Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Adware popups explosion when click on new tabs or link mouseovers


  • Please log in to reply
12 replies to this topic

#1 Hez

Hez

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Local time:10:29 PM

Posted 21 February 2015 - 02:20 AM

Upon returning home after two months away, found the home computer (Lenovo desktop; Win7; i7; purchased Feb 2013) infested with adware virus.  This condition was non-existent when I left home after Thanksgiving 2013.  After some digging, I purchased SpyHunter4 for USD40.  It scanned the computer and came up with a long list of spyware cookies, tracking cookies, adware, and other malware.  Of course, to "fix" the problem, I would have to purchase the rest of the software.  After resisting and searching for alternatives, I made the purchase.
But, SpyHunter4 only removes the malware it finds during a scan.  There is something buried in the compute that causes the problems to start coming back.  To test this, I did a scan (which takes about 45 minutes) and immediately repeated the scan after performing the "fix" from the first scan.  A noticeably smaller number of malware was discovered.  When I did a scan again with the internet cable disconnected and "fixed" it, the repeat scan produced ZERO malware.  And, after a "fix" and continued surfing on the web, popups slowly start coming back in intensity...as time passes by.
I have CCleaner and Malwarebytes programs.  I've used these for years and kept them up to date.  They find nothing when I run these.
Now I want to get to the root of the problem and eliminate it.  There was no need for any SpyHunter4 type of software at all before I left home.  That is the position I want to get back to again.
Please help.
Respectfully,
Hez Bolton

Edited by Queen-Evie, 21 February 2015 - 09:45 AM.
moved from Windows 7 to Am I Infected


BC AdBot (Login to Remove)

 


#2 Sintharius

Sintharius

    Bleepin' Sniper


  • Members
  • 5,639 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Netherlands
  • Local time:07:29 AM

Posted 21 February 2015 - 04:24 AM

I have reported this post to a Moderator to be moved. In the meanwhile, please do not make any changes to your machine while waiting for assistance.

Alex

#3 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:29 AM

Posted 27 February 2015 - 10:39 AM

Hello,

We will be helping you with your problems. Please be patient while we assist you.

Some points for you to keep in mind while we are helping you to make things go easier and faster for both of us:

  • Please do NOT run, install or uninstall any programs, unless instructed to do so.
    We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.

NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.
- Do NOT backup any unknown files ending in .exe, .com, .scr, .pif, and .bat since files of these types are more likely to be infected.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to

For Win 8, Win 7 and Win Vista: "Windows Orb"> Programs > Accessories > Notepad
For Win XP: Start Menu > All Programs > Accessories > Notepad.

Please remember to copy the entire post so you do not miss any instructions.

----------------------------------------------

Please do the following:

:step1:

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


  • Double-click on TDSSKiller.exe on your desktop to run the tool for known TDSS variants.
  • Win Vista/Win 7 / Win 8 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click on change parameters
  • Under Objects to scan, check the boxes next to Verify file digital signatures, Detect TDLFS file system, then click OK.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • Note: If Cure is not an option, Skip instead, do NOT choose Delete or Quarantine unless instructed.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2014_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the full contents of that file in your next reply. - If the log is too long, then split it into multiple posts.

:step2:

Please download AdwCleaner by Xplode onto your Desktop.


  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan.
  • Confirm each time with Ok.
  • Then click on Clean.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

:step3:

Please download Farbar Service Scanner to the Desktop of the computer with the issue, and run it.


  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press Scan.
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the full contents of the log in your next reply.

:step4:

Please download MiniToolBox, save it to your Desktop and run it.

Checkmark the following checkboxes:


  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices (Only Problems)
  • List Users, Partitions and Memory size.
  • List Minidump Files
  • List Restore points

NOTE: When using "Reset FF Proxy Settings" option Firefox should be closed.

Click Go and post the full contents of the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.


Edited by dev00790, 27 February 2015 - 10:39 AM.

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#4 Hez

Hez
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Local time:10:29 PM

Posted 28 February 2015 - 08:38 PM

Thank you for helping me.  I printed out your email instructions and am going line by line.  I could not find the "Watch Topic" button you mentioned in your NOTE.  So that step has not been done.The TDSSKiller scan found nothing.... then, I went to the next step and ran adwcleaner.exe......the logfile it generated is below....I AM PROCEEDING to your next step (#3) and performing the steps you stated....I will not be waiting to hear back from you regarding this post....let me know if I should do something different....Thanks

 

[start of logfile from adwcleaner.exe]

# AdwCleaner v4.111 - Logfile created 28/02/2015 at 17:14:47
# Updated 18/02/2015 by Xplode
# Database : 2015-02-18.3 [Server]
# Operating system : Windows 8.1  (x64)
# Username : Hezekiah - BOLTONSPC
# Running from : C:\Users\Hezekiah\Desktop\AdwCleaner(1).exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

File Deleted : C:\Users\Hezekiah\AppData\Local\Temp\Uninstall.exe

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Mozilla Firefox v35.0.1 (x86 en-US)


*************************

AdwCleaner[R0].txt - [4188 bytes] - [16/02/2015 22:05:41]
AdwCleaner[R1].txt - [4247 bytes] - [16/02/2015 22:10:02]
AdwCleaner[R2].txt - [4306 bytes] - [16/02/2015 22:17:09]
AdwCleaner[R3].txt - [4365 bytes] - [16/02/2015 22:44:04]
AdwCleaner[R4].txt - [1097 bytes] - [28/02/2015 17:13:23]
AdwCleaner[S0].txt - [3846 bytes] - [16/02/2015 22:46:06]
AdwCleaner[S1].txt - [1027 bytes] - [28/02/2015 17:14:47]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1086  bytes] ##########
 



#5 Hez

Hez
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Local time:10:29 PM

Posted 28 February 2015 - 08:52 PM

Hello again....I just posted the logfile from the adwcleaner.exe scan and moved on the FARBAR SERVICE SCANNER.....I ran the FSS.exe program and the logfile generated is posted below....After posting that, I will be moving on to the next line of instructions in your email reply.....Thanks again.....Hez Bolton...looking forward to being bug free!!!

 

[logfile from FSS.exe]

Farbar Service Scanner Version: 17-01-2015
Ran by Hezekiah (administrator) on 28-02-2015 at 17:45:44
Running from "C:\Users\Hezekiah\Desktop"
Microsoft Windows 8.1  (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Action Center:
============


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Demand. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend: ""%ProgramFiles%\Windows Defender\MsMpEng.exe"".


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MsMpEng.exe => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****



#6 Hez

Hez
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Local time:10:29 PM

Posted 28 February 2015 - 09:44 PM

Hez here one last time til I hear back from you.

I think I forgot to transfer MINITOOLBOX to my desktop before I launched it.

I hope that is not a wrench/spanner in the works.

Anything you want done over, I'll be happy to do.

 

Thanks again and in advance,

 

Hez......short for Hezekiah



#7 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:29 AM

Posted 04 March 2015 - 01:23 PM

Hello,thanks for posting in the 3 day topic.

Please do rerun and post the Minitoolbox log.

What is your Browser?

Also run these.

lv0mVRW.pngJunkware Removal Tool
  • Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
cvMlKv6.pngESET Online Scanner
  • Hold down Control and click on this link to open ESET Online Scanner in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE: Sometimes if ESET finds no infections it will not create a log.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#8 Hez

Hez
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Local time:10:29 PM

Posted 05 March 2015 - 12:00 AM

Thanks Boopme,

My browser is FIREFOX/MOZILLA

Here is the logfile from "minitoolbox" scan:

 

[start of logfile]

MiniToolBox by Farbar  Version: 30-11-2014
Ran by Hezekiah (administrator) on 04-03-2015 at 20:56:19
Running from "C:\Users\Hezekiah\Desktop"
Microsoft Windows 8.1  (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================



========================= IP Configuration: ================================

Realtek PCIe GBE Family Controller = Ethernet (Connected)
1x1 11b/g/n Wireless LAN PCI Express Half Mini Card Adapter = Wi-Fi (Hardware not present)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled
add route prefix=169.254.0.0/16 interface="iftype0_0" nexthop=192.168.1.2 metric=1 publish=Yes
set interface interface="Local Area Connection* 1" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 11" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="ethernet_3" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled


popd
# End of IPv4 configuration



Windows IP Configuration

   Host Name . . . . . . . . . . . . : BoltonsPC
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
   Physical Address. . . . . . . . . : 74-27-EA-C3-AF-08
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::2c80:45ee:c04c:e82b%4(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.1.2(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Wednesday, March 4, 2015 2:22:19 PM
   Lease Expires . . . . . . . . . . : Thursday, March 5, 2015 2:22:19 PM
   Default Gateway . . . . . . . . . : 192.168.1.1
   DHCP Server . . . . . . . . . . . : 192.168.1.1
   DHCPv6 IAID . . . . . . . . . . . : 259270634
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-19-BF-D8-BB-74-27-EA-C3-AF-08
   DNS Servers . . . . . . . . . . . : 192.168.1.1
   NetBIOS over Tcpip. . . . . . . . : Enabled
Server:  UnKnown
Address:  192.168.1.1

Name:    google.com
Addresses:  2607:f8b0:400a:806::200e
      216.58.216.142


Pinging google.com [216.58.216.174] with 32 bytes of data:
Reply from 216.58.216.174: bytes=32 time=12ms TTL=55
Reply from 216.58.216.174: bytes=32 time=14ms TTL=55

Ping statistics for 216.58.216.174:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 12ms, Maximum = 14ms, Average = 13ms
Server:  UnKnown
Address:  192.168.1.1

Name:    yahoo.com
Addresses:  98.139.183.24
      98.138.253.109
      206.190.36.45


Pinging yahoo.com [206.190.36.45] with 32 bytes of data:
Reply from 206.190.36.45: bytes=32 time=20ms TTL=51
Reply from 206.190.36.45: bytes=32 time=19ms TTL=51

Ping statistics for 206.190.36.45:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 19ms, Maximum = 20ms, Average = 19ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
  4...74 27 ea c3 af 08 ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1      192.168.1.2     20
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      169.254.0.0      255.255.0.0         On-link       192.168.1.2     21
  169.254.255.255  255.255.255.255         On-link       192.168.1.2    276
      192.168.1.0    255.255.255.0         On-link       192.168.1.2    276
      192.168.1.2  255.255.255.255         On-link       192.168.1.2    276
    192.168.1.255  255.255.255.255         On-link       192.168.1.2    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link       192.168.1.2    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link       192.168.1.2    276
===========================================================================
Persistent Routes:
  Network Address          Netmask  Gateway Address  Metric
      169.254.0.0      255.255.0.0      192.168.1.2       1
===========================================================================

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  1    306 ::1/128                  On-link
  4    276 fe80::/64                On-link
  4    276 fe80::2c80:45ee:c04c:e82b/128
                                    On-link
  1    306 ff00::/8                 On-link
  4    276 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [53760] (Microsoft Corporation)
Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [68096] (Microsoft Corporation)
Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [68096] (Microsoft Corporation)
Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [65536] (Microsoft Corporation)
Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [21504] (Microsoft Corporation)
Catalog9 01 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 02 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 03 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 04 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 05 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 06 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 07 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 08 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 09 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 10 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [67584] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [30208] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (02/28/2015 05:23:26 PM) (Source: Application Hang) (User: )
Description: The program backgroundTaskHost.exe version 6.3.9600.16384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: f24

Start Time: 01d053bd9816502f

Termination Time: 4294967295

Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe

Report Id: 8e4f426e-bfb1-11e4-bebe-7427eac3af08

Faulting package full name: C59AD0AF.LenovoCloudStorageBySugarSync_1.3.0.889_neutral__m3tnjedffpfhj

Faulting package-relative application ID: App

Error: (02/28/2015 11:19:44 AM) (Source: Application Hang) (User: )
Description: The program backgroundTaskHost.exe version 6.3.9600.16384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: d7c

Start Time: 01d0538acc3880d9

Termination Time: 4294967295

Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe

Report Id: bfa74073-bf7e-11e4-bebc-7427eac3af08

Faulting package full name: C59AD0AF.LenovoCloudStorageBySugarSync_1.3.0.889_neutral__m3tnjedffpfhj

Faulting package-relative application ID: App

Error: (02/27/2015 01:09:26 AM) (Source: Application Hang) (User: )
Description: The program backgroundTaskHost.exe version 6.3.9600.16384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 3f0

Start Time: 01d0526c65b8480e

Termination Time: 4294967295

Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe

Report Id: 5383dd02-be60-11e4-bebc-7427eac3af08

Faulting package full name: C59AD0AF.LenovoCloudStorageBySugarSync_1.3.0.889_neutral__m3tnjedffpfhj

Faulting package-relative application ID: App

Error: (02/27/2015 01:05:00 AM) (Source: Application Hang) (User: )
Description: The program Spyhunter4.exe version 4.19.13.4482 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: b70

Start Time: 01d0526c5f2e90f8

Termination Time: 4294967295

Application Path: C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe

Report Id: b20782a3-be5f-11e4-bebc-7427eac3af08

Faulting package full name:

Faulting package-relative application ID:

Error: (02/22/2015 11:14:28 PM) (Source: Application Error) (User: )
Description: Faulting application name: YouTubeDownloader.exe, version: 4.0.284.0, time stamp: 0x540494b4
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17278, time stamp: 0x53eebf2e
Exception code: 0xe0434352
Fault offset: 0x000000000000606c
Faulting process id: 0x1e74
Faulting application start time: 0xYouTubeDownloader.exe0
Faulting application path: YouTubeDownloader.exe1
Faulting module path: YouTubeDownloader.exe2
Report Id: YouTubeDownloader.exe3
Faulting package full name: YouTubeDownloader.exe4
Faulting package-relative application ID: YouTubeDownloader.exe5

Error: (02/22/2015 11:14:28 PM) (Source: .NET Runtime) (User: )
Description: Application: YouTubeDownloader.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.FileNotFoundException
Stack:
   at FreeYouTubeDownloader.Program.Main()

Error: (02/22/2015 11:14:04 PM) (Source: Application Error) (User: )
Description: Faulting application name: YouTubeDownloader.exe, version: 4.0.284.0, time stamp: 0x540494b4
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17278, time stamp: 0x53eebf2e
Exception code: 0xe0434352
Fault offset: 0x000000000000606c
Faulting process id: 0xb18
Faulting application start time: 0xYouTubeDownloader.exe0
Faulting application path: YouTubeDownloader.exe1
Faulting module path: YouTubeDownloader.exe2
Report Id: YouTubeDownloader.exe3
Faulting package full name: YouTubeDownloader.exe4
Faulting package-relative application ID: YouTubeDownloader.exe5

Error: (02/22/2015 11:14:04 PM) (Source: .NET Runtime) (User: )
Description: Application: YouTubeDownloader.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.FileNotFoundException
Stack:
   at FreeYouTubeDownloader.Program.Main()

Error: (02/21/2015 03:12:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: BOLTONSPC)
Description: Activation of app Microsoft.SkypeApp_kzf8qxf38zg5c!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (02/20/2015 10:04:05 PM) (Source: Application Hang) (User: )
Description: The program backgroundTaskHost.exe version 6.3.9600.16384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1d6c

Start Time: 01d04d9b7cafd298

Termination Time: 4294967295

Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe

Report Id: 702aa225-b98f-11e4-beb9-b00594ee441b

Faulting package full name: C59AD0AF.LenovoCloudStorageBySugarSync_1.3.0.889_neutral__m3tnjedffpfhj

Faulting package-relative application ID: App


System errors:
=============
Error: (02/28/2015 05:18:12 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Optimizer Pro Crash Monitor service to connect.

Error: (02/28/2015 01:00:36 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Optimizer Pro Crash Monitor service to connect.

Error: (02/27/2015 01:04:18 AM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Optimizer Pro Crash Monitor service to connect.

Error: (02/27/2015 01:02:34 AM) (Source: Service Control Manager) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error:
%%1068

Error: (02/27/2015 01:02:34 AM) (Source: Service Control Manager) (User: )
Description: The Network Location Awareness service depends on the DHCP Client service which failed to start because of the following error:
%%1068

Error: (02/27/2015 01:02:34 AM) (Source: Service Control Manager) (User: )
Description: The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:
%%1068

Error: (02/27/2015 01:02:34 AM) (Source: Service Control Manager) (User: )
Description: The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:
%%1068

Error: (02/27/2015 01:02:34 AM) (Source: Service Control Manager) (User: )
Description: The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub System service which failed to start because of the following error:
%%31

Error: (02/27/2015 01:02:34 AM) (Source: Service Control Manager) (User: )
Description: The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error:
%%1068

Error: (02/27/2015 01:02:34 AM) (Source: Service Control Manager) (User: )
Description: The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error:
%%1068


Microsoft Office Sessions:
=========================
Error: (02/28/2015 05:23:26 PM) (Source: Application Hang)(User: )
Description: backgroundTaskHost.exe6.3.9600.16384f2401d053bd9816502f4294967295C:\WINDOWS\system32\backgroundTaskHost.exe8e4f426e-bfb1-11e4-bebe-7427eac3af08C59AD0AF.LenovoCloudStorageBySugarSync_1.3.0.889_neutral__m3tnjedffpfhjApp

Error: (02/28/2015 11:19:44 AM) (Source: Application Hang)(User: )
Description: backgroundTaskHost.exe6.3.9600.16384d7c01d0538acc3880d94294967295C:\WINDOWS\system32\backgroundTaskHost.exebfa74073-bf7e-11e4-bebc-7427eac3af08C59AD0AF.LenovoCloudStorageBySugarSync_1.3.0.889_neutral__m3tnjedffpfhjApp

Error: (02/27/2015 01:09:26 AM) (Source: Application Hang)(User: )
Description: backgroundTaskHost.exe6.3.9600.163843f001d0526c65b8480e4294967295C:\WINDOWS\system32\backgroundTaskHost.exe5383dd02-be60-11e4-bebc-7427eac3af08C59AD0AF.LenovoCloudStorageBySugarSync_1.3.0.889_neutral__m3tnjedffpfhjApp

Error: (02/27/2015 01:05:00 AM) (Source: Application Hang)(User: )
Description: Spyhunter4.exe4.19.13.4482b7001d0526c5f2e90f84294967295C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exeb20782a3-be5f-11e4-bebc-7427eac3af08

Error: (02/22/2015 11:14:28 PM) (Source: Application Error)(User: )
Description: YouTubeDownloader.exe4.0.284.0540494b4KERNELBASE.dll6.3.9600.1727853eebf2ee0434352000000000000606c1e7401d04f385cc7ea55C:\Users\Hezekiah\Documents\Computers\YouTubeDownloader.exeC:\WINDOWS\system32\KERNELBASE.dll9a793a83-bb2b-11e4-beb9-b00594ee441b

Error: (02/22/2015 11:14:28 PM) (Source: .NET Runtime)(User: )
Description: Application: YouTubeDownloader.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.FileNotFoundException
Stack:
   at FreeYouTubeDownloader.Program.Main()

Error: (02/22/2015 11:14:04 PM) (Source: Application Error)(User: )
Description: YouTubeDownloader.exe4.0.284.0540494b4KERNELBASE.dll6.3.9600.1727853eebf2ee0434352000000000000606cb1801d04f384df90225C:\Users\Hezekiah\Documents\Computers\YouTubeDownloader.exeC:\WINDOWS\system32\KERNELBASE.dll8c0c1254-bb2b-11e4-beb9-b00594ee441b

Error: (02/22/2015 11:14:04 PM) (Source: .NET Runtime)(User: )
Description: Application: YouTubeDownloader.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.FileNotFoundException
Stack:
   at FreeYouTubeDownloader.Program.Main()

Error: (02/21/2015 03:12:51 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: BOLTONSPC)
Description: Microsoft.SkypeApp_kzf8qxf38zg5c!App-2144927142

Error: (02/20/2015 10:04:05 PM) (Source: Application Hang)(User: )
Description: backgroundTaskHost.exe6.3.9600.163841d6c01d04d9b7cafd2984294967295C:\WINDOWS\system32\backgroundTaskHost.exe702aa225-b98f-11e4-beb9-b00594ee441bC59AD0AF.LenovoCloudStorageBySugarSync_1.3.0.889_neutral__m3tnjedffpfhjApp



=========================== Installed Programs ============================
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.4.0.2710 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.5.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.1.4 - Canon Inc.)
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.4.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.1.5.14 - Canon Inc.)
Canon MX470 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX470_series) (Version: 1.00 - Canon Inc.)
Canon MX470 series On-screen Manual (HKLM-x32\...\Canon MX470 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon MX470 series User Registration (HKLM-x32\...\Canon MX470 series User Registration) (Version:  - ?Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 2.1.0 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 2.1.0 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.2.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.3.0 - Canon Inc.)
Canon Speed Dial Utility (HKLM-x32\...\Speed Dial Utility) (Version: 1.4.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.)
CyberLink PhotoDirector 3 (x32 Version: 3.0.1.4107 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Driver & Application Installation (HKLM-x32\...\{BFECCF2A-F094-4066-8BFA-29CCBB7F6602}) (Version: 6.12.0911 - Lenovo)
Free YouTube Downloader 4.0.284 (HKLM-x32\...\{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1) (Version:  - HOW Inc.)
Intel AppUp(SM) center (HKLM-x32\...\Intel AppUp(SM) center 33057) (Version: 3.6.1.33057.10 - Intel)
Intel® Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36702 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3907 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.0.1083 - Intel Corporation)
Intel® Rapid Storage Technology (Version: 12.0.0.1083 - Intel Corporation) Hidden
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.27.798.1 - Intel Corporation) Hidden
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Java Auto Updater (x32 Version: 2.1.71.14 - Oracle, Inc.) Hidden
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Lenovo Assistant (HKLM-x32\...\{B2DE4F30-B8C7-49C0-85B9-2F37A5290F00}) (Version: 2.0.0.29 - Lenovo)
Lenovo Blacksilk USB Keyboard Driver (HKLM-x32\...\{B266E062-D6C5-485B-B426-51B152B041A6}) (Version: V1.4.11.0608 - Lenovo)
Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.5 - CEWE COLOR AG u Co. OHG)
Lenovo Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.7408 - CyberLink Corp.)
Lenovo Power2Go (x32 Version: 6.0.7408 - CyberLink Corp.) Hidden
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5108.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5108.52 - CyberLink Corp.) Hidden
Lenovo Rescue System (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 4.0.0.1511 - CyberLink Corp.)
Lenovo Rescue System (Version: 4.0.0.1511 - CyberLink Corp.) Hidden
Lenovo Solution Center (HKLM\...\{13BD494D-9ACD-420B-A291-E145DED92EF6}) (Version: 2.6.001.00 - Lenovo Group Limited)
LVT (HKLM-x32\...\{9E3469A6-443A-452C-BF44-8D7CE3A9A7E2}) (Version: 5.00.0914 - Lenovo)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKCU\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 35.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
Photo Gallery (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.10.1226.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6743 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4123-B2B9-173F09590E16}) (Version: 1.01.0187 - REALTEK Semiconductor Corp.)
RegHunter (HKLM-x32\...\RegHunter) (Version: 1.3.3.1613 - Enigma Software Group, LLC)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Sophos Anti-Virus (HKLM-x32\...\{D929B3B5-56C6-46CC-B3A3-A1A784CBB8E4}) (Version: 10.3.7 - Sophos Limited)
Sophos AutoUpdate (HKLM-x32\...\{D924231F-D02D-4E0B-B511-CC4A0E3ED547}) (Version: 3.1.1.18 - Sophos Limited)
Sophos Remote Management System (HKLM-x32\...\{FED1005D-CBC8-45D5-A288-FFC7BB304121}) (Version: 3.4.1 - Sophos Limited)
SpyHunter 4 (HKLM-x32\...\SpyHunter) (Version: 4.19.13.4482 - Enigma Software Group, LLC)
VueScan x64 (HKLM\...\VueScan x64) (Version:  - )
Windows Live Communications Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
WPS Office (9.1.0.4759) (HKCU\...\WPS Office) (Version: 9.1.0.4759 - Kingsoft Corp.)

========================= Memory info: ===================================

Percentage of memory in use: 19%
Total physical RAM: 8106.39 MB
Available physical RAM: 6545.01 MB
Total Pagefile: 16810.39 MB
Available Pagefile: 15162.45 MB
Total Virtual: 4095.88 MB
Available Virtual: 3972.17 MB

========================= Partitions: =====================================

1 Drive c: (Windows8_OS) (Fixed) (Total:904.47 GB) (Free:762.43 GB) NTFS

========================= Users: ========================================

User accounts for \\BOLTONSPC

Administrator            Guest                    Hezekiah                 
Naomi Williams           SophosSAUBOLTONSPC0      

========================= Minidump Files ==================================

No minidump file found

========================= Restore Points ==================================

15-02-2015 01:04:14 LavasoftWeCompanion
17-02-2015 06:12:50 Before ADWCLEANER is ran and cleaning occurs; 16Feb2015
26-02-2015 06:49:06 Scheduled Checkpoint
28-02-2015 19:25:03 Before starting to rid of ADWARE and other things-28Feb2015

**** End of log ****
 



#9 Hez

Hez
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Local time:10:29 PM

Posted 05 March 2015 - 01:34 AM

Here is the JRT.txt flie saved to the desktop.  I will be re-enabling my FIREWALL after sending thsi text file.......Then on to the ESET section of your instructions.

 

[start of text file]

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.3 (03.01.2015:1)
OS: Windows 8.1 x64
Ran by Hezekiah on Wed 03/04/2015 at 22:18:51.12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] "C:\WINDOWS\wininit.ini"



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Hezekiah\appdata\local\free youtube downloader"
Successfully deleted: [Folder] "C:\Program Files (x86)\free youtube downloader"



~~~ FireFox

Emptied folder: C:\Users\Hezekiah\AppData\Roaming\mozilla\firefox\profiles\sbukwne4.default\minidumps [8 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 03/04/2015 at 22:20:12.61
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 



#10 Hez

Hez
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Local time:10:29 PM

Posted 05 March 2015 - 03:16 AM

Boopme,

This is the text file generated by ESET following it's online scan.  It detected another anti-virus program which I disabled (SOPHOS) before proceeding with the scan. 

QUESTION:  to disable all the anti-virus protection, does that include both the software program AND the firewall?  This may seem like a very basic question, but I'm not sure. 

 

[start of text/logfile]

C:\Users\Hezekiah\AppData\Local\Temp\nsc3251.tmp\apphelp.dll    a variant of Win32/Toolbar.SearchSuite.X potentially unwanted application    deleted - quarantined
C:\Users\Hezekiah\AppData\Local\Temp\nsc3251.tmp\soffer.dll    a variant of Win32/Soffer.A potentially unwanted application    deleted - quarantined
C:\Users\Hezekiah\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\3146794-6a8b299d    multiple threats    cleaned by deleting - quarantined
C:\Users\Hezekiah\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\1ab9355c-627fb06e    multiple threats    cleaned by deleting - quarantined
C:\Users\Hezekiah\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\24effe63-6220ae5e    multiple threats    cleaned by deleting - quarantined
C:\Users\Hezekiah\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\75fe53f4-68c823e6    multiple threats    cleaned by deleting - quarantined
C:\Users\Hezekiah\Documents\Computers\Utilities for Computer\gusetup.exe    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Computers\Utilities for Computer\VirtumundoBeGone.exe    Win32/PrcView potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads\FLVPlayerSetup.exe    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads\FoxitReader502.0718_enu_Setup.exe    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads\GOMPLAYERENSETUP.EXE    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads\zaSetup_92_106_000_en.exe    a variant of Win32/Toolbar.Conduit.AI potentially unwanted application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads_ALL\Avery Wizard 4.01 - US 20111209.exe    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads_ALL\ccsetup317.exe    Win32/Bundled.Toolbar.Google.E potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads_ALL\ccsetup318.exe    Win32/Bundled.Toolbar.Google.E potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads_ALL\ccsetup319.exe    Win32/Bundled.Toolbar.Google.E potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads_ALL\ccsetup323.exe    Win32/Bundled.Toolbar.Google.E potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads_ALL\ccsetup326.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads_ALL\ccsetup408.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads_ALL\FreeYouTubeDownload(1).exe.part    Win32/Toolbar.Conduit potentially unwanted application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads_ALL\FreeYouTubeDownload.exe    Win32/Toolbar.Conduit potentially unwanted application    deleted - quarantined
C:\Users\Hezekiah\Documents\Downloads_ALL\media.player.codec.pack.v4.2.4.setup.exe    a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Downloads\adawarefreeantivirus-setup.exe    a variant of Win32/DownloadAdmin.I potentially unwanted application    deleted - quarantined
C:\Users\Hezekiah\Downloads\ccsetup410.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Downloads\ccsetup418.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Downloads\ccsetup419.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Downloads\ccsetup503.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Downloads\FreemakeVideoDownloaderSetup(1).exe    Win32/OpenCandy potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Downloads\FreemakeVideoDownloaderSetup.exe    Win32/OpenCandy potentially unsafe application    deleted - quarantined
C:\Users\Hezekiah\Downloads\iLividSetup-r120-n-bf.exe    Win32/Toolbar.SearchSuite potentially unwanted application    deleted - quarantined
C:\Users\Hezekiah\Downloads\Minecraft Download Manager.exe    a variant of Win32/InstallCore.UE potentially unwanted application    deleted - quarantined
C:\Users\Hezekiah\Downloads\Windows Live Movie Maker Download Manager.exe    a variant of Win32/InstallCore.PV potentially unwanted application    deleted - quarantined
C:\Users\Hezekiah\Downloads\WindowsMovieMaker_Setup.exe    a variant of Win32/InstallCore.WI potentially unwanted application    deleted - quarantined
C:\Users\Hezekiah\Downloads\youtubevideodownloader-setup.exe    a variant of Win32/DownloadAdmin.I potentially unwanted application    deleted - quarantined

[end of ESET text/logfile]

 

I look forward to your response and next set of instructions.

Respectfully.....................Hez



#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:29 AM

Posted 05 March 2015 - 01:18 PM

Nice clean...

Yes, only the Antivirus program.

In the Control Panel , Uninstall Java 7 Update 71

In Firefox, Add ons/Plugins, look for unknown add ons and disable.

How to disable extensions and plugins

Keeping your third-party plugins up to date


Last, Empty your temp folders using TFC (Temporary File Cleaner)
  • Please download TFC by Old Timer and save it to your desktop.
    alternate download link
  • Save any unsaved work. (TFC will close ALL open programs including your browser!)
  • Double-click on TFC.exe to run it. (If you are using Vista or above, right-click on the file and choose "Run As Administrator".)
  • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway allowing Windows to load normally (not into Safe Mode) to ensure a complete clean.
How is it now?

Edited by boopme, 05 March 2015 - 01:19 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#12 Hez

Hez
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Local time:10:29 PM

Posted 06 March 2015 - 02:20 AM

Boopme,

 

Thanks again.

I uninstalled "Java 7 Update 7i".

As for the Add ons/Plugins for Firefox, I did not disable anything I observed.  And, all plug-ins were indicated as "Up to date".

TFC removed a ton of stuff from all users.

I was not prompted to reboot by TFC, but I did it anyway.

Right now, I feel that things are back to normal with regards to the ADWARE/POPUPS!  I'm guessing that you all saw things that guided your feedback to me and directed me accordingly.

Thanks to all..........................Hez

[How can I donate to the cause?]



#13 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:29 AM

Posted 09 March 2015 - 01:45 PM

Yes that is correct and the Reboot was important.

Thanks for the offer... I do not accept donations nor does BC.. But I will recommend, if you'd like to contribute to something that would be very much appreciated..
Make a donation to some people here that would appreciate it. They help or developed some of the tools we use here to clean computers or are ajust hard workers.

Click on a name below, say JSntgRvr, Now scroll down their post and you will see a PayPal link.

I am still adding to this list.

farbar
fireman4it
JSntgRvr
m0le
myrti
sempai
Thunder
SweetTech
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users