AVG is out. Avast is in, and Glary is uninstalled. To be honest, I'm a little worried about the Glary thing. It is somehow getting installed on the computers at work, and I was a little suspicious of it when I first saw it on one of those PCs but guessed that one of my co-workers in IT decided to install it.

I am very careful about tools that are advertised with "FIX ALL ERRORS" and "SPEED UP YOUR MACHINE". Without some level of registry and system knowledge users are not able to control what are they doing actually. Below you will find two good readings about this kind of software:
Microsoft support policy for the use of registry cleaning utilities
Miekiemoes (Microsoft MVP) blog

Post me fresh FRST & Addidtion reports. Let's see what has changed and what still has to be done.

FRST.gif Fix with Farbar Recovery Scan Tool

icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif

icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

Press the WindowsKey.png + R on your keyboard at the same time. Type Notepad and click OK.

  • Copy the entire content of the codebox below and paste into the Notepad document:

    startHKLM\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start http://www.avg.com/w...C05RDIwQy0zN1RT"&"inst=NzctMTIyNzA3NzAwOS1GSSsxLUZMMTArMS1ERFQrMC1UVUcrMy1MU0QrM (the data entry has 100 more characters).Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Metacafe.lnkShortcutTarget: Metacafe.lnk -> C:\$RECYCLE.BIN\S-1-5-21-3726736968-409882640-1958551794-1000\MetacafeAgent.exe (No File)Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No FileWinsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [223232] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)S3 catchme; \??\C:\ComboFix\catchme.sys [X]2014-08-22 14:00 - 2014-08-23 16:48 - 00000000 ____D () C:\ProgramData\HitmanPro2014-08-20 18:46 - 2014-08-20 18:46 - 00000666 _____ () C:\Toolbars.dat2014-08-19 23:07 - 2014-08-27 09:44 - 00000000 ____D () C:\ProgramData\GlarySoft2014-08-17 16:29 - 2014-08-17 16:29 - 04763288 _____ (AVG Technologies) C:\Users\savas.kyriakidis\Downloads\avg_avct_stb_all_2014_4745.exe2014-08-17 15:54 - 2014-08-17 15:54 - 04462440 _____ (AVG Technologies) C:\Users\savas.kyriakidis\Downloads\avg_avct_stb_all_2014_4335_welcomecmp.exe2014-08-16 17:04 - 2014-08-16 17:05 - 04755832 _____ (AVG Technologies) C:\Users\savas.kyriakidis\Downloads\avg_free_stb_all_2014_4744_cnet.exe2014-08-15 13:32 - 2014-08-15 13:32 - 06534584 _____ (Systweak Software ) C:\Users\savas.kyriakidis\Downloads\PCDiagnosisProTPSSetup.exe2014-08-14 18:19 - 2014-08-27 09:44 - 00000000 ____D () C:\Users\savas.kyriakidis\AppData\Roaming\GlarySoft2014-08-14 18:19 - 2014-08-23 11:16 - 00000000 ____D () C:\Users\savas.kyriakidis\AppData\Roaming\DiskDefrag2014-08-14 18:18 - 2014-08-14 18:18 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup (5).exe2014-08-14 18:18 - 2014-08-14 18:18 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup (4).exe2014-08-14 18:15 - 2014-08-14 18:16 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup (3).exe2014-08-14 18:15 - 2014-08-14 18:15 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup (2).exe2014-08-14 18:14 - 2014-08-14 18:14 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup (1).exe2014-08-14 18:13 - 2014-08-14 18:13 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup.exe2014-08-15 11:17 - 2014-08-15 11:17 - 03552760 _____ (tuneuppro.com ) C:\Users\savas.kyriakidis\Downloads\tall_150803173445318587.exe2014-08-15 11:17 - 2014-08-15 11:17 - 03552760 _____ (tuneuppro.com ) C:\Users\savas.kyriakidis\Downloads\tall_150803172000784607.exe2014-08-14 17:37 - 2014-08-14 17:40 - 03552760 _____ (tuneuppro.com ) C:\Users\savas.kyriakidis\Downloads\tall_140809374825884190.exe2014-08-14 17:37 - 2014-08-14 17:37 - 03552760 _____ (tuneuppro.com ) C:\Users\savas.kyriakidis\Downloads\tall_140809372042763201.exe2014-08-14 17:37 - 2014-08-14 17:37 - 03552760 _____ (tuneuppro.com ) C:\Users\savas.kyriakidis\Downloads\tall_140809371092783465.exe2014-08-27 10:44 - 2011-07-10 19:25 - 00000000 ____D () C:\Program Files\AVG2014-08-27 10:41 - 2014-08-27 10:41 - 03386520 _____ (AVG Technologies CZ, s.r.o.) C:\Users\savas.kyriakidis\Downloads\avg_remover_stf_x86_2014_4116.exe2014-08-27 09:44 - 2014-08-19 23:07 - 00000000 ____D () C:\ProgramData\GlarySoft2014-08-27 09:44 - 2014-08-14 18:19 - 00000000 ____D () C:\Users\savas.kyriakidis\AppData\Roaming\GlarySoft2014-08-22 14:32 - 2014-08-22 14:32 - 00000000 ____D () C:\Users\savas.kyriakidis\Documents\ProcAlyzer Dumps2014-08-16 12:05 - 2014-08-16 12:05 - 00000000 ____D () C:\ProgramData\SlimWare Utilities Inc2014-08-16 12:05 - 2014-08-15 20:57 - 00000000 ____D () C:\Users\savas.kyriakidis\AppData\Local\SlimWare Utilities Inc2014-08-16 12:04 - 2014-08-16 12:04 - 00000000 ____D () C:\Users\savas.kyriakidis\AppData\Local\Downloaded Installers2014-08-16 09:22 - 2014-08-15 20:56 - 00000000 ____D () C:\Program Files\DriverUpdateAlternateDataStreams: C:\ProgramData\TEMP:0B4227B4AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2Task: {FCAFF07B-D3AC-4A0C-A6E2-6C23DFC270C9} - \{B7983C11-5FD9-12B1-4EAA-DE223F2AD5D5} No Task File <==== ATTENTIONTask: {C22BB22A-70B9-4AEA-B6E6-2234A457F078} - System32\Tasks\SlimCleaner Plus (Scheduled Scan - savas.kyriakidis) => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exeC:\Program Files\SlimCleaner PlusTask: {C22BB22A-70B9-4AEA-B6E6-2234A457F078} - System32\Tasks\SlimCleaner Plus (Scheduled Scan - savas.kyriakidis) => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exeTask: {788B04FA-AA4F-4BCC-9AAE-A2881E7E64E6} - \Scheduled Update for Ask Toolbar No Task File <==== ATTENTIONTask: {510F6543-BD19-48A5-9E5E-D5E371879760} - System32\Tasks\AVG\PC Tuneup 2011\Integrator\Start On Rita Logon => C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exeC:\Program Files\AVGTask: {510F6543-BD19-48A5-9E5E-D5E371879760} - System32\Tasks\AVG\PC Tuneup 2011\Integrator\Start On Rita Logon => C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exeTask: {30B9F70E-3CAE-49C3-9D96-BE89B7AA59AB} - \Time Trigger Test Task No Task File <==== ATTENTIONTask: {2343967C-C69F-44DE-8AA3-E9113A3466E5} - \Security Center Update - 754758581 No Task File <==== ATTENTIONTask: {1D455FF0-01E6-438C-A9D6-27C72AC03552} - \PC Performer No Task File <==== ATTENTIONCMD: netsh winsock resetEmptyTemp:end
  • Click File, Save As and type fixlist.txt as the File Name.

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.

    > XP users click run after receipt of Windows Security Warning - Open File.

    > 8 users will be prompted about Windows SmartScreen protection - click More information and Run.

  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please include it in your reply.

Share on other sites

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:23-08-2014

Ran by savas.kyriakidis at 2014-08-27 14:33:58 Run:2

Running from F:\

Boot Mode: Normal




Content of fixlist:



HKLM\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start http://www.avg.com/w...C05RDIwQy0zN1RT"&"inst=NzctMTIyNzA3NzAwOS1GSSsxLUZMMTArMS1ERFQrMC1UVUcrMy1MU0QrM (the data entry has 100 more characters).

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Metacafe.lnk

ShortcutTarget: Metacafe.lnk -> C:\$RECYCLE.BIN\S-1-5-21-3726736968-409882640-1958551794-1000\MetacafeAgent.exe (No File)

Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File

Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [223232] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"

Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)

S3 catchme; \??\C:\ComboFix\catchme.sys [X]

2014-08-22 14:00 - 2014-08-23 16:48 - 00000000 ____D () C:\ProgramData\HitmanPro

2014-08-20 18:46 - 2014-08-20 18:46 - 00000666 _____ () C:\Toolbars.dat

2014-08-19 23:07 - 2014-08-27 09:44 - 00000000 ____D () C:\ProgramData\GlarySoft

2014-08-17 16:29 - 2014-08-17 16:29 - 04763288 _____ (AVG Technologies) C:\Users\savas.kyriakidis\Downloads\avg_avct_stb_all_2014_4745.exe

2014-08-17 15:54 - 2014-08-17 15:54 - 04462440 _____ (AVG Technologies) C:\Users\savas.kyriakidis\Downloads\avg_avct_stb_all_2014_4335_welcomecmp.exe

2014-08-16 17:04 - 2014-08-16 17:05 - 04755832 _____ (AVG Technologies) C:\Users\savas.kyriakidis\Downloads\avg_free_stb_all_2014_4744_cnet.exe

2014-08-15 13:32 - 2014-08-15 13:32 - 06534584 _____ (Systweak Software ) C:\Users\savas.kyriakidis\Downloads\PCDiagnosisProTPSSetup.exe

2014-08-14 18:19 - 2014-08-27 09:44 - 00000000 ____D () C:\Users\savas.kyriakidis\AppData\Roaming\GlarySoft

2014-08-14 18:19 - 2014-08-23 11:16 - 00000000 ____D () C:\Users\savas.kyriakidis\AppData\Roaming\DiskDefrag

2014-08-14 18:18 - 2014-08-14 18:18 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup (5).exe

2014-08-14 18:18 - 2014-08-14 18:18 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup (4).exe

2014-08-14 18:15 - 2014-08-14 18:16 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup (3).exe

2014-08-14 18:15 - 2014-08-14 18:15 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup (2).exe

2014-08-14 18:14 - 2014-08-14 18:14 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup (1).exe

2014-08-14 18:13 - 2014-08-14 18:13 - 14416448 _____ () C:\Users\savas.kyriakidis\Downloads\gu5setup.exe

2014-08-15 11:17 - 2014-08-15 11:17 - 03552760 _____ (tuneuppro.com ) C:\Users\savas.kyriakidis\Downloads\tall_150803173445318587.exe

2014-08-15 11:17 - 2014-08-15 11:17 - 03552760 _____ (tuneuppro.com ) C:\Users\savas.kyriakidis\Downloads\tall_150803172000784607.exe

2014-08-14 17:37 - 2014-08-14 17:40 - 03552760 _____ (tuneuppro.com ) C:\Users\savas.kyriakidis\Downloads\tall_140809374825884190.exe

2014-08-14 17:37 - 2014-08-14 17:37 - 03552760 _____ (tuneuppro.com ) C:\Users\savas.kyriakidis\Downloads\tall_140809372042763201.exe

2014-08-14 17:37 - 2014-08-14 17:37 - 03552760 _____ (tuneuppro.com ) C:\Users\savas.kyriakidis\Downloads\tall_140809371092783465.exe

2014-08-27 10:44 - 2011-07-10 19:25 - 00000000 ____D () C:\Program Files\AVG

2014-08-27 10:41 - 2014-08-27 10:41 - 03386520 _____ (AVG Technologies CZ, s.r.o.) C:\Users\savas.kyriakidis\Downloads\avg_remover_stf_x86_2014_4116.exe

2014-08-27 09:44 - 2014-08-19 23:07 - 00000000 ____D () C:\ProgramData\GlarySoft

2014-08-27 09:44 - 2014-08-14 18:19 - 00000000 ____D () C:\Users\savas.kyriakidis\AppData\Roaming\GlarySoft

2014-08-22 14:32 - 2014-08-22 14:32 - 00000000 ____D () C:\Users\savas.kyriakidis\Documents\ProcAlyzer Dumps

2014-08-16 12:05 - 2014-08-16 12:05 - 00000000 ____D () C:\ProgramData\SlimWare Utilities Inc

2014-08-16 12:05 - 2014-08-15 20:57 - 00000000 ____D () C:\Users\savas.kyriakidis\AppData\Local\SlimWare Utilities Inc

2014-08-16 12:04 - 2014-08-16 12:04 - 00000000 ____D () C:\Users\savas.kyriakidis\AppData\Local\Downloaded Installers

2014-08-16 09:22 - 2014-08-15 20:56 - 00000000 ____D () C:\Program Files\DriverUpdate

AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4

AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2

Task: {FCAFF07B-D3AC-4A0C-A6E2-6C23DFC270C9} - \{B7983C11-5FD9-12B1-4EAA-DE223F2AD5D5} No Task File <==== ATTENTION

Task: {C22BB22A-70B9-4AEA-B6E6-2234A457F078} - System32\Tasks\SlimCleaner Plus (Scheduled Scan - savas.kyriakidis) => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe

C:\Program Files\SlimCleaner Plus

Task: {C22BB22A-70B9-4AEA-B6E6-2234A457F078} - System32\Tasks\SlimCleaner Plus (Scheduled Scan - savas.kyriakidis) => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe

Task: {788B04FA-AA4F-4BCC-9AAE-A2881E7E64E6} - \Scheduled Update for Ask Toolbar No Task File <==== ATTENTION

Task: {510F6543-BD19-48A5-9E5E-D5E371879760} - System32\Tasks\AVG\PC Tuneup 2011\Integrator\Start On Rita Logon => C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe

C:\Program Files\AVG

Task: {510F6543-BD19-48A5-9E5E-D5E371879760} - System32\Tasks\AVG\PC Tuneup 2011\Integrator\Start On Rita Logon => C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe

Task: {30B9F70E-3CAE-49C3-9D96-BE89B7AA59AB} - \Time Trigger Test Task No Task File <==== ATTENTION

Task: {2343967C-C69F-44DE-8AA3-E9113A3466E5} - \Security Center Update - 754758581 No Task File <==== ATTENTION

Task: {1D455FF0-01E6-438C-A9D6-27C72AC03552} - \PC Performer No Task File <==== ATTENTION

CMD: netsh winsock reset





HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AvgUninstallURL => value deleted successfully.

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Metacafe.lnk => Moved successfully.

C:\$RECYCLE.BIN\S-1-5-21-3726736968-409882640-1958551794-1000\MetacafeAgent.exe not found.

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully.

"HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => Key not found.

Winsock: Catalog5 entry 000000000001\\LibraryPath  was set successfully to %SystemRoot%\system32\NLAapi.dll

"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007" => Key deleted successfully.

catchme => Service deleted successfully.

C:\ProgramData\HitmanPro => Moved successfully.

C:\Toolbars.dat => Moved successfully.

C:\ProgramData\GlarySoft => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\avg_avct_stb_all_2014_4745.exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\avg_avct_stb_all_2014_4335_welcomecmp.exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\avg_free_stb_all_2014_4744_cnet.exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\PCDiagnosisProTPSSetup.exe => Moved successfully.

C:\Users\savas.kyriakidis\AppData\Roaming\GlarySoft => Moved successfully.

C:\Users\savas.kyriakidis\AppData\Roaming\DiskDefrag => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\gu5setup (5).exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\gu5setup (4).exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\gu5setup (3).exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\gu5setup (2).exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\gu5setup (1).exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\gu5setup.exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\tall_150803173445318587.exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\tall_150803172000784607.exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\tall_140809374825884190.exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\tall_140809372042763201.exe => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\tall_140809371092783465.exe => Moved successfully.

C:\Program Files\AVG => Moved successfully.

C:\Users\savas.kyriakidis\Downloads\avg_remover_stf_x86_2014_4116.exe => Moved successfully.

"C:\ProgramData\GlarySoft" => File/Directory not found.

"C:\Users\savas.kyriakidis\AppData\Roaming\GlarySoft" => File/Directory not found.

C:\Users\savas.kyriakidis\Documents\ProcAlyzer Dumps => Moved successfully.

C:\ProgramData\SlimWare Utilities Inc => Moved successfully.

C:\Users\savas.kyriakidis\AppData\Local\SlimWare Utilities Inc => Moved successfully.

C:\Users\savas.kyriakidis\AppData\Local\Downloaded Installers => Moved successfully.

C:\Program Files\DriverUpdate => Moved successfully.

C:\ProgramData\TEMP => ":0B4227B4" ADS removed successfully.

C:\ProgramData\TEMP => ":DFC5A2B2" ADS removed successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FCAFF07B-D3AC-4A0C-A6E2-6C23DFC270C9}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FCAFF07B-D3AC-4A0C-A6E2-6C23DFC270C9}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B7983C11-5FD9-12B1-4EAA-DE223F2AD5D5}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C22BB22A-70B9-4AEA-B6E6-2234A457F078}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C22BB22A-70B9-4AEA-B6E6-2234A457F078}" => Key deleted successfully.

C:\Windows\System32\Tasks\SlimCleaner Plus (Scheduled Scan - savas.kyriakidis) => Moved successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SlimCleaner Plus (Scheduled Scan - savas.kyriakidis)" => Key deleted successfully.

"C:\Program Files\SlimCleaner Plus" => File/Directory not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C22BB22A-70B9-4AEA-B6E6-2234A457F078}" => Key not found.

C:\Windows\System32\Tasks\SlimCleaner Plus (Scheduled Scan - savas.kyriakidis) not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SlimCleaner Plus (Scheduled Scan - savas.kyriakidis)" => Key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{788B04FA-AA4F-4BCC-9AAE-A2881E7E64E6}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{788B04FA-AA4F-4BCC-9AAE-A2881E7E64E6}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{510F6543-BD19-48A5-9E5E-D5E371879760}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{510F6543-BD19-48A5-9E5E-D5E371879760}" => Key deleted successfully.

C:\Windows\System32\Tasks\AVG\PC Tuneup 2011\Integrator\Start On Rita Logon => Moved successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG\PC Tuneup 2011\Integrator\Start On Rita Logon" => Key deleted successfully.

"C:\Program Files\AVG" => File/Directory not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{510F6543-BD19-48A5-9E5E-D5E371879760}" => Key not found.

C:\Windows\System32\Tasks\AVG\PC Tuneup 2011\Integrator\Start On Rita Logon not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG\PC Tuneup 2011\Integrator\Start On Rita Logon" => Key not found.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{30B9F70E-3CAE-49C3-9D96-BE89B7AA59AB}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{30B9F70E-3CAE-49C3-9D96-BE89B7AA59AB}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Time Trigger Test Task" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2343967C-C69F-44DE-8AA3-E9113A3466E5}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2343967C-C69F-44DE-8AA3-E9113A3466E5}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 754758581" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1D455FF0-01E6-438C-A9D6-27C72AC03552}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D455FF0-01E6-438C-A9D6-27C72AC03552}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Performer" => Key deleted successfully.


=========  netsh winsock reset =========


Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003


Sucessfully reset the Winsock Catalog.

You must restart the computer in order to complete the reset.



========= End of CMD: =========


EmptyTemp: => Removed 200 MB temporary data.



The system needed a reboot. 


==== End of Fixlog ====

Very good :)
Update me about any remaining issues.

51c9d14017fa0-SecurityCheck.PNG Scan with Security Check

Please download Security Check by Screen317 and save it to your desktop.

  • Right-click on 51c9d14017fa0-SecurityCheck.PNG icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Follow onscreen instructions inside the black box. This scan won't take long.
  • Soon a notepad document called checkup.txt will open automaticaly.

Please include the content of that document.

Here you go:

 Results of screen317's Security Check version 0.99.87  
 Windows Vista Service Pack 2 x86 (UAC is enabled)  
 Internet Explorer 9  
 Internet Explorer 8  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
 WMI entry may not exist for antivirus; attempting automatic update. 
`````````Anti-malware/Other Utilities Check:````````` 
 Adobe Reader 10.1.11 Adobe Reader out of Date!  
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast avastui.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 0 % 
````````````````````End of Log`````````````````````` 
About the line stating that Reader is out of date, I checked for updates from the program, and it claims that this version is the most up-to-date. I know Reader XI is out there, but Adobe doesn't seem to want to let me download it. If this isn't a serious concern, then just ignore this last part of my post.
I'm afraid I'm not really sure what you are wanting, as your last post did not specify how you wanted me to update you about any remaining issues. I assume, because your last message consisted on a quote to your last reply yesterday concerning the Security Check log, that you want me to run that scan again. Here are the results.


Results of screen317's Security Check version 0.99.87 
 Windows Vista Service Pack 2 x86 (UAC is enabled) 
 Internet Explorer 9 
 Internet Explorer 8 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled! 
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Adobe Reader 10.1.11 Adobe Reader out of Date! 
````````Process Check: objlist.exe by Laurent```````` 
 AVAST Software Avast AvastSvc.exe 
 AVAST Software Avast avastui.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 0 %
````````````````````End of Log``````````````````````

So, just an update from me? No scan?


The system appears to be working much better now. The safer/codeidentifiers/0 section of the registry has not added back any restrictions on what applications can be run. No more Chrome auto-generating windows are appearing, pointed to an IP address.


Everything looks good now, in my opinion.

That's what I wanted to hear / read actually :)
51a5ce45263de-delfix.png Clean with DelFix
Please download DelFix by Xplode and save it to your desktop.

  • Right-click on 51a5ce45263de-delfix.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Ensure that Remove disinfection tools, Purge system restore and Reset system settings are checked.
  • Push Run.
  • When finished, it will display a notepad report.

Include it for my review.
Here you are.


Deleted : C:\Users\savas.kyriakidis\Desktop\JRT.txt
Deleted : C:\Users\savas.kyriakidis\Downloads\ComboFix.exe
Deleted : C:\Windows\grep.exe
Deleted : C:\Windows\PEV.exe
Deleted : C:\Windows\NIRCMD.exe
Deleted : C:\Windows\MBR.exe
Deleted : C:\Windows\SED.exe
Deleted : C:\Windows\SWREG.exe
Deleted : C:\Windows\SWSC.exe
Deleted : C:\Windows\SWXCACLS.exe
Deleted : C:\Windows\Zip.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe
~ Cleaning system restore ...
Deleted : RP #2081 [scheduled Checkpoint | 08/11/2014 02:11:41]
Deleted : RP #2082 [scheduled Checkpoint | 08/11/2014 15:01:42]
Deleted : RP #2083 [scheduled Checkpoint | 08/12/2014 10:45:08]
Deleted : RP #2084 [scheduled Checkpoint | 08/14/2014 02:36:25]
Deleted : RP #2086 [Tuneup Pro Thu, Aug 14, 14  17:59 | 08/14/2014 21:59:38]
Deleted : RP #2088 [Advanced-System Protector | 08/14/2014 23:31:34]
Deleted : RP #2089 [Removed SofTest | 08/15/2014 23:47:04]
Deleted : RP #2090 [Removed DriverUpdate | 08/16/2014 13:18:06]
Deleted : RP #2091 [Removed HTC Sync. | 08/16/2014 13:29:10]
Deleted : RP #2092 [Removed HTC Sync. | 08/16/2014 13:44:46]
Deleted : RP #2093 [Removed HTC BMP USB Driver. | 08/16/2014 14:02:17]
Deleted : RP #2095 [Advanced-System Protector | 08/16/2014 16:47:50]
Deleted : RP #2096 [installed AVG 2014 | 08/16/2014 21:58:06]
Deleted : RP #2097 [Removed SlimCleaner Plus | 08/16/2014 22:11:41]
Deleted : RP #2098 [Removed HTC Driver Installer. | 08/16/2014 22:14:50]
Deleted : RP #2099 [installed AVG 2014 | 08/17/2014 19:56:09]
Deleted : RP #2100 [installed AVG 2014 | 08/17/2014 19:59:04]
Deleted : RP #2101 [Removed AVG 2014 | 08/17/2014 20:03:04]
Deleted : RP #2102 [installed AVG 2011 | 08/17/2014 20:04:51]
Deleted : RP #2103 [installed AVG 2014 | 08/17/2014 21:08:16]
Deleted : RP #2104 [installed AVG 2014 | 08/17/2014 21:16:20]
Deleted : RP #2105 [Removed AVG 2014 | 08/17/2014 21:24:43]
Deleted : RP #2106 [installed AVG 2011 | 08/17/2014 21:26:10]
Deleted : RP #2108 [Advanced-System Protector | 08/19/2014 21:04:48]
Deleted : RP #2110 [Advanced-System Protector | 08/21/2014 01:40:12]
Deleted : RP #2111 [Checkpoint by HitmanPro | 08/23/2014 20:47:11]
Deleted : RP #2112 [Removed AVG 2011 | 08/26/2014 12:19:57]
Deleted : RP #2113 [Removed AVG 2011 | 08/26/2014 12:22:43]
Deleted : RP #2114 [scheduled Checkpoint | 08/27/2014 04:00:00]
Deleted : RP #2115 [Removed AVG 2011 | 08/27/2014 13:28:23]
Deleted : RP #2117 [avast! antivirus system restore point | 08/27/2014 14:51:04]
Deleted : RP #2118 [Removed Dell Dock | 08/27/2014 20:12:59]
Deleted : RP #2119 [Removed Java 6 Update 5 | 08/27/2014 20:28:20]
New restore point created !
~ Resetting system settings ... OK
########## - EOF - ##########
Thank you for all of your help. I will be donating.
I appreciate it :)

Below you will find my thoughts about securing your machine. Go ahead through it, you will benefit from some useful advice about safe computing.


Recommended reading:

icon_exclaim.gif MUST READ - security tips: Computer Security - a short guide to staying safer online.
icon_exclaim.gif MUST READ - general maintenance: What to do if your Computer is running slowly?

Recommended additional software:

icon_arrow.gif TFC - to clean unneeded temporary files.
icon_arrow.gif Malwarebytes' Anti-Malware - to scan your system from time to time in search for malware.
icon_arrow.gif Malwarebytes' Anti-Exploit - to prevent plenty of mostly exploited vulnerabilities.
icon_arrow.gif McShield - to prevent infections spread by removable media.
icon_arrow.gif CryptoPrevent - to secure yourself from very severe CryptoLocker infection.
icon_arrow.gif Unchecky - to prevent from installing additional foistware, implemented in legitimate installations.

Now if you have any other questions, feel free to ask me. Otherwise simply acknowledge my recommendations and this topic will be closed.


Stay safe,
Naat :)

Sorry about the delay on replying. I'm in the process of leaving my current job and starting a new one. So, it's become very busy around here lately. Anyhow, I have pointed this thread out to the owner of the PC and emphasized the importance of your last post and the links therein. Also, I just completed the donation process. Thank you for your help.


Mods, you have the greenlight from me to close this thread.

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

