Jump to content

Pops with ad-type.google.com and redirecting tradeadexchange.com


Recommended Posts

Hi I am facing this issue, where if i click on any webpage, it leads to new popup which starts with ad-type.google.com and then redirects to tradeadexchange.com or goo.gl or other websites which change from time to time. I have tried several anti-malware programs available on the Cnet.com downloads, it is a very persistant infection, malwarebytes, spybot etc, adwcleaner found some folder related to babylon, bitguard, opencandy and HPadddata, which were deleted by adwcleaner, I have also removed all extra software, only very basic software remains, also removed any add-on, reset browsers tried to search in safe mode with networking as well, the scans are clean but the redirect pops remain.

 

Farbar scans are attached and additional.txt reports are attached , can you please advise how to handle this. 

 

Regards

 

Sameer

----------

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-08-2015
Ran by SAMEER (ATTENTION: The logged in user is not administrator) on KBC-PC (18-08-2015 10:21:12)
Running from C:\Downloads\Farbar
Loaded Profiles: SAMEER (Available Profiles: KBC & SAMEER)
Platform: Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> csrss.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> lsm.exe
Failed to access process -> winlogon.exe
Failed to access process -> svchost.exe
Failed to access process -> ASCService.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> SLsvc.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> agrsmsvc.exe
Failed to access process -> svchost.exe
Failed to access process -> CLCapSvc.exe
Failed to access process -> FreeAgentService.exe
Failed to access process -> McSACore.exe
Failed to access process -> mfemms.exe
Failed to access process -> mfevtps.exe
Failed to access process -> svchost.exe
Failed to access process -> mfevtps.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> RichVideo.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
Failed to access process -> mfefire.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> CLSched.exe
Failed to access process -> McAPExe.exe
Failed to access process -> rundll32.exe
Failed to access process -> mfefire.exe
Failed to access process -> McSvHost.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
Failed to access process -> svchost.exe
Failed to access process -> WmiPrvSE.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [155648 2006-09-12] (Alps Electric Co., Ltd.)
HKLM\...\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [562688 2015-02-11] (McAfee, Inc.)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKLM\...\Policies\Explorer\Run: [] =>
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig]  <===== ATTENTION
HKU\S-1-5-21-595894999-490155728-2440704941-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6453528 2015-07-18] (Piriform Ltd)
HKU\S-1-5-18\...\RunOnce: [] => [X]

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-595894999-490155728-2440704941-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.co.in/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-595894999-490155728-2440704941-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} ->  No File
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll [2015-03-03] (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 113.193.1.60 113.193.0.148
Tcpip\..\Interfaces\{7A8B311E-52BC-474D-92E3-3E6266593E19}: [DhcpNameServer] 113.193.1.60 113.193.0.148

FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-03-03] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-14] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-14] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-06-18]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files\McAfee\SiteAdvisor [2014-03-05]
FF HKLM\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-03-05]

Chrome:
=======
CHR Profile: C:\Users\SAMEER\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (SiteAdvisor) - C:\Users\SAMEER\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-07-31]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\SAMEER\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-31]
CHR Extension: (Chrome Web Store Payments) - C:\Users\SAMEER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-31]
CHR Extension: (Gmail) - C:\Users\SAMEER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-26]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx [2014-03-05]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdvancedSystemCareService8; C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe [814880 2015-04-03] (IObit)
R2 CLCapSvc; C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvc.exe [274529 2007-01-06] () [File not signed]
R2 CLSched; C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSched.exe [118879 2007-01-06] () [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2008-07-07] (Macrovision Europe Ltd.) [File not signed]
R2 FreeAgentGoNext Service; D:\Program Files\Sync\FreeAgentService.exe [189736 2009-12-18] (Seagate Technology LLC)
R2 HomeNetSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 iphlpsvc; C:\Windows\System32\svchost.exe [21504 2008-01-19] (Microsoft Corporation)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-31] (IObit)
R2 lmhosts; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [132160 2015-08-04] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [690408 2015-03-03] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [476680 2015-02-27] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [196600 2015-02-17] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [334576 2015-03-01] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [238288 2015-02-17] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2008-07-18] (Hewlett-Packard) [File not signed]
R2 NlaSvc; C:\Windows\System32\svchost.exe [21504 2008-01-19] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-07-18] (Hewlett-Packard) [File not signed]
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [262247 2007-01-05] () [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S2 0044371439871909mcinstcleanup; C:\Windows\TEMP\004437~1.EXE -cleanup -nolog [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [9728 2006-11-23] (Lenovo Corporation)
R3 AKSIFDH; C:\Windows\System32\DRIVERS\aksifdh.sys [48296 2007-09-11] (Aladdin Knowledge Systems, Ltd.)
S3 CapFilt; C:\Windows\system32\Drivers\CapFilt.sys [18944 2007-09-21] (ensurebit) [File not signed]
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [61848 2015-02-17] (McAfee, Inc.)
R1 DritekPortIO; C:\Program Files\EzButton\DPortIO.sys [20112 2006-11-02] (Dritek System Inc.)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2010-07-15] () [File not signed]
R3 eTSCFLT; C:\Windows\System32\DRIVERS\eTSCFLT.sys [12456 2007-09-11] (Aladdin Knowledge Systems, Ltd.)
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2010-07-15] () [File not signed]
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [147912 2013-09-23] (McAfee, Inc.)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [95616 2012-09-06] (Huawei Technologies Co., Ltd.)
S3 huawei_cdcecm; C:\Windows\System32\DRIVERS\ew_jucdcecm.sys [67584 2012-09-06] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27520 2012-09-06] (Huawei Technologies Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [304928 2015-02-17] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [260248 2015-02-17] (McAfee, Inc.)
R0 mfedisk; C:\Windows\System32\DRIVERS\mfedisk.sys [82800 2015-02-17] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [371648 2015-02-17] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [648552 2015-02-17] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [380496 2015-01-16] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [80760 2015-01-16] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [217584 2015-02-17] (McAfee, Inc.)
R3 TridVid; C:\Windows\System32\DRIVERS\TridVid.sys [159104 2007-09-21] (Trident Multimedia Technologies Co.,Ltd)
S3 UDA; C:\Windows\System32\Drivers\rcudawdm.sys [25760 2012-04-17] (Rainbow China Co,. Ltd.)
S3 wdf_usb_vista; C:\Windows\System32\DRIVERS\usb2ser_vista.sys [38912 2012-10-11] (MediaTek Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 EraserUtilDrv11110; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11110.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
U2 wuaserv; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-17 17:16 - 2015-08-17 17:17 - 00000583 _____ C:\AdwCleaner[s11].txt
2015-08-17 15:40 - 2015-08-17 15:40 - 00000000 ____D C:\ProgramData\ProductData
2015-08-17 14:31 - 2015-07-22 02:25 - 01206192 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-17 14:31 - 2015-07-21 21:37 - 03605440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-08-17 14:31 - 2015-07-21 21:37 - 03553216 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-17 14:31 - 2015-07-21 21:37 - 00140224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys
2015-08-17 14:31 - 2015-07-21 21:37 - 00056256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-17 14:31 - 2015-07-21 21:33 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll
2015-08-17 14:31 - 2015-07-21 21:33 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-17 14:31 - 2015-07-21 21:33 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-17 14:30 - 2015-08-01 00:57 - 00103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-17 14:29 - 2015-07-09 19:50 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2015-08-17 14:28 - 2015-07-11 01:07 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-17 14:27 - 2015-07-11 21:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-17 14:24 - 2015-07-18 21:33 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-17 14:23 - 2015-08-01 03:38 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-08-17 14:23 - 2015-08-01 02:11 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-17 14:23 - 2015-08-01 02:10 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-08-17 14:23 - 2015-08-01 02:05 - 00682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-08-17 14:23 - 2015-08-01 02:03 - 02066944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-17 14:23 - 2015-08-01 02:03 - 01072640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-17 14:23 - 2015-08-01 02:03 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-17 14:23 - 2015-08-01 02:03 - 00297472 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-17 14:23 - 2015-07-11 01:07 - 01402368 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-17 14:23 - 2015-07-11 01:07 - 01253376 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-17 13:01 - 2015-08-17 13:01 - 00122311 _____ C:\Users\KBC\Desktop\JRT.txt
2015-08-17 12:15 - 2015-08-17 12:15 - 00001654 _____ C:\Windows\PFRO.log
2015-08-17 10:56 - 2015-08-18 10:21 - 00000000 ____D C:\FRST
2015-08-17 10:53 - 2015-08-17 10:54 - 01676800 _____ (Farbar) C:\Users\SAMEER\Downloads\FRST (1).exe
2015-08-17 10:19 - 2015-08-17 10:22 - 00000584 _____ C:\AdwCleaner[s10].txt
2015-08-16 16:48 - 2015-08-16 16:50 - 00000582 _____ C:\AdwCleaner[s9].txt
2015-08-16 16:36 - 2015-08-16 16:36 - 00000000 ____D C:\Users\SAMEER\AppData\Local\HP
2015-08-16 16:29 - 2015-08-16 16:29 - 00000903 _____ C:\Users\SAMEER\Desktop\Internet Explorer.lnk
2015-08-16 15:46 - 2015-07-01 21:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-16 15:45 - 2015-07-09 19:55 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-16 15:45 - 2015-07-09 19:55 - 00151040 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-16 13:43 - 2015-08-16 13:43 - 00000626 _____ C:\Users\KBC\Desktop\Tcpview.exe.lnk
2015-08-16 11:23 - 2015-08-16 11:23 - 00000981 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2015-08-16 11:22 - 2015-08-16 11:46 - 00001922 _____ C:\Users\Public\Desktop\Advanced SystemCare 8.lnk
2015-08-16 11:22 - 2015-08-16 11:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8
2015-08-16 11:10 - 2015-08-16 11:10 - 00000778 _____ C:\AdwCleaner[C6].txt
2015-08-16 11:06 - 2015-08-16 11:07 - 00000675 _____ C:\AdwCleaner[s8].txt
2015-08-15 22:52 - 2015-08-15 22:52 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-15 22:52 - 2015-08-15 22:52 - 00000859 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-08-15 22:52 - 2015-08-15 22:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-15 22:51 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-15 22:51 - 2015-06-18 08:41 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-08-15 22:51 - 2015-06-18 08:41 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-08-15 22:13 - 2015-08-17 17:19 - 00035064 _____ C:\Windows\system32\Drivers\TrueSight.sys
2015-08-15 22:13 - 2015-08-15 22:49 - 00000000 ____D C:\ProgramData\RogueKiller
2015-08-15 20:16 - 2015-08-15 22:52 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-08-14 16:54 - 2015-08-14 16:54 - 00001931 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-14 16:54 - 2015-08-14 16:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-14 16:52 - 2015-08-18 09:59 - 00000880 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-14 16:52 - 2015-08-18 09:48 - 00000876 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-14 16:39 - 2015-08-14 16:39 - 00000293 _____ C:\Users\SAMEER\Desktop\Local Disk © - Shortcut.lnk
2015-08-14 14:19 - 2015-08-14 15:51 - 00000000 ____D C:\Users\SAMEER\AppData\Local\AdFender
2015-08-14 14:07 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\is-K9FIV.tmp
2015-08-14 12:43 - 2015-07-23 02:24 - 12386816 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-14 12:43 - 2015-07-23 02:24 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-14 12:43 - 2015-07-23 02:21 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-14 12:43 - 2015-07-23 02:17 - 09751040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-14 12:43 - 2015-07-23 02:16 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-14 12:43 - 2015-07-23 02:16 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-14 12:43 - 2015-07-23 02:15 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-14 12:43 - 2015-07-23 02:15 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-08-14 12:43 - 2015-07-23 02:15 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-14 12:43 - 2015-07-23 02:13 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-14 12:43 - 2015-07-23 02:13 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-08-14 12:43 - 2015-07-23 02:13 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-08-14 12:43 - 2015-07-23 02:12 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-13 15:53 - 2015-08-13 15:53 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-12 12:39 - 2015-08-15 11:38 - 00000000 ____D C:\AdwCleaner
2015-08-05 00:03 - 2015-08-05 00:03 - 00877152 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2015-08-05 00:03 - 2015-08-05 00:03 - 00538208 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2015-08-01 19:05 - 2015-08-01 20:01 - 00000000 ____D C:\Users\SAMEER\AppData\Roaming\Skype
2015-08-01 19:05 - 2015-08-01 19:05 - 00000000 ____D C:\Users\SAMEER\AppData\Local\Skype
2015-08-01 13:38 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default\AppData\Roaming\ProductData
2015-08-01 13:38 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ProductData
2015-08-01 09:52 - 2015-07-03 21:34 - 01316864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-31 16:24 - 2015-07-31 16:24 - 00000000 ____D C:\Users\SAMEER\AppData\Roaming\ProductData
2015-07-31 16:23 - 2015-08-18 09:49 - 00013072 _____ C:\Users\SAMEER\AppData\Roaming\nvModes.dat
2015-07-31 16:23 - 2015-08-18 09:49 - 00013072 _____ C:\Users\SAMEER\AppData\Roaming\nvModes.001
2015-07-31 15:34 - 2015-06-08 14:13 - 00348488 _____ (Lavasoft Limited) C:\Windows\system32\LavasoftTcpService.dll
2015-07-31 15:29 - 2015-08-12 13:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2015-07-31 14:12 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default\AppData\Roaming\IObit
2015-07-31 14:12 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default User\AppData\Roaming\IObit
2015-07-30 22:25 - 2015-08-18 09:58 - 01010393 _____ C:\Windows\WindowsUpdate.log
2015-07-29 16:58 - 2015-06-17 22:20 - 02264576 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-29 16:58 - 2015-06-17 20:39 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-29 16:57 - 2015-06-12 21:31 - 00298496 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-29 16:44 - 2015-04-24 21:24 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-07-29 16:39 - 2015-03-05 08:02 - 00244152 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-07-29 16:39 - 2015-03-05 07:53 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-07-29 16:00 - 2015-05-31 13:41 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-07-29 16:00 - 2015-04-11 04:52 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-07-29 15:58 - 2015-06-27 21:33 - 00783872 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-29 15:58 - 2015-06-27 21:32 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-29 15:58 - 2015-06-27 21:32 - 00218112 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-29 15:58 - 2015-06-27 21:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-07-29 15:58 - 2015-06-27 19:51 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-29 15:58 - 2015-06-27 19:51 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-29 15:58 - 2015-06-12 18:43 - 00440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-07-29 15:58 - 2015-04-30 21:33 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-07-29 15:58 - 2015-01-09 05:47 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-29 15:57 - 2015-05-09 04:38 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-07-29 15:55 - 2015-05-05 04:21 - 10628608 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-07-29 15:55 - 2015-05-05 04:20 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-07-29 15:55 - 2015-05-05 04:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-07-29 15:55 - 2015-05-05 04:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-07-29 15:55 - 2015-05-05 02:51 - 08147456 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-07-26 15:07 - 2015-08-14 16:40 - 00000000 ____D C:\Users\SAMEER\AppData\Local\Google
2015-07-26 15:06 - 2015-07-31 16:55 - 00000000 ____D C:\Users\SAMEER\AppData\Roaming\IObit

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-18 10:19 - 2007-09-21 09:43 - 15966515 _____ C:\FaceProv.log
2015-08-18 09:48 - 2006-11-02 18:28 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-18 09:48 - 2006-11-02 18:15 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-18 09:48 - 2006-11-02 18:15 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-18 09:47 - 2008-01-28 14:40 - 00000012 _____ C:\Windows\bthservsdp.dat
2015-08-18 09:47 - 2006-11-02 18:28 - 00032646 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-17 17:10 - 2011-02-28 09:46 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-17 17:08 - 2013-07-31 15:16 - 00000000 ____D C:\Windows\system32\MRT
2015-08-17 17:02 - 2006-11-02 16:48 - 00000000 ____D C:\Windows\Microsoft.NET
2015-08-17 17:01 - 2006-11-02 15:54 - 129304528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-08-17 16:53 - 2006-11-02 15:53 - 00000254 _____ C:\Windows\win.ini
2015-08-17 15:38 - 2006-11-02 18:14 - 00399736 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-17 15:34 - 2006-11-02 18:05 - 00000000 ____D C:\Windows\system32\XPSViewer
2015-08-17 12:16 - 2008-01-25 10:14 - 00090657 _____ C:\Users\KBC\AppData\Roaming\nvModes.001
2015-08-17 10:51 - 2011-12-30 16:35 - 00000000 ____D C:\fakepath
2015-08-17 10:24 - 2015-03-31 20:13 - 00000000 ____D C:\ProgramData\IObit
2015-08-17 10:17 - 2012-10-05 22:32 - 00000000 ____D C:\Temp delete after use
2015-08-16 16:36 - 2008-03-03 10:34 - 00000000 ____D C:\Users\SAMEER\AppData\Local\VirtualStore
2015-08-16 13:44 - 2010-02-16 13:51 - 00000000 ____D C:\Users\KBC\AppData\Local\CrashDumps
2015-08-16 11:51 - 2008-01-25 10:14 - 00090657 _____ C:\Users\KBC\AppData\Roaming\nvModes.dat
2015-08-16 11:31 - 2008-03-03 10:34 - 00000000 ____D C:\Users\SAMEER
2015-08-16 11:19 - 2015-03-31 20:00 - 00000000 ____D C:\Program Files\IObit
2015-08-16 07:40 - 2014-03-05 13:19 - 00000000 ____D C:\Program Files\McAfee
2015-08-15 11:47 - 2015-02-22 19:50 - 00000000 ____D C:\Users\KBC\AppData\Local\Google
2015-08-14 16:53 - 2015-02-22 19:51 - 00000000 ____D C:\Program Files\Google
2015-08-14 16:30 - 2009-06-24 14:18 - 00000000 ____D C:\ProgramData\Skype
2015-08-14 16:27 - 2014-03-10 19:37 - 00000000 ____D C:\Program Files\VideoLAN
2015-08-14 16:22 - 2008-01-29 17:37 - 00000909 _____ C:\Users\KBC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-14 16:07 - 2009-11-09 11:28 - 00766602 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-14 14:51 - 2008-02-13 17:32 - 00000000 ____D C:\Program Files\Acro Software
2015-08-14 14:50 - 2008-02-13 17:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2015-08-01 11:05 - 2007-09-21 09:45 - 00026822 _____ C:\HeadVideo.log
2015-07-31 22:51 - 2014-09-12 15:04 - 00000000 ____D C:\Program Files\DC-Unlocker
2015-07-31 20:56 - 2006-11-02 16:48 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-07-31 17:22 - 2011-10-28 11:17 - 00000000 ____D C:\Program Files\Camtech
2015-07-31 16:56 - 2012-05-24 19:29 - 00000000 ____D C:\Users\KBC\AppData\Roaming\Philipp Winterberg
2015-07-30 21:59 - 2011-02-27 12:34 - 00000000 ____D C:\Windows\pss
2015-07-30 21:56 - 2011-02-27 10:00 - 00000764 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-30 21:56 - 2011-02-27 10:00 - 00000000 ____D C:\Program Files\CCleaner
2015-07-30 21:46 - 2011-02-25 17:06 - 00000000 ____D C:\Program Files\Adobe
2015-07-30 21:46 - 2008-01-25 17:00 - 00000000 ____D C:\ProgramData\Adobe
2015-07-30 21:46 - 2008-01-25 17:00 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-07-30 21:45 - 2011-06-04 11:33 - 00000000 ____D C:\Program Files\EASEUS
2015-07-30 19:51 - 2008-02-19 16:00 - 00060928 _____ C:\Users\KBC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-30 17:06 - 2011-02-27 10:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-30 11:47 - 2006-11-02 16:48 - 00000000 ____D C:\Windows\rescache
2015-07-26 15:36 - 2014-09-12 17:53 - 00000000 ____D C:\Program Files\Common Files\XCPCSync.OEM
2015-07-26 15:36 - 2011-07-05 12:22 - 00000000 ____D C:\Users\KBC\AppData\Local\Research In Motion
2015-07-26 15:36 - 2010-11-14 12:27 - 00004819 _____ C:\Users\KBC\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2015-07-26 15:36 - 2010-07-09 14:33 - 00000000 ____D C:\Program Files\Common Files\Research In Motion
2015-07-26 15:07 - 2008-03-03 10:36 - 00106864 _____ C:\Users\SAMEER\AppData\Local\GDIPFONTCACHEV1.DAT

==================== Files in the root of some directories =======

2015-07-31 16:23 - 2015-08-18 09:49 - 0013072 _____ () C:\Users\SAMEER\AppData\Roaming\nvModes.001
2015-07-31 16:23 - 2015-08-18 09:49 - 0013072 _____ () C:\Users\SAMEER\AppData\Roaming\nvModes.dat
2014-02-20 16:13 - 2014-02-20 16:13 - 0000057 _____ () C:\ProgramData\Ament.ini
2013-03-25 15:30 - 2013-03-25 15:30 - 0002001 _____ () C:\ProgramData\eTdsWizard1314_A8D59B57-C4D3-4DEE-88D4-9466F7421A5F.swidtag
2009-06-24 14:28 - 2009-06-24 14:28 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2008-02-12 14:45 - 2014-04-12 14:40 - 0043280 _____ () C:\ProgramData\hpzinstall.log

Some files in TEMP:
====================
C:\Users\KBC\AppData\Local\Temp\ASCSetup_478330.exe
C:\Users\KBC\AppData\Local\Temp\ASCSetup_6832921.exe
C:\Users\KBC\AppData\Local\Temp\dllnt_dump.dll

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

ATTENTION: ==> Kan geen toegang krijgen tot BCD. Gebruiker is geen beheerder.

==================== End of log ============================

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version:17-08-2015
Ran by SAMEER (2015-08-18 10:22:19)
Running from C:\Downloads\Farbar
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-595894999-490155728-2440704941-500 - Administrator - Disabled)
Guest (S-1-5-21-595894999-490155728-2440704941-501 - Limited - Enabled)
KBC (S-1-5-21-595894999-490155728-2440704941-1001 - Administrator - Enabled) => C:\Users\KBC
SAMEER (S-1-5-21-595894999-490155728-2440704941-1002 - Limited - Enabled) => C:\Users\SAMEER

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Out of date) {A751AC20-3B48-5237-898A-78C4436BB78D}
AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

32 Bit HP CIO Components Installer (Version: 3.1.1 - Hewlett-Packard) Hidden
Advanced SystemCare 8 (HKLM\...\Advanced SystemCare 8_is1) (Version: 8.3.0 - IObit)
Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version:  - Agere Systems)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform)
DHTML Editing Component (HKLM\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
EASEUS Partition Master 6.5.2 Home Edition (HKLM\...\EASEUS Partition Master Home Edition_is1) (Version:  - EASEUS)
Easy Button (HKLM\...\EzButton) (Version:  - )
EasyCapture2.5 (HKLM\...\EasyCapture2.5) (Version:  - )
EnergyCut (HKLM\...\{6E127727-CE4B-40E4-9A7D-9D65CDE0A15C}) (Version: 1.00 - )
eToken PKI Client 4.55 (HKLM\...\{2146B7E6-FC1C-4230-9952-E9CA2260AA08}) (Version: 4.55.22 - Aladdin Knowledge Systems Ltd.)
Google Chrome (HKLM\...\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
HP Deskjet 3540 series Basic Device Software (HKLM\...\{29E641BB-2183-4653-B589-18B10E5D9635}) (Version: 32.1.145.46951 - Hewlett-Packard Co.)
HP Deskjet 3540 series Help (HKLM\...\{1D456349-7D00-479E-A2A9-C846CE390FE5}) (Version: 30.0.0 - Hewlett Packard)
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Internet Telephone (Version: 4.60 - Callserve Communications Ltd) Hidden
Internet Telephone 4.60 (HKLM\...\{B24E6473-5600-42D0-BD57-8E4B85ACD0BD}) (Version:  - )
IObit Uninstaller (HKLM\...\IObitUninstall) (Version: 4.3.0.5 - IObit)
Lenovo Bluetooth with Enhanced Data Rate Software 6.0.1.3400 (HKLM\...\{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}) (Version: 6.0.1.3400 - Lenovo.)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
McAfee Internet Security (HKLM\...\MSC) (Version: 14.0.339 - McAfee, Inc.)
McAfee SiteAdvisor (HKLM\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.7.264 - McAfee, Inc.)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Business 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
Power2Go 5.0 (HKLM\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version:  - )
PowerCineama MagicDirector Module (HKLM\...\{13E613EF-BB55-11D9-9D77-000129760D75}) (Version:  - )
PowerCinema MakeDisc Module (HKLM\...\{FC4F90EC-B1DA-11D9-9D77-000129760D75}) (Version:  - )
Product Improvement Study for HP Deskjet 3540 series (HKLM\...\{6945C9BA-710C-4776-BB1C-F5F2368AE45E}) (Version: 32.1.145.46951 - Hewlett-Packard Co.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5350 - Realtek Semiconductor Corp.)
Seagate Manager Installer (HKLM\...\InstallShield_{3F5CFC1C-653B-4B22-9153-2BDDF2E03C0E}) (Version: 2.01.0700 - Seagate)
Seagate Manager Installer (Version: 2.01.0700 - Seagate) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
ShuttleCenter (HKLM\...\{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version:  - )
Spelling Dictionaries Support For Adobe Reader 8 (HKLM\...\{AC76BA86-7AD7-5464-3428-800000000003}) (Version: 8.0.0 - Adobe Systems)
Tally.ERP 9 (HKLM\...\{AAF5BFFE-1A0B-4A9E-B726-82AC4DD26B59}) (Version:  - ©Tally Solutions Pvt. Ltd., 1988-2011.)
VeriFace (HKLM\...\VeriFace) (Version:  - )
Windows Driver Package - Animation Technologies Inc. (TridVid) Media  (01/17/2007 1.287.3.10) (HKLM\...\A06EE73B1C7DE59F5A907866B9F81C6A89C49529) (Version: 01/17/2007 1.287.3.10 - Animation Technologies Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Restore Points =========================

ATTENTION: System Restore is disabled
Check "winmgmt" service or repair WMI.

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 15:53 - 2006-09-19 03:11 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job =>
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job =>

==================== Loaded Modules (Whitelisted) ==============

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318} => "default"="DiskDrive"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318} => "default"="DiskDrive"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-595894999-490155728-2440704941-1002\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 113.193.1.60 - 113.193.0.148
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: EnergyCut => C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe
MSCONFIG\startupreg: EzButton => C:\PROGRA~1\EzButton\EzButton.EXE
MSCONFIG\startupreg: Web Companion => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{220A476B-2141-449D-97EA-DBDA5CED72C0}] => (Allow) C:\Program Files\Lenovo\ShuttleCenter\PCMService.exe
FirewallRules: [{A8C034E5-DF54-44B8-A7A8-58EC1EC3DA18}] => (Allow) C:\Program Files\Lenovo\ShuttleCenter\PCMService.exe
FirewallRules: [{63C51BF3-A473-45F9-AA15-805921301115}] => (Allow) E:\setup\hpznui01.exe
FirewallRules: [{81B5AEA8-4A93-4596-835D-560BE99C65D4}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{FB21CEB4-2A28-4E9D-A279-EB54545DD1E6}] => (Allow) LPort=80
FirewallRules: [{2030BD37-94FF-42A5-B91B-518748F4B633}] => (Allow) LPort=80
FirewallRules: [{F968B3A9-1A68-4965-A197-70674883C713}] => (Allow) LPort=80
FirewallRules: [{A2702353-55E3-44ED-88D8-D1A0A8EDDF58}] => (Allow) C:\Program Files\HP\HP Deskjet 3540 series\Bin\DeviceSetup.exe
FirewallRules: [{D1F5E28F-7053-4A6F-BC0F-004589AD897F}] => (Allow) LPort=5357
FirewallRules: [{870B7F5E-22FB-40F2-8722-75D88567B902}] => (Allow) C:\Program Files\HP\HP Deskjet 3540 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{0F642D0E-4922-49AD-AEAE-E318A9EDDEC6}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{8BD673B0-C91A-4F8F-A4BC-DCF3DE6D332D}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{427C8CB5-8362-47AC-942F-A4AFE073965F}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{4D4956A9-88F3-4D3C-8DCA-70A746A4AF7E}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: Microsoft Tun Miniport Adapter #2
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

==================== Event log errors: =========================

Application errors:
==================
Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/17/2015 05:08:02 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (08/17/2015 05:08:01 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

Error: (08/17/2015 03:49:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16684 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 1248
Start Time: 01d0d8d609462d32
Termination Time: 125

Error: (08/17/2015 02:17:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16684 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 10ac
Start Time: 01d0d8c8329774b9
Termination Time: 141

Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The interface is unknown

Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/17/2015 12:14:09 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/16/2015 04:13:33 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

System errors:
=============
Error: (08/18/2015 09:49:52 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (08/18/2015 09:49:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (08/18/2015 09:48:26 AM) (Source: HTTP) (EventID: 15021) (User: )
Description: \Device\Http\ReqQueue0.0.0.0:4482

Error: (08/18/2015 09:43:49 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (08/18/2015 09:43:39 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (08/18/2015 09:42:14 AM) (Source: HTTP) (EventID: 15021) (User: )
Description: \Device\Http\ReqQueue0.0.0.0:4482

Error: (08/17/2015 05:22:29 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000SysMain

Error: (08/17/2015 05:21:59 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000TrkWks

Error: (08/17/2015 05:16:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (08/17/2015 05:14:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Microsoft Office:
=========================
Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/17/2015 05:08:02 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (08/17/2015 05:08:01 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

Error: (08/17/2015 03:49:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.16684124801d0d8d609462d32125

Error: (08/17/2015 02:17:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.1668410ac01d0d8c8329774b9141

Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The interface is unknown

Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/17/2015 12:14:09 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/16/2015 04:13:33 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

CodeIntegrity:
===================================
  Date: 2015-08-18 10:22:09.998
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 10:22:09.390
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 10:22:08.875
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 10:22:08.376
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 10:22:07.518
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 10:22:07.018
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 10:22:06.519
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 10:22:06.020
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 10:22:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\is-K9FIV.tmp because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 10:22:04.881
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\is-K9FIV.tmp because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: Intel® Core2 CPU T5300 @ 1.73GHz
Percentage of memory in use: 49%
Total physical RAM: 2045.75 MB
Available physical RAM: 1036.33 MB
Total Virtual: 4328 MB
Available Virtual: 3330.38 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:58.9 GB) (Free:23.95 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:78.24 GB) (Free:72 GB) NTFS

==================== MBR & Partition Table ==================

==================== End of log ============================

 

 

Link to post
Share on other sites

Hello Sameer and :welcome:! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
You should have admin rights to proceed working here.

Ran by SAMEER (ATTENTION: The logged in user is not administrator) on KBC-PC (18-08-2015 10:21:12)

Then generate new fresh FRST log files.

Link to post
Share on other sites

Thank you Borislav, appreciate your assistance.

Herewith the updated scans with admin login now.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-08-2015
Ran by KBC (administrator) on KBC-PC (18-08-2015 17:38:00)
Running from C:\Downloads\Farbar
Loaded Profiles: KBC (Available Profiles: KBC & SAMEER)
Platform: Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IObit) C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
() C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvc.exe
(Seagate Technology LLC) D:\Program Files\Sync\FreeAgentService.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
() C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSched.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 8\Monitor.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Seagate LLC) D:\Program Files\FreeAgent Status\stxmenumgr.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [155648 2006-09-12] (Alps Electric Co., Ltd.)
HKLM\...\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [562688 2015-02-11] (McAfee, Inc.)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKLM\...\Policies\Explorer\Run: [] =>
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig]  <===== ATTENTION
HKU\S-1-5-19\...\RunOnce: [] => [X]
HKU\S-1-5-20\...\RunOnce: [] => [X]
HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6453528 2015-07-18] (Piriform Ltd)
HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\Run: [Advanced SystemCare 8] => C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe [2429728 2015-04-08] (IObit)
HKU\S-1-5-18\...\RunOnce: [] => [X]

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-595894999-490155728-2440704941-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
HKU\S-1-5-21-595894999-490155728-2440704941-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} ->  No File
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Toolbar: HKU\S-1-5-21-595894999-490155728-2440704941-1001 -> No Name - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -  No File
Toolbar: HKU\S-1-5-21-595894999-490155728-2440704941-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll [2015-03-03] (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 113.193.1.60 113.193.0.148
Tcpip\..\Interfaces\{7A8B311E-52BC-474D-92E3-3E6266593E19}: [DhcpNameServer] 113.193.1.60 113.193.0.148

FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-03-03] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-14] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-14] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-06-18]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files\McAfee\SiteAdvisor [2014-03-05]
FF HKLM\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-03-05]

Chrome:
=======
CHR Profile: C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-15]
CHR Extension: (Google Drive) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-15]
CHR Extension: (Google Search) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-15]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-15]
CHR Extension: (Gmail) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-15]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx [2014-03-05]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdvancedSystemCareService8; C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe [814880 2015-04-03] (IObit)
R2 CLCapSvc; C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvc.exe [274529 2007-01-06] () [File not signed]
R2 CLSched; C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSched.exe [118879 2007-01-06] () [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2008-07-07] (Macrovision Europe Ltd.) [File not signed]
R2 FreeAgentGoNext Service; D:\Program Files\Sync\FreeAgentService.exe [189736 2009-12-18] (Seagate Technology LLC)
R2 HomeNetSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-31] (IObit)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [132160 2015-08-04] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [690408 2015-03-03] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [476680 2015-02-27] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [196600 2015-02-17] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [334576 2015-03-01] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [238288 2015-02-17] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2008-07-18] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-07-18] (Hewlett-Packard) [File not signed]
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [262247 2007-01-05] () [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [9728 2006-11-23] (Lenovo Corporation)
R3 AKSIFDH; C:\Windows\System32\DRIVERS\aksifdh.sys [48296 2007-09-11] (Aladdin Knowledge Systems, Ltd.)
S3 CapFilt; C:\Windows\system32\Drivers\CapFilt.sys [18944 2007-09-21] (ensurebit) [File not signed]
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [61848 2015-02-17] (McAfee, Inc.)
R1 DritekPortIO; C:\Program Files\EzButton\DPortIO.sys [20112 2006-11-02] (Dritek System Inc.)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2010-07-15] () [File not signed]
R3 eTSCFLT; C:\Windows\System32\DRIVERS\eTSCFLT.sys [12456 2007-09-11] (Aladdin Knowledge Systems, Ltd.)
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2010-07-15] () [File not signed]
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [147912 2013-09-23] (McAfee, Inc.)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [95616 2012-09-06] (Huawei Technologies Co., Ltd.)
S3 huawei_cdcecm; C:\Windows\System32\DRIVERS\ew_jucdcecm.sys [67584 2012-09-06] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27520 2012-09-06] (Huawei Technologies Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [304928 2015-02-17] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [260248 2015-02-17] (McAfee, Inc.)
R0 mfedisk; C:\Windows\System32\DRIVERS\mfedisk.sys [82800 2015-02-17] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [371648 2015-02-17] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [648552 2015-02-17] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [380496 2015-01-16] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [80760 2015-01-16] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [217584 2015-02-17] (McAfee, Inc.)
R3 TridVid; C:\Windows\System32\DRIVERS\TridVid.sys [159104 2007-09-21] (Trident Multimedia Technologies Co.,Ltd)
S3 UDA; C:\Windows\System32\Drivers\rcudawdm.sys [25760 2012-04-17] (Rainbow China Co,. Ltd.)
S3 wdf_usb_vista; C:\Windows\System32\DRIVERS\usb2ser_vista.sys [38912 2012-10-11] (MediaTek Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 EraserUtilDrv11110; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11110.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
U2 wuaserv; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-17 17:16 - 2015-08-17 17:17 - 00000583 _____ C:\AdwCleaner[s11].txt
2015-08-17 15:40 - 2015-08-17 15:40 - 00000000 ____D C:\ProgramData\ProductData
2015-08-17 14:31 - 2015-07-22 02:25 - 01206192 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-17 14:31 - 2015-07-21 21:37 - 03605440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-08-17 14:31 - 2015-07-21 21:37 - 03553216 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-17 14:31 - 2015-07-21 21:37 - 00140224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys
2015-08-17 14:31 - 2015-07-21 21:37 - 00056256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-17 14:31 - 2015-07-21 21:33 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll
2015-08-17 14:31 - 2015-07-21 21:33 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-17 14:31 - 2015-07-21 21:33 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-17 14:30 - 2015-08-01 00:57 - 00103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-17 14:29 - 2015-07-09 19:50 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2015-08-17 14:28 - 2015-07-11 01:07 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-17 14:27 - 2015-07-11 21:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-17 14:24 - 2015-07-18 21:33 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-17 14:23 - 2015-08-01 03:38 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-08-17 14:23 - 2015-08-01 02:11 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-17 14:23 - 2015-08-01 02:10 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-08-17 14:23 - 2015-08-01 02:05 - 00682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-08-17 14:23 - 2015-08-01 02:03 - 02066944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-17 14:23 - 2015-08-01 02:03 - 01072640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-17 14:23 - 2015-08-01 02:03 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-17 14:23 - 2015-08-01 02:03 - 00297472 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-17 14:23 - 2015-07-11 01:07 - 01402368 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-17 14:23 - 2015-07-11 01:07 - 01253376 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-17 13:01 - 2015-08-17 13:01 - 00122311 _____ C:\Users\KBC\Desktop\JRT.txt
2015-08-17 12:15 - 2015-08-17 12:15 - 00001654 _____ C:\Windows\PFRO.log
2015-08-17 10:56 - 2015-08-18 17:38 - 00000000 ____D C:\FRST
2015-08-17 10:53 - 2015-08-17 10:54 - 01676800 _____ (Farbar) C:\Users\SAMEER\Downloads\FRST (1).exe
2015-08-17 10:19 - 2015-08-17 10:22 - 00000584 _____ C:\AdwCleaner[s10].txt
2015-08-16 16:48 - 2015-08-16 16:50 - 00000582 _____ C:\AdwCleaner[s9].txt
2015-08-16 16:36 - 2015-08-16 16:36 - 00000000 ____D C:\Users\SAMEER\AppData\Local\HP
2015-08-16 16:29 - 2015-08-16 16:29 - 00000903 _____ C:\Users\SAMEER\Desktop\Internet Explorer.lnk
2015-08-16 15:46 - 2015-07-01 21:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-16 15:45 - 2015-07-09 19:55 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-16 15:45 - 2015-07-09 19:55 - 00151040 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-16 13:43 - 2015-08-16 13:43 - 00000626 _____ C:\Users\KBC\Desktop\Tcpview.exe.lnk
2015-08-16 11:23 - 2015-08-16 11:23 - 00000981 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2015-08-16 11:22 - 2015-08-18 17:27 - 00001922 _____ C:\Users\Public\Desktop\Advanced SystemCare 8.lnk
2015-08-16 11:22 - 2015-08-16 11:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8
2015-08-16 11:10 - 2015-08-16 11:10 - 00000778 _____ C:\AdwCleaner[C6].txt
2015-08-16 11:06 - 2015-08-16 11:07 - 00000675 _____ C:\AdwCleaner[s8].txt
2015-08-15 22:52 - 2015-08-15 22:52 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-15 22:52 - 2015-08-15 22:52 - 00000859 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-08-15 22:52 - 2015-08-15 22:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-15 22:51 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-15 22:51 - 2015-06-18 08:41 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-08-15 22:51 - 2015-06-18 08:41 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-08-15 22:13 - 2015-08-17 17:19 - 00035064 _____ C:\Windows\system32\Drivers\TrueSight.sys
2015-08-15 22:13 - 2015-08-15 22:49 - 00000000 ____D C:\ProgramData\RogueKiller
2015-08-15 20:16 - 2015-08-15 22:52 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-08-14 16:54 - 2015-08-14 16:54 - 00001931 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-14 16:54 - 2015-08-14 16:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-14 16:52 - 2015-08-18 17:36 - 00000876 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-14 16:52 - 2015-08-18 11:15 - 00000880 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-14 16:39 - 2015-08-14 16:39 - 00000293 _____ C:\Users\SAMEER\Desktop\Local Disk © - Shortcut.lnk
2015-08-14 14:19 - 2015-08-14 15:51 - 00000000 ____D C:\Users\SAMEER\AppData\Local\AdFender
2015-08-14 14:07 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\is-K9FIV.tmp
2015-08-14 12:43 - 2015-07-23 02:24 - 12386816 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-14 12:43 - 2015-07-23 02:24 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-14 12:43 - 2015-07-23 02:21 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-14 12:43 - 2015-07-23 02:17 - 09751040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-14 12:43 - 2015-07-23 02:16 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-14 12:43 - 2015-07-23 02:16 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-14 12:43 - 2015-07-23 02:15 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-14 12:43 - 2015-07-23 02:15 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-08-14 12:43 - 2015-07-23 02:15 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-14 12:43 - 2015-07-23 02:13 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-14 12:43 - 2015-07-23 02:13 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-08-14 12:43 - 2015-07-23 02:13 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-08-14 12:43 - 2015-07-23 02:12 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-13 15:53 - 2015-08-13 15:53 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-12 12:39 - 2015-08-15 11:38 - 00000000 ____D C:\AdwCleaner
2015-08-05 00:03 - 2015-08-05 00:03 - 00877152 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2015-08-05 00:03 - 2015-08-05 00:03 - 00538208 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2015-08-01 19:05 - 2015-08-01 20:01 - 00000000 ____D C:\Users\SAMEER\AppData\Roaming\Skype
2015-08-01 19:05 - 2015-08-01 19:05 - 00000000 ____D C:\Users\SAMEER\AppData\Local\Skype
2015-08-01 13:38 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default\AppData\Roaming\ProductData
2015-08-01 13:38 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ProductData
2015-08-01 09:52 - 2015-07-03 21:34 - 01316864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-31 16:24 - 2015-07-31 16:24 - 00000000 ____D C:\Users\SAMEER\AppData\Roaming\ProductData
2015-07-31 16:23 - 2015-08-18 17:27 - 00013072 _____ C:\Users\SAMEER\AppData\Roaming\nvModes.dat
2015-07-31 16:23 - 2015-08-18 17:27 - 00013072 _____ C:\Users\SAMEER\AppData\Roaming\nvModes.001
2015-07-31 15:34 - 2015-06-08 14:13 - 00348488 _____ (Lavasoft Limited) C:\Windows\system32\LavasoftTcpService.dll
2015-07-31 15:29 - 2015-08-12 13:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2015-07-31 14:12 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default\AppData\Roaming\IObit
2015-07-31 14:12 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default User\AppData\Roaming\IObit
2015-07-30 22:25 - 2015-08-18 17:36 - 01026260 _____ C:\Windows\WindowsUpdate.log
2015-07-29 16:58 - 2015-06-17 22:20 - 02264576 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-29 16:58 - 2015-06-17 20:39 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-29 16:57 - 2015-06-12 21:31 - 00298496 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-29 16:44 - 2015-04-24 21:24 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-07-29 16:39 - 2015-03-05 08:02 - 00244152 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-07-29 16:39 - 2015-03-05 07:53 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-07-29 16:00 - 2015-05-31 13:41 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-07-29 16:00 - 2015-04-11 04:52 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-07-29 15:58 - 2015-06-27 21:33 - 00783872 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-29 15:58 - 2015-06-27 21:32 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-29 15:58 - 2015-06-27 21:32 - 00218112 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-29 15:58 - 2015-06-27 21:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-07-29 15:58 - 2015-06-27 19:51 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-29 15:58 - 2015-06-27 19:51 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-29 15:58 - 2015-06-12 18:43 - 00440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-07-29 15:58 - 2015-04-30 21:33 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-07-29 15:58 - 2015-01-09 05:47 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-29 15:57 - 2015-05-09 04:38 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-07-29 15:55 - 2015-05-05 04:21 - 10628608 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-07-29 15:55 - 2015-05-05 04:20 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-07-29 15:55 - 2015-05-05 04:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-07-29 15:55 - 2015-05-05 04:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-07-29 15:55 - 2015-05-05 02:51 - 08147456 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-07-26 15:07 - 2015-08-14 16:40 - 00000000 ____D C:\Users\SAMEER\AppData\Local\Google
2015-07-26 15:06 - 2015-07-31 16:55 - 00000000 ____D C:\Users\SAMEER\AppData\Roaming\IObit

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-18 17:36 - 2008-01-25 10:14 - 00090657 _____ C:\Users\KBC\AppData\Roaming\nvModes.001
2015-08-18 17:36 - 2007-09-21 09:43 - 15968896 _____ C:\FaceProv.log
2015-08-18 17:27 - 2014-03-05 13:19 - 00000000 ____D C:\Program Files\McAfee
2015-08-18 17:27 - 2006-11-02 18:28 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-18 17:27 - 2006-11-02 18:15 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-18 17:27 - 2006-11-02 18:15 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-18 11:30 - 2008-01-28 14:40 - 00000012 _____ C:\Windows\bthservsdp.dat
2015-08-18 11:30 - 2006-11-02 18:28 - 00032646 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-17 17:10 - 2011-02-28 09:46 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-17 17:08 - 2013-07-31 15:16 - 00000000 ____D C:\Windows\system32\MRT
2015-08-17 17:02 - 2006-11-02 16:48 - 00000000 ____D C:\Windows\Microsoft.NET
2015-08-17 17:01 - 2006-11-02 15:54 - 129304528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-08-17 16:53 - 2006-11-02 15:53 - 00000254 _____ C:\Windows\win.ini
2015-08-17 15:38 - 2006-11-02 18:14 - 00399736 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-17 15:34 - 2006-11-02 18:05 - 00000000 ____D C:\Windows\system32\XPSViewer
2015-08-17 10:51 - 2011-12-30 16:35 - 00000000 ____D C:\fakepath
2015-08-17 10:24 - 2015-03-31 20:13 - 00000000 ____D C:\ProgramData\IObit
2015-08-17 10:17 - 2012-10-05 22:32 - 00000000 ____D C:\Temp delete after use
2015-08-16 16:36 - 2008-03-03 10:34 - 00000000 ____D C:\Users\SAMEER\AppData\Local\VirtualStore
2015-08-16 13:44 - 2010-02-16 13:51 - 00000000 ____D C:\Users\KBC\AppData\Local\CrashDumps
2015-08-16 11:51 - 2008-01-25 10:14 - 00090657 _____ C:\Users\KBC\AppData\Roaming\nvModes.dat
2015-08-16 11:31 - 2015-03-31 20:31 - 52871168 _____ C:\Windows\system32\config\SOFTWARE.iobit
2015-08-16 11:31 - 2015-03-31 20:31 - 45637632 _____ C:\Windows\system32\config\COMPONENTS.iobit
2015-08-16 11:31 - 2015-03-31 20:31 - 00278528 _____ C:\Windows\system32\config\DEFAULT.iobit
2015-08-16 11:31 - 2015-03-31 20:31 - 00094208 _____ C:\Windows\system32\config\SAM.iobit
2015-08-16 11:31 - 2015-03-31 20:31 - 00028672 _____ C:\Windows\system32\config\SECURITY.iobit
2015-08-16 11:31 - 2008-03-03 10:34 - 00000000 ____D C:\Users\SAMEER
2015-08-16 11:19 - 2015-03-31 20:00 - 00000000 ____D C:\Program Files\IObit
2015-08-15 11:47 - 2015-02-22 19:50 - 00000000 ____D C:\Users\KBC\AppData\Local\Google
2015-08-14 16:53 - 2015-02-22 19:51 - 00000000 ____D C:\Program Files\Google
2015-08-14 16:30 - 2009-06-24 14:18 - 00000000 ____D C:\ProgramData\Skype
2015-08-14 16:27 - 2014-03-10 19:37 - 00000000 ____D C:\Program Files\VideoLAN
2015-08-14 16:22 - 2008-01-29 17:37 - 00000909 _____ C:\Users\KBC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-14 16:07 - 2009-11-09 11:28 - 00766602 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-14 14:51 - 2008-02-13 17:32 - 00000000 ____D C:\Program Files\Acro Software
2015-08-14 14:50 - 2008-02-13 17:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2015-08-01 11:05 - 2007-09-21 09:45 - 00026822 _____ C:\HeadVideo.log
2015-07-31 22:51 - 2014-09-12 15:04 - 00000000 ____D C:\Program Files\DC-Unlocker
2015-07-31 20:56 - 2006-11-02 16:48 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-07-31 17:22 - 2011-10-28 11:17 - 00000000 ____D C:\Program Files\Camtech
2015-07-31 16:56 - 2012-05-24 19:29 - 00000000 ____D C:\Users\KBC\AppData\Roaming\Philipp Winterberg
2015-07-30 21:59 - 2011-02-27 12:34 - 00000000 ____D C:\Windows\pss
2015-07-30 21:56 - 2011-02-27 10:00 - 00000764 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-30 21:56 - 2011-02-27 10:00 - 00000000 ____D C:\Program Files\CCleaner
2015-07-30 21:46 - 2011-02-25 17:06 - 00000000 ____D C:\Program Files\Adobe
2015-07-30 21:46 - 2008-01-25 17:00 - 00000000 ____D C:\ProgramData\Adobe
2015-07-30 21:46 - 2008-01-25 17:00 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-07-30 21:45 - 2011-06-04 11:33 - 00000000 ____D C:\Program Files\EASEUS
2015-07-30 19:51 - 2008-02-19 16:00 - 00060928 _____ C:\Users\KBC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-30 17:06 - 2011-02-27 10:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-30 11:47 - 2006-11-02 16:48 - 00000000 ____D C:\Windows\rescache
2015-07-26 15:36 - 2014-09-12 17:53 - 00000000 ____D C:\Program Files\Common Files\XCPCSync.OEM
2015-07-26 15:36 - 2011-07-05 12:22 - 00000000 ____D C:\Users\KBC\AppData\Local\Research In Motion
2015-07-26 15:36 - 2010-11-14 12:27 - 00004819 _____ C:\Users\KBC\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2015-07-26 15:36 - 2010-07-09 14:33 - 00000000 ____D C:\Program Files\Common Files\Research In Motion
2015-07-26 15:07 - 2008-03-03 10:36 - 00106864 _____ C:\Users\SAMEER\AppData\Local\GDIPFONTCACHEV1.DAT

==================== Files in the root of some directories =======

2008-01-25 11:34 - 2010-12-24 09:37 - 0011760 ____H () C:\Users\KBC\AppData\Roaming\KBC.idx
2008-01-25 10:14 - 2015-08-18 17:36 - 0090657 _____ () C:\Users\KBC\AppData\Roaming\nvModes.001
2008-01-25 10:14 - 2015-08-16 11:51 - 0090657 _____ () C:\Users\KBC\AppData\Roaming\nvModes.dat
2010-11-14 13:02 - 2014-09-27 16:27 - 0005691 _____ () C:\Users\KBC\AppData\Roaming\Rim.Desktop.Exception.log
2010-11-14 12:27 - 2015-07-26 15:36 - 0004819 _____ () C:\Users\KBC\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2011-07-05 12:22 - 2014-09-27 16:27 - 0001925 _____ () C:\Users\KBC\AppData\Roaming\Rim.DesktopHelper.Exception.log
2008-02-05 14:45 - 2013-12-20 14:23 - 0007484 _____ () C:\Users\KBC\AppData\Local\d3d9caps.dat
2008-02-19 16:00 - 2015-07-30 19:51 - 0060928 _____ () C:\Users\KBC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-20 16:13 - 2014-02-20 16:13 - 0000057 _____ () C:\ProgramData\Ament.ini
2013-03-25 15:30 - 2013-03-25 15:30 - 0002001 _____ () C:\ProgramData\eTdsWizard1314_A8D59B57-C4D3-4DEE-88D4-9466F7421A5F.swidtag
2009-06-24 14:28 - 2009-06-24 14:28 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2008-02-12 14:45 - 2014-04-12 14:40 - 0043280 _____ () C:\ProgramData\hpzinstall.log

Some files in TEMP:
====================
C:\Users\KBC\AppData\Local\Temp\ASCSetup_478330.exe
C:\Users\KBC\AppData\Local\Temp\ASCSetup_6832921.exe
C:\Users\KBC\AppData\Local\Temp\dllnt_dump.dll

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-08-18 17:36

==================== End of log ============================

 

 

 

Results of Addition Scan

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version:17-08-2015
Ran by KBC (2015-08-18 17:40:22)
Running from C:\Downloads\Farbar
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-595894999-490155728-2440704941-500 - Administrator - Disabled)
Guest (S-1-5-21-595894999-490155728-2440704941-501 - Limited - Enabled)
KBC (S-1-5-21-595894999-490155728-2440704941-1001 - Administrator - Enabled) => C:\Users\KBC
SAMEER (S-1-5-21-595894999-490155728-2440704941-1002 - Limited - Enabled) => C:\Users\SAMEER

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Out of date) {A751AC20-3B48-5237-898A-78C4436BB78D}
AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

32 Bit HP CIO Components Installer (Version: 3.1.1 - Hewlett-Packard) Hidden
Advanced SystemCare 8 (HKLM\...\Advanced SystemCare 8_is1) (Version: 8.3.0 - IObit)
Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version:  - Agere Systems)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform)
DHTML Editing Component (HKLM\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
EASEUS Partition Master 6.5.2 Home Edition (HKLM\...\EASEUS Partition Master Home Edition_is1) (Version:  - EASEUS)
Easy Button (HKLM\...\EzButton) (Version:  - )
EasyCapture2.5 (HKLM\...\EasyCapture2.5) (Version:  - )
EnergyCut (HKLM\...\{6E127727-CE4B-40E4-9A7D-9D65CDE0A15C}) (Version: 1.00 - )
eToken PKI Client 4.55 (HKLM\...\{2146B7E6-FC1C-4230-9952-E9CA2260AA08}) (Version: 4.55.22 - Aladdin Knowledge Systems Ltd.)
Google Chrome (HKLM\...\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
HP Deskjet 3540 series Basic Device Software (HKLM\...\{29E641BB-2183-4653-B589-18B10E5D9635}) (Version: 32.1.145.46951 - Hewlett-Packard Co.)
HP Deskjet 3540 series Help (HKLM\...\{1D456349-7D00-479E-A2A9-C846CE390FE5}) (Version: 30.0.0 - Hewlett Packard)
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Internet Telephone (Version: 4.60 - Callserve Communications Ltd) Hidden
Internet Telephone 4.60 (HKLM\...\{B24E6473-5600-42D0-BD57-8E4B85ACD0BD}) (Version:  - )
IObit Uninstaller (HKLM\...\IObitUninstall) (Version: 4.3.0.5 - IObit)
Lenovo Bluetooth with Enhanced Data Rate Software 6.0.1.3400 (HKLM\...\{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}) (Version: 6.0.1.3400 - Lenovo.)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
McAfee Internet Security (HKLM\...\MSC) (Version: 14.0.339 - McAfee, Inc.)
McAfee SiteAdvisor (HKLM\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.7.264 - McAfee, Inc.)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Business 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
Power2Go 5.0 (HKLM\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version:  - )
PowerCineama MagicDirector Module (HKLM\...\{13E613EF-BB55-11D9-9D77-000129760D75}) (Version:  - )
PowerCinema MakeDisc Module (HKLM\...\{FC4F90EC-B1DA-11D9-9D77-000129760D75}) (Version:  - )
Product Improvement Study for HP Deskjet 3540 series (HKLM\...\{6945C9BA-710C-4776-BB1C-F5F2368AE45E}) (Version: 32.1.145.46951 - Hewlett-Packard Co.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5350 - Realtek Semiconductor Corp.)
Seagate Manager Installer (HKLM\...\InstallShield_{3F5CFC1C-653B-4B22-9153-2BDDF2E03C0E}) (Version: 2.01.0700 - Seagate)
Seagate Manager Installer (Version: 2.01.0700 - Seagate) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
ShuttleCenter (HKLM\...\{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version:  - )
Spelling Dictionaries Support For Adobe Reader 8 (HKLM\...\{AC76BA86-7AD7-5464-3428-800000000003}) (Version: 8.0.0 - Adobe Systems)
Tally.ERP 9 (HKLM\...\{AAF5BFFE-1A0B-4A9E-B726-82AC4DD26B59}) (Version:  - ©Tally Solutions Pvt. Ltd., 1988-2011.)
VeriFace (HKLM\...\VeriFace) (Version:  - )
Windows Driver Package - Animation Technologies Inc. (TridVid) Media  (01/17/2007 1.287.3.10) (HKLM\...\A06EE73B1C7DE59F5A907866B9F81C6A89C49529) (Version: 01/17/2007 1.287.3.10 - Animation Technologies Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Restore Points =========================

ATTENTION: System Restore is disabled

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 15:53 - 2006-09-19 03:11 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {13C6C1CE-9781-4B73-B921-A8FE300322BD} - System32\Tasks\{C2DA5577-8068-4880-B1FE-EA2D7177E005} => C:\Program Files\Skype\Phone\Skype.exe
Task: {690110F9-717A-45C2-A552-B1289FB8B3AC} - \Uninstaller_SkipUac_KBC -> No File <==== ATTENTION
Task: {7C0510C3-385B-4A45-A44D-F513D932CA50} - \Uninstaller_SkipUac_SAMEER -> No File <==== ATTENTION
Task: {B04931F7-062C-4800-933A-9872D722C34D} - System32\Tasks\ASC8_PerformanceMonitor => C:\Program Files\IObit\Advanced SystemCare 8\Monitor.exe [2015-06-10] (IObit)
Task: {B885FFD3-0FC5-4552-A6B8-B5C242FD867B} - System32\Tasks\ASC8_SkipUac_KBC => C:\Program Files\IObit\Advanced SystemCare 8\ASC.exe [2015-06-16] (IObit)
Task: {C38B5FCF-E267-47FE-AE3A-17DCE91C428B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-07-18] (Piriform Ltd)
Task: {C4EA356D-F28F-4B05-ACAC-758FD74EF2BF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-14] (Google Inc.)
Task: {E368F072-F70E-4002-BFFA-CEEAC5845396} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-14] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2015-08-16 11:22 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files\IObit\Advanced SystemCare 8\sqlite3.dll
2007-09-21 09:42 - 2007-01-06 08:01 - 00274529 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvc.exe
2007-09-21 09:42 - 2007-01-06 08:01 - 00237671 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapEngine.dll
2007-09-21 09:42 - 2007-01-06 08:01 - 00032768 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvcps.dll
2007-09-21 09:41 - 2007-01-05 20:02 - 00262247 ____N () C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2007-09-21 09:42 - 2007-01-06 08:01 - 00118879 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSched.exe
2007-09-21 09:42 - 2007-01-06 08:01 - 00114785 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSchMgr.dll
2007-09-21 09:42 - 2007-01-06 08:01 - 00339968 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLTinyDB.dll
2015-08-16 11:22 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files\IObit\Advanced SystemCare 8\madExcept_.bpl
2015-08-16 11:22 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files\IObit\Advanced SystemCare 8\madBasic_.bpl
2015-08-16 11:22 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files\IObit\Advanced SystemCare 8\madDisAsm_.bpl
2015-08-16 11:22 - 2013-01-15 18:47 - 00893248 _____ () C:\Program Files\IObit\Advanced SystemCare 8\webres.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318} => "default"="DiskDrive"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318} => "default"="DiskDrive"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
IE trusted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\webcompanion.com -> hxxp://webcompanion.com

IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\100sexlinks.com -> 100sexlinks.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\101hotteens.com -> 101hotteens.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\101lottery.com -> 101lottery.com

There are 4786 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-595894999-490155728-2440704941-1001\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 113.193.1.60 - 113.193.0.148
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: EnergyCut => C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe
MSCONFIG\startupreg: EzButton => C:\PROGRA~1\EzButton\EzButton.EXE
MSCONFIG\startupreg: Web Companion => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{220A476B-2141-449D-97EA-DBDA5CED72C0}] => (Allow) C:\Program Files\Lenovo\ShuttleCenter\PCMService.exe
FirewallRules: [{A8C034E5-DF54-44B8-A7A8-58EC1EC3DA18}] => (Allow) C:\Program Files\Lenovo\ShuttleCenter\PCMService.exe
FirewallRules: [{63C51BF3-A473-45F9-AA15-805921301115}] => (Allow) E:\setup\hpznui01.exe
FirewallRules: [{81B5AEA8-4A93-4596-835D-560BE99C65D4}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{FB21CEB4-2A28-4E9D-A279-EB54545DD1E6}] => (Allow) LPort=80
FirewallRules: [{2030BD37-94FF-42A5-B91B-518748F4B633}] => (Allow) LPort=80
FirewallRules: [{F968B3A9-1A68-4965-A197-70674883C713}] => (Allow) LPort=80
FirewallRules: [{A2702353-55E3-44ED-88D8-D1A0A8EDDF58}] => (Allow) C:\Program Files\HP\HP Deskjet 3540 series\Bin\DeviceSetup.exe
FirewallRules: [{D1F5E28F-7053-4A6F-BC0F-004589AD897F}] => (Allow) LPort=5357
FirewallRules: [{870B7F5E-22FB-40F2-8722-75D88567B902}] => (Allow) C:\Program Files\HP\HP Deskjet 3540 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{0F642D0E-4922-49AD-AEAE-E318A9EDDEC6}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{8BD673B0-C91A-4F8F-A4BC-DCF3DE6D332D}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{427C8CB5-8362-47AC-942F-A4AFE073965F}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{4D4956A9-88F3-4D3C-8DCA-70A746A4AF7E}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: Microsoft Tun Miniport Adapter #2
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

==================== Event log errors: =========================

Application errors:
==================
Error: (08/18/2015 11:30:01 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/17/2015 05:08:02 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (08/17/2015 05:08:01 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

Error: (08/17/2015 03:49:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16684 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 1248
Start Time: 01d0d8d609462d32
Termination Time: 125

Error: (08/17/2015 02:17:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16684 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 10ac
Start Time: 01d0d8c8329774b9
Termination Time: 141

Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The interface is unknown

Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/17/2015 12:14:09 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

System errors:
=============
Error: (08/18/2015 05:28:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (08/18/2015 05:28:36 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (08/18/2015 05:27:07 PM) (Source: HTTP) (EventID: 15021) (User: )
Description: \Device\Http\ReqQueue0.0.0.0:4482

Error: (08/18/2015 09:49:52 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (08/18/2015 09:49:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (08/18/2015 09:48:26 AM) (Source: HTTP) (EventID: 15021) (User: )
Description: \Device\Http\ReqQueue0.0.0.0:4482

Error: (08/18/2015 09:43:49 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (08/18/2015 09:43:39 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (08/18/2015 09:42:14 AM) (Source: HTTP) (EventID: 15021) (User: )
Description: \Device\Http\ReqQueue0.0.0.0:4482

Error: (08/17/2015 05:22:29 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000SysMain

Microsoft Office:
=========================
Error: (08/18/2015 11:30:01 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/17/2015 05:08:02 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (08/17/2015 05:08:01 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: EmdCacheC:\Windows\system32\emdmgmt.dll4

Error: (08/17/2015 03:49:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.16684124801d0d8d609462d32125

Error: (08/17/2015 02:17:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.1668410ac01d0d8c8329774b9141

Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The interface is unknown

Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

Error: (08/17/2015 12:14:09 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid

CodeIntegrity:
===================================
  Date: 2015-08-18 17:40:13.297
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 17:40:12.798
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 17:40:12.283
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 17:40:11.784
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 17:40:10.864
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 17:40:10.364
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 17:40:09.850
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 17:40:09.304
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 17:40:08.648
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\is-K9FIV.tmp because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-18 17:40:08.149
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\is-K9FIV.tmp because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: Intel® Core2 CPU T5300 @ 1.73GHz
Percentage of memory in use: 52%
Total physical RAM: 2045.75 MB
Available physical RAM: 972.71 MB
Total Virtual: 4328 MB
Available Virtual: 3305.63 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:58.9 GB) (Free:23.79 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (LENOVO) (Fixed) (Total:78.24 GB) (Free:72 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149.1 GB) (Disk ID: C3FFC3FF)
Partition 1: (Active) - (Size=58.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=11.9 GB) - (Type=12)
Partition 3: (Not Active) - (Size=78.2 GB) - (Type=OF Extended)

Link to post
Share on other sites

Step 1

Download attached fixlist.txt file and save it to the Desktop.

NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST/FRST64 and press the Fix button just once and wait.

If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.

When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

Step 2

Please run Malwarebytes Anti-Malware with admin rights, update it and perform a threat scan. Post your log file here.

In your next reply, post the following log files:

  • FRST log
  • Malwarebytes' Anti-Malware log

fixlist.txt

Link to post
Share on other sites

Thank you for the suggestions.

 

Herewith Step 1 : As I had saved FRST to a particular directory, I have saved the Fix list also to same directory and run the fix. The fixlog is attached herewith

 

Fix result of Farbar Recovery Scan Tool (x86) Version:17-08-2015
Ran by KBC (2015-08-18 19:23:44) Run:1
Running from C:\Downloads\Farbar
Loaded Profiles: KBC (Available Profiles: KBC & SAMEER)
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKLM\...\Policies\Explorer\Run: [] => 
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig]  <===== ATTENTION
HKU\S-1-5-19\...\RunOnce: [] => [X]
HKU\S-1-5-20\...\RunOnce: [] => [X]
HKU\S-1-5-18\...\RunOnce: [] => [X]
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
ATTENTION: System Restore is disabled
Task: {690110F9-717A-45C2-A552-B1289FB8B3AC} - \Uninstaller_SkipUac_KBC -> No File <==== ATTENTION
Task: {7C0510C3-385B-4A45-A44D-F513D932CA50} - \Uninstaller_SkipUac_SAMEER -> No File <==== ATTENTION
2015-07-31 14:12 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default\AppData\Roaming\IObit
2015-07-31 14:12 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default User\AppData\Roaming\IObit
2015-07-26 15:06 - 2015-07-31 16:55 - 00000000 ____D C:\Users\SAMEER\AppData\Roaming\IObit
2015-08-17 10:24 - 2015-03-31 20:13 - 00000000 ____D C:\ProgramData\IObit
2015-08-16 11:19 - 2015-03-31 20:00 - 00000000 ____D C:\Program Files\IObit
C:\Users\KBC\AppData\Local\Temp\ASCSetup_478330.exe
C:\Users\KBC\AppData\Local\Temp\ASCSetup_6832921.exe
Hosts:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
end
*****************
 
Error: (0) Failed to create a restore point.
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\ => value removed successfully.
"HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore" => key removed successfully.
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ => value removed successfully.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ => value removed successfully.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ => value removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
ATTENTION: System Restore is disabled => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{690110F9-717A-45C2-A552-B1289FB8B3AC}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{690110F9-717A-45C2-A552-B1289FB8B3AC}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_KBC" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7C0510C3-385B-4A45-A44D-F513D932CA50}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C0510C3-385B-4A45-A44D-F513D932CA50}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_SAMEER" => key removed successfully.
C:\Users\Default\AppData\Roaming\IObit => moved successfully.
"C:\Users\Default User\AppData\Roaming\IObit" => File/Folder not found.
C:\Users\SAMEER\AppData\Roaming\IObit => moved successfully.
C:\ProgramData\IObit => moved successfully.
C:\Program Files\IObit => moved successfully.
C:\Users\KBC\AppData\Local\Temp\ASCSetup_478330.exe => moved successfully.
C:\Users\KBC\AppData\Local\Temp\ASCSetup_6832921.exe => moved successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
 
=========  netsh advfirewall reset =========
 
Ok.
 
 
========= End of CMD: =========
 
 
=========  netsh advfirewall set allprofiles state ON =========
 
Ok.
 
 
========= End of CMD: =========
 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========  netsh winsock reset catalog =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
========= End of CMD: =========
 
 
=========  ipconfig /release =========
 
 
Windows IP Configuration
 
No operation can be performed on Wireless Network Connection while it has its media disconnected.
 
Wireless LAN adapter Wireless Network Connection:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : gwlan
 
Ethernet adapter Local Area Connection:
 
   Connection-specific DNS Suffix  . : 
   Link-local IPv6 Address . . . . . : fe80::7c9f:3909:34c6:e4c3%8
   Default Gateway . . . . . . . . . : 
 
Tunnel adapter Local Area Connection* 6:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 7:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 9:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 20:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 22:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 11:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 12:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 13:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 19:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 21:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 23:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 24:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
========= End of CMD: =========
 
 
=========  ipconfig /renew =========
 
 
Windows IP Configuration
 
No operation can be performed on Wireless Network Connection while it has its media disconnected.
 
Wireless LAN adapter Wireless Network Connection:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : gwlan
 
Ethernet adapter Local Area Connection:
 
   Connection-specific DNS Suffix  . : 
   Link-local IPv6 Address . . . . . : fe80::7c9f:3909:34c6:e4c3%8
   IPv4 Address. . . . . . . . . . . : 10.24.48.75
   Subnet Mask . . . . . . . . . . . : 255.255.224.0
   Default Gateway . . . . . . . . . : 10.24.32.1
 
Tunnel adapter Local Area Connection* 6:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 7:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 9:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 20:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 22:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 11:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 12:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 13:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 19:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 21:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 23:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Local Area Connection* 24:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
========= End of CMD: =========
 
 
=========  netsh int ipv4 reset =========
 
Reseting Echo Request, OK!
Reseting Global, OK!
Reseting Interface, OK!
A reboot is required to complete this action.
 
 
========= End of CMD: =========
 
 
=========  netsh int ipv6 reset =========
 
Reseting Echo Request, OK!
A reboot is required to complete this action.
 
 
========= End of CMD: =========
 
 
========= RemoveProxy: =========
 
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully.
HKU\S-1-5-21-595894999-490155728-2440704941-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\S-1-5-21-595894999-490155728-2440704941-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully.
 
 
========= End of RemoveProxy: =========
 
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.0.6001 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
Unable to cancel {950CE921-B254-41F6-9455-1BED4DD8B0BC}.
Unable to cancel {E4FC8433-B266-4759-B249-4DE1F7800BA0}.
{B7A6416B-7E7D-44E1-A4DA-8626AC1EFB0C} canceled.
{37A5F8C9-4D1E-4749-8475-E953A7588CE7} canceled.
{A0F9B74E-C776-45AC-9884-65A4A2872897} canceled.
{AA4CD04D-3CA0-4F69-BFB6-BC50EBCA5982} canceled.
{3505F79C-C4D7-4FAD-96AE-5092E9E21F4F} canceled.
5 out of 7 jobs canceled.
 
========= End of CMD: =========
 
EmptyTemp: => 106.7 MB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 19:27:04 ====
 
AND HEREWITH STEP 2 : UPDATED MALWAREBYTES ANTIMALWARE AND RAN A SCAN, LOG FILE ATTACHED
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 18/08/2015
Scan Time: 19:32:10
Logfile: malwarebytes AntiMalware Log 18Aug.txt
Administrator: Yes
 
Version: 2.1.8.1057
Malware Database: v2015.08.18.04
Rootkit Database: v2015.08.16.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: KBC
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 351276
Time Elapsed: 29 min, 29 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
Link to post
Share on other sites

Step 1

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Step 2

Please scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.

    ESET OnlineScan

  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer.

      Save it to your Desktop.

    • Double click on the esetsmartinstaller_enu.png to download the ESET Smart Installer. icon on your Desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under Scan Settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • In your next reply, post the following log files:
    • Junkware Removal Tool log
    • ESET Online Scanner log
Link to post
Share on other sites

Thank you for the suggestions.

 

Herewith attached : Step 1 : JRT

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.6 (08.10.2015:1)
OS: Windows Vista Home Basic x86
Ran by KBC on 19/08/2015 at 14:33:34.70
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

~~~ Services

Successfully deleted: [service] 0109111439974235mcinstcleanup [Reboot required]

 

~~~ Tasks

 

~~~ Registry Values

 

~~~ Registry Keys

 

~~~ Files

 

~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\productdata
Successfully deleted: [Folder] C:\Users\KBC\AppData\Roaming\productdata

 

~~~ Chrome

[C:\Users\KBC\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\KBC\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\KBC\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\KBC\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19/08/2015 at 14:36:18.71
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

AND STEP 2 : ESET SCAN REPORT

 

C:\AdwCleaner\Quarantine\C\Users\KBC\AppData\Roaming\OpenCandy\910E037E089F4F0094BD8933F3C6B67F\SearchGolTB.exe.vir a variant of Win32/Toolbar.Babylon.F potentially unwanted application cleaned by deleting - quarantined
C:\Downloads\ccsetup508.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application deleted - quarantined

 

 

Thank you for taking a look at the above.

 

Regards

 

Sameer

Link to post
Share on other sites

Please manually delete your AdwCleaner.exe and then:

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan button. Wait until is finished.
  • Click on Clean.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner\AdwCleaner[s0].txt as well.
Link to post
Share on other sites

Thank you friend, for continuing advise.

 

Herewith attached is the scan of Adwcleaner, which was duly reloaded from the link you sent, the scan seemed relatively clean. The problem of ad popups still continues, regretably.

 

# AdwCleaner v5.002 - Logfile created 20/08/2015 at 13:23:05
# Updated 18/08/2015 by Xplode
# Database : 2015-08-18.2 [server]
# Operating system : Windows Vista Home Basic Service Pack 2 (x86)
# Username : KBC - KBC-PC
# Running from : C:\Downloads\Adwcleaner\AdwCleaner.exe
# Option : Cleaning

***** [ Services ] *****

***** [ Folders ] *****

***** [ Files ] *****

***** [ Shortcuts ] *****

***** [ Scheduled tasks ] *****

***** [ Registry ] *****

***** [ Web browsers ] *****

*************************

:: Proxy settings cleared
:: Winsock settings cleared

*************************

C:\AdwCleaner[C6].txt - [778 bytes] - [16/08/2015 11:10:31]
C:\AdwCleaner[s10].txt - [584 bytes] - [17/08/2015 10:19:23]
C:\AdwCleaner[s11].txt - [583 bytes] - [17/08/2015 17:16:38]
C:\AdwCleaner[s8].txt - [675 bytes] - [16/08/2015 11:06:00]
C:\AdwCleaner[s9].txt - [582 bytes] - [16/08/2015 16:48:14]

########## EOF - C:\AdwCleaner\AdwCleaner[C7].txt - [951 bytes] ##########

Link to post
Share on other sites

  • Please download GeekUninstaller and save it to desktop.
  • Extract the archive and run the file geek.exe
  • Right click on the Chrome (the example above is for Mozilla Firefox) and click on the Uninstall... button.

    XhV2QLa.png

  • Once the uninstallation is complete, the following window will appear to let you remove all leftovers including unnecessary files, useless folders, registry entries related to the uninstalled program.

    This is just an example for Mozilla Firefox. It should be similiar to you:

    geekuninstaller-3.png

  • Click on the Finish button to remove all detected traces.
  • Finally, click on the Close button to complete and go back to the main interface of Geek Uninstaller.
  • Close the program and reboot your system
When you are done, please download and install Google Chrome from their official website.
Link to post
Share on other sites

OK, I deleted existing FRST.exe, downloaded fresh copy from bleepingcomputer.com and here are the results of the scan. Problem of ad popups continue.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:21-08-2015
Ran by KBC (administrator) on KBC-PC (21-08-2015 11:13:23)
Running from C:\Downloads\Farbar
Loaded Profiles: KBC (Available Profiles: KBC & SAMEER)
Platform: Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: IE)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
() C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Seagate Technology LLC) D:\Program Files\Sync\FreeAgentService.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
() C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSched.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [155648 2006-09-12] (Alps Electric Co., Ltd.)
HKLM\...\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [562688 2015-02-11] (McAfee, Inc.)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6453528 2015-07-18] (Piriform Ltd)
HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\Run: [Advanced SystemCare 8] => "C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-595894999-490155728-2440704941-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} ->  No File
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Toolbar: HKU\S-1-5-21-595894999-490155728-2440704941-1001 -> No Name - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -  No File
Toolbar: HKU\S-1-5-21-595894999-490155728-2440704941-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll [2015-03-03] (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 5.152.219.50 37.220.8.190
Tcpip\..\Interfaces\{7A8B311E-52BC-474D-92E3-3E6266593E19}: [DhcpNameServer] 5.152.219.50 37.220.8.190
 
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-03-03] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.5\npGoogleUpdate3.dll [2015-08-20] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.5\npGoogleUpdate3.dll [2015-08-20] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-06-18]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files\McAfee\SiteAdvisor [2014-03-05]
FF HKLM\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-03-05]
 
Chrome: 
=======
CHR Profile: C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-20]
CHR Extension: (Google Docs) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-20]
CHR Extension: (Google Drive) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-20]
CHR Extension: (YouTube) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-20]
CHR Extension: (Google Search) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-20]
CHR Extension: (Google Sheets) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-20]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-20]
CHR Extension: (Gmail) - C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-20]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 CLCapSvc; C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvc.exe [274529 2007-01-06] () [File not signed]
R2 CLSched; C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSched.exe [118879 2007-01-06] () [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2008-07-07] (Macrovision Europe Ltd.) [File not signed]
R2 FreeAgentGoNext Service; D:\Program Files\Sync\FreeAgentService.exe [189736 2009-12-18] (Seagate Technology LLC)
R2 HomeNetSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [132160 2015-08-04] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [690408 2015-03-03] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [476680 2015-02-27] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [196600 2015-02-17] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [334576 2015-03-01] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [238288 2015-02-17] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2008-07-18] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-07-18] (Hewlett-Packard) [File not signed]
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [262247 2007-01-05] () [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S2 AdvancedSystemCareService8; C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe [X]
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R5 ACPI; C:\Windows\System32\drivers\acpi.sys [265688 2009-04-11] (Microsoft Corporation)
R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [9728 2006-11-23] (Lenovo Corporation)
R3 AKSIFDH; C:\Windows\System32\DRIVERS\aksifdh.sys [48296 2007-09-11] (Aladdin Knowledge Systems, Ltd.)
R5 atapi; C:\Windows\System32\drivers\atapi.sys [19944 2009-04-11] (Microsoft Corporation)
S3 CapFilt; C:\Windows\system32\Drivers\CapFilt.sys [18944 2007-09-21] (ensurebit) [File not signed]
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [61848 2015-02-17] (McAfee, Inc.)
R5 CLFS; C:\Windows\System32\CLFS.sys [244152 2015-03-05] (Microsoft Corporation)
R5 Compbatt; C:\Windows\System32\DRIVERS\compbatt.sys [20792 2008-01-19] (Microsoft Corporation)
R5 crcdisk; C:\Windows\System32\drivers\crcdisk.sys [22632 2006-11-02] (Microsoft Corporation)
R5 disk; C:\Windows\System32\drivers\disk.sys [53736 2009-04-11] (Microsoft Corporation)
R1 DritekPortIO; C:\Program Files\EzButton\DPortIO.sys [20112 2006-11-02] (Dritek System Inc.)
R5 Ecache; C:\Windows\System32\drivers\ecache.sys [140224 2015-07-21] (Microsoft Corporation)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2010-07-15] () [File not signed]
R3 eTSCFLT; C:\Windows\System32\DRIVERS\eTSCFLT.sys [12456 2007-09-11] (Aladdin Knowledge Systems, Ltd.)
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2010-07-15] () [File not signed]
R5 FileInfo; C:\Windows\System32\drivers\fileinfo.sys [58936 2008-01-19] (Microsoft Corporation)
R5 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Microsoft Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [147912 2013-09-23] (McAfee, Inc.)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [95616 2012-09-06] (Huawei Technologies Co., Ltd.)
S3 huawei_cdcecm; C:\Windows\System32\DRIVERS\ew_jucdcecm.sys [67584 2012-09-06] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27520 2012-09-06] (Huawei Technologies Co., Ltd.)
R5 intelide; C:\Windows\System32\drivers\intelide.sys [17976 2008-01-19] (Microsoft Corporation)
R5 KSecDD; C:\Windows\System32\Drivers\ksecdd.sys [440768 2015-06-12] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [304928 2015-02-17] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [260248 2015-02-17] (McAfee, Inc.)
R5 mfedisk; C:\Windows\System32\DRIVERS\mfedisk.sys [82800 2015-02-17] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [371648 2015-02-17] (McAfee, Inc.)
R5 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [648552 2015-02-17] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [380496 2015-01-16] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [80760 2015-01-16] (McAfee, Inc.)
R5 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [217584 2015-02-17] (McAfee, Inc.)
R5 MountMgr; C:\Windows\System32\drivers\mountmgr.sys [56256 2015-07-21] (Microsoft Corporation)
R5 msisadrv; C:\Windows\System32\drivers\msisadrv.sys [16440 2008-01-19] (Microsoft Corporation)
R5 Mup; C:\Windows\System32\Drivers\mup.sys [48104 2009-04-11] (Microsoft Corporation)
R5 NDIS; C:\Windows\System32\drivers\ndis.sys [527848 2009-04-11] (Microsoft Corporation)
R5 partmgr; C:\Windows\System32\drivers\partmgr.sys [53120 2012-03-21] (Microsoft Corporation)
R5 pci; C:\Windows\System32\drivers\pci.sys [149480 2009-04-11] (Microsoft Corporation)
R5 pcmcia; C:\Windows\System32\DRIVERS\pcmcia.sys [177640 2009-04-11] (Microsoft Corporation)
R5 spldr; C:\Windows\system32\Drivers\spldr.sys [21048 2008-01-19] (Microsoft Corporation)
R5 Tcpip; C:\Windows\System32\drivers\tcpip.sys [905664 2014-04-05] (Microsoft Corporation)
R3 TridVid; C:\Windows\System32\DRIVERS\TridVid.sys [159104 2007-09-21] (Trident Multimedia Technologies Co.,Ltd)
S3 UDA; C:\Windows\System32\Drivers\rcudawdm.sys [25760 2012-04-17] (Rainbow China Co,. Ltd.)
R5 volmgr; C:\Windows\System32\drivers\volmgr.sys [52792 2008-01-19] (Microsoft Corporation)
R5 volmgrx; C:\Windows\System32\drivers\volmgrx.sys [292840 2009-04-11] (Microsoft Corporation)
R5 volsnap; C:\Windows\System32\drivers\volsnap.sys [224640 2012-08-21] (Microsoft Corporation)
R5 Wdf01000; C:\Windows\System32\drivers\Wdf01000.sys [527064 2013-06-27] (Microsoft Corporation)
S3 wdf_usb_vista; C:\Windows\System32\DRIVERS\usb2ser_vista.sys [38912 2012-10-11] (MediaTek Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 EraserUtilDrv11110; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11110.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
U2 wuaserv; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-21 11:02 - 2015-08-21 11:02 - 272400325 _____ C:\Windows\MEMORY.DMP
2015-08-21 11:02 - 2015-08-21 11:02 - 00155840 _____ C:\Windows\Minidump\Mini082115-01.dmp
2015-08-20 15:21 - 2015-08-20 15:21 - 00001931 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-20 15:21 - 2015-08-20 15:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-20 15:13 - 2015-08-21 11:18 - 00000880 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-20 15:13 - 2015-08-21 11:09 - 00000876 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-20 10:35 - 2015-08-15 04:33 - 12386816 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-20 10:35 - 2015-08-15 04:26 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-20 10:35 - 2015-08-15 04:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-19 14:38 - 2015-08-19 14:38 - 00000000 ____D C:\Program Files\ESET
2015-08-19 14:36 - 2015-08-19 14:36 - 00001277 _____ C:\Users\KBC\Desktop\JRT.txt
2015-08-17 17:16 - 2015-08-17 17:17 - 00000583 _____ C:\AdwCleaner[s11].txt
2015-08-17 14:31 - 2015-07-22 02:25 - 01206192 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-17 14:31 - 2015-07-21 21:37 - 03605440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-08-17 14:31 - 2015-07-21 21:37 - 03553216 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-17 14:31 - 2015-07-21 21:37 - 00140224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys
2015-08-17 14:31 - 2015-07-21 21:37 - 00056256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-17 14:31 - 2015-07-21 21:33 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll
2015-08-17 14:31 - 2015-07-21 21:33 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-17 14:31 - 2015-07-21 21:33 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-17 14:30 - 2015-08-01 00:57 - 00103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-17 14:29 - 2015-07-09 19:50 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2015-08-17 14:28 - 2015-07-11 01:07 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-17 14:27 - 2015-07-11 21:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-17 14:24 - 2015-07-18 21:33 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-17 14:23 - 2015-08-01 03:38 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-08-17 14:23 - 2015-08-01 03:16 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-08-17 14:23 - 2015-08-01 02:11 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-17 14:23 - 2015-08-01 02:10 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-08-17 14:23 - 2015-08-01 02:05 - 00682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-08-17 14:23 - 2015-08-01 02:03 - 02066944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-17 14:23 - 2015-08-01 02:03 - 01072640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-17 14:23 - 2015-08-01 02:03 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-17 14:23 - 2015-08-01 02:03 - 00297472 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-17 14:23 - 2015-07-11 01:07 - 01402368 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-17 14:23 - 2015-07-11 01:07 - 01253376 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-17 12:15 - 2015-08-20 18:50 - 00002484 _____ C:\Windows\PFRO.log
2015-08-17 10:56 - 2015-08-21 11:13 - 00000000 ____D C:\FRST
2015-08-17 10:53 - 2015-08-17 10:54 - 01676800 _____ (Farbar) C:\Users\SAMEER\Downloads\FRST (1).exe
2015-08-17 10:19 - 2015-08-17 10:22 - 00000584 _____ C:\AdwCleaner[s10].txt
2015-08-16 16:48 - 2015-08-16 16:50 - 00000582 _____ C:\AdwCleaner[s9].txt
2015-08-16 16:36 - 2015-08-16 16:36 - 00000000 ____D C:\Users\SAMEER\AppData\Local\HP
2015-08-16 16:29 - 2015-08-16 16:29 - 00000903 _____ C:\Users\SAMEER\Desktop\Internet Explorer.lnk
2015-08-16 15:46 - 2015-07-01 21:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-16 15:45 - 2015-07-09 19:55 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-16 15:45 - 2015-07-09 19:55 - 00151040 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-16 13:43 - 2015-08-16 13:43 - 00000626 _____ C:\Users\KBC\Desktop\Tcpview.exe.lnk
2015-08-16 11:23 - 2015-08-16 11:23 - 00000981 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2015-08-16 11:22 - 2015-08-18 17:27 - 00001922 _____ C:\Users\Public\Desktop\Advanced SystemCare 8.lnk
2015-08-16 11:22 - 2015-08-16 11:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8
2015-08-16 11:10 - 2015-08-16 11:10 - 00000778 _____ C:\AdwCleaner[C6].txt
2015-08-16 11:06 - 2015-08-16 11:07 - 00000675 _____ C:\AdwCleaner[s8].txt
2015-08-15 22:52 - 2015-08-18 19:31 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-15 22:52 - 2015-08-15 22:52 - 00000859 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-08-15 22:52 - 2015-08-15 22:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-15 22:51 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-15 22:51 - 2015-06-18 08:41 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-08-15 22:51 - 2015-06-18 08:41 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-08-15 22:13 - 2015-08-17 17:19 - 00035064 _____ C:\Windows\system32\Drivers\TrueSight.sys
2015-08-15 22:13 - 2015-08-15 22:49 - 00000000 ____D C:\ProgramData\RogueKiller
2015-08-15 20:16 - 2015-08-15 22:52 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-08-14 16:39 - 2015-08-14 16:39 - 00000293 _____ C:\Users\SAMEER\Desktop\Local Disk © - Shortcut.lnk
2015-08-14 14:19 - 2015-08-14 15:51 - 00000000 ____D C:\Users\SAMEER\AppData\Local\AdFender
2015-08-14 14:07 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\is-K9FIV.tmp
2015-08-14 12:43 - 2015-07-23 02:24 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-14 12:43 - 2015-07-23 02:21 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-14 12:43 - 2015-07-23 02:17 - 09751040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-14 12:43 - 2015-07-23 02:16 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-14 12:43 - 2015-07-23 02:16 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-14 12:43 - 2015-07-23 02:15 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-14 12:43 - 2015-07-23 02:15 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-08-14 12:43 - 2015-07-23 02:15 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-14 12:43 - 2015-07-23 02:14 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-14 12:43 - 2015-07-23 02:13 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-08-14 12:43 - 2015-07-23 02:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-08-14 12:43 - 2015-07-23 02:13 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-08-14 12:43 - 2015-07-23 02:12 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-13 15:53 - 2015-08-13 15:53 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-12 12:39 - 2015-08-20 13:23 - 00000000 ____D C:\AdwCleaner
2015-08-05 00:03 - 2015-08-05 00:03 - 00877152 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2015-08-05 00:03 - 2015-08-05 00:03 - 00538208 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2015-08-01 19:05 - 2015-08-01 20:01 - 00000000 ____D C:\Users\SAMEER\AppData\Roaming\Skype
2015-08-01 19:05 - 2015-08-01 19:05 - 00000000 ____D C:\Users\SAMEER\AppData\Local\Skype
2015-08-01 13:38 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default\AppData\Roaming\ProductData
2015-08-01 13:38 - 2015-08-01 13:38 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ProductData
2015-08-01 09:52 - 2015-07-03 21:34 - 01316864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-31 16:24 - 2015-07-31 16:24 - 00000000 ____D C:\Users\SAMEER\AppData\Roaming\ProductData
2015-07-31 16:23 - 2015-08-18 17:27 - 00013072 _____ C:\Users\SAMEER\AppData\Roaming\nvModes.dat
2015-07-31 16:23 - 2015-08-18 17:27 - 00013072 _____ C:\Users\SAMEER\AppData\Roaming\nvModes.001
2015-07-31 15:34 - 2015-06-08 14:13 - 00348488 _____ (Lavasoft Limited) C:\Windows\system32\LavasoftTcpService.dll
2015-07-31 15:29 - 2015-08-12 13:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2015-07-30 22:25 - 2015-08-21 11:16 - 01183588 _____ C:\Windows\WindowsUpdate.log
2015-07-29 16:58 - 2015-06-17 22:20 - 02264576 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-29 16:58 - 2015-06-17 20:39 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-29 16:57 - 2015-06-12 21:31 - 00298496 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-29 16:44 - 2015-04-24 21:24 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-07-29 16:39 - 2015-03-05 08:02 - 00244152 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-07-29 16:39 - 2015-03-05 07:53 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-07-29 16:00 - 2015-05-31 13:41 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-07-29 16:00 - 2015-04-11 04:52 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-07-29 15:58 - 2015-06-27 21:33 - 00783872 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-29 15:58 - 2015-06-27 21:32 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-29 15:58 - 2015-06-27 21:32 - 00218112 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-29 15:58 - 2015-06-27 21:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-07-29 15:58 - 2015-06-27 19:51 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-29 15:58 - 2015-06-27 19:51 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-29 15:58 - 2015-06-12 18:43 - 00440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-07-29 15:58 - 2015-04-30 21:33 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-07-29 15:58 - 2015-01-09 05:47 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-29 15:57 - 2015-05-09 04:38 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-07-29 15:55 - 2015-05-05 04:21 - 10628608 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-07-29 15:55 - 2015-05-05 04:20 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-07-29 15:55 - 2015-05-05 04:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-07-29 15:55 - 2015-05-05 04:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-07-29 15:55 - 2015-05-05 02:51 - 08147456 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-07-26 15:07 - 2015-08-14 16:40 - 00000000 ____D C:\Users\SAMEER\AppData\Local\Google
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-21 11:09 - 2008-01-25 10:14 - 00090657 _____ C:\Users\KBC\AppData\Roaming\nvModes.dat
2015-08-21 11:09 - 2008-01-25 10:14 - 00090657 _____ C:\Users\KBC\AppData\Roaming\nvModes.001
2015-08-21 11:08 - 2007-09-21 09:43 - 15982795 _____ C:\FaceProv.log
2015-08-21 11:08 - 2006-11-02 18:28 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-21 11:08 - 2006-11-02 18:15 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-21 11:08 - 2006-11-02 18:15 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-21 11:07 - 2008-01-28 14:40 - 00000012 _____ C:\Windows\bthservsdp.dat
2015-08-21 11:07 - 2006-11-02 18:28 - 00032646 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-21 11:03 - 2014-03-05 13:19 - 00000000 ____D C:\Program Files\McAfee
2015-08-21 11:02 - 2011-09-29 13:25 - 00000000 ____D C:\Windows\Minidump
2015-08-20 15:21 - 2015-02-22 19:50 - 00000000 ____D C:\Users\KBC\AppData\Local\Google
2015-08-20 15:20 - 2015-02-22 19:51 - 00000000 ____D C:\Program Files\Google
2015-08-20 15:13 - 2014-09-27 16:17 - 00000000 ____D C:\Users\KBC\AppData\Local\Deployment
2015-08-17 17:10 - 2011-02-28 09:46 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-17 17:08 - 2013-07-31 15:16 - 00000000 ____D C:\Windows\system32\MRT
2015-08-17 17:02 - 2006-11-02 16:48 - 00000000 ____D C:\Windows\Microsoft.NET
2015-08-17 17:01 - 2006-11-02 15:54 - 129304528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-08-17 16:53 - 2006-11-02 15:53 - 00000254 _____ C:\Windows\win.ini
2015-08-17 15:38 - 2006-11-02 18:14 - 00399736 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-17 15:34 - 2006-11-02 18:05 - 00000000 ____D C:\Windows\system32\XPSViewer
2015-08-17 10:51 - 2011-12-30 16:35 - 00000000 ____D C:\fakepath
2015-08-17 10:17 - 2012-10-05 22:32 - 00000000 ____D C:\Temp delete after use
2015-08-16 16:36 - 2008-03-03 10:34 - 00000000 ____D C:\Users\SAMEER\AppData\Local\VirtualStore
2015-08-16 13:44 - 2010-02-16 13:51 - 00000000 ____D C:\Users\KBC\AppData\Local\CrashDumps
2015-08-16 11:31 - 2015-03-31 20:31 - 52871168 _____ C:\Windows\system32\config\SOFTWARE.iobit
2015-08-16 11:31 - 2015-03-31 20:31 - 45637632 _____ C:\Windows\system32\config\COMPONENTS.iobit
2015-08-16 11:31 - 2015-03-31 20:31 - 00278528 _____ C:\Windows\system32\config\DEFAULT.iobit
2015-08-16 11:31 - 2015-03-31 20:31 - 00094208 _____ C:\Windows\system32\config\SAM.iobit
2015-08-16 11:31 - 2015-03-31 20:31 - 00028672 _____ C:\Windows\system32\config\SECURITY.iobit
2015-08-16 11:31 - 2008-03-03 10:34 - 00000000 ____D C:\Users\SAMEER
2015-08-14 16:30 - 2009-06-24 14:18 - 00000000 ____D C:\ProgramData\Skype
2015-08-14 16:27 - 2014-03-10 19:37 - 00000000 ____D C:\Program Files\VideoLAN
2015-08-14 16:22 - 2008-01-29 17:37 - 00000909 _____ C:\Users\KBC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-14 16:07 - 2009-11-09 11:28 - 00766602 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-14 14:51 - 2008-02-13 17:32 - 00000000 ____D C:\Program Files\Acro Software
2015-08-14 14:50 - 2008-02-13 17:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2015-08-01 11:05 - 2007-09-21 09:45 - 00026822 _____ C:\HeadVideo.log
2015-07-31 22:51 - 2014-09-12 15:04 - 00000000 ____D C:\Program Files\DC-Unlocker
2015-07-31 20:56 - 2006-11-02 16:48 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-07-31 17:22 - 2011-10-28 11:17 - 00000000 ____D C:\Program Files\Camtech
2015-07-31 16:56 - 2012-05-24 19:29 - 00000000 ____D C:\Users\KBC\AppData\Roaming\Philipp Winterberg
2015-07-30 21:59 - 2011-02-27 12:34 - 00000000 ____D C:\Windows\pss
2015-07-30 21:56 - 2011-02-27 10:00 - 00000764 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-30 21:56 - 2011-02-27 10:00 - 00000000 ____D C:\Program Files\CCleaner
2015-07-30 21:46 - 2011-02-25 17:06 - 00000000 ____D C:\Program Files\Adobe
2015-07-30 21:46 - 2008-01-25 17:00 - 00000000 ____D C:\ProgramData\Adobe
2015-07-30 21:46 - 2008-01-25 17:00 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-07-30 21:45 - 2011-06-04 11:33 - 00000000 ____D C:\Program Files\EASEUS
2015-07-30 19:51 - 2008-02-19 16:00 - 00060928 _____ C:\Users\KBC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-30 17:06 - 2011-02-27 10:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-30 11:47 - 2006-11-02 16:48 - 00000000 ____D C:\Windows\rescache
2015-07-26 15:36 - 2014-09-12 17:53 - 00000000 ____D C:\Program Files\Common Files\XCPCSync.OEM
2015-07-26 15:36 - 2011-07-05 12:22 - 00000000 ____D C:\Users\KBC\AppData\Local\Research In Motion
2015-07-26 15:36 - 2010-11-14 12:27 - 00004819 _____ C:\Users\KBC\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2015-07-26 15:36 - 2010-07-09 14:33 - 00000000 ____D C:\Program Files\Common Files\Research In Motion
2015-07-26 15:07 - 2008-03-03 10:36 - 00106864 _____ C:\Users\SAMEER\AppData\Local\GDIPFONTCACHEV1.DAT
 
==================== Files in the root of some directories =======
 
2008-01-25 11:34 - 2010-12-24 09:37 - 0011760 ____H () C:\Users\KBC\AppData\Roaming\KBC.idx
2008-01-25 10:14 - 2015-08-21 11:09 - 0090657 _____ () C:\Users\KBC\AppData\Roaming\nvModes.001
2008-01-25 10:14 - 2015-08-21 11:09 - 0090657 _____ () C:\Users\KBC\AppData\Roaming\nvModes.dat
2010-11-14 13:02 - 2014-09-27 16:27 - 0005691 _____ () C:\Users\KBC\AppData\Roaming\Rim.Desktop.Exception.log
2010-11-14 12:27 - 2015-07-26 15:36 - 0004819 _____ () C:\Users\KBC\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2011-07-05 12:22 - 2014-09-27 16:27 - 0001925 _____ () C:\Users\KBC\AppData\Roaming\Rim.DesktopHelper.Exception.log
2008-02-05 14:45 - 2013-12-20 14:23 - 0007484 _____ () C:\Users\KBC\AppData\Local\d3d9caps.dat
2008-02-19 16:00 - 2015-07-30 19:51 - 0060928 _____ () C:\Users\KBC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-20 16:13 - 2014-02-20 16:13 - 0000057 _____ () C:\ProgramData\Ament.ini
2013-03-25 15:30 - 2013-03-25 15:30 - 0002001 _____ () C:\ProgramData\eTdsWizard1314_A8D59B57-C4D3-4DEE-88D4-9466F7421A5F.swidtag
2009-06-24 14:28 - 2009-06-24 14:28 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2008-02-12 14:45 - 2014-04-12 14:40 - 0043280 _____ () C:\ProgramData\hpzinstall.log
 
Some files in TEMP:
====================
C:\Users\KBC\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-08-21 11:14
 
==================== End of log ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version:21-08-2015
Ran by KBC (2015-08-21 11:19:13)
Running from C:\Downloads\Farbar
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-595894999-490155728-2440704941-500 - Administrator - Disabled)
Guest (S-1-5-21-595894999-490155728-2440704941-501 - Limited - Enabled)
KBC (S-1-5-21-595894999-490155728-2440704941-1001 - Administrator - Enabled) => C:\Users\KBC
SAMEER (S-1-5-21-595894999-490155728-2440704941-1002 - Limited - Enabled) => C:\Users\SAMEER
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
32 Bit HP CIO Components Installer (Version: 3.1.1 - Hewlett-Packard) Hidden
Advanced SystemCare 8 (HKLM\...\Advanced SystemCare 8_is1) (Version: 8.3.0 - IObit)
Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version:  - Agere Systems)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform)
DHTML Editing Component (HKLM\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
EASEUS Partition Master 6.5.2 Home Edition (HKLM\...\EASEUS Partition Master Home Edition_is1) (Version:  - EASEUS)
Easy Button (HKLM\...\EzButton) (Version:  - )
EasyCapture2.5 (HKLM\...\EasyCapture2.5) (Version:  - )
EnergyCut (HKLM\...\{6E127727-CE4B-40E4-9A7D-9D65CDE0A15C}) (Version: 1.00 - )
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version:  - )
eToken PKI Client 4.55 (HKLM\...\{2146B7E6-FC1C-4230-9952-E9CA2260AA08}) (Version: 4.55.22 - Aladdin Knowledge Systems Ltd.)
Google Chrome (HKLM\...\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
Google Update Helper (Version: 1.3.28.5 - Google Inc.) Hidden
HP Deskjet 3540 series Basic Device Software (HKLM\...\{29E641BB-2183-4653-B589-18B10E5D9635}) (Version: 32.1.145.46951 - Hewlett-Packard Co.)
HP Deskjet 3540 series Help (HKLM\...\{1D456349-7D00-479E-A2A9-C846CE390FE5}) (Version: 30.0.0 - Hewlett Packard)
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Internet Telephone (Version: 4.60 - Callserve Communications Ltd) Hidden
Internet Telephone 4.60 (HKLM\...\{B24E6473-5600-42D0-BD57-8E4B85ACD0BD}) (Version:  - )
IObit Uninstaller (HKLM\...\IObitUninstall) (Version: 4.3.0.5 - IObit)
Lenovo Bluetooth with Enhanced Data Rate Software 6.0.1.3400 (HKLM\...\{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}) (Version: 6.0.1.3400 - Lenovo.)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
McAfee Internet Security (HKLM\...\MSC) (Version: 14.0.339 - McAfee, Inc.)
McAfee SiteAdvisor (HKLM\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.7.264 - McAfee, Inc.)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Business 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
Power2Go 5.0 (HKLM\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version:  - )
PowerCineama MagicDirector Module (HKLM\...\{13E613EF-BB55-11D9-9D77-000129760D75}) (Version:  - )
PowerCinema MakeDisc Module (HKLM\...\{FC4F90EC-B1DA-11D9-9D77-000129760D75}) (Version:  - )
Product Improvement Study for HP Deskjet 3540 series (HKLM\...\{6945C9BA-710C-4776-BB1C-F5F2368AE45E}) (Version: 32.1.145.46951 - Hewlett-Packard Co.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5350 - Realtek Semiconductor Corp.)
Seagate Manager Installer (HKLM\...\InstallShield_{3F5CFC1C-653B-4B22-9153-2BDDF2E03C0E}) (Version: 2.01.0700 - Seagate)
Seagate Manager Installer (Version: 2.01.0700 - Seagate) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
ShuttleCenter (HKLM\...\{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version:  - )
Spelling Dictionaries Support For Adobe Reader 8 (HKLM\...\{AC76BA86-7AD7-5464-3428-800000000003}) (Version: 8.0.0 - Adobe Systems)
Tally.ERP 9 (HKLM\...\{AAF5BFFE-1A0B-4A9E-B726-82AC4DD26B59}) (Version:  - ©Tally Solutions Pvt. Ltd., 1988-2011.)
VeriFace (HKLM\...\VeriFace) (Version:  - )
Windows Driver Package - Animation Technologies Inc. (TridVid) Media  (01/17/2007 1.287.3.10) (HKLM\...\A06EE73B1C7DE59F5A907866B9F81C6A89C49529) (Version: 01/17/2007 1.287.3.10 - Animation Technologies Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 15:53 - 2015-08-18 19:24 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {13C6C1CE-9781-4B73-B921-A8FE300322BD} - System32\Tasks\{C2DA5577-8068-4880-B1FE-EA2D7177E005} => C:\Program Files\Skype\Phone\Skype.exe
Task: {9753E2A9-837F-4E66-A703-E350EB992CAB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-20] (Google Inc.)
Task: {B04931F7-062C-4800-933A-9872D722C34D} - System32\Tasks\ASC8_PerformanceMonitor => C:\Program Files\IObit\Advanced SystemCare 8\Monitor.exe
Task: {B885FFD3-0FC5-4552-A6B8-B5C242FD867B} - System32\Tasks\ASC8_SkipUac_KBC => C:\Program Files\IObit\Advanced SystemCare 8\ASC.exe
Task: {C38B5FCF-E267-47FE-AE3A-17DCE91C428B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-07-18] (Piriform Ltd)
Task: {E7C20040-2D2B-4F01-9F6E-8AFC31A88791} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-20] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2007-09-21 09:42 - 2007-01-06 08:01 - 00274529 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvc.exe
2007-09-21 09:42 - 2007-01-06 08:01 - 00237671 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapEngine.dll
2007-09-21 09:42 - 2007-01-06 08:01 - 00032768 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvcps.dll
2007-09-21 09:41 - 2007-01-05 20:02 - 00262247 ____N () C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2007-09-21 09:42 - 2007-01-06 08:01 - 00118879 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSched.exe
2007-09-21 09:42 - 2007-01-06 08:01 - 00114785 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSchMgr.dll
2007-09-21 09:42 - 2007-01-06 08:01 - 00339968 _____ () C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLTinyDB.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318} => "default"="DiskDrive"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318} => "default"="DiskDrive"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
IE trusted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\webcompanion.com -> hxxp://webcompanion.com
 
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\100sexlinks.com -> 100sexlinks.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\101hotteens.com -> 101hotteens.com
IE restricted site: HKU\S-1-5-21-595894999-490155728-2440704941-1001\...\101lottery.com -> 101lottery.com
 
There are 4786 more restricted sites.
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-595894999-490155728-2440704941-1001\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 5.152.219.50 - 37.220.8.190
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: EnergyCut => C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe
MSCONFIG\startupreg: EzButton => C:\PROGRA~1\EzButton\EzButton.EXE
MSCONFIG\startupreg: Web Companion => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [{2B1930AF-46A1-4ABC-B339-C9771625098B}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Microsoft Tun Miniport Adapter #2
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/18/2015 11:30:01 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (08/17/2015 05:08:02 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4
 
Error: (08/17/2015 05:08:01 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: EmdCacheC:\Windows\system32\emdmgmt.dll4
 
Error: (08/17/2015 03:49:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16684 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 1248
Start Time: 01d0d8d609462d32
Termination Time: 125
 
Error: (08/17/2015 02:17:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16684 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 10ac
Start Time: 01d0d8c8329774b9
Termination Time: 141
 
Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The interface is unknown
 
Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (08/17/2015 12:14:09 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
 
System errors:
=============
Error: (08/21/2015 11:10:16 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: LiveUpdate%%2
 
Error: (08/21/2015 11:10:16 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
 
Error: (08/21/2015 11:10:16 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Advanced SystemCare Service 8%%2
 
Error: (08/21/2015 11:09:57 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (08/21/2015 11:08:43 AM) (Source: HTTP) (EventID: 15021) (User: )
Description: \Device\Http\ReqQueue0.0.0.0:4482
 
Error: (08/21/2015 11:04:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: LiveUpdate%%2
 
Error: (08/21/2015 11:04:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
 
Error: (08/21/2015 11:04:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Advanced SystemCare Service 8%%2
 
Error: (08/21/2015 11:04:05 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (08/21/2015 11:02:47 AM) (Source: HTTP) (EventID: 15021) (User: )
Description: \Device\Http\ReqQueue0.0.0.0:4482
 
 
Microsoft Office:
=========================
Error: (08/18/2015 11:30:01 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (08/18/2015 09:47:29 AM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (08/17/2015 05:08:02 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4
 
Error: (08/17/2015 05:08:01 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: EmdCacheC:\Windows\system32\emdmgmt.dll4
 
Error: (08/17/2015 03:49:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.16684124801d0d8d609462d32125
 
Error: (08/17/2015 02:17:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.1668410ac01d0d8c8329774b9141
 
Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The interface is unknown
 
Error: (08/17/2015 12:42:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (08/17/2015 12:14:09 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
 
CodeIntegrity:
===================================
  Date: 2015-08-21 11:18:48.584
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-21 11:18:47.960
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-21 11:18:47.383
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-21 11:18:46.759
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-21 11:18:45.417
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-21 11:18:44.809
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-21 11:18:44.122
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-21 11:18:43.514
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-21 11:18:42.297
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\is-K9FIV.tmp because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-21 11:18:41.626
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\is-K9FIV.tmp because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core2 CPU T5300 @ 1.73GHz
Percentage of memory in use: 57%
Total physical RAM: 2045.75 MB
Available physical RAM: 859.3 MB
Total Virtual: 4326.02 MB
Available Virtual: 2976.7 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:58.9 GB) (Free:23.3 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (LENOVO) (Fixed) (Total:78.24 GB) (Free:72 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149.1 GB) (Disk ID: C3FFC3FF)
Partition 1: (Active) - (Size=58.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=11.9 GB) - (Type=12)
Partition 3: (Not Active) - (Size=78.2 GB) - (Type=OF Extended)
 
==================== End of log ============================
Link to post
Share on other sites

  • Please download ZHPCleaner (by NicolasCoolman) to your desktop.
  • Double click on ZHPCleaner to run the tool. (Vista/Windows 7/8 users right-click and select Run As Administrator).
  • Please click on the Ashampoo_Snap_20140819_13h09m50s_001__zp button.
  • Then press the y3pI4LR.png button.
  • During the scan any open instances of the browsers will be closed automatically.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.
Link to post
Share on other sites

Here attached is the scan of the ZHP cleaner. 

 

~ ZHPCleaner v2015.8.26.332 by Nicolas Coolman (2015/08/26)
~ Run by KBC (Administrator)  (26/08/2015 19:05:31)
~ State version : Version OK
~ Type : Scan
~ Report : C:\Users\KBC\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\KBC\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows VISTA, 32-bit Service Pack 2 (Build 6002)
 
 
---\\  Services (0)
~ No malicious or unnecessary items found.
 
 
---\\  Browser internet (0)
~ No malicious or unnecessary items found.
 
 
---\\  Hosts file (1)
~ The hosts file is legitimate (1)
 
 
---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.
 
 
---\\  Explorer ( File, Folder) (0)
~ No malicious or unnecessary items found.
 
 
---\\  Registry ( Key, Value, Data) (0)
~ No malicious or unnecessary items found.
 
 
---\\ Result of repair
~ Any repair made
~ Browser not found (Mozilla Firefox)
~ Browser not found (Opera Software)
 
 
---\\ Statistics
~ Items scanned : 48659
~ Items found : 0
~ Items cancelled : 0
~ Items repaired : 0
 
 
~ End of search in 23 minutes
===================
ZHPCleaner--26082015-19_28_34.txt
 
 
Thank you for suggesting further action. ( i will be tied up over the next few days, hence my further response may be somewhat delayed.)
Link to post
Share on other sites

  • Please download ZOEK (by Smeenk) and save it to your desktop.
  • Right-click on 51a612a8b27e2-Zoek.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.

    52b6de58f1952-Zoek_Startpagina_5.0.0.0.P

  • In the main box please paste in the following script:

    createsrpoint;FFdefaults;autoclean;
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive).
  • Post its content into your next reply.
Link to post
Share on other sites

Thankyou for the suggestion.

 

I have attached the logs below, after that I rechecked browser and the pop-up ads are unfortunately still happening  :

 

 
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by KBC on 01/09/2015 at 19:34:29.91.
Microsoft® Windows Vista™ Home Basic  6.0.6002 Service Pack 2 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Downloads\Zoek\zoek\zoek.exe [scan all users] [script inserted] 
 
==== System Restore Info ======================
 
01/09/2015 19:38:09 Zoek.exe System Restore Point Created Successfully.
 
==== Empty Folders Check ======================
 
C:\Program Files\Acro Software deleted successfully
C:\Program Files\Camtech deleted successfully
C:\Program Files\DC-Unlocker deleted successfully
C:\Program Files\MSXML 4.0 deleted successfully
C:\Program Files\stinger deleted successfully
C:\Program Files\VideoLAN deleted successfully
C:\Program Files\Common Files\XCPCSync.OEM deleted successfully
C:\PROGRA~2\WinZipSE deleted successfully
C:\PROGRA~2\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} deleted successfully
C:\Users\Default\AppData\Roaming\ProductData deleted successfully
C:\Users\KBC\AppData\Roaming\Philipp Winterberg deleted successfully
C:\Users\SAMEER\AppData\Roaming\Itel deleted successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\CrashDumps deleted successfully
 
==== Deleting CLSID Registry Keys ======================
 
HKEY_USERS\S-1-5-21-595894999-490155728-2440704941-1001\Software\Microsoft\Internet Explorer\SearchScopes\{93FE6A51-45E9-4590-B71D-16364EB6A54F} deleted successfully
 
==== Deleting CLSID Registry Values ======================
 
 
==== Deleting Services ======================
 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LiveUpdateSvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\LiveUpdateSvc deleted successfully
 
==== Batch Command(s) Run By Tool======================
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
==== Deleting Files \ Folders ======================
 
C:\Program Files\Acro Software not found
C:\Program Files\Camtech not found
C:\Program Files\DC-Unlocker not found
C:\Program Files\stinger not found
C:\Program Files\VideoLAN not found
C:\PROGRA~2\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} not found
C:\Program Files\Free Download Manager deleted
C:\Users\KBC\AppData\Roaming\Rim.Desktop.Exception.log deleted
C:\Users\KBC\AppData\Roaming\Rim.Desktop.HttpServerSetup.log deleted
C:\Users\KBC\AppData\Roaming\Rim.DesktopHelper.Exception.log deleted
C:\Users\SAMEER\AppData\Roaming\ProductData deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\lavasoft\WebCompanion deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Windows\system32\LavasoftTcpService.dll deleted
 
==== Firefox Extensions Registry ======================
 
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files\McAfee\SiteAdvisor" [01/09/2015 19:15]
 
==== Chromium Look ======================
 
Google Chrome Version: 44.0.2403.157
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
fheoggkfdfchfphceeifdbepaooicaho - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx[17/08/2015 20:22]
 
Chrome Hotword Shared Module - KBC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
Chrome Hotword Shared Module - SAMEER\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
 
==== Chromium Startpages ======================
 
C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Preferences
1DCFA36F2166B0626BC2818701EE3092F3827FAC52555F573BEE48DEDA9","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"7D04C1241660FBA94ED78261FC57619B47ADFDD21D431A0A952E8E8CB2C3CA1C","pjkljhegncpnkpknbcohdijeoejaedia":"A3E23745C2A38B877D641A6882FCF831BF8DAEBD9587B7DBE2911E27DCF7F4EC"}},"google":{"services":{"account_id":"8DE2B1179323AA8D6BC2427875BFF09FD6858BEF499BAA32185BCF842648800B","last_username":"574907C6F7402856A9AB28D0D989F47EAC2A447181341F5CF99FD61EDDA6D5E5","username":"DCEB34A3D342F559940A31CB23F2347599EEB9B03222639EF94588CD7C6968A0"}},"homepage":"6667CA6B2A6BED56469BD741F260FF5EA136CD2600D102E50E98C3243C3ABADA","homepage_is_newtabpage":"5A4273500B1A088B2B455C4876555FD928D5DECC89CB3C5DA547C981BE6C70DB","pinned_tabs":"6C78BE8D55324BFB0DECA9E9B16FE9660D73A72680FC3BC2838BC173E6777341","prefs":{"preference_reset_time":"BBC98ADF6BA36C3CDF27D617A034BD5748D1DD117009A6A256459611389BB375"},"profile":{"reset_prompt_memento":"FF0526C4B23EBDBCA4CAF288B87D273767A2E011A2EC90AD59D43D4DFECB08FF"},"safebrowsing":{"incidents_sent":"356B9037C74DB46A92F984DF0D2DF48656EB8BA64CC0090E4718445FE8E066E7"},"search_provider_overrides":"B0C6EF8D5B6CEA6E9BE770833229E6619A82B2C7A8FEABEF312D2B67753940B7","session":{"restore_on_startup":"415F7CDEF2FD054609604194E46CFC91EFC7CD1D8010F2294017EDE7D6E7C50F","startup_urls":"3258CA2DD91A946B39D5253F762A422E8D8128FE642E18B77AB3DA1910D6D035"},"software_reporter":{"prompt_reason":"BDFCEF55CBBC8575A072DA3DA31A4213FD5337752361B37D3C9EC0470392DB90","prompt_seed":"C26C6D5D044AD5F96873ED033CE74EFFF5160EAC6F805E3293F227279E4FA846","prompt_version":"A40A519310B98DAD21AE909A1A98402FBD92D169F6F74008BC31879466135D69"},"sync":{"remaining_rollback_tries":"F365221B73D8F812BB1A46679B91BCAE740B558E1B227C00225BFEA45C9C1227"}},"super_mac":"33B0A8A0D5D6A363F1404BE7CAD4509F495BDE3611B6159DA26EC769922356FA"},"session":{"restore_on_startup":4,"startup_urls":["https://www.malwarebytes.org/]}}
 
 
==== Set IE to Default ======================
 
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{93FE6A51-45E9-4590-B71D-16364EB6A54F}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{93FE6A51-45E9-4590-B71D-16364EB6A54F}] not found
 
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
 
==== All HKCU SearchScopes ======================
 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
 
==== Deleting Registry Keys ======================
 
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Web Companion deleted successfully
 
==== Empty IE Cache ======================
 
C:\Users\KBC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\SAMEER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3HLYSIS1 will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CBN04ZCO will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E6OIBL4G will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EVDV215S will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3HLYSIS1 will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CBN04ZCO will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E6OIBL4G will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EVDV215S will be deleted at reboot
C:\Users\KBC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
 
==== Empty FireFox Cache ======================
 
No FireFox Profiles found
 
==== Empty Chrome Cache ======================
 
C:\Users\KBC\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\SAMEER\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
 
==== Empty All Flash Cache ======================
 
Flash Cache Emptied Successfully
 
==== Empty All Java Cache ======================
 
Java Cache cleared successfully
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=9 folders=4 452411 bytes)
 
==== Empty Temp Folders ======================
 
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\KBC\AppData\Local\Temp will be emptied at reboot
C:\Users\SAMEER\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
 
==== After Reboot ======================
 
==== Empty Temp Folders ======================
 
C:\Windows\Temp successfully emptied
C:\Users\KBC\AppData\Local\Temp successfully emptied
 
==== Empty Recycle Bin ======================
 
C:\$RECYCLE.BIN successfully emptied
 
==== Deleting Files / Folders ======================
 
"C:\Users\KBC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3HLYSIS1" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CBN04ZCO" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E6OIBL4G" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EVDV215S" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3HLYSIS1" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CBN04ZCO" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E6OIBL4G" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EVDV215S" not found
 
==== EOF on 02/09/2015 at  8:56:30.84 ======================
Link to post
Share on other sites

  • Please download GeekUninstaller and save it to desktop.
  • Extract the archive and run the file geek.exe
  • Right click on the Chrome (the example above is for Mozilla Firefox) and click on the Uninstall... button.

    XhV2QLa.png

  • Once the uninstallation is complete, the following window will appear to let you remove all leftovers including unnecessary files, useless folders, registry entries related to the uninstalled program.

    This is just an example for Mozilla Firefox. It should be similiar to you:

    geekuninstaller-3.png

  • Click on the Finish button to remove all detected traces.
  • Finally, click on the Close button to complete and go back to the main interface of Geek Uninstaller.
  • Close the program and reboot your system
When you are done, please download and install Google Chrome from their official website.
Link to post
Share on other sites

Used the Geek uninstaller to uninstall Google chrome, deleted leftovers.

Restarted the computer.

Downloaded google chrome from the google website and installed it.

Started google chrome. Unfortunately the pop up ads are still there, wherever I click in any website , except the secure websites starting with https:

 

Regards

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.