015 04:15:32 PM) (Source: SideBySide) (EventID: 33) (User: )</p><p>Description: Activation context generation failed for "40.0.2214.111,language="&#x2a;",type="win32",version="40.0.2214.111"1".</p><p>Dependent Assembly 40.0.2214.111,language="&#x2a;",type="win32",version="40.0.2214.111" could not be found.</p><p>Please use sxstrace.exe for detailed diagnosis.</p><p></p><p>Error: (09/12/2014 09:01:07 AM) (Source: Application Hang) (EventID: 1002) (User: )</p><p>Description: The program msinfo32.exe version 6.1.7601.17514 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.</p><p></p><p>Process ID: 1380</p><p></p><p>Start Time: 01cfce9a0f701e65</p><p></p><p>Termination Time: 62</p><p></p><p>Application Path: C:\windows\system32\msinfo32.exe</p><p></p><p>Report Id: 969d1b33-3a8d-11e4-ae63-00266c513509</p><p></p><p>Error: (09/12/2014 08:33:57 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.</p><p></p><p></p><p>Details:</p><p>AddWin32ServiceFiles: Unable to back up image of service vulsrsebjh64 since QueryServiceConfig API failed</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p>.</p><p></p><p>Error: (09/12/2014 08:33:57 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.</p><p></p><p></p><p>Details:</p><p>AddWin32ServiceFiles: Unable to back up image of service SW-Sustainer since QueryServiceConfig API failed</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p>.</p><p></p><p>Error: (09/12/2014 08:33:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.</p><p></p><p></p><p>Details:</p><p>AddWin32ServiceFiles: Unable to back up image of service AllDaySavingsService64 since QueryServiceConfig API failed</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p>.</p><p></p><p>Error: (09/12/2014 08:33:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.</p><p></p><p></p><p>Details:</p><p>AddLegacyDriverFiles: Unable to back up image of binary netfilter64.</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p>.</p><p></p><p>Error: (09/12/2014 08:32:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.</p><p></p><p></p><p>Details:</p><p>AddWin32ServiceFiles: Unable to back up image of service vulsrsebjh64 since QueryServiceConfig API failed</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p>.</p><p></p><p>Error: (09/12/2014 08:32:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.</p><p></p><p></p><p>Details:</p><p>AddWin32ServiceFiles: Unable to back up image of service SW-Sustainer since QueryServiceConfig API failed</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p>.</p><p></p><p></p><p>System errors:</p><p>=============</p><p>Error: (02/26/2015 04:46:57 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The PnkBstrA service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p>Error: (02/26/2015 03:09:41 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )</p><p>Description: %NT AUTHORITY60 has encountered an error trying to update signatures.</p><p></p><p> New Signature Version: </p><p></p><p> Previous Signature Version: 113.69.0.0</p><p></p><p> Update Source: %NT AUTHORITY51</p><p></p><p> Update Stage: 4.6.0305.00</p><p></p><p> Source Path: 4.6.0305.01</p><p></p><p> Signature Type: %NT AUTHORITY602</p><p></p><p> Update Type: %NT AUTHORITY604</p><p></p><p> User: NT AUTHORITY\NETWORK SERVICE</p><p></p><p> Current Engine Version: %NT AUTHORITY605</p><p></p><p> Previous Engine Version: %NT AUTHORITY606</p><p></p><p> Error code: %NT AUTHORITY607</p><p></p><p> Error description: %NT AUTHORITY608</p><p></p><p>Error: (02/26/2015 03:09:41 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )</p><p>Description: %NT AUTHORITY60 has encountered an error trying to update signatures.</p><p></p><p> New Signature Version: </p><p></p><p> Previous Signature Version: 1.191.4826.0</p><p></p><p> Update Source: %NT AUTHORITY51</p><p></p><p> Update Stage: 4.6.0305.00</p><p></p><p> Source Path: 4.6.0305.01</p><p></p><p> Signature Type: %NT AUTHORITY602</p><p></p><p> Update Type: %NT AUTHORITY604</p><p></p><p> User: NT AUTHORITY\NETWORK SERVICE</p><p></p><p> Current Engine Version: %NT AUTHORITY605</p><p></p><p> Previous Engine Version: %NT AUTHORITY606</p><p></p><p> Error code: %NT AUTHORITY607</p><p></p><p> Error description: %NT AUTHORITY608</p><p></p><p>Error: (02/26/2015 03:09:41 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )</p><p>Description: %NT AUTHORITY60 has encountered an error trying to update signatures.</p><p></p><p> New Signature Version: </p><p></p><p> Previous Signature Version: 1.191.4826.0</p><p></p><p> Update Source: %NT AUTHORITY51</p><p></p><p> Update Stage: 4.6.0305.00</p><p></p><p> Source Path: 4.6.0305.01</p><p></p><p> Signature Type: %NT AUTHORITY602</p><p></p><p> Update Type: %NT AUTHORITY604</p><p></p><p> User: NT AUTHORITY\NETWORK SERVICE</p><p></p><p> Current Engine Version: %NT AUTHORITY605</p><p></p><p> Previous Engine Version: %NT AUTHORITY606</p><p></p><p> Error code: %NT AUTHORITY607</p><p></p><p> Error description: %NT AUTHORITY608</p><p></p><p>Error: (02/26/2015 03:09:41 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )</p><p>Description: %NT AUTHORITY60 has encountered an error trying to update signatures.</p><p></p><p> New Signature Version: </p><p></p><p> Previous Signature Version: 1.191.4826.0</p><p></p><p> Update Source: %NT AUTHORITY59</p><p></p><p> Update Stage: 4.6.0305.00</p><p></p><p> Source Path: 4.6.0305.01</p><p></p><p> Signature Type: %NT AUTHORITY602</p><p></p><p> Update Type: %NT AUTHORITY604</p><p></p><p> User: NT AUTHORITY\SYSTEM</p><p></p><p> Current Engine Version: %NT AUTHORITY605</p><p></p><p> Previous Engine Version: %NT AUTHORITY606</p><p></p><p> Error code: %NT AUTHORITY607</p><p></p><p> Error description: %NT AUTHORITY608</p><p></p><p>Error: (02/26/2015 03:07:45 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )</p><p>Description: %NT AUTHORITY60 has encountered an error trying to update signatures.</p><p></p><p> New Signature Version: </p><p></p><p> Previous Signature Version: 113.69.0.0</p><p></p><p> Update Source: %NT AUTHORITY51</p><p></p><p> Update Stage: 4.6.0305.00</p><p></p><p> Source Path: 4.6.0305.01</p><p></p><p> Signature Type: %NT AUTHORITY602</p><p></p><p> Update Type: %NT AUTHORITY604</p><p></p><p> User: NT AUTHORITY\NETWORK SERVICE</p><p></p><p> Current Engine Version: %NT AUTHORITY605</p><p></p><p> Previous Engine Version: %NT AUTHORITY606</p><p></p><p> Error code: %NT AUTHORITY607</p><p></p><p> Error description: %NT AUTHORITY608</p><p></p><p>Error: (02/26/2015 03:07:45 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )</p><p>Description: %NT AUTHORITY60 has encountered an error trying to update signatures.</p><p></p><p> New Signature Version: </p><p></p><p> Previous Signature Version: 1.191.4826.0</p><p></p><p> Update Source: %NT AUTHORITY51</p><p></p><p> Update Stage: 4.6.0305.00</p><p></p><p> Source Path: 4.6.0305.01</p><p></p><p> Signature Type: %NT AUTHORITY602</p><p></p><p> Update Type: %NT AUTHORITY604</p><p></p><p> User: NT AUTHORITY\NETWORK SERVICE</p><p></p><p> Current Engine Version: %NT AUTHORITY605</p><p></p><p> Previous Engine Version: %NT AUTHORITY606</p><p></p><p> Error code: %NT AUTHORITY607</p><p></p><p> Error description: %NT AUTHORITY608</p><p></p><p>Error: (02/26/2015 03:07:45 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )</p><p>Description: %NT AUTHORITY60 has encountered an error trying to update signatures.</p><p></p><p> New Signature Version: </p><p></p><p> Previous Signature Version: 1.191.4826.0</p><p></p><p> Update Source: %NT AUTHORITY51</p><p></p><p> Update Stage: 4.6.0305.00</p><p></p><p> Source Path: 4.6.0305.01</p><p></p><p> Signature Type: %NT AUTHORITY602</p><p></p><p> Update Type: %NT AUTHORITY604</p><p></p><p> User: NT AUTHORITY\NETWORK SERVICE</p><p></p><p> Current Engine Version: %NT AUTHORITY605</p><p></p><p> Previous Engine Version: %NT AUTHORITY606</p><p></p><p> Error code: %NT AUTHORITY607</p><p></p><p> Error description: %NT AUTHORITY608</p><p></p><p>Error: (02/26/2015 03:07:45 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )</p><p>Description: %NT AUTHORITY60 has encountered an error trying to update signatures.</p><p></p><p> New Signature Version: </p><p></p><p> Previous Signature Version: 1.191.4826.0</p><p></p><p> Update Source: %NT AUTHORITY59</p><p></p><p> Update Stage: 4.6.0305.00</p><p></p><p> Source Path: 4.6.0305.01</p><p></p><p> Signature Type: %NT AUTHORITY602</p><p></p><p> Update Type: %NT AUTHORITY604</p><p></p><p> User: NT AUTHORITY\SYSTEM</p><p></p><p> Current Engine Version: %NT AUTHORITY605</p><p></p><p> Previous Engine Version: %NT AUTHORITY606</p><p></p><p> Error code: %NT AUTHORITY607</p><p></p><p> Error description: %NT AUTHORITY608</p><p></p><p>Error: (02/12/2015 10:46:10 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)</p><p>Description: The following fatal alert was generated: 10. The internal error state is 10.</p><p></p><p></p><p>Microsoft Office Sessions:</p><p>=========================</p><p>Error: (02/26/2015 04:18:36 PM) (Source: SideBySide) (EventID: 33) (User: )</p><p>Description: 37.0.2062.124,language="&#x2a;",type="win32",version="37.0.2062.124"C:\$Recycle.Bin\S-1-5-21-1608575498-428315075-3764911856-1003\$RATX73Q.exe</p><p></p><p>Error: (02/26/2015 04:15:32 PM) (Source: SideBySide) (EventID: 33) (User: )</p><p>Description: 40.0.2214.111,language="&#x2a;",type="win32",version="40.0.2214.111"C:\$Recycle.Bin\S-1-5-21-1608575498-428315075-3764911856-1003\$RMJIWFK.exe</p><p></p><p>Error: (02/26/2015 04:15:32 PM) (Source: SideBySide) (EventID: 33) (User: )</p><p>Description: 40.0.2214.111,language="&#x2a;",type="win32",version="40.0.2214.111"C:\$Recycle.Bin\S-1-5-21-1608575498-428315075-3764911856-1003\$RMJIWFK.exe</p><p></p><p>Error: (09/12/2014 09:01:07 AM) (Source: Application Hang) (EventID: 1002) (User: )</p><p>Description: msinfo32.exe6.1.7601.17514138001cfce9a0f701e6562C:\windows\system32\msinfo32.exe969d1b33-3a8d-11e4-ae63-00266c513509</p><p></p><p>Error: (09/12/2014 08:33:57 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: </p><p>Details:</p><p>AddWin32ServiceFiles: Unable to back up image of service vulsrsebjh64 since QueryServiceConfig API failed</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p></p><p>Error: (09/12/2014 08:33:57 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: </p><p>Details:</p><p>AddWin32ServiceFiles: Unable to back up image of service SW-Sustainer since QueryServiceConfig API failed</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p></p><p>Error: (09/12/2014 08:33:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: </p><p>Details:</p><p>AddWin32ServiceFiles: Unable to back up image of service AllDaySavingsService64 since QueryServiceConfig API failed</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p></p><p>Error: (09/12/2014 08:33:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: </p><p>Details:</p><p>AddLegacyDriverFiles: Unable to back up image of binary netfilter64.</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p></p><p>Error: (09/12/2014 08:32:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: </p><p>Details:</p><p>AddWin32ServiceFiles: Unable to back up image of service vulsrsebjh64 since QueryServiceConfig API failed</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p></p><p>Error: (09/12/2014 08:32:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )</p><p>Description: </p><p>Details:</p><p>AddWin32ServiceFiles: Unable to back up image of service SW-Sustainer since QueryServiceConfig API failed</p><p></p><p>System Error:</p><p>The system cannot find the file specified.</p><p></p><p></p><p>==================== Memory info =========================== </p><p></p><p>Processor: Intel(R) Celeron(R) CPU 900 @ 2.20GHz</p><p>Percentage of memory in use: 65%</p><p>Total physical RAM: 1915.98 MB</p><p>Available physical RAM: 662.13 MB</p><p>Total Pagefile: 3831.95 MB</p><p>Available Pagefile: 1905.42 MB</p><p>Total Virtual: 8192 MB</p><p>Available Virtual: 8191.84 MB</p><p></p><p>==================== Drives ================================</p><p></p><p>Drive c: (TI105847W0E) (Fixed) (Total:127.88 GB) (Free:96.23 GB) NTFS ==>[System with boot components (obtained from reading drive)]</p><p></p><p>==================== MBR & Partition Table ==================</p><p></p><p>========================================================</p><p>Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.9 GB) (Disk ID: A3418076)</p><p>Partition 1: (Active) - (Size=1.5 GB) - (Type=27)</p><p>Partition 2: (Not Active) - (Size=127.9 GB) - (Type=07 NTFS)</p><p>Partition 3: (Not Active) - (Size=8.9 GB) - (Type=17)</p><p></p><p>==================== End Of Log ============================</p></blockquote><p></p>
[QUOTE="Steele Duke, post: 354519, member: 34543"] Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-02-2015 01 Ran by jerry (administrator) on JENNIFER-PC on 26-02-2015 17:01:24 Running from C:\Users\jerry\Downloads Loaded Profiles: jerry (Available profiles: jerry) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: [URL]http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/[/URL] ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Java\jre6\bin\ssvagent.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Windows\System32\dinotify.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [] => [X] HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [520760 2010-03-10] (Conexant Systems, Inc.) HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] () HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated) HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2561848 2014-12-10] (Malwarebytes Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1608575498-428315075-3764911856-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd) HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [301568 2013-05-21] (Microsoft Corporation) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: [S-1-5-21-1608575498-428315075-3764911856-1003] => http=127.0.0.1:57914;https=127.0.0.1:57914 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = [URL]http://www.google.com[/URL] HKU\S-1-5-21-1608575498-428315075-3764911856-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [URL]http://www.google.com/ig?brand=TSNA&bmod=TSNA[/URL] SearchScopes: HKLM -> DefaultScope {BF47E6B2-ED0A-40C0-A260-69DF9E0FC686} URL = [URL]http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA[/URL] SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {BF47E6B2-ED0A-40C0-A260-69DF9E0FC686} URL = [URL]http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA[/URL] SearchScopes: HKLM-x32 -> DefaultScope value is missing. SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {6B3F49F9-BDC7-49E7-8CB7-B5052FFBE44E} URL = [URL]http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA[/URL] SearchScopes: HKU\S-1-5-21-1608575498-428315075-3764911856-1003 -> DefaultScope {6C4FF731-A058-460D-B6C7-8D5C42153056} URL = [URL]https://www.google.com/search?q={searchTerms}[/URL] SearchScopes: HKU\S-1-5-21-1608575498-428315075-3764911856-1003 -> {6C4FF731-A058-460D-B6C7-8D5C42153056} URL = [URL]https://www.google.com/search?q={searchTerms}[/URL] SearchScopes: HKU\S-1-5-21-1608575498-428315075-3764911856-1003 -> {BF47E6B2-ED0A-40C0-A260-69DF9E0FC686} URL = SearchScopes: HKU\S-1-5-21-1608575498-428315075-3764911856-1003 -> {EC43DE6D-2551-4562-B52A-3660817F235C} URL = [URL]http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA[/URL] BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.43.1 FireFox: ======== FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-1608575498-428315075-3764911856-1003: @citrixonline.com/appdetectorplugin -> C:\Users\jerry\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online) Chrome: ======= CHR HomePage: Default -> hxxp://[URL="http://www.google.com/"]www.google.com/[/URL] CHR StartupUrls: Default -> "hxxp://google.com/" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} CHR Profile: C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (pricechopp) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\akbhfeplmhgobbfpagoocjhoflolfeel [2014-08-05] CHR Extension: (Google Drive) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-04] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-05] CHR Extension: (YouTube) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-04] CHR Extension: (Google Search) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-04] CHR Extension: (Gmail Offline) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2014-09-23] CHR Extension: (priciecchop) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhjjeefmnjpgeblclenngnklodenplap [2014-08-05] CHR Extension: (NextCoup) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfdjhdenipmoeffffojjehmkefiedeno [2014-08-05] CHR Extension: (emails2docs) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\mokbchipfpaaoioeljkgpojddoecnbce [2014-09-23] CHR Extension: (Google Wallet) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-04] CHR Extension: (Salesforce.com) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooaoeobbhfgkohkegpbidjjnkhjfccao [2014-08-04] CHR Extension: (Gmail) - C:\Users\jerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-04] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.) R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [555320 2014-12-10] (Malwarebytes Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) S2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [66872 2013-10-31] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [63064 2014-12-10] () R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-26] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed] S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-26 17:01 - 2015-02-26 17:02 - 00013069 _____ () C:\Users\jerry\Downloads\FRST.txt 2015-02-26 17:01 - 2015-02-26 17:01 - 00000000 ____D () C:\FRST 2015-02-26 17:00 - 2015-02-26 17:00 - 02087936 _____ (Farbar) C:\Users\jerry\Downloads\FRST64.exe 2015-02-26 16:59 - 2015-02-26 16:59 - 01127424 _____ (Farbar) C:\Users\jerry\Downloads\FRST.exe 2015-02-26 16:47 - 2015-02-26 16:48 - 00000000 ____D () C:\ProgramData\Malwarebytes Anti-Exploit 2015-02-26 16:47 - 2015-02-26 16:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit 2015-02-26 16:47 - 2015-02-26 16:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Exploit 2015-02-26 16:43 - 2015-02-26 16:45 - 02967032 _____ (Malwarebytes ) C:\Users\jerry\Downloads\mbae-setup-1.05.1.1016.exe 2015-02-26 16:43 - 2015-02-26 16:45 - 00448512 _____ (OldTimer Tools) C:\Users\jerry\Downloads\TFC.exe 2015-02-26 16:33 - 2015-02-26 16:33 - 00002266 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-02-26 16:29 - 2015-02-26 16:33 - 00000000 ____D () C:\Program Files (x86)\Google 2015-02-26 16:28 - 2015-02-26 16:28 - 00000000 ____D () C:\Users\jerry\AppData\Local\Deployment 2015-02-26 16:28 - 2015-02-26 16:28 - 00000000 ____D () C:\Users\jerry\AppData\Local\Apps\2.0 2015-02-26 15:53 - 2015-02-26 15:53 - 00010902 _____ () C:\Users\jerry\Documents\cc_20150226_155313.reg 2015-02-26 15:52 - 2015-02-26 15:53 - 00110586 _____ () C:\Users\jerry\Documents\cc_20150226_155243.reg 2015-02-26 15:35 - 2015-02-26 15:38 - 05325352 _____ (Piriform Ltd) C:\Users\jerry\Downloads\ccsetup503pro.exe 2015-02-12 23:16 - 2015-02-26 16:29 - 00003640 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-12 23:10 - 2015-02-12 23:14 - 00000000 ____D () C:\Users\jerry\AppData\Roaming\Apple Computer 2015-02-12 23:10 - 2015-02-12 23:10 - 00000000 ____D () C:\Users\jerry\AppData\Local\Apple Computer 2015-02-12 23:09 - 2015-02-12 23:09 - 00001764 _____ () C:\Users\Public\Desktop\iTunes.lnk 2015-02-12 23:09 - 2015-02-12 23:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-02-12 23:08 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\windows\system32\Drivers\GEARAspiWDM.sys 2015-02-12 23:06 - 2015-02-12 23:06 - 00000000 ____D () C:\Program Files\iPod 2015-02-12 23:06 - 2015-02-12 23:06 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-02-12 23:05 - 2015-02-12 23:08 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-02-12 23:03 - 2015-02-12 23:03 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2015-02-12 23:03 - 2015-02-12 23:03 - 00000000 ____D () C:\windows\System32\Tasks\Apple 2015-02-12 23:03 - 2015-02-12 23:03 - 00000000 ____D () C:\Users\jerry\AppData\Local\Apple 2015-02-12 23:02 - 2015-02-12 23:03 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2015-02-12 23:00 - 2015-02-12 23:01 - 00000000 ____D () C:\Program Files\Bonjour 2015-02-12 23:00 - 2015-02-12 23:01 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2015-02-12 22:59 - 2015-02-12 23:05 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-02-12 22:38 - 2015-02-12 22:40 - 152439600 _____ (Apple Inc.) C:\Users\jerry\Downloads\itunes6464setup.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-26 16:57 - 2014-08-05 11:09 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-26 16:47 - 2013-04-21 18:53 - 00000892 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-26 16:46 - 2013-03-30 09:55 - 01770429 _____ () C:\windows\WindowsUpdate.log 2015-02-26 16:34 - 2013-04-21 18:53 - 00000896 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-26 16:29 - 2013-04-21 18:53 - 00003892 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-26 15:43 - 2013-04-24 20:09 - 00000000 ____D () C:\Program Files\CCleaner 2015-02-26 15:41 - 2013-04-24 20:09 - 00002772 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC 2015-02-26 15:41 - 2013-04-24 20:09 - 00000833 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2015-02-13 00:47 - 2009-07-13 22:45 - 00018736 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-13 00:47 - 2009-07-13 22:45 - 00018736 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-12 23:50 - 2014-08-05 11:09 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-02-12 23:50 - 2014-08-05 11:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-02-12 23:50 - 2014-08-05 11:08 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-02-12 23:41 - 2009-07-13 22:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2015-02-12 22:58 - 2013-11-26 21:36 - 00000000 ____D () C:\ProgramData\Apple 2015-02-12 22:53 - 2014-09-12 09:39 - 00005617 _____ () C:\windows\system32\lvcoinst.log 2015-02-12 22:53 - 2014-09-12 09:39 - 00000000 ____D () C:\Program Files\Common Files\logishrd 2015-02-12 22:50 - 2014-09-12 08:29 - 00000000 ____D () C:\Program Files (x86)\Logitech 2015-02-12 22:44 - 2009-07-13 23:13 - 00782510 _____ () C:\windows\system32\PerfStringBackup.INI 2015-02-12 22:36 - 2009-07-13 23:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-13 00:41 ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-02-2015 01 Ran by jerry at 2015-02-26 17:02:35 Running from C:\Users\jerry\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.42.34 - Adobe Systems Incorporated) Adobe Reader 9.3 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A93000000001}) (Version: 9.3.0 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{2FE00055-C4F3-4F7A-AEDD-E198D54CF12F}) (Version: 3.1.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{28791292-D18D-42FA-AE66-3D3D20AA8618}) (Version: 3.1.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{5ED7462B-EF58-4757-B609-53755021EC34}) (Version: 8.1.0.18 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.27 - Atheros Communications Inc.) Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 5.2 - Atheros) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.111.0.64 - Conexant) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2086 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) iTunes (HKLM\...\{7B8D4E8A-EA2B-4A71-BFEB-A4AAAB87C5D0}) (Version: 12.1.0.71 - Apple Inc.) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java(TM) 6 Update 17 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216017FF}) (Version: 6.0.170 - Sun Microsystems, Inc.) Malwarebytes Anti-Exploit version 1.05.1.1016 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.05.1.1016 - Malwarebytes) Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.8.1 - Synaptics Incorporated) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 12-09-2014 16:05:37 Windows Update 12-09-2014 17:25:51 Installed Webassessor Sentinel Security Shield™ x64 13-09-2014 02:00:11 Windows Update 14-09-2014 02:00:12 Windows Update 23-09-2014 13:31:44 Windows Update 23-09-2014 13:57:38 Installed AT&T Connect Participant Application v10.7.114. 23-09-2014 14:07:00 Removed AT&T Connect Participant Application v10.7.114. 23-09-2014 14:10:03 Removed Bonjour 23-09-2014 14:12:53 Removed Microsoft Office File Validation Add-In 23-09-2014 14:13:17 Removed Microsoft PowerPoint Viewer 23-09-2014 14:15:15 Removed Microsoft Works 25-09-2014 12:45:57 Windows Update 23-10-2014 14:52:52 Scheduled Checkpoint 23-10-2014 14:53:18 Windows Update 12-02-2015 22:46:10 Removed Webassessor Sentinel Security Shield™ x64 12-02-2015 23:03:34 Installed iTunes 26-02-2015 16:11:32 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 20:34 - 2009-06-10 15:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {27E0CBD2-1912-421B-8B0D-48CBEB964A2F} - System32\Tasks\{8E77E671-FD11-402A-BB70-1B0DD76E39F3} => pcalua.exe -a C:\Users\jerry\Downloads\Impactor_0.9.14\impactor\installer_x86.exe -d C:\Users\jerry\Downloads\Impactor_0.9.14\impactor Task: {502A5686-CC6E-4661-953C-A3BD84C4A245} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION Task: {939335F8-FEE1-4F7A-92AC-1AF8BB932045} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-26] (Google Inc.) Task: {A2C5E0AA-82B4-4660-A0BF-285A1F418E2B} - System32\Tasks\{2DD3EE5F-22D2-4E9B-86C8-21F05D23691D} => pcalua.exe -a C:\Users\jennifer\Downloads\wlsetup-web.exe -d C:\Users\jennifer\Downloads Task: {AE47C330-7824-4137-9889-803BEF5988C1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {D3345348-5D94-4D6E-8D4F-3ED0BA4D362E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-26] (Google Inc.) Task: {E9E87C08-088E-4314-B079-0E20FFED6BD0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-02-19] (Piriform Ltd) Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2015-01-20 22:35 - 2015-01-20 22:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-01-20 22:35 - 2015-01-20 22:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2015-02-26 16:33 - 2015-02-17 16:44 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libglesv2.dll 2015-02-26 16:33 - 2015-02-17 16:44 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libegl.dll 2015-02-26 16:33 - 2015-02-17 16:44 - 09171272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\pdf.dll 2015-02-26 16:33 - 2015-02-17 16:44 - 14965064 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1608575498-428315075-3764911856-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\jerry\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.43.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: ehRecvr => 3 MSCONFIG\Services: ehSched => 3 MSCONFIG\Services: Fax => 3 MSCONFIG\Services: HomeGroupListener => 3 MSCONFIG\Services: HomeGroupProvider => 3 MSCONFIG\Services: iphlpsvc => 2 MSCONFIG\Services: napagent => 3 MSCONFIG\Services: SCardSvr => 3 MSCONFIG\Services: SCPolicySvc => 3 MSCONFIG\Services: TabletInputService => 3 MSCONFIG\Services: WMPNetworkSvc => 2 MSCONFIG\Services: WPCSvc => 3 MSCONFIG\startupfolder: C:^Users^jerry^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk => C:\windows\pss\Logitech . Product Registration.lnk.Startup MSCONFIG\startupreg: LogitechVideoRepair => C:\Program Files (x86)\Logitech\Video\ISStart.exe MSCONFIG\startupreg: LogitechVideoTray => C:\Program Files (x86)\Logitech\Video\LogiTray.exe MSCONFIG\startupreg: Safer-Surf => C:\Program Files (x86)\ver5Safer-Surf\Safer-Surf.exe ==================== Accounts: ============================= Administrator (S-1-5-21-1608575498-428315075-3764911856-500 - Administrator - Disabled) Guest (S-1-5-21-1608575498-428315075-3764911856-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1608575498-428315075-3764911856-1002 - Limited - Enabled) jerry (S-1-5-21-1608575498-428315075-3764911856-1003 - Administrator - Enabled) => C:\Users\jerry ==================== Faulty Device Manager Devices ============= Name: Microsoft Teredo Tunneling Adapter Description: Microsoft Teredo Tunneling Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (02/26/2015 04:18:36 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "37.0.2062.124,language="*",type="win32",version="37.0.2062.124"1". Dependent Assembly 37.0.2062.124,language="*",type="win32",version="37.0.2062.124" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (02/26/2015 04:15:32 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "40.0.2214.111,language="*",type="win32",version="40.0.2214.111"1". Dependent Assembly 40.0.2214.111,language="*",type="win32",version="40.0.2214.111" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (02/26/2015 04:15:32 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "40.0.2214.111,language="*",type="win32",version="40.0.2214.111"1". Dependent Assembly 40.0.2214.111,language="*",type="win32",version="40.0.2214.111" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (09/12/2014 09:01:07 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program msinfo32.exe version 6.1.7601.17514 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1380 Start Time: 01cfce9a0f701e65 Termination Time: 62 Application Path: C:\windows\system32\msinfo32.exe Report Id: 969d1b33-3a8d-11e4-ae63-00266c513509 Error: (09/12/2014 08:33:57 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image of service vulsrsebjh64 since QueryServiceConfig API failed System Error: The system cannot find the file specified. . Error: (09/12/2014 08:33:57 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image of service SW-Sustainer since QueryServiceConfig API failed System Error: The system cannot find the file specified. . Error: (09/12/2014 08:33:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image of service AllDaySavingsService64 since QueryServiceConfig API failed System Error: The system cannot find the file specified. . Error: (09/12/2014 08:33:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary netfilter64. System Error: The system cannot find the file specified. . Error: (09/12/2014 08:32:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image of service vulsrsebjh64 since QueryServiceConfig API failed System Error: The system cannot find the file specified. . Error: (09/12/2014 08:32:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image of service SW-Sustainer since QueryServiceConfig API failed System Error: The system cannot find the file specified. . System errors: ============= Error: (02/26/2015 04:46:57 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The PnkBstrA service terminated unexpectedly. It has done this 1 time(s). Error: (02/26/2015 03:09:41 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 113.69.0.0 Update Source: %NT AUTHORITY51 Update Stage: 4.6.0305.00 Source Path: 4.6.0305.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (02/26/2015 03:09:41 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.191.4826.0 Update Source: %NT AUTHORITY51 Update Stage: 4.6.0305.00 Source Path: 4.6.0305.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (02/26/2015 03:09:41 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.191.4826.0 Update Source: %NT AUTHORITY51 Update Stage: 4.6.0305.00 Source Path: 4.6.0305.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (02/26/2015 03:09:41 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.191.4826.0 Update Source: %NT AUTHORITY59 Update Stage: 4.6.0305.00 Source Path: 4.6.0305.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (02/26/2015 03:07:45 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 113.69.0.0 Update Source: %NT AUTHORITY51 Update Stage: 4.6.0305.00 Source Path: 4.6.0305.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (02/26/2015 03:07:45 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.191.4826.0 Update Source: %NT AUTHORITY51 Update Stage: 4.6.0305.00 Source Path: 4.6.0305.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (02/26/2015 03:07:45 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.191.4826.0 Update Source: %NT AUTHORITY51 Update Stage: 4.6.0305.00 Source Path: 4.6.0305.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (02/26/2015 03:07:45 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.191.4826.0 Update Source: %NT AUTHORITY59 Update Stage: 4.6.0305.00 Source Path: 4.6.0305.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (02/12/2015 10:46:10 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Microsoft Office Sessions: ========================= Error: (02/26/2015 04:18:36 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: 37.0.2062.124,language="*",type="win32",version="37.0.2062.124"C:\$Recycle.Bin\S-1-5-21-1608575498-428315075-3764911856-1003\$RATX73Q.exe Error: (02/26/2015 04:15:32 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: 40.0.2214.111,language="*",type="win32",version="40.0.2214.111"C:\$Recycle.Bin\S-1-5-21-1608575498-428315075-3764911856-1003\$RMJIWFK.exe Error: (02/26/2015 04:15:32 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: 40.0.2214.111,language="*",type="win32",version="40.0.2214.111"C:\$Recycle.Bin\S-1-5-21-1608575498-428315075-3764911856-1003\$RMJIWFK.exe Error: (09/12/2014 09:01:07 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: msinfo32.exe6.1.7601.17514138001cfce9a0f701e6562C:\windows\system32\msinfo32.exe969d1b33-3a8d-11e4-ae63-00266c513509 Error: (09/12/2014 08:33:57 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddWin32ServiceFiles: Unable to back up image of service vulsrsebjh64 since QueryServiceConfig API failed System Error: The system cannot find the file specified. Error: (09/12/2014 08:33:57 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddWin32ServiceFiles: Unable to back up image of service SW-Sustainer since QueryServiceConfig API failed System Error: The system cannot find the file specified. Error: (09/12/2014 08:33:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddWin32ServiceFiles: Unable to back up image of service AllDaySavingsService64 since QueryServiceConfig API failed System Error: The system cannot find the file specified. Error: (09/12/2014 08:33:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary netfilter64. System Error: The system cannot find the file specified. Error: (09/12/2014 08:32:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddWin32ServiceFiles: Unable to back up image of service vulsrsebjh64 since QueryServiceConfig API failed System Error: The system cannot find the file specified. Error: (09/12/2014 08:32:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddWin32ServiceFiles: Unable to back up image of service SW-Sustainer since QueryServiceConfig API failed System Error: The system cannot find the file specified. ==================== Memory info =========================== Processor: Intel(R) Celeron(R) CPU 900 @ 2.20GHz Percentage of memory in use: 65% Total physical RAM: 1915.98 MB Available physical RAM: 662.13 MB Total Pagefile: 3831.95 MB Available Pagefile: 1905.42 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (TI105847W0E) (Fixed) (Total:127.88 GB) (Free:96.23 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.9 GB) (Disk ID: A3418076) Partition 1: (Active) - (Size=1.5 GB) - (Type=27) Partition 2: (Not Active) - (Size=127.9 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=8.9 GB) - (Type=17) ==================== End Of Log ============================ [/QUOTE]
Insert quotes…
Verification
Post reply
Top