Windows Explorer has stopped working - black screen

Thanks in advance for any help you can provide.


My older (2008?) Toshiba running on Windows Vista Home Edition restarted out of nowhere yesterday (it acted like it was shutting down/restarting properly, but I did not initiate it) while I was working on it, and when it rebooted and I logged in, I then received an error that Windows Exlorer has stopped working, and the screen is black.  I cannot see my desktop, icons, taskbar, etc.  I have only been able to run things from the Task Manager, which I open with Ctrl+Alt+Del.  I could see my icons and the taskbar, Start menu, etc. in safe mode.


I since downloaded AVG (my McAfee had recently expired, but I use this computer infrequently) and ran that, as well as Malwarebytes.  I also ran Ad-Aware which I already had on my PC.  All of them found problems during some scans, but after restarting and running them additional times, they are not currently finding problems.  I tried System Restore to two different restore points, as well.  It says the restores were successful, but the Windows Explorer problem did not go away.  I also tried to remove my old McAfee and replaced an old version of Java.


I saw someone else on this forum had had this problem in the past and was able to get it solved, so I hope the same can be done in this case! 


The log from the FRST scan is copied below and the Addition log is attached.


Thank you -




Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-04-2014
Ran by Alison (administrator) on ALISON-PC on 29-04-2014 18:12:36
Running from C:\Users\Alison\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

Welcome to the forum.

See if you're able to run ComboFix:

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix


http://www.bleepingcomputer.com/download/combofix/dl/12/ <---ComboFix direct download

Please make sure you click download buttons that look similar to this, not "sponsored ad links":


Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.



If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.


Link to post
This appeared to fix the problem.  As soon as the log was saved I could see my start menu, background, and icons again.  I disabled my antivirus programs and ran ComboFix from the desktop. When it was done I was not able to access the internet, so I rebooted as the ComboFix guide instructed.  During the reboot I got the blue screen 'dump' and it cited "Bad_Pool_Caller".  Then it kept logging in, asked me what mode since it was in error recovery (I did normal mode), and then it seemed to load normally and here we are.


The log is below.  Thank you for your help!



ComboFix 14-04-30.01 - Alison 04/30/2014  15:20:11.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3062.1946 [GMT -4:00]
Running from: c:\users\Alison\Desktop\ComboFix.exe
AV: AVG Internet Security 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
FW: AVG Internet Security 2014 *Disabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
SP: AVG Internet Security 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Lets clear up all these AVs you have on the system first:

You have AVG, Ad-Aware and some McAfee:

AV: AVG Internet Security 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
FW: AVG Internet Security 2014 *Disabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
SP: AVG Internet Security 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


You can't have 2 AVs on the system.
What do you want to keep?? AVG??

Please uninstall the rest (not Defender)

You can run the McAfee Consumer Product Removal Tool to clean up any McAfee leftovers:


When done.....run another scan with FRST.exe and please make sure the Addition Box is checked.


Link to post
Share on other sites

Thanks for that. The McAfee leftovers were pesky.  I kept AVG, got rid of AdAware.


FRST log below, Addition attached.


Thank you -



Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:30-04-2014 03
Ran by Alison (administrator) on ALISON-PC on 30-04-2014 17:10:13
Running from C:\Users\Alison\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
( ) C:\Windows\System32\lxeacoms.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
() C:\Toshiba\IVP\ISM\pinger.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
() C:\Toshiba\IVP\swupdate\swupdtmr.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe
() C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\loggingserver.exe
() C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe
() C:\Program Files\Toshiba\Utilities\KeNotify.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
() C:\Program Files\Lexmark S300-S400 Series\ezprint.exe
(SEIKO EPSON CORPORATION) C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe
() C:\Program Files\AVG Secure Search\vprot.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(TOSHIBA) C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Spotify Ltd) C:\Users\Alison\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynToshiba.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
==================== One Month Created Files and Folders ========
2014-04-30 17:09 - 2014-04-30 17:09 - 00000000 ____D () C:\Users\Alison\Desktop\FRST-OlderVersion
2014-04-30 16:39 - 2014-04-30 16:39 - 03218352 _____ (McAfee, Inc.) C:\Users\Alison\Downloads\MCPR.exe
2014-04-30 16:04 - 2014-04-30 16:59 - 00000374 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-04-30 16:04 - 2014-04-30 16:04 - 00143376 _____ () C:\Windows\Minidump\Mini043014-01.dmp
2014-04-30 15:44 - 2014-04-30 15:44 - 00016323 _____ () C:\ComboFix.txt
2014-04-30 15:16 - 2011-06-26 02:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-30 15:16 - 2010-11-07 13:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-30 15:16 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-30 15:16 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-30 15:16 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-30 15:16 - 2000-08-30 20:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-30 15:16 - 2000-08-30 20:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-30 15:16 - 2000-08-30 20:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-30 14:52 - 2014-04-30 14:52 - 05197895 ____R (Swearware) C:\Users\Alison\Desktop\ComboFix.exe
2014-04-30 14:44 - 2014-04-30 15:44 - 00000000 ____D () C:\Qoobox
2014-04-30 14:44 - 2014-04-30 14:45 - 05197895 _____ (Swearware) C:\Users\Alison\Downloads\ComboFix (1).exe
2014-04-30 14:43 - 2014-04-30 15:42 - 00000000 ____D () C:\Windows\erdnt
2014-04-30 14:43 - 2014-04-30 14:43 - 05197895 ____R (Swearware) C:\Users\Alison\Downloads\ComboFix.exe
2014-04-29 18:15 - 2014-04-29 18:17 - 00033688 _____ () C:\Users\Alison\Desktop\Addition.txt
2014-04-29 18:12 - 2014-04-30 17:11 - 00020586 _____ () C:\Users\Alison\Desktop\FRST.txt
2014-04-29 18:12 - 2014-04-30 17:10 - 00000000 ____D () C:\FRST
2014-04-29 18:11 - 2014-04-30 17:09 - 01050624 _____ (Farbar) C:\Users\Alison\Desktop\FRST.exe
2014-04-29 17:31 - 2014-04-29 17:31 - 00001635 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-04-29 17:31 - 2014-04-29 17:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-04-29 17:30 - 2014-04-29 17:31 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-04-29 17:30 - 2014-04-29 17:31 - 00000000 ____D () C:\Program Files\iTunes
2014-04-29 17:30 - 2014-04-29 17:30 - 00000000 ____D () C:\Program Files\iPod
2014-04-29 17:17 - 2014-04-29 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-04-29 17:16 - 2014-04-29 17:17 - 00000000 ____D () C:\Program Files\QuickTime
2014-04-29 16:55 - 2014-04-29 16:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-04-29 16:49 - 2014-04-29 16:49 - 00000807 _____ () C:\Users\Public\Desktop\AVG.lnk
2014-04-29 16:48 - 2014-04-29 16:49 - 00000000 ____D () C:\ProgramData\Avg
2014-04-29 16:47 - 2014-04-29 16:49 - 00000000 ____D () C:\Users\Alison\AppData\Local\AvgSetupLog
2014-04-29 16:47 - 2014-04-29 16:47 - 00000000 ____D () C:\Users\Alison\AppData\Local\Avg
2014-04-29 15:24 - 2014-04-30 15:07 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-29 15:23 - 2014-04-29 15:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-29 15:23 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-29 15:23 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-29 15:23 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-29 14:33 - 2014-04-29 15:33 - 17931952 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-04-29 11:19 - 2014-04-29 11:19 - 04981160 _____ (Adobe Systems Inc.) C:\Users\Alison\Downloads\Shockwave_Installer_Slim.exe
2014-04-29 11:08 - 2014-04-29 11:08 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alison\Downloads\mbam-setup- (1).exe
2014-04-29 11:06 - 2014-04-29 11:07 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alison\Downloads\mbam-setup-
2014-04-29 10:59 - 2014-04-29 11:11 - 00000680 _____ () C:\Users\Alison\AppData\Local\d3d9caps.dat
2014-04-28 22:33 - 2014-04-28 22:33 - 00008618 _____ () C:\Users\Alison\Desktop\4-28-2-custom-OTL.Txt
2014-04-28 22:12 - 2014-04-28 22:12 - 00047854 _____ () C:\Users\Alison\Desktop\4-28-1-Extras.Txt
2014-04-28 22:08 - 2014-04-28 22:08 - 00100156 _____ () C:\Users\Alison\Desktop\4-28-1-OTL.Txt
2014-04-28 22:06 - 2014-04-28 22:06 - 00047854 _____ () C:\Users\Alison\Desktop\Extras.Txt
2014-04-28 21:58 - 2014-04-28 22:32 - 00008618 _____ () C:\Users\Alison\Desktop\OTL.Txt
2014-04-28 19:18 - 2014-04-29 15:23 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-28 19:18 - 2014-04-28 19:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-28 16:25 - 2014-04-28 16:25 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\AVG2014
2014-04-28 16:24 - 2014-04-28 16:24 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\TuneUp Software
2014-04-28 16:21 - 2014-04-29 16:53 - 00000000 ____D () C:\ProgramData\AVG2014
2014-04-28 16:21 - 2014-04-28 16:21 - 00000000 ____D () C:\$AVG
2014-04-28 16:20 - 2014-04-29 16:49 - 00000000 ____D () C:\Program Files\AVG
2014-04-28 16:16 - 2014-04-30 16:10 - 00000000 ____D () C:\ProgramData\MFAData
2014-04-28 16:16 - 2014-04-28 16:28 - 00000000 ____D () C:\Users\Alison\AppData\Local\Avg2014
2014-04-28 16:16 - 2014-04-28 16:16 - 00000000 ____D () C:\Users\Alison\AppData\Local\MFAData
2014-04-28 11:26 - 2014-04-28 14:40 - 00064512 _____ () C:\Users\Alison\Desktop\bundle-zip_PAI_Metadata.xls
2014-04-27 14:51 - 2014-04-27 14:52 - 00000000 ____D () C:\ProgramData\AVG Secure Search(202)
2014-04-18 15:02 - 2014-04-18 15:02 - 00199960 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdriverx.sys
2014-04-17 18:44 - 2014-04-17 18:44 - 00029184 _____ () C:\Users\Alison\Downloads\Hourlypaytemplate_2014_ADavies.xls
2014-04-15 13:56 - 2014-04-30 14:38 - 00001942 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-15 13:56 - 2014-04-29 10:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-15 13:46 - 2014-04-29 10:46 - 00000000 ____D () C:\Users\Alison\AppData\Local\Skype
2014-04-15 13:45 - 2014-04-29 10:46 - 00000000 ___RD () C:\Program Files\Skype
2014-04-15 13:45 - 2014-04-29 10:46 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\Skype
2014-04-15 13:45 - 2014-04-15 13:45 - 00001878 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-04-15 13:45 - 2014-04-15 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-04-15 13:45 - 2014-04-15 13:45 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-04-15 13:44 - 2014-04-29 10:45 - 00000000 ____D () C:\ProgramData\Skype
2014-04-15 03:33 - 2014-03-07 19:51 - 12347904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-15 03:33 - 2014-03-07 19:20 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-15 03:33 - 2014-03-07 19:12 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-15 03:33 - 2014-03-07 19:03 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-15 03:33 - 2014-03-07 19:02 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-15 03:33 - 2014-03-07 19:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-15 03:33 - 2014-03-07 19:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-04-15 03:33 - 2014-03-07 18:59 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-15 03:33 - 2014-03-07 18:57 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-04-15 03:33 - 2014-03-07 18:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-15 03:33 - 2014-03-07 18:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-15 03:33 - 2014-03-07 18:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-15 03:33 - 2014-03-07 18:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-15 03:33 - 2014-03-07 18:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-15 03:33 - 2014-03-07 18:52 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-04-15 03:33 - 2014-03-07 18:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-14 12:37 - 2014-04-25 20:10 - 00000000 ____D () C:\Users\Alison\Desktop\TFAll
2014-04-14 11:33 - 2014-02-07 06:38 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-04-14 11:33 - 2014-02-03 06:37 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-04-14 11:33 - 2013-12-04 22:12 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-04-14 11:32 - 2014-02-05 21:56 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-14 11:31 - 2014-01-30 03:46 - 00876032 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-04-14 11:28 - 2013-11-12 20:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-04-14 10:26 - 2014-04-27 18:54 - 00000000 ____D () C:\Users\Alison\AppData\Local\AVG Secure Search
2014-04-14 10:03 - 2014-04-29 10:47 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-04-14 10:02 - 2014-04-29 10:47 - 00000000 ____D () C:\Program Files\AVG Secure Search
2014-03-31 16:11 - 2014-03-31 16:11 - 00211224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdix.sys
2014-03-31 16:11 - 2014-03-31 16:11 - 00108312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx86.sys
==================== One Month Modified Files and Folders =======
2014-04-30 17:11 - 2014-04-29 18:12 - 00020586 _____ () C:\Users\Alison\Desktop\FRST.txt
2014-04-30 17:10 - 2014-04-29 18:12 - 00000000 ____D () C:\FRST
2014-04-30 17:09 - 2014-04-30 17:09 - 00000000 ____D () C:\Users\Alison\Desktop\FRST-OlderVersion
2014-04-30 17:09 - 2014-04-29 18:11 - 01050624 _____ (Farbar) C:\Users\Alison\Desktop\FRST.exe
2014-04-30 17:05 - 2006-11-02 06:33 - 00759542 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-30 17:04 - 2008-04-07 11:21 - 01226605 _____ () C:\Windows\WindowsUpdate.log
2014-04-30 17:00 - 2010-08-11 10:25 - 00028845 _____ () C:\ProgramData\lxeascan.log
2014-04-30 16:59 - 2014-04-30 16:04 - 00000374 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-04-30 16:59 - 2010-04-14 04:11 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-30 16:58 - 2013-09-13 18:03 - 00095374 _____ () C:\Windows\PFRO.log
2014-04-30 16:58 - 2006-11-02 09:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-30 16:58 - 2006-11-02 08:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-30 16:58 - 2006-11-02 08:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-30 16:56 - 2006-11-02 09:01 - 00032634 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-04-30 16:49 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\config\Journal
2014-04-30 16:39 - 2014-04-30 16:39 - 03218352 _____ (McAfee, Inc.) C:\Users\Alison\Downloads\MCPR.exe
2014-04-30 16:35 - 2010-04-14 04:11 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-30 16:35 - 2009-09-20 11:50 - 00000912 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2393571190-2996653842-2028706402-1000UA.job
2014-04-30 16:33 - 2013-06-09 14:18 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-30 16:10 - 2014-04-28 16:16 - 00000000 ____D () C:\ProgramData\MFAData
2014-04-30 16:04 - 2014-04-30 16:04 - 00143376 _____ () C:\Windows\Minidump\Mini043014-01.dmp
2014-04-30 16:04 - 2008-07-18 20:22 - 367062149 _____ () C:\Windows\MEMORY.DMP
2014-04-30 16:04 - 2008-07-18 20:22 - 00000000 ____D () C:\Windows\Minidump
2014-04-30 15:44 - 2014-04-30 15:44 - 00016323 _____ () C:\ComboFix.txt
2014-04-30 15:44 - 2014-04-30 14:44 - 00000000 ____D () C:\Qoobox
2014-04-30 15:44 - 2006-11-02 07:18 - 00000000 __RHD () C:\Users\Default
2014-04-30 15:44 - 2006-11-02 07:18 - 00000000 ___RD () C:\Users\Public
2014-04-30 15:42 - 2014-04-30 14:43 - 00000000 ____D () C:\Windows\erdnt
2014-04-30 15:40 - 2006-11-02 06:23 - 00000215 _____ () C:\Windows\system.ini
2014-04-30 15:07 - 2014-04-29 15:24 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-30 14:52 - 2014-04-30 14:52 - 05197895 ____R (Swearware) C:\Users\Alison\Desktop\ComboFix.exe
2014-04-30 14:45 - 2014-04-30 14:44 - 05197895 _____ (Swearware) C:\Users\Alison\Downloads\ComboFix (1).exe
2014-04-30 14:43 - 2014-04-30 14:43 - 05197895 ____R (Swearware) C:\Users\Alison\Downloads\ComboFix.exe
2014-04-30 14:38 - 2014-04-15 13:56 - 00001942 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-29 18:17 - 2014-04-29 18:15 - 00033688 _____ () C:\Users\Alison\Desktop\Addition.txt
2014-04-29 17:31 - 2014-04-29 17:31 - 00001635 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-04-29 17:31 - 2014-04-29 17:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-04-29 17:31 - 2014-04-29 17:30 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-04-29 17:31 - 2014-04-29 17:30 - 00000000 ____D () C:\Program Files\iTunes
2014-04-29 17:30 - 2014-04-29 17:30 - 00000000 ____D () C:\Program Files\iPod
2014-04-29 17:30 - 2008-07-04 23:08 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-04-29 17:22 - 2008-06-29 15:35 - 00000000 ____D () C:\Users\Alison
2014-04-29 17:20 - 2008-07-04 23:08 - 00000000 ____D () C:\ProgramData\Apple
2014-04-29 17:17 - 2014-04-29 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-04-29 17:17 - 2014-04-29 17:16 - 00000000 ____D () C:\Program Files\QuickTime
2014-04-29 16:55 - 2014-04-29 16:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-04-29 16:53 - 2014-04-28 16:21 - 00000000 ____D () C:\ProgramData\AVG2014
2014-04-29 16:49 - 2014-04-29 16:49 - 00000807 _____ () C:\Users\Public\Desktop\AVG.lnk
2014-04-29 16:49 - 2014-04-29 16:48 - 00000000 ____D () C:\ProgramData\Avg
2014-04-29 16:49 - 2014-04-29 16:47 - 00000000 ____D () C:\Users\Alison\AppData\Local\AvgSetupLog
2014-04-29 16:49 - 2014-04-28 16:20 - 00000000 ____D () C:\Program Files\AVG
2014-04-29 16:47 - 2014-04-29 16:47 - 00000000 ____D () C:\Users\Alison\AppData\Local\Avg
2014-04-29 15:33 - 2014-04-29 14:33 - 17931952 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-04-29 15:33 - 2013-06-09 14:18 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-04-29 15:33 - 2011-07-29 13:04 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-04-29 15:23 - 2014-04-29 15:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-29 15:23 - 2014-04-28 19:18 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-29 14:26 - 2008-12-31 22:05 - 00000410 _____ () C:\Windows\brwmark.ini
2014-04-29 11:19 - 2014-04-29 11:19 - 04981160 _____ (Adobe Systems Inc.) C:\Users\Alison\Downloads\Shockwave_Installer_Slim.exe
2014-04-29 11:19 - 2009-03-15 11:03 - 00000000 ____D () C:\Windows\system32\Adobe
2014-04-29 11:15 - 2008-06-29 15:35 - 00000000 ____D () C:\Users\Alison\AppData\Local\Google
2014-04-29 11:11 - 2014-04-29 10:59 - 00000680 _____ () C:\Users\Alison\AppData\Local\d3d9caps.dat
2014-04-29 11:08 - 2014-04-29 11:08 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alison\Downloads\mbam-setup- (1).exe
2014-04-29 11:07 - 2014-04-29 11:06 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Alison\Downloads\mbam-setup-
2014-04-29 10:51 - 2006-11-02 06:22 - 54525952 _____ () C:\Windows\system32\config\software_previous
2014-04-29 10:51 - 2006-11-02 06:22 - 35651584 _____ () C:\Windows\system32\config\components_previous
2014-04-29 10:51 - 2006-11-02 06:22 - 25427968 _____ () C:\Windows\system32\config\system_previous
2014-04-29 10:51 - 2006-11-02 06:22 - 00786432 _____ () C:\Windows\system32\config\default_previous
2014-04-29 10:51 - 2006-11-02 06:22 - 00262144 _____ () C:\Windows\system32\config\security_previous
2014-04-29 10:51 - 2006-11-02 06:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous
2014-04-29 10:47 - 2014-04-15 13:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-29 10:47 - 2014-04-14 10:03 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-04-29 10:47 - 2014-04-14 10:02 - 00000000 ____D () C:\Program Files\AVG Secure Search
2014-04-29 10:47 - 2013-06-10 16:15 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\Zip Opener Packages
2014-04-29 10:47 - 2013-06-10 16:15 - 00000000 ____D () C:\Program Files\Common Files\AVG Secure Search
2014-04-29 10:47 - 2011-10-24 12:24 - 00000000 ____D () C:\Program Files\Bonjour
2014-04-29 10:47 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\spool
2014-04-29 10:47 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\Msdtc
2014-04-29 10:46 - 2014-04-15 13:46 - 00000000 ____D () C:\Users\Alison\AppData\Local\Skype
2014-04-29 10:46 - 2014-04-15 13:45 - 00000000 ___RD () C:\Program Files\Skype
2014-04-29 10:46 - 2014-04-15 13:45 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\Skype
2014-04-29 10:46 - 2013-09-12 21:15 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\GlarySoft
2014-04-29 10:46 - 2013-09-12 14:25 - 00000000 ____D () C:\AI_CS2_IE_NonRet
2014-04-29 10:46 - 2013-09-11 19:24 - 00000000 ____D () C:\Program Files\Common Files\Adobe Systems Shared
2014-04-29 10:46 - 2013-09-11 15:17 - 00000000 ____D () C:\PhSp_CS2_UE_Ret
2014-04-29 10:46 - 2013-06-28 19:20 - 00000000 ____D () C:\Program Files\Dropbox
2014-04-29 10:46 - 2013-06-04 15:37 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\Spotify
2014-04-29 10:46 - 2010-12-07 21:41 - 00000000 ____D () C:\Program Files\Lexmark Toolbar
2014-04-29 10:46 - 2010-12-07 21:41 - 00000000 ____D () C:\Program Files\Lexmark
2014-04-29 10:46 - 2010-12-07 21:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lexmark
2014-04-29 10:46 - 2010-12-07 21:28 - 00000000 ____D () C:\Program Files\Lexmark S300-S400 Series
2014-04-29 10:46 - 2010-11-13 15:03 - 00000000 ____D () C:\ProgramData\Lexmark S300-S400 Series
2014-04-29 10:46 - 2010-10-09 12:03 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-04-29 10:46 - 2010-10-03 13:13 - 00000000 ____D () C:\Program Files\Lexmark Printable Web
2014-04-29 10:46 - 2008-06-29 19:21 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-04-29 10:46 - 2008-02-18 23:02 - 00000000 ____D () C:\ProgramData\Adobe
2014-04-29 10:46 - 2008-02-18 23:02 - 00000000 ____D () C:\Program Files\Adobe
2014-04-29 10:46 - 2006-11-02 08:37 - 00000000 ____D () C:\Windows\twain_32
2014-04-29 10:46 - 2006-11-02 07:18 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-04-29 10:46 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\registration
2014-04-29 10:46 - 2005-01-02 02:49 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-04-29 10:45 - 2014-04-15 13:44 - 00000000 ____D () C:\ProgramData\Skype
2014-04-29 10:45 - 2013-09-15 14:19 - 00000000 ____D () C:\Program Files\Lavasoft
2014-04-29 10:45 - 2013-09-13 13:36 - 00000000 ____D () C:\Users\Alison\AppData\Local\Seven Zip
2014-04-29 10:45 - 2013-06-28 14:33 - 00000000 ____D () C:\ProgramData\AVG SafeGuard toolbar
2014-04-29 10:45 - 2013-06-10 16:15 - 00000000 ____D () C:\Program Files\AVG SafeGuard toolbar
2014-04-29 10:45 - 2011-07-29 13:39 - 00000000 ____D () C:\Program Files\Apple Software Update
2014-04-29 10:45 - 2010-11-16 20:15 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-04-29 10:45 - 2010-11-16 20:15 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2014-04-29 10:45 - 2010-11-16 20:15 - 00000000 ____D () C:\Program Files\Shutterfly
2014-04-29 10:45 - 2010-08-06 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson
2014-04-29 10:45 - 2010-08-06 14:02 - 00000000 ____D () C:\Program Files\ABBYY FineReader 6.0 Sprint
2014-04-29 10:45 - 2010-08-06 13:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Creativity Suite
2014-04-29 10:45 - 2010-08-06 13:56 - 00000000 ____D () C:\Program Files\epson
2014-04-29 10:45 - 2010-05-27 13:57 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\Microsoft Corporation
2014-04-29 10:45 - 2010-04-14 22:07 - 00000000 ____D () C:\Program Files\Windows Live
2014-04-29 10:45 - 2010-04-14 22:07 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
2014-04-29 10:45 - 2010-02-24 15:25 - 00000000 ____D () C:\Program Files\DIFX
2014-04-29 10:45 - 2010-02-14 02:55 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\Mozilla
2014-04-29 10:45 - 2010-02-02 01:49 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\McAfee
2014-04-29 10:45 - 2009-11-27 21:49 - 00000000 ____D () C:\ProgramData\Real
2014-04-29 10:45 - 2009-10-16 23:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2014-04-29 10:45 - 2009-10-16 23:19 - 00000000 ____D () C:\Program Files\Acro Software
2014-04-29 10:45 - 2009-09-18 13:00 - 00000000 ____D () C:\Windows\system32\EventProviders
2014-04-29 10:45 - 2009-07-23 00:14 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\Sprint
2014-04-29 10:45 - 2009-05-30 14:47 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2014-04-29 10:45 - 2008-11-08 22:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VSO
2014-04-29 10:45 - 2008-11-08 22:10 - 00000000 ____D () C:\Program Files\VSO
2014-04-29 10:45 - 2008-09-02 21:44 - 00000000 ____D () C:\Users\Public\Downloads\Floppy Disk Folder
2014-04-29 10:45 - 2008-09-02 21:44 - 00000000 ____D () C:\Users\Public\Downloads\EGP Manual
2014-04-29 10:45 - 2008-08-26 20:33 - 00000000 ____D () C:\Program Files\Western Digital Technologies
2014-04-29 10:45 - 2008-07-05 19:23 - 00000000 ____D () C:\Users\Alison\AppData\Local\Microsoft Games
2014-04-29 10:45 - 2008-07-05 12:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2014-04-29 10:45 - 2008-07-05 12:14 - 00000000 ____D () C:\Program Files\PhotoDeluxe HE 3.0
2014-04-29 10:45 - 2008-07-05 12:14 - 00000000 ____D () C:\KPCMS
2014-04-29 10:45 - 2008-07-02 15:46 - 00000000 ____D () C:\Users\Public\Downloads\Eudora
2014-04-29 10:45 - 2008-07-02 15:21 - 00000000 ____D () C:\Program Files\Qualcomm
2014-04-29 10:45 - 2008-06-29 19:21 - 00000000 ____D () C:\Program Files\Microsoft CAPICOM
2014-04-29 10:45 - 2008-06-29 17:45 - 00000000 ____D () C:\Program Files\Common Files\L&H
2014-04-29 10:45 - 2008-06-29 17:44 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio
2014-04-29 10:45 - 2008-06-29 17:24 - 00000000 ____D () C:\Program Files\Synaptics
2014-04-29 10:45 - 2008-06-29 15:43 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\Adobe
2014-04-29 10:45 - 2008-04-07 11:50 - 00000000 ____D () C:\Program Files\Camera Assistant Software for Toshiba
2014-04-29 10:45 - 2008-04-07 11:49 - 00000000 ____D () C:\ProgramData\Intel
2014-04-29 10:45 - 2008-04-07 11:43 - 00000000 ____D () C:\Program Files\Apoint2K
2014-04-29 10:45 - 2008-04-07 11:25 - 00000000 ____D () C:\Windows\system32\Lang
2014-04-29 10:45 - 2008-02-18 23:32 - 00000000 ____D () C:\ProgramData\Google
2014-04-29 10:45 - 2008-02-18 23:30 - 00000000 ____D () C:\Program Files\Google
2014-04-29 10:45 - 2008-02-18 23:22 - 00000000 ____D () C:\ProgramData\WildTangent
2014-04-29 10:45 - 2008-02-18 23:05 - 00000000 ____D () C:\Program Files\Java
2014-04-29 10:45 - 2008-02-18 23:05 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-04-29 10:45 - 2008-02-18 22:36 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2014-04-29 10:45 - 2008-02-18 22:27 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-04-29 10:45 - 2008-02-18 22:27 - 00000000 ____D () C:\Program Files\Realtek
2014-04-29 10:45 - 2008-02-18 22:19 - 00000000 ____D () C:\Program Files\Toshiba
2014-04-29 10:45 - 2008-02-18 22:15 - 00000000 ____D () C:\Windows\system32\Macromed
2014-04-29 10:45 - 2006-11-02 08:42 - 00000000 ____D () C:\Windows\WindowsMobile
2014-04-29 10:45 - 2006-11-02 08:42 - 00000000 ____D () C:\Windows\system32\winrm
2014-04-29 10:45 - 2006-11-02 08:42 - 00000000 ____D () C:\Windows\system32\WCN
2014-04-29 10:45 - 2006-11-02 08:42 - 00000000 ____D () C:\Windows\system32\slmgr
2014-04-29 10:45 - 2006-11-02 08:42 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2014-04-29 10:45 - 2006-11-02 08:37 - 00000000 ____D () C:\Windows\system32\XPSViewer
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\Web
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\Speech
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\SMI
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\RemInst
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\networklist
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\MUI
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\licensing
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\IME
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\rescache
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Program Files\Common Files\System
2014-04-29 10:45 - 2006-11-02 07:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-04-29 10:45 - 2005-01-02 03:04 - 00000000 ____D () C:\Windows\sold.old
2014-04-29 10:45 - 2005-01-02 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-04-29 10:45 - 2005-01-02 02:54 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-04-29 10:45 - 2005-01-02 02:47 - 00000000 ____D () C:\Program Files\Microsoft Works
2014-04-29 10:44 - 2008-06-29 15:35 - 00000000 ___RD () C:\Users\Alison\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-04-29 10:44 - 2008-02-20 15:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media
2014-04-29 10:44 - 2008-02-20 15:16 - 00000000 ____D () C:\Program Files\InterVideo
2014-04-29 10:44 - 2008-02-20 15:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD MovieFactory for TOSHIBA
2014-04-29 10:44 - 2008-02-20 15:12 - 00000000 ____D () C:\ProgramData\Ulead Systems
2014-04-29 10:44 - 2008-02-20 15:12 - 00000000 ____D () C:\Program Files\Ulead Systems
2014-04-29 10:44 - 2008-02-20 15:12 - 00000000 ____D () C:\Program Files\Common Files\Ulead Systems
2014-04-29 10:44 - 2008-02-18 23:22 - 00000000 ____D () C:\Program Files\TOSHIBA Games
2014-04-29 10:44 - 2008-02-18 23:13 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared
2014-04-29 10:44 - 2008-02-18 22:54 - 00000000 ____D () C:\Windows\Downloaded Installations
2014-04-29 10:44 - 2008-02-18 22:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA
2014-04-29 10:44 - 2008-02-18 22:18 - 00000000 ____D () C:\Toshiba
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Windows\Performance
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Windows\DigitalLocker
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Users\Public\Recorded TV
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Program Files\Windows Photo Gallery
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Program Files\Windows Journal
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Program Files\Windows Defender
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Program Files\Windows Collaboration
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Program Files\Windows Calendar
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Program Files\MSBuild
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Program Files\Movie Maker
2014-04-29 10:44 - 2006-11-02 08:37 - 00000000 ____D () C:\Program Files\Microsoft Games
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\com
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\system32\catroot2.old
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\Speech
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\security
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\schemas
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\Resources
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\Provisioning
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\PLA
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\MSAgent
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\IME
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\Help
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Windows\Branding
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Program Files\Windows NT
2014-04-29 10:44 - 2006-11-02 07:18 - 00000000 ____D () C:\Program Files\Common Files\SpeechEngines
2014-04-28 22:33 - 2014-04-28 22:33 - 00008618 _____ () C:\Users\Alison\Desktop\4-28-2-custom-OTL.Txt
2014-04-28 22:32 - 2014-04-28 21:58 - 00008618 _____ () C:\Users\Alison\Desktop\OTL.Txt
2014-04-28 22:12 - 2014-04-28 22:12 - 00047854 _____ () C:\Users\Alison\Desktop\4-28-1-Extras.Txt
2014-04-28 22:08 - 2014-04-28 22:08 - 00100156 _____ () C:\Users\Alison\Desktop\4-28-1-OTL.Txt
2014-04-28 22:06 - 2014-04-28 22:06 - 00047854 _____ () C:\Users\Alison\Desktop\Extras.Txt
2014-04-28 19:18 - 2014-04-28 19:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-28 18:57 - 2013-06-04 21:03 - 00262144 _____ () C:\Windows\system32\config\ELAM
2014-04-28 16:28 - 2014-04-28 16:16 - 00000000 ____D () C:\Users\Alison\AppData\Local\Avg2014
2014-04-28 16:25 - 2014-04-28 16:25 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\AVG2014
2014-04-28 16:24 - 2014-04-28 16:24 - 00000000 ____D () C:\Users\Alison\AppData\Roaming\TuneUp Software
2014-04-28 16:21 - 2014-04-28 16:21 - 00000000 ____D () C:\$AVG
2014-04-28 16:16 - 2014-04-28 16:16 - 00000000 ____D () C:\Users\Alison\AppData\Local\MFAData
2014-04-28 14:40 - 2014-04-28 11:26 - 00064512 _____ () C:\Users\Alison\Desktop\bundle-zip_PAI_Metadata.xls
2014-04-27 18:54 - 2014-04-14 10:26 - 00000000 ____D () C:\Users\Alison\AppData\Local\AVG Secure Search
2014-04-27 14:52 - 2014-04-27 14:51 - 00000000 ____D () C:\ProgramData\AVG Secure Search(202)
2014-04-25 20:10 - 2014-04-14 12:37 - 00000000 ____D () C:\Users\Alison\Desktop\TFAll
2014-04-21 10:35 - 2009-09-20 11:50 - 00000860 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2393571190-2996653842-2028706402-1000Core.job
2014-04-20 18:55 - 2013-06-04 15:39 - 00000000 ____D () C:\Users\Alison\AppData\Local\Spotify
2014-04-18 15:02 - 2014-04-18 15:02 - 00199960 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdriverx.sys
2014-04-17 18:44 - 2014-04-17 18:44 - 00029184 _____ () C:\Users\Alison\Downloads\Hourlypaytemplate_2014_ADavies.xls
2014-04-17 10:11 - 2013-09-16 21:53 - 00000843 _____ () C:\Windows\setupact.log
2014-04-15 13:45 - 2014-04-15 13:45 - 00001878 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-04-15 13:45 - 2014-04-15 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-04-15 13:45 - 2014-04-15 13:45 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-04-15 03:56 - 2006-11-02 08:47 - 00535952 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-15 03:37 - 2006-11-02 06:23 - 00000240 _____ () C:\Windows\win.ini
2014-04-15 03:14 - 2013-09-14 14:36 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-15 03:07 - 2010-06-07 03:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-04-14 10:03 - 2008-02-20 15:04 - 00000000 ____D () C:\Windows\system32\RTCOM
2014-04-14 10:02 - 2013-06-10 16:15 - 00042272 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2014-04-03 09:51 - 2014-04-29 15:23 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-29 15:23 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-29 15:23 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 16:11 - 2014-03-31 16:11 - 00211224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdix.sys
2014-03-31 16:11 - 2014-03-31 16:11 - 00108312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx86.sys
2014-03-31 03:51 - 2006-11-02 06:24 - 88028728 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-30 17:04
==================== End Of Log ============================


One additional thing-  I thought I'd paused the AVG full scan that wanted to run when I restarted, but looks like it went through and it found and cleaned one thing.  Here are the details:


Thread: Trojan horse Patched_c.ADKY

Object name: C:\Windows\System32\DriverStore\FileRepository\kr10n.inf_f8c77270\KR10N.

Severity: High

State: Secured

Identified by: Scan

Date: 4/30/2014, 7:05:54 PM




Link to post
Share on other sites

Please uninstall these 2 AVG toolbars:

AVG SafeGuard toolbar 
AVG Security Toolbar 

Here's why:


Download the attached fixlist.txt to the same folder as FRST.exe.
Run FRST.exe and click Fix only once and wait
The tool will create a log (Fixlog.txt) in the folder, please post it to your reply.


Please download AdwCleaner from HERE or HERE to your desktop.

  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you may want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review. (all items found are adware/spyware/foistware)
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted:
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.


For Malwarebytes 2.0, please run a Threat Scan
Click on Settings > Detection and Protection > Non-Malware Protection > PUP (Potentially Unwanted Program) detections > Make sure it's set to Treat detections as malware
Same for PUM (Potentially Unwanted Modifications)
Quarantine all that's found
Post the log

Let me know how it is, MrC

Link to post
Share on other sites

Had to use Revo to uninstall the AVG toolbars as instructed in your first link, as the method described by AVG (on the toolbar itself, in IE in my case) did nothing, and going through add/remove programs would start the uninstall but it would stop saying it didn't finish/work.
Logs below.
Logs below.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:30-04-2014 03
Ran by Alison at 2014-04-30 21:15:15 Run:1
Running from C:\Users\Alison\Desktop
Boot Mode: Normal
Content of fixlist:
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe
CHR HKLM\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files\Lavasoft\AdAware SecureSearch Toolbar\chrome-newtab-search.crx [2014-04-15]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
R2 vToolbarUpdater18.0.5; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [1771032 2014-04-14] (AVG Secure Search)
[4032] C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe => Process closed successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\oejkcgajlodefenbbjdnaiahmbnnoole => Key deleted successfully.
"C:\Program Files\Lavasoft\AdAware SecureSearch Toolbar\chrome-newtab-search.crx" => File/Directory not found.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
vToolbarUpdater18.0.5 => Service deleted successfully.
C:\Users\Alison\AppData\Roaming\McAfee => Moved successfully.
==== End of Fixlog ====
# AdwCleaner v3.205 - Report created 30/04/2014 at 21:30:03
# Updated 28/04/2014 by Xplode
# Operating System : Windows Vista Home Premium Service Pack 2 (32 bits)
# Username : Alison - ALISON-PC
# Running from : C:\Users\Alison\Downloads\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : vToolbarUpdater18.0.5
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files\Toolbar Cleaner
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Alison\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Alison\AppData\LocalLow\adawaretb
Folder Deleted : C:\Users\Alison\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Alison\AppData\Roaming\DSite
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Key Deleted : HKLM\Software\Classes\popcaploader.popcaploaderctrl2
Key Deleted : HKLM\Software\Classes\popcaploader.popcaploaderctrl2.1
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E4E3E0F8-CD30-4380-8CE9-B96904BDEFCA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE8A736F-4124-4D9C-B4B1-3B12381EFABE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C9C5DEAF-0A1F-4660-8279-9EDFAD6FEFE1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Key Deleted : HKCU\Software\dsiteproducts
Key Deleted : HKCU\Software\WEDLMNGR
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\adawaretb
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\Toolbar Cleaner
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG SafeGuard toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DSite
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Zip Opener Packages
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16545
-\\ Google Chrome v34.0.1847.131
[ File : C:\Users\Alison\AppData\Local\Google\Chrome\User Data\Default\preferences ]
AdwCleaner[R0].txt - [5478 octets] - [30/04/2014 21:21:31]
AdwCleaner[s0].txt - [5673 octets] - [30/04/2014 21:30:03]
########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [5733 octets] ##########






Sorry, didn't get a notification about your post for some reason.  


Still working great and no signs of issues returning.  No sign of the AVG toolbars being pesky, either (though I was never having the same issues with them taking over browsers as others mention online bc I disabled it early on).


Thank you so much for your help!  



Lets check your computers security before you go and we have a little cleanup to do also:

Download Security Check by screen317 from HERE or HERE.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • If you get Unsupported operating system. Aborting now, just reboot and try again.
  • A Notepad document should open automatically called checkup.txt.
  • Please Post the contents of that document.
  • Do Not Attach It!!!
Link to post
Share on other sites

Here's the log. 



 Results of screen317's Security Check version 0.99.82  


 Internet Explorer 11  

``````````````Antivirus/Firewall Check:`````````````` 

 Windows Security Center service is not running! This report may not be accurate! 

AVG Internet Security 2014   

 WMI entry may not exist for antivirus; attempting automatic update. 

`````````Anti-malware/Other Utilities Check:````````` 

 Adobe Flash Player  

 Google Chrome 34.0.1847.116  

 Google Chrome 34.0.1847.131  

````````Process Check: objlist.exe by Laurent````````  

`````````````````System Health check````````````````` 

 Total Fragmentation on Drive C::  

````````````````````End of Log`````````````````````` 
That looks OK.....

A little clean up to do....

Please Uninstall ComboFix: (if you used it)

Press the Windows logo key + R to bring up the "run box"

Copy and paste next command in the field:

ComboFix /uninstall

Make sure there's a space between Combofix and /


Then hit enter. (it may look like CF is re-installing but it's not)

This will uninstall Combofix, delete its related folders and files, hide file extensions, hide the system/hidden files and clears System Restore cache and create new Restore point

(If that doesn't work.....you can simply rename ComboFix.exe to Uninstall.exe and double click it to complete the uninstall or download and run the uninstaller)


bwebb7v.jpgDownload Delfix from here and save it to your desktop. (you may already have this)

  • Ensure Remove disinfection tools is checked.
  • Click the Run button.
  • Reboot
Any other programs or logs that are still remaining, you can manually delete. (right click.....Delete)

IE: RogueKiller.exe, RKreport.txt, RK_Quarantine folder, C:\FRST folder, FRST-OlderVersion folder, MBAR folder, etc....AdwCleaner > just run the program and click uninstall.


If you used FRST and can't delete the quarantine folder:

Download the fixlist.txt to the same folder as FRST.exe.

Run FRST.exe and click Fix only once and wait

That will delete the quarantine folder created by FRST.

The rest you can manually delete.


Any questions...please post back.

If you think I've helped you, please leave a comment > click on my avatar picture > click Profile Feed.

Take a look at My Preventive Maintenance to avoid being infected again. (My Preventive Maintenance also found HERE)

Good Luck and Thanks for using the forum, MrC

Link to post
Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

