Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

about:blank possible malware?


  • This topic is locked This topic is locked
20 replies to this topic

#1 Angel White

Angel White

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Arizona Bay
  • Local time:10:02 PM

Posted 06 June 2015 - 11:05 PM

Referred from here: http://www.bleepingcomputer.com/forums/t/577976/aboutblank ~ OB

HI! i have been, for the last several days attempting with the the very friendly help of your staff members to "fix" this about:blank redirect problem i have had ongoing for about a year.  it slows down everything. when i go to anything, a webpage it hangs for a few seconds to a minute or so, sometimes. its not a homepage thing, it doesnt come up when i open a new tab or the bring the browser up, just when i go to a new webpage, and usually when i click an external link...it doesnt effect my home page or start up page, just redirects me to it then onto the page i wanted. 
 
So far i have cleaned with Ccleaner, and System Mechanic ( a tool i wanted to try out, but since uninstalled) and SuperAntispyware.  i recently also ran Avast antivirus. all this on my own.
 
With your guys' help, we tried using CWShredder. We did find a gamebar and something like websearch, i think CoolWebSearch came up on that.. They had me change the homepage (just in case). they also had me use the following tools: MiniToolbox, Screen317 Security Check, Speccy, RKiLL, adwcleaner and Malwarebytes. 
 
Everything came back ok except for the first one (the gamebar and coolwebsearch) and a lot of errors. something to do with iTunes. so i just uninstalled it. and everything is up to date...
 
Anyway at first after all this it seemed ok with the speed was great! and then the about:blank came back right after rebooting my machine, it came up right away on the start page. then it redirected me  a couple times. it doesnt seem to happen all the time tho, so i am confused.. 
 
BTW that was the only time i had it come up on the start page. it hasnt since. 
 
 
 
Windows 8.1 64 bit; Desktop (UTD)
Google Chrome (UTD)
Avast avp
Malwarebytes
SuperAntispyware
Ccleaner
 
 
 
 
 
 
So, followed the prep guide and here are the logs--
 
 
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:06-06-2015
Ran by pam (administrator) on MINE on 06-06-2015 20:16:54
Running from C:\Users\pam\Downloads
Loaded Profiles: pam (Available Profiles: pam)
Platform: Windows 8.1 Connected (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Google Inc.) C:\Users\pam\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Runtime Software) C:\Program Files (x86)\Runtime Software\DriveImage XML\dixml.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7506648 2014-01-11] (Realtek Semiconductor)
HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [3957816 2014-02-07] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [415288 2014-02-07] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [415288 2014-02-07] (Hewlett-Packard)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-01-24] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-11] (Avast Software s.r.o.)
HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7799576 2015-05-20] (SUPERAntiSpyware)
HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\Run: [Google Update] => C:\Users\pam\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-09-02] (Google Inc.)
HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\Run: [Google+ Auto Backup] => C:\Users\pam\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [3754312 2015-02-13] (Google Inc.)
HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8322328 2015-05-08] (Piriform Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-04-23] (Avast Software s.r.o.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK14/1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK14/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK14/1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK14/1
HKU\S-1-5-21-1548870796-431023125-660753347-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK14/1
HKU\S-1-5-21-1548870796-431023125-660753347-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://js.redirect.hp.com/jumpstation?bd=all&c=143&locale=ww_ww&pf=cndt&s=ieHPtab&tp=iehome
HKU\S-1-5-21-1548870796-431023125-660753347-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://js.redirect.hp.com/jumpstation?bd=all&c=143&locale=ww_ww&pf=cndt&s=ieHPtab&tp=iehome
HKU\S-1-5-21-1548870796-431023125-660753347-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKU\S-1-5-21-1548870796-431023125-660753347-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
SearchScopes: HKLM -> {0311EA1F-04F0-4893-A4CF-416D079F3AC1} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link_code=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {0311EA1F-04F0-4893-A4CF-416D079F3AC1} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link_code=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1548870796-431023125-660753347-1001 -> {0311EA1F-04F0-4893-A4CF-416D079F3AC1} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link_code=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-1548870796-431023125-660753347-1001 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = http://mumbojumbo.start.iplay.com/searchresults.aspx?o=chrome&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1548870796-431023125-660753347-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-17] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-04] (Avast Software s.r.o.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-17] (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-17] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-04] (Avast Software s.r.o.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-17] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
 
FireFox:
========
FF ProfilePath: C:\Users\pam\AppData\Roaming\Mozilla\Firefox\Profiles\3nh7ww8g.default
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-05-18] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-18] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-08-12] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-17] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-17] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-14] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [2015-04-10] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1548870796-431023125-660753347-1001: @tools.google.com/Google Update;version=3 -> C:\Users\pam\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1548870796-431023125-660753347-1001: @tools.google.com/Google Update;version=9 -> C:\Users\pam\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.)
FF Extension: WOT - C:\Users\pam\AppData\Roaming\Mozilla\Firefox\Profiles\3nh7ww8g.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-05-31]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-08]
 
Chrome: 
=======
CHR Profile: C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-15]
CHR Extension: (Google Docs) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-15]
CHR Extension: (Google Drive) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-15]
CHR Extension: (YouTube) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-15]
CHR Extension: (Google Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-15]
CHR Extension: (Google Sheets) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-15]
CHR Extension: (Avast Online Security) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-15]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-15]
CHR Extension: (Google Wallet) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-15]
CHR Extension: (Gmail) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-15]
CHR Profile: C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Ask Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf [2014-08-13]
CHR Extension: (Google Docs) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-13]
CHR Extension: (Google Drive) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-13]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-13]
CHR Extension: (YouTube) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-13]
CHR Extension: (Google Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-13]
CHR Extension: (Webroot Filtering Extension) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kjeghcllfecehndceplomkocgfbklffd [2014-08-13]
CHR Extension: (Google Wallet) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-13]
CHR Extension: (Webroot Password Manager) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab [2014-08-13]
CHR Extension: (Gmail) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-13]
CHR Profile: C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2
CHR Extension: (Ask Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf [2014-09-05]
CHR Extension: (Google Slides) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-05]
CHR Extension: (Google Docs) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-05]
CHR Extension: (Google Drive) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-05]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-05]
CHR Extension: (YouTube) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-05]
CHR Extension: (Google Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-05]
CHR Extension: (Google Sheets) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-05]
CHR Extension: (Webroot Filtering Extension) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\kjeghcllfecehndceplomkocgfbklffd [2014-09-05]
CHR Extension: (Google Wallet) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-05]
CHR Extension: (Webroot Password Manager) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab [2014-09-05]
CHR Extension: (Gmail) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-05]
CHR Profile: C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3
CHR Extension: (Ask Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf [2014-09-05]
CHR Extension: (Google Docs) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-05]
CHR Extension: (Google Drive) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-05]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-05]
CHR Extension: (YouTube) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-05]
CHR Extension: (Google Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-05]
CHR Extension: (Google Sheets) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-05]
CHR Extension: (Google Wallet) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-05]
CHR Extension: (Gmail) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-05]
CHR Profile: C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4
CHR Extension: (Google Slides) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-17]
CHR Extension: (Unfriend Notify for Facebook) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ahigpjeolkfgjdaeodlmaceggigbpeoh [2014-11-13]
CHR Extension: (Google Docs) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-17]
CHR Extension: (Google Drive) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-17]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-17]
CHR Extension: (WOT) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-11-13]
CHR Extension: (YouTube) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-17]
CHR Extension: (Adblock Plus) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-13]
CHR Extension: (Google Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-17]
CHR Extension: (HTML5 video for YouTube™) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\dolajcekhnohkpncmhgledbmndjpblei [2014-11-13]
CHR Extension: (Scroll Button) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fbkobdcckhcgleanepepnfaficicaogg [2014-11-13]
CHR Extension: (Google Sheets) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-17]
CHR Extension: (Spaaze) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\hofabcapkmnnhhccplipkecnjbmgoegl [2014-11-13]
CHR Extension: (Arcane Legends) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ibmlkgieigeddcedpbijnpojheoddido [2014-11-13]
CHR Extension: (Social Fixer for Facebook) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2014-11-13]
CHR Extension: (WeatherBug (Legacy App)) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak [2014-11-13]
CHR Extension: (Deadmau5 Green Edition) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\iphfjhmkmdjocaaopmgpeikabebejihc [2014-11-13]
CHR Extension: (International Internet TV ) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\jpfaflofhdeeaikcajgalgbpgejbmihk [2014-11-13]
CHR Extension: (Ball And Wall) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\kcmmmjjfnehcoglgiddaebjngdbgpiih [2014-11-13]
CHR Extension: (Scroll to Top) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\khnloieeghjghmpjeaopaenibbneljpk [2014-11-13]
CHR Extension: (Unfriend Alerts) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\lgbeldbnadmemecalekdfnffgobkpafc [2014-11-13]
CHR Extension: (Google Maps) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-11-13]
CHR Extension: (WeatherBug) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\mekeaeklopjambfhgndcddmpfbinkdpb [2014-11-13]
CHR Extension: (WeatherBug) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\njkkjobcechefaoknodniidfjapgfoco [2014-11-13]
CHR Extension: (Google Wallet) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-17]
CHR Extension: (Weather Underground) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjejbgheonogbpfkkjigbmahaljipoej [2014-11-13]
CHR Extension: (Gmail) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-17]
CHR Profile: C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 5
CHR Profile: C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6
CHR Extension: (Google Slides) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-13]
CHR Extension: (Google Docs) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-13]
CHR Extension: (Google Drive) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-13]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-13]
CHR Extension: (YouTube) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-13]
CHR Extension: (Google Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-13]
CHR Extension: (Avast SafePrice) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-01-23]
CHR Extension: (Google Sheets) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-13]
CHR Extension: (Avast Online Security) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-01-23]
CHR Extension: (Google Wallet) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-13]
CHR Extension: (Gmail) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-13]
CHR Profile: C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7
CHR Extension: (Google Docs) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-15]
CHR Extension: (Google Drive) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-15]
CHR Extension: (WOT) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2015-02-10]
CHR Extension: (YouTube) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-15]
CHR Extension: (Adblock Plus) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-15]
CHR Extension: (Google Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-15]
CHR Extension: (Tampermonkey) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2015-03-24]
CHR Extension: (Google Sheets) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-15]
CHR Extension: (Weather) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\gdhhajdfefljnoihedjgannejglblohb [2015-02-11]
CHR Extension: (Bookmark Manager) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-01-29]
CHR Extension: (Pin It Button) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-02-28]
CHR Extension: (Stylish Facebook Themes) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\haomkemhnjlojfjklokcbkjkdanghlic [2015-05-19]
CHR Extension: (Spaaze) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\hofabcapkmnnhhccplipkecnjbmgoegl [2014-11-15]
CHR Extension: (Arcane Legends) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\ibmlkgieigeddcedpbijnpojheoddido [2014-11-15]
CHR Extension: (Social Fixer for Facebook) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2015-02-10]
CHR Extension: (Deadmau5 Green Edition) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\iphfjhmkmdjocaaopmgpeikabebejihc [2014-11-15]
CHR Extension: (International Internet TV ) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\jpfaflofhdeeaikcajgalgbpgejbmihk [2014-11-15]
CHR Extension: (Scroll to Top) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\khnloieeghjghmpjeaopaenibbneljpk [2015-02-10]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Google Maps) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-11-15]
CHR Extension: (WeatherBug) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\mekeaeklopjambfhgndcddmpfbinkdpb [2015-02-12]
CHR Extension: (Fairshare) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\mkaliidbdemijhjchoaoomhfifplapmi [2015-05-19]
CHR Extension: (WeatherBug) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\njkkjobcechefaoknodniidfjapgfoco [2015-02-10]
CHR Extension: (Google Wallet) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-15]
CHR Extension: (Weather Underground) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\pjejbgheonogbpfkkjigbmahaljipoej [2014-11-15]
CHR Extension: (Gmail) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-15]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-20]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-23] (Avast Software s.r.o.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [373312 2015-04-10] (WildTangent)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [88064 2014-02-07] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-11] (Realtek Semiconductor)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-07-02] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 1394ohci; C:\Windows\System32\drivers\1394ohci.sys [231424 2013-08-22] (Microsoft Corporation) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-23] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-04-23] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-23] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-23] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-23] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-04-23] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-04-23] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-04-23] ()
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3888640 2014-02-14] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-02-25] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-06-06] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R1 RawDisk3; C:\windows\system32\drivers\rawdsk3.sys [32912 2015-03-25] (EldoS Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
U3 McAPExe; No ImagePath
U3 McMPFSvc; No ImagePath
U3 McNaiAnn; No ImagePath
U3 mfecore; No ImagePath
U3 MSK80Service; No ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-06 20:16 - 2015-06-06 20:21 - 00034272 _____ C:\Users\pam\Downloads\FRST.txt
2015-06-06 20:15 - 2015-06-06 20:17 - 00000000 ____D C:\FRST
2015-06-06 20:14 - 2015-06-06 20:14 - 02108928 _____ (Farbar) C:\Users\pam\Downloads\FRST64.exe
2015-06-06 19:52 - 2015-06-06 19:52 - 00000000 ____D C:\Users\pam\New folder
2015-06-06 19:51 - 2015-06-06 19:51 - 00000000 ____D C:\Users\pam\Documents\New folder
2015-06-06 19:47 - 2015-06-06 19:47 - 00001130 _____ C:\Users\Public\Desktop\DriveImage XML.lnk
2015-06-06 19:47 - 2015-06-06 19:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Runtime Software
2015-06-06 19:47 - 2015-06-06 19:47 - 00000000 ____D C:\Program Files (x86)\Runtime Software
2015-06-06 19:43 - 2015-06-06 19:44 - 02026456 _____ C:\Users\pam\Downloads\dixmlsetup.exe
2015-06-06 18:54 - 2015-06-06 18:57 - 19709440 _____ (Luis Cobian, CobianSoft) C:\Users\pam\Downloads\Unconfirmed 481682.crdownload
2015-06-03 20:40 - 2015-06-03 20:40 - 00077615 _____ C:\Users\pam\Downloads\download-2.jpeg
2015-06-03 12:21 - 2015-05-15 15:01 - 00133288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-06-03 12:21 - 2015-05-15 14:05 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-06-03 12:21 - 2015-05-15 13:47 - 00355328 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-06-03 12:21 - 2015-05-15 13:23 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-06-03 12:21 - 2015-05-15 12:42 - 03682304 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-06-03 12:21 - 2015-05-15 12:32 - 00035840 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-06-03 12:21 - 2015-05-15 12:31 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-06-03 12:21 - 2015-05-15 12:28 - 02223104 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-06-03 12:21 - 2015-05-15 12:28 - 00408064 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2015-06-03 12:21 - 2015-05-15 12:28 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-06-03 12:21 - 2015-05-15 12:27 - 00891904 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-06-03 12:21 - 2015-05-15 12:21 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-06-03 12:21 - 2015-05-15 12:21 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-06-03 12:21 - 2015-05-15 12:19 - 00721920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-06-03 12:21 - 2015-05-15 12:19 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-06-03 12:20 - 2015-05-25 06:23 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2015-06-03 12:20 - 2015-05-25 06:07 - 01430528 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2015-06-03 12:20 - 2015-05-22 06:08 - 00700416 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-06-03 12:20 - 2015-05-21 06:08 - 01119232 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-06-03 12:20 - 2015-05-21 06:08 - 01020928 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-06-03 12:20 - 2015-05-21 06:08 - 00756736 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-06-03 12:20 - 2015-05-21 06:08 - 00422912 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-06-03 12:20 - 2015-05-21 06:08 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-06-03 12:20 - 2015-05-21 06:08 - 00045568 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-06-03 12:20 - 2015-04-16 15:07 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-06-03 10:26 - 2015-06-03 10:27 - 05127432 _____ (Piriform Ltd) C:\Users\pam\Downloads\spsetup128 (1).exe
2015-06-03 09:48 - 2015-06-03 09:48 - 00195104 _____ C:\Users\pam\Documents\DBA1.tmp
2015-06-01 13:04 - 2015-06-03 12:37 - 00000334 _____ C:\windows\Tasks\HPCeeScheduleForpam.job
2015-06-01 13:04 - 2015-06-03 07:15 - 00003144 _____ C:\windows\System32\Tasks\HPCeeScheduleForpam
2015-06-01 11:02 - 2015-06-01 12:43 - 00000000 ____D C:\AdwCleaner
2015-06-01 11:01 - 2015-06-01 11:01 - 02231296 _____ C:\Users\pam\Documents\adwcleaner_4.206.exe
2015-06-01 10:53 - 2015-06-01 10:53 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\pam\Documents\rkill.exe
2015-06-01 00:38 - 2015-04-17 19:13 - 00207272 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2015-06-01 00:38 - 2015-04-17 19:13 - 00206760 _____ (Oracle Corporation) C:\windows\system32\java.exe
2015-06-01 00:38 - 2015-04-17 19:13 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2015-06-01 00:16 - 2015-06-01 00:21 - 00000000 ____D C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-05-31 22:28 - 2015-05-31 22:28 - 00018414 _____ C:\Users\pam\Documents\Result.txt
2015-05-31 22:26 - 2015-05-31 22:26 - 00403456 _____ (Farbar) C:\Users\pam\Documents\MiniToolBox.exe
2015-05-31 21:49 - 2015-05-31 21:49 - 00243344 _____ C:\Users\pam\Documents\Firefox Setup Stub 38.0.1.exe
2015-05-31 21:19 - 2015-06-03 10:28 - 00000815 _____ C:\Users\Public\Desktop\Speccy.lnk
2015-05-31 21:19 - 2015-06-03 10:28 - 00000000 ____D C:\Program Files\Speccy
2015-05-31 21:19 - 2015-05-31 21:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2015-05-31 21:18 - 2015-05-31 21:19 - 05127432 _____ (Piriform Ltd) C:\Users\pam\Downloads\spsetup128.exe
2015-05-31 21:09 - 2015-05-31 21:09 - 00852639 _____ C:\Users\pam\Documents\SecurityCheck.exe
2015-05-31 21:06 - 2015-05-31 21:06 - 00000000 ____D C:\Users\pam\AppData\Local\GWX
2015-05-31 18:50 - 2015-05-31 18:51 - 00532480 _____ (Trend Micro Incorporated) C:\Users\pam\Documents\cwshredder.exe
2015-05-30 05:23 - 2015-05-30 05:23 - 00000406 _____ C:\windows\system32\ioloBootDefrag.cfg
2015-05-30 04:50 - 2015-03-25 09:53 - 00032912 _____ (EldoS Corporation) C:\windows\system32\Drivers\rawdsk3.sys
2015-05-30 04:46 - 2015-05-30 04:48 - 48761128 _____ (iolo technologies, LLC ) C:\Users\pam\Documents\SystemMechanic_14.5.1.37.exe
2015-05-30 04:41 - 2015-05-30 04:43 - 48761128 _____ (iolo technologies, LLC ) C:\Users\pam\Documents\Unconfirmed 199117.crdownload
2015-05-30 02:01 - 2015-05-30 02:01 - 00000000 ____D C:\Users\pam\Downloads\html
2015-05-30 00:36 - 2015-05-30 00:41 - 00000000 ____D C:\Users\pam\Downloads\photos
2015-05-29 23:59 - 2015-05-30 00:26 - 432367241 _____ C:\Users\pam\Downloads\facebook-angeltankian.zip
2015-05-29 23:19 - 2014-09-15 15:21 - 00038018 ____N C:\Users\pam\Documents\messages_sent.csv
2015-05-26 20:56 - 2015-05-26 20:56 - 00002278 _____ C:\Users\pam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2015-05-26 13:29 - 2015-05-26 13:30 - 06549184 _____ (Piriform Ltd) C:\Users\pam\Documents\ccsetup506.exe
2015-05-21 14:50 - 2015-04-09 17:40 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\UIAutomationCore.dll
2015-05-21 14:50 - 2015-04-09 17:17 - 01018880 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAutomationCore.dll
2015-05-21 14:50 - 2015-04-08 15:41 - 00158720 _____ (Microsoft Corporation) C:\windows\SysWOW64\rgb9rast.dll
2015-05-21 14:50 - 2015-04-08 15:07 - 00410336 _____ C:\windows\system32\ApnDatabase.xml
2015-05-21 14:50 - 2015-04-01 15:42 - 03097600 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
2015-05-21 14:50 - 2015-04-01 15:30 - 02483712 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
2015-05-21 14:50 - 2015-03-01 18:43 - 00222208 _____ (Microsoft Corporation) C:\windows\system32\rastapi.dll
2015-05-21 14:50 - 2015-03-01 18:21 - 00207872 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastapi.dll
2015-05-21 14:39 - 2015-04-15 23:17 - 00325464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBXHCI.SYS
2015-05-21 14:39 - 2015-04-13 15:37 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\authz.dll
2015-05-21 14:39 - 2015-04-13 15:34 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\authz.dll
2015-05-21 14:39 - 2015-03-31 21:21 - 00337408 _____ (Microsoft Corporation) C:\windows\system32\SearchProtocolHost.exe
2015-05-21 14:39 - 2015-03-31 21:18 - 00468480 _____ (Microsoft Corporation) C:\windows\system32\mssph.dll
2015-05-21 14:39 - 2015-03-31 21:17 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\mssphtb.dll
2015-05-21 14:39 - 2015-03-31 21:08 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\mssvp.dll
2015-05-21 14:39 - 2015-03-31 20:46 - 03633664 _____ (Microsoft Corporation) C:\windows\system32\tquery.dll
2015-05-21 14:39 - 2015-03-31 20:17 - 02551808 _____ (Microsoft Corporation) C:\windows\system32\mssrch.dll
2015-05-21 14:39 - 2015-03-31 20:17 - 00903168 _____ (Microsoft Corporation) C:\windows\system32\SearchIndexer.exe
2015-05-21 14:39 - 2015-03-31 19:53 - 00391680 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssph.dll
2015-05-21 14:39 - 2015-03-31 19:53 - 00272896 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchProtocolHost.exe
2015-05-21 14:39 - 2015-03-31 19:45 - 02749952 _____ (Microsoft Corporation) C:\windows\SysWOW64\tquery.dll
2015-05-21 14:39 - 2015-03-31 19:45 - 00699392 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssvp.dll
2015-05-21 14:39 - 2015-03-31 19:14 - 01920000 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssrch.dll
2015-05-21 14:39 - 2015-03-31 19:12 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchIndexer.exe
2015-05-21 14:39 - 2015-03-19 20:49 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\compstui.dll
2015-05-21 14:39 - 2015-03-19 20:08 - 00477184 _____ (Microsoft Corporation) C:\windows\system32\puiobj.dll
2015-05-21 14:39 - 2015-03-19 19:37 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\puiobj.dll
2015-05-21 14:39 - 2015-03-19 19:07 - 01091072 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2015-05-21 02:15 - 2015-05-21 02:16 - 00000000 ____D C:\Users\pam\AppData\Roaming\PhotoFiltre 7
2015-05-21 02:15 - 2015-05-21 02:15 - 00001081 _____ C:\Users\pam\Desktop\PhotoFiltre 7.lnk
2015-05-21 02:15 - 2015-05-21 02:15 - 00000000 ____D C:\Users\pam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7
2015-05-21 02:15 - 2015-05-21 02:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7
2015-05-21 02:15 - 2015-05-21 02:15 - 00000000 ____D C:\Program Files (x86)\PhotoFiltre 7
2015-05-21 02:13 - 2015-05-21 02:13 - 05239812 _____ C:\Users\pam\Documents\pf7-setup-en-7-2-1.exe
2015-05-20 12:56 - 2015-05-20 12:56 - 00000000 ____D C:\Users\pam\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2015-05-20 12:53 - 2015-05-20 12:53 - 02603176 _____ C:\Users\pam\Documents\AdobeDownloadAssistant.exe
2015-05-20 08:35 - 2015-05-20 08:35 - 00048028 _____ C:\Users\pam\Documents\C523.tmp
2015-05-19 22:40 - 2015-05-19 23:03 - 00002704 _____ C:\Users\pam\Documents\software_removal_tool.log
2015-05-19 22:40 - 2015-05-19 22:40 - 00000198 _____ C:\Users\pam\Documents\debug.log
2015-05-18 13:17 - 2015-05-18 13:17 - 00108836 _____ C:\Users\pam\Documents\16efee_dabc58cb958e47419cf868b52db8fe71.png_srz_p_484_279_75_22_0.50_1.20_0.00_png_srz
2015-05-18 13:17 - 2015-05-18 13:17 - 00015864 _____ C:\Users\pam\Documents\16efee_b86bb30d50534860927c5ffdd8696059.jpg_srz_p_438_279_75_22_0.50_1.20_0.00_jpg_srz
2015-05-18 13:16 - 2015-05-18 13:16 - 00140114 _____ C:\Users\pam\Documents\16efee_d7034ecad2ae4e218f9e3ad8a5172f47.png_srz_p_437_282_75_22_0.50_1.20_0.00_png_srz
2015-05-18 13:16 - 2015-05-18 13:16 - 00124274 _____ C:\Users\pam\Documents\16efee_875e81a8e18c423b9e27366355bde8f0.png_srz_p_488_282_75_22_0.50_1.20_0.00_png_srz
2015-05-14 20:51 - 2015-05-14 20:51 - 00028607 _____ C:\Users\pam\Documents\FC16.tmp
2015-05-12 19:26 - 2015-04-30 13:35 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 19:26 - 2015-04-30 13:35 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 18:56 - 2015-05-12 18:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-12 18:53 - 2015-05-12 18:53 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-12 18:53 - 2015-05-12 18:53 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-05-12 18:31 - 2015-03-10 18:49 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\sdbinst.exe
2015-05-12 18:31 - 2015-03-10 18:09 - 00021504 _____ (Microsoft Corporation) C:\windows\SysWOW64\sdbinst.exe
2015-05-12 18:25 - 2015-03-17 10:26 - 00467776 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2015-05-12 18:24 - 2015-03-08 19:02 - 00057856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthhfenum.sys
2015-05-12 18:22 - 2015-04-09 17:34 - 02256896 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
2015-05-12 18:22 - 2015-04-09 17:11 - 01943040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2015-05-12 18:15 - 2015-04-30 16:05 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-05-12 18:15 - 2015-04-30 15:48 - 00358912 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-05-12 18:14 - 2015-03-19 18:56 - 00080384 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ahcache.sys
2015-05-12 18:14 - 2015-03-03 18:32 - 00172544 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Input.Inking.dll
2015-05-12 18:14 - 2015-03-03 18:12 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Input.Inking.dll
2015-05-12 18:13 - 2015-01-29 17:53 - 02819584 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers.dll
2015-05-12 18:10 - 2015-04-01 15:22 - 02985984 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbgeng.dll
2015-05-12 18:10 - 2015-04-01 15:20 - 04417536 _____ (Microsoft Corporation) C:\windows\system32\dbgeng.dll
2015-05-12 18:10 - 2015-03-31 20:45 - 01491456 _____ (Microsoft Corporation) C:\windows\system32\dbghelp.dll
2015-05-12 18:10 - 2015-03-31 19:31 - 01207296 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbghelp.dll
2015-05-12 18:10 - 2015-03-12 18:11 - 02162176 _____ (Microsoft Corporation) C:\windows\system32\SRH.dll
2015-05-12 18:10 - 2015-03-12 17:39 - 01812992 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRH.dll
2015-05-12 18:09 - 2015-04-13 15:48 - 04180480 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-05-12 18:09 - 2015-04-09 18:00 - 01996800 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-05-12 18:09 - 2015-04-09 17:50 - 01387008 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-05-12 18:09 - 2015-04-09 17:26 - 01560576 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-05-12 18:08 - 2015-04-02 17:35 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\PhotoMetadataHandler.dll
2015-05-12 18:08 - 2015-04-02 17:14 - 00364544 _____ (Microsoft Corporation) C:\windows\SysWOW64\PhotoMetadataHandler.dll
2015-05-12 18:07 - 2015-04-08 15:55 - 00410128 _____ (Microsoft Corporation) C:\windows\system32\services.exe
2015-05-12 18:07 - 2015-03-12 19:02 - 00316416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\udfs.sys
2015-05-12 18:06 - 2015-03-05 19:47 - 01696256 _____ (Microsoft Corporation) C:\windows\system32\wevtsvc.dll
2015-05-12 18:05 - 2015-02-17 16:19 - 00186368 _____ (Microsoft Corporation) C:\windows\system32\dpapisrv.dll
2015-05-12 18:01 - 2015-03-12 21:03 - 00239424 _____ (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys
2015-05-12 18:01 - 2015-03-12 21:03 - 00154432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys
2015-05-12 18:00 - 2015-03-29 22:47 - 00561928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-05-12 18:00 - 2015-03-26 20:27 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2015-05-12 18:00 - 2015-03-26 19:50 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2015-05-12 18:00 - 2015-03-26 19:48 - 01441792 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-05-12 17:59 - 2015-03-05 20:08 - 02067968 _____ (Microsoft Corporation) C:\windows\system32\wpdshext.dll
2015-05-12 17:59 - 2015-03-05 19:43 - 01969664 _____ (Microsoft Corporation) C:\windows\SysWOW64\wpdshext.dll
2015-05-12 17:57 - 2015-04-21 10:14 - 24971776 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-05-12 17:57 - 2015-04-21 09:24 - 19691008 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-05-12 17:56 - 2015-04-21 09:50 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-05-12 17:56 - 2015-04-21 09:50 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-05-12 17:56 - 2015-04-21 09:49 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-05-12 17:56 - 2015-04-21 09:37 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-05-12 17:56 - 2015-04-21 09:35 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-05-12 17:56 - 2015-04-21 09:31 - 06025728 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-05-12 17:56 - 2015-04-21 09:13 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2015-05-12 17:56 - 2015-04-21 09:11 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-05-12 17:56 - 2015-04-21 09:09 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-05-12 17:56 - 2015-04-21 09:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-05-12 17:56 - 2015-04-21 09:07 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-05-12 17:56 - 2015-04-21 09:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-05-12 17:56 - 2015-04-21 09:04 - 02278400 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-05-12 17:56 - 2015-04-21 08:59 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-05-12 17:56 - 2015-04-21 08:58 - 00664576 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-05-12 17:56 - 2015-04-21 08:52 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-05-12 17:56 - 2015-04-21 08:49 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-05-12 17:56 - 2015-04-21 08:49 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-05-12 17:56 - 2015-04-21 08:49 - 00374272 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-05-12 17:56 - 2015-04-21 08:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-05-12 17:56 - 2015-04-21 08:40 - 14401536 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-05-12 17:56 - 2015-04-21 08:38 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-05-12 17:56 - 2015-04-21 08:37 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2015-05-12 17:56 - 2015-04-21 08:36 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-05-12 17:56 - 2015-04-21 08:32 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-05-12 17:56 - 2015-04-21 08:31 - 04305920 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-05-12 17:56 - 2015-04-21 08:28 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-05-12 17:56 - 2015-04-21 08:27 - 02352128 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-05-12 17:56 - 2015-04-21 08:26 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-05-12 17:56 - 2015-04-21 08:26 - 00327168 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-05-12 17:56 - 2015-04-21 08:25 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-05-12 17:56 - 2015-04-21 08:17 - 12828672 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-05-12 17:56 - 2015-04-21 08:15 - 01547264 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-05-12 17:56 - 2015-04-21 08:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-05-12 17:56 - 2015-04-21 08:02 - 01882112 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-05-12 17:56 - 2015-04-21 07:58 - 01310208 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-05-12 17:56 - 2015-04-21 07:56 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-06 20:00 - 2013-08-22 08:36 - 00000000 ____D C:\windows\system32\sru
2015-06-06 19:57 - 2014-09-02 19:24 - 00000910 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1548870796-431023125-660753347-1001UA.job
2015-06-06 19:52 - 2014-08-04 20:20 - 00000000 ____D C:\Users\pam
2015-06-06 19:43 - 2014-08-20 10:26 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-06-06 19:41 - 2014-08-04 20:46 - 00000916 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-06 19:41 - 2014-08-04 20:46 - 00000912 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-06 18:17 - 2014-12-24 06:50 - 00136408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-06 16:46 - 2015-04-19 09:41 - 01740035 _____ C:\windows\WindowsUpdate.log
2015-06-06 16:21 - 2014-08-04 20:43 - 00003902 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{3BEB4DDC-4176-4FD5-871D-3C25A4416060}
2015-06-06 16:17 - 2013-08-22 08:36 - 00000000 ____D C:\windows\AppReadiness
2015-06-06 02:11 - 2014-08-04 20:26 - 00003596 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1548870796-431023125-660753347-1001
2015-06-05 20:57 - 2014-09-02 19:23 - 00000858 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1548870796-431023125-660753347-1001Core.job
2015-06-05 03:18 - 2013-08-22 08:36 - 00000000 ____D C:\windows\rescache
2015-06-03 12:39 - 2014-08-04 20:24 - 00000000 ___DO C:\Users\pam\OneDrive
2015-06-03 12:37 - 2015-04-23 23:25 - 00002233 _____ C:\windows\setupact.log
2015-06-03 12:37 - 2013-08-22 07:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-06-03 12:36 - 2013-08-22 06:25 - 00262144 ___SH C:\windows\system32\config\BBI
2015-06-03 12:35 - 2014-12-12 20:53 - 00000000 ____D C:\windows\system32\appraiser
2015-06-03 12:35 - 2014-08-07 01:56 - 00000000 ___SD C:\windows\system32\CompatTel
2015-06-03 12:22 - 2013-08-22 08:20 - 00000000 ____D C:\windows\CbsTemp
2015-06-03 07:15 - 2014-08-06 09:57 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2015-06-03 07:14 - 2014-05-18 20:33 - 00000000 ____D C:\windows\Hewlett-Packard
2015-06-03 07:14 - 2014-04-02 04:27 - 00000000 ____D C:\SWSETUP
2015-06-02 23:49 - 2015-04-23 23:24 - 00012590 _____ C:\windows\PFRO.log
2015-06-01 12:45 - 2014-08-20 10:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-06-01 12:13 - 2014-12-24 06:49 - 00001121 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-01 12:13 - 2014-12-24 06:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-01 12:13 - 2014-12-24 06:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-06-01 00:39 - 2015-01-29 13:59 - 00000000 ____D C:\Program Files\Java
2015-06-01 00:21 - 2015-04-13 00:15 - 00001772 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-06-01 00:21 - 2015-04-13 00:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-06-01 00:16 - 2015-04-13 00:14 - 00000000 ____D C:\Program Files\iTunes
2015-06-01 00:16 - 2015-04-13 00:14 - 00000000 ____D C:\Program Files\iPod
2015-06-01 00:16 - 2015-04-13 00:14 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-06-01 00:16 - 2014-08-29 12:23 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-05-31 22:39 - 2014-10-16 23:31 - 00000000 ____D C:\Program Files (x86)\Java
2015-05-31 22:27 - 2014-08-20 10:56 - 00001178 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-05-31 22:27 - 2014-08-20 10:56 - 00001166 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-05-31 22:27 - 2014-08-20 10:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-05-31 19:57 - 2013-08-22 08:36 - 00000000 __RSD C:\windows\Media
2015-05-30 05:33 - 2013-08-22 08:36 - 00000000 ___RD C:\windows\Offline Web Pages
2015-05-26 13:33 - 2014-08-04 23:25 - 00000841 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-05-26 13:32 - 2014-08-04 23:25 - 00000000 ____D C:\Program Files\CCleaner
2015-05-25 11:02 - 2014-08-04 20:48 - 00002210 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-23 09:59 - 2015-04-04 22:43 - 00000000 ____D C:\Users\pam\AppData\Roaming\Skype
2015-05-23 09:59 - 2014-11-30 17:24 - 00000000 ____D C:\ProgramData\Skype
2015-05-21 14:52 - 2013-08-22 08:36 - 00000000 ___RD C:\windows\ToastData
2015-05-21 12:14 - 2015-04-20 16:47 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-05-19 14:47 - 2015-04-04 15:36 - 00000000 ___SD C:\windows\SysWOW64\GWX
2015-05-19 14:47 - 2015-04-04 15:36 - 00000000 ___SD C:\windows\system32\GWX
2015-05-18 09:53 - 2014-08-20 10:26 - 00003718 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-05-15 20:52 - 2014-09-02 19:24 - 00003852 _____ C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1548870796-431023125-660753347-1001UA
2015-05-15 20:52 - 2014-09-02 19:24 - 00003472 _____ C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1548870796-431023125-660753347-1001Core
2015-05-14 19:36 - 2014-08-04 20:46 - 00003888 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-14 19:36 - 2014-08-04 20:46 - 00003652 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-14 18:58 - 2013-08-22 07:44 - 00346856 _____ C:\windows\system32\FNTCACHE.DAT
2015-05-14 18:54 - 2013-08-22 08:36 - 00000000 ___RD C:\windows\ImmersiveControlPanel
2015-05-14 18:54 - 2013-08-22 06:36 - 00000000 ____D C:\windows\system32\AdvancedInstallers
2015-05-14 02:36 - 2014-08-04 23:03 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-05-12 19:22 - 2014-08-07 02:17 - 00000000 ____D C:\windows\system32\MRT
2015-05-12 19:07 - 2014-08-07 02:17 - 140425016 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-05-12 18:46 - 2014-03-18 02:38 - 00000000 ____D C:\Program Files\Windows Journal
 
==================== Files in the root of some directories =======
 
2014-08-04 20:35 - 2014-08-04 20:35 - 10395072 _____ (Webroot Software, Inc.) C:\Program Files (x86)\Common Files\wruninstall.exe
2014-12-19 23:16 - 2014-12-19 23:16 - 0001456 _____ () C:\Users\pam\AppData\Local\recently-used.xbel
 
Some files in TEMP:
====================
C:\Users\pam\AppData\Local\Temp\Extract.exe
C:\Users\pam\AppData\Local\Temp\Quarantine.exe
C:\Users\pam\AppData\Local\Temp\SP71319.exe
C:\Users\pam\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-05-28 09:02
 
==================== End of log ============================

 
 
 
 
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:06-06-2015
Ran by pam at 2015-06-06 20:22:17
Running from C:\Users\pam\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1548870796-431023125-660753347-500 - Administrator - Disabled)
Guest (S-1-5-21-1548870796-431023125-660753347-501 - Limited - Disabled)
pam (S-1-5-21-1548870796-431023125-660753347-1001 - Administrator - Enabled) => C:\Users\pam
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
4 Elements II (x32 Version: 2.2.0.98 - WildTangent) Hidden
7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 17.0.0.172 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader Driver  (HKLM-x32\...\AmUStor) (Version: 20.21.3317.03861 - Alcor Micro Corp.)
Alcor Micro USB Card Reader Driver  (x32 Version: 20.21.3317.03861 - Alcor Micro Corp.) Hidden
AMD Catalyst Install Manager (HKLM\...\{1FFAF315-ADDB-013D-0A76-7783A203E02D}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software)
Azkend 2: The World Beneath (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Build-a-lot Mysteries (x32 Version: 3.0.2.51 - WildTangent) Hidden
Building the Great Wall of China Collector's Edition (x32 Version: 3.0.2.48 - WildTangent) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform)
Curse at Twilight (x32 Version: 3.0.2.51 - WildTangent) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.6.3728 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.5.4824 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.6.3702 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.6.3625 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3.3626 - CyberLink Corp.)
DisableMSDefender (Version: 1.0.0 - Hewlett-Packard Company) Hidden
DriveImage XML (Private Edition) (HKLM-x32\...\{F7E1CA14-B39D-452A-960B-39423DDDD933}) (Version: 2.50.000 - Runtime Software)
Evernote v. 5.1.1 (HKLM-x32\...\{19ABCFE2-7EED-11E3-B98A-00163E98E7D6}) (Version: 5.1.1.2334 - Evernote Corp.)
Fishdom 3: Collector's Edition (x32 Version: 3.0.2.38 - WildTangent) Hidden
Fort Defense (x32 Version: 3.0.2.51 - WildTangent) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.81 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Google+ Auto Backup (HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\Google+ Auto Backup) (Version: 1.0.27.161 - Google, Inc.)
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
Hotel (HKLM-x32\...\Hotel) (Version: 1.1.0.0 - MumboJumbo)
HP Documentation (HKLM-x32\...\{06600E94-1C34-40E2-AB09-D30AECF78172}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7493.4758 - Hewlett-Packard)
HP SimplePass (HKLM-x32\...\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.01.06 - Hewlett-Packard)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard)
iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
Inst5675 (Version: 8.01.06 - Softex Inc.) Hidden
Inst5676 (Version: 8.01.06 - Softex Inc.) Hidden
iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418045F0}) (Version: 8.0.450 - Oracle Corporation)
Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Lost in Reefs 2 (x32 Version: 3.0.2.51 - WildTangent) Hidden
LUXOR Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Midnight Mysteries The Edgar Allan Poe Conspiracy (HKLM-x32\...\Midnight Mysteries The Edgar Allan Poe Conspiracy) (Version: 1.1.0.0 - MumboJumbo)
Mozilla Firefox 38.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 38.0.1 (x86 en-US)) (Version: 38.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 38.0.1 - Mozilla)
Mystery P.I. - Curious Case of Counterfeit Cove (x32 Version: 2.2.0.98 - WildTangent) Hidden
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
PhotoFiltre 7 (HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\PhotoFiltre 7) (Version:  - )
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Pinger (HKLM-x32\...\Pinger 1.4.0.1) (Version: 1.4.0.1 - Pinger Inc.)
Pinger (x32 Version: 1.4.0.1 - Pinger Inc.) Hidden
Qualcomm Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Qualcomm Atheros)
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.30175 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7135 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.0.7316 - CyberLink Corp.) Hidden
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
RegiStax 6 (HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\RegiStax 6) (Version:  - )
RegiStax 6.1.0.8 update (HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\RegiStax 6.1.0.8 update) (Version:  - )
Roads of Rome 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.101 - Skype Technologies S.A.)
Solitaire Mystery Four Seasons (x32 Version: 3.0.2.51 - WildTangent) Hidden
Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1186 - SUPERAntiSpyware.com)
Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden
The Legend of Crystal Valley (HKLM-x32\...\The Legend of Crystal Valley) (Version: 1.1.0.0 - MumboJumbo)
The Secret of Margrave Manor (HKLM-x32\...\The Secret of Margrave Manor) (Version: 1.1.0.0 - MumboJumbo)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Viking Saga (x32 Version: 3.0.2.48 - WildTangent) Hidden
WhoCrashed 5.03 (HKLM\...\WhoCrashed_is1) (Version:  - Resplendence Software Projects Sp.)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App for HP (x32 Version: 4.0.11.2 - WildTangent) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1548870796-431023125-660753347-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\pam\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1548870796-431023125-660753347-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\pam\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
 
==================== Restore Points =========================
 
19-05-2015 14:43:09 Windows Update
27-05-2015 14:19:32 Scheduled Checkpoint
31-05-2015 22:37:03 Removed Java 7 Update 80
03-06-2015 07:10:10 HPSF Applying updates
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 06:25 - 2013-08-22 06:25 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {03944FD1-ED8B-4DE2-8971-A5ED051B0A22} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-06] (Microsoft Corporation)
Task: {153DF99C-2BBB-4189-93DB-4C4F88E4516D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
Task: {1E0FE72F-7F67-48DA-8FA3-354AD4C664E0} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2015-05-12] (Microsoft Corporation)
Task: {20E142F6-BE3B-4809-94DD-D71F1C885E02} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-03-15] (Microsoft Corporation)
Task: {357E8FDD-06A2-434C-807B-93DC3F633B4C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd)
Task: {4DE5E944-4FEE-4D34-87FD-A233D2CBF433} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {5033037D-AC97-4B4E-B3B1-7936FBEC128B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {726FBDBE-030D-45AC-AA2C-40D25B90454D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {7B25AA79-0730-4E0A-9E5E-FF4BE7F1E3DC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-04] (Google Inc.)
Task: {8243E8ED-C867-433B-973A-FE7B08B4B8D2} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {857B8FBE-BF10-4E8C-952A-33494B3205FA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2015-04-14] (Hewlett-Packard)
Task: {88AA885B-8F0E-4241-91FF-ADE4A5C41DA6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {8EABC2D1-5E39-4122-9202-1F9E96759247} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {8F86803A-87C5-49A7-8E34-533A60363AE0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
Task: {90BBAFA9-6509-46F4-8ED2-E7C6180404EB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1548870796-431023125-660753347-1001Core => C:\Users\pam\AppData\Local\Google\Update\GoogleUpdate.exe [2014-09-02] (Google Inc.)
Task: {9323E878-8351-4036-96F0-58F4E0D8E6FA} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-18] (Adobe Systems Incorporated)
Task: {9582B57C-34EB-4C1D-9BB3-F56D53324D87} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-04] (Google Inc.)
Task: {9BE13FC7-5300-44F9-B608-E496E2443D5B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-04-23] (Avast Software s.r.o.)
Task: {C1172571-B7F7-4127-AFCB-C6F8975C42C3} - System32\Tasks\HPCeeScheduleForpam => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {C671ED06-88F4-4955-BE7E-FFCC5BE5DFF2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1548870796-431023125-660753347-1001UA => C:\Users\pam\AppData\Local\Google\Update\GoogleUpdate.exe [2014-09-02] (Google Inc.)
Task: {CC3D1C8A-FB9D-42B0-B124-4DE94577E708} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
Task: {EB107065-7110-4092-8022-49EE56DEE563} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2015-04-14] (Hewlett-Packard)
Task: {F672869D-EB5A-4537-A309-792CD9002E7F} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1548870796-431023125-660753347-1001Core.job => C:\Users\pam\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1548870796-431023125-660753347-1001UA.job => C:\Users\pam\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForpam.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-02-07 10:24 - 2014-02-07 10:24 - 02108928 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2014-02-07 10:21 - 2014-02-07 10:21 - 00021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll
2014-02-07 10:21 - 2014-02-07 10:21 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2014-02-07 10:21 - 2014-02-07 10:21 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2014-02-07 10:40 - 2014-02-07 10:40 - 00368528 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll
2014-02-07 10:40 - 2014-02-07 10:40 - 00714128 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-02-07 10:28 - 2014-02-07 10:28 - 00065024 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2014-02-07 10:37 - 2014-02-07 10:37 - 00098304 _____ () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\BrandingNet4.dll
2015-05-25 11:02 - 2015-05-22 14:09 - 01670472 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libglesv2.dll
2015-05-25 11:02 - 2015-05-22 14:09 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libegl.dll
2013-08-09 10:11 - 2013-08-09 10:11 - 00607744 _____ () C:\windows\system32\spool\DRIVERS\x64\3\JobCapsA.dll
2015-05-25 11:02 - 2015-05-22 14:09 - 26787144 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\PepperFlash\pepflashplayer.dll
2015-04-23 23:17 - 2015-04-23 23:17 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-04-23 23:17 - 2015-04-23 23:17 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-06-03 10:30 - 2015-06-03 10:30 - 02951680 _____ () C:\Program Files\AVAST Software\Avast\defs\15060301\algo.dll
2015-06-06 15:07 - 2015-06-06 15:07 - 02952192 _____ () C:\Program Files\AVAST Software\Avast\defs\15060601\algo.dll
2015-02-13 04:15 - 2015-02-13 04:15 - 03219456 _____ () C:\Users\pam\AppData\Local\Programs\Google\Google+ Auto Backup\gpuploader_i18n.dll
2015-03-20 11:04 - 2015-03-20 11:05 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\pam\OneDrive:ms-properties
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1548870796-431023125-660753347-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\pam\Downloads\IMG_0763.JPG
DNS Servers: 192.168.0.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\...\StartupApproved\Run32: => "ApnTBMon"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\StartupApproved\Run: => "Pokki"
HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-1548870796-431023125-660753347-1001\...\StartupApproved\Run: => "Skype"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{241F5620-5CF3-4892-873D-A58D2FFE8028}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{47810DD3-A880-4662-9DDC-BDE48EE12BDD}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{361EF913-B9A0-442F-932C-A42E14C913F9}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{A8D412F5-0FFF-464A-A7B0-8FB9D19F9584}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{8DD21DA8-80BC-43A8-A81C-2FD517DA2AD2}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{75D628E6-A503-4029-B63F-651CFDE7C680}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2CD692BE-4456-4865-879D-E0159C443552}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5B91F64F-B3D6-4A58-9143-65FD07E5B8D0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6B17B952-70A2-4197-A967-92DD5B9BA69B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{B957568E-FF30-435A-A53B-1E4EC5CADF11}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1E7C50F3-4F82-4497-A286-1907A5939CCE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1B8426AD-0ABB-4EEF-B273-60D45DC0B37E}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{DF2CA6B1-E302-4858-8696-5131B4B52F24}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{D619EEB4-0AEA-4857-8E00-03B64D2DFCC2}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/06/2015 07:37:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1157688
 
Error: (06/06/2015 07:37:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1157688
 
Error: (06/06/2015 07:37:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/06/2015 07:37:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1152360
 
Error: (06/06/2015 07:37:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1152360
 
Error: (06/06/2015 07:37:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/06/2015 07:37:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1148500
 
Error: (06/06/2015 07:37:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1148500
 
Error: (06/06/2015 07:37:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/06/2015 07:37:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1147016
 
 
System errors:
=============
Error: (06/04/2015 02:46:23 PM) (Source: DCOM) (EventID: 10010) (User: MINE)
Description: Microsoft.Windows.PhotoManager
 
Error: (06/04/2015 03:50:11 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume Windows.
 
A corruption was found in a file system index structure.  The file reference number is 0x3000000005841.  The name of the file is "\Windows\System32".  The corrupted index attribute is ":$I30:$INDEX_ALLOCATION".
 
Error: (06/03/2015 11:40:38 AM) (Source: DCOM) (EventID: 10010) (User: MINE)
Description: App
 
Error: (06/01/2015 02:46:05 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume Windows.
 
A corruption was found in a file system index structure.  The file reference number is 0x3000000005841.  The name of the file is "\Windows\System32".  The corrupted index attribute is ":$I30:$INDEX_ALLOCATION".
 
Error: (06/01/2015 00:44:53 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\windows\system32\athihvs.dll
 
Error: (06/01/2015 00:44:53 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\windows\system32\athihvs.dll
 
Error: (06/01/2015 00:44:45 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\windows\system32\athihvs.dll
 
Error: (06/01/2015 00:43:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The HP Support Assistant Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (06/01/2015 00:43:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Apple Mobile Device Service service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (06/01/2015 00:43:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
 
Microsoft Office:
=========================
Error: (06/06/2015 07:37:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1157688
 
Error: (06/06/2015 07:37:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1157688
 
Error: (06/06/2015 07:37:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/06/2015 07:37:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1152360
 
Error: (06/06/2015 07:37:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1152360
 
Error: (06/06/2015 07:37:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/06/2015 07:37:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1148500
 
Error: (06/06/2015 07:37:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1148500
 
Error: (06/06/2015 07:37:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/06/2015 07:37:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1147016
 
 
==================== Memory info =========================== 
 
Processor: AMD E1-2500 APU with Radeon™ HD Graphics 
Percentage of memory in use: 70%
Total physical RAM: 3517.38 MB
Available physical RAM: 1021.34 MB
Total Pagefile: 8702.55 MB
Available Pagefile: 3526 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:450.22 GB) (Free:355.45 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Recovery Image) (Fixed) (Total:14.06 GB) (Free:1.77 GB) NTFS ==>[System with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 760C9FF9)
 
Partition: GPT Partition Type.
 
==================== End of log ============================
 
 
 
 
 

Thank you in advance for any help you can provide! :)

Edited by Orange Blossom, 06 June 2015 - 11:48 PM.


BC AdBot (Login to Remove)

 


#2 satchfan

satchfan

  • Malware Response Team
  • 2,857 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:06:02 AM

Posted 07 June 2015 - 03:41 AM

Hello Angel White and welcome to Bleeping Computer.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

================================================

It’s a good idea to move Farbar Recovery Scan Tool to your desktop otherwise future fixes may not work.


  • go to your Downloads folder and locate Farbar Recovery Scan Tool
  • right click and select Cut
  • go to an empty spot on your desktop, right click and select Paste

Farbar Recovery Scan Tool should now be on your desktop.

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below.


SearchScopes: HKLM -> {0311EA1F-04F0-4893-A4CF-416D079F3AC1} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link_code=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {0311EA1F-04F0-4893-A4CF-416D079F3AC1} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link_code=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-1548870796-431023125-660753347-1001 -> {0311EA1F-04F0-4893-A4CF-416D079F3AC1} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link_code=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-1548870796-431023125-660753347-1001 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = http://mumbojumbo.start.iplay.com/searchresults.aspx?o=chrome&q={searchTerms}
CHR Extension: (Ask Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf [2014-08-13]
CHR Extension: (Ask Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf [2014-09-05]
CHR Extension: (Ask Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf [2014-09-05]
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

================================================

Run Zoek

Download zoek.exe to your Desktop:

Important : Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.

  • on Windows Vista, 7, and 8, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    
    chrdefaults;
    emptyalltemp;
    emptyclsid;
    autoclean;
    ipconfig /flushdns;b
    
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

After you've done that, please run AdwCleaner again and also send that log.

Logs to include with next post:

Fixlog.txt
zoek-results.log
New AdwCleaner log


Thanks

Satchfan

 


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#3 Angel White

Angel White
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Arizona Bay
  • Local time:10:02 PM

Posted 07 June 2015 - 05:44 PM

HI! Thank you so much for your fast reply. 

 

I competed all scan logs as requested. Although not sure if the adwcleaner actually worked.  when it seemed to be finished scanning no log came up to check, or "report" as i expected. so i just clicked "clean". please let me know if i need to rescan using that tool. maybe i didnt wait long enough but it was about an hour. Thank you. 

 

here are the scan logs: 

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version:06-06-2015
Ran by pam at 2015-06-07 12:27:48 Run:1
Running from C:\Users\pam\Desktop
Loaded Profiles: pam (Available Profiles: pam)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
SearchScopes: HKU\S-1-5-21-1548870796-431023125-660753347-1001 -> {0311EA1F-04F0-4893-A4CF-416D079F3AC1} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link_code=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-1548870796-431023125-660753347-1001 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = http://mumbojumbo.start.iplay.com/searchresults.aspx?o=chrome&q={searchTerms}
CHR Extension: (Ask Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf [2014-08-13]
CHR Extension: (Ask Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf [2014-09-05]
CHR Extension: (Ask Search) - C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf [2014-09-05]
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf
*****************
 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0311EA1F-04F0-4893-A4CF-416D079F3AC1}" => key removed successfully
HKCR\CLSID\{0311EA1F-04F0-4893-A4CF-416D079F3AC1} => key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0311EA1F-04F0-4893-A4CF-416D079F3AC1}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0311EA1F-04F0-4893-A4CF-416D079F3AC1} => key not found. 
"HKU\S-1-5-21-1548870796-431023125-660753347-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0311EA1F-04F0-4893-A4CF-416D079F3AC1}" => key removed successfully
HKCR\CLSID\{0311EA1F-04F0-4893-A4CF-416D079F3AC1} => key not found. 
"HKU\S-1-5-21-1548870796-431023125-660753347-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{36377DD7-B3EB-42f5-986F-680BAF59BA9D}" => key removed successfully
HKCR\CLSID\{36377DD7-B3EB-42f5-986F-680BAF59BA9D} => key not found. 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf => moved successfully.
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf => moved successfully.
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf => moved successfully.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\WRkrn" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\WRSVC" => key removed successfully
"C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf" => File/Folder not found.
 
==== End of Fixlog 12:27:55 ====
 
 
 
 
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by pam on Sun 06/07/2015 at 12:46:04.76.
Microsoft Windows 8.1 with Bing 6.3.9600  x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\pam\Downloads\zoek.exe [Scan all users] [Script inserted] 
 
==== System Restore Info ======================
 
6/7/2015 12:52:34 PM Zoek.exe System Restore Point Created Successfully.
 
==== Empty Folders Check ======================
 
C:\Program Files\Webroot deleted successfully
C:\Users\pam\AppData\Roaming\hpqlog deleted successfully
C:\Users\pam\AppData\Local\MediaShow deleted successfully
 
==== Deleting CLSID Registry Keys ======================
 
 
==== Deleting CLSID Registry Values ======================
 
 
==== Deleting Services ======================
 
 
==== FireFox Fix ======================
 
ProfilePath: C:\Users\pam\AppData\Roaming\Mozilla\Firefox\Profiles\3nh7ww8g.default
 
user.js not found
---- Lines isearch removed from prefs.js ----
user_pref("weboftrust.search.avg.url", "^http(s)?\\:\\/\\/isearch\\.avg\\.com\\/search\\?");
---- Lines ask.com removed from prefs.js ----
user_pref("weboftrust.search.ask.display", "Ask.com Web Search");
---- Lines offers removed from prefs.js ----
user_pref("weboftrust.category.301", "{\"name\":\"301\",\"group\":\"4\",\"text\":\"Online tracking\",\"description\":\"Based on your experience the si
---- FireFox user.js and prefs.js backups ---- 
 
prefs_20150607_0154_.backup
 
==== Batch Command(s) Run By Tool======================
 
 
==== Deleting Files \ Folders ======================
 
C:\Users\Public\Pokki deleted
C:\Users\pam\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Start Menu.lnk deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Default\AppData\Local\Pokki deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\pam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk deleted
C:\Users\pam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk deleted
C:\windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\gpt.ini deleted
C:\windows\Syswow64\REN804C.tmp deleted
C:\Users\pam\AppData\Roaming\Mozilla\Firefox\Profiles\3nh7ww8g.default\jetpack deleted
 
==== Firefox Extensions Registry ======================
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [04/23/2015 11:17 PM]
 
==== Firefox Extensions ======================
 
ProfilePath: C:\Users\pam\AppData\Roaming\Mozilla\Firefox\Profiles\3nh7ww8g.default
- WOT - %ProfilePath%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
 
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
==== Firefox Plugins ======================
 
Profilepath: C:\Users\pam\AppData\Roaming\Mozilla\Firefox\Profiles\3nh7ww8g.default
2E661988463BCFA1B95D4DAAB9B0B6FA - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll - Shockwave Flash
08ACECEB47FAF053C468D8AFE44709AD - C:\Users\pam\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll - Google Update
 
 
==== Chromium Look ======================
 
Google Chrome Version: 43.0.2357.81
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[03/20/2015 11:04 AM]
 
Avast Online Security - pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Hotword Shared Module - pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
Google Voice Search Hotword (Beta) - pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Webroot Filtering Extension - pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kjeghcllfecehndceplomkocgfbklffd
Webroot Password Manager - pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab
Google Voice Search Hotword (Beta) - pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Webroot Filtering Extension - pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\kjeghcllfecehndceplomkocgfbklffd
Webroot Password Manager - pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab
Google Voice Search Hotword (Beta) - pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Google Voice Search Hotword (Beta) - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
WOT - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\bhmmomiinigofkjcapegjjndpbikblnp
Scroll Button - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fbkobdcckhcgleanepepnfaficicaogg
Spaaze - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\hofabcapkmnnhhccplipkecnjbmgoegl
Arcane Legends - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ibmlkgieigeddcedpbijnpojheoddido
Social Fixer for Facebook - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb
WeatherBug (Legacy App) - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak
Deadmau5 Green Edition - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\iphfjhmkmdjocaaopmgpeikabebejihc
International Internet TV - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\jpfaflofhdeeaikcajgalgbpgejbmihk
Scroll to Top - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\khnloieeghjghmpjeaopaenibbneljpk
Unfriend Alerts - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\lgbeldbnadmemecalekdfnffgobkpafc
WeatherBug - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\mekeaeklopjambfhgndcddmpfbinkdpb
WeatherBug - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\njkkjobcechefaoknodniidfjapgfoco
Google Voice Search Hotword (Beta) - pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Avast SafePrice - pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\gomekmidlodglbbmalcneegieacbdmki
WOT - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\bhmmomiinigofkjcapegjjndpbikblnp
Tampermonkey - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo
Bookmark Manager - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\gmlllbghnfkpflemihljekbapjopfjik
Stylish Facebook Themes - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\haomkemhnjlojfjklokcbkjkdanghlic
Spaaze - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\hofabcapkmnnhhccplipkecnjbmgoegl
Arcane Legends - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\ibmlkgieigeddcedpbijnpojheoddido
Social Fixer for Facebook - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb
Deadmau5 Green Edition - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\iphfjhmkmdjocaaopmgpeikabebejihc
International Internet TV - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\jpfaflofhdeeaikcajgalgbpgejbmihk
Scroll to Top - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\khnloieeghjghmpjeaopaenibbneljpk
Chrome Hotword Shared Module - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\lccekmodgklaepjeofjdjpbminllajkg
WeatherBug - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\mekeaeklopjambfhgndcddmpfbinkdpb
Fairshare - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\mkaliidbdemijhjchoaoomhfifplapmi
WeatherBug - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\njkkjobcechefaoknodniidfjapgfoco
Weather Underground - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\pjejbgheonogbpfkkjigbmahaljipoej
 
==== Chromium Startpages ======================
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Preferences
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Preferences
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Preferences
"startup_urls": [ "http://www.google.com/", "http://yahoo.genieo.com/?v=w3i8", "http://mysearch.avg.com?cid={B74061FB-D9EC-4C13-AD37-28B5B6A546AE}&mid=f03055a1d84f47d08281d16f2ae9dd91-0b56751693a1a6eef81875233f858dde1af65aff&lang=en&ds=ts019&coid=avgtbdists&cmpid=&pr=sa&d=2014-04-04 21:17:05&v=18.0.5.292&pid=safeguard&sg=&sap=hp", "http://mysearch.avg.com?cid={B74061FB-D9EC-4C13-AD37-28B5B6A546AE}&mid=f03055a1d84f47d08281d16f2ae9dd91-0b56751693a1a6eef81875233f858dde1af65aff&lang=en&ds=ts019&coid=avgtbdists&cmpid=&pr=sa&d=2014-04-04 21:17:05&v=18.1.0.443&pid=safeguard&sg=&sap=hp" ]
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Preferences
":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\43.0.2357.81\\internal-nacl-plugin","version":""},{"enabled":true,"name":"Chrome PDF Viewer","path":"internal-pdf-viewer","version":""},{"enabled":true,"name":"Adobe Flash Player"},{"enabled":true,"name":"Chrome PDF Viewer"},{"enabled":false,"name":"Chrome Remote Desktop Viewer"},{"enabled":true,"name":"Native Client"},{"enabled":true,"name":"Widevine Content Decryption Module"}],"removed_old_component_pepper_flash_settings":true,"show_details":true},"printing":{"print_preview_sticky_settings":{"appState":"{\"version\":2,\"isGcpPromoDismissed\":false,\"selectedDestinationId\":\"HP ePrint\",\"selectedDestinationOrigin\":\"local\",\"selectedDestinationAccount\":\"\",\"selectedDestinationCapabilities\":{\"printer\":{\"collate\":{},\"color\":{\"option\":[{\"is_default\":true,\"type\":\"STANDARD_COLOR\",\"vendor_id\":\"2\"},{\"type\":\"STANDARD_MONOCHROME\",\"vendor_id\":\"1\"}]},\"copies\":{},\"dpi\":{\"option\":[{\"horizontal_dpi\":600,\"is_default\":true,\"vertical_dpi\":600}]},\"duplex\":{\"option\":[{\"is_default\":true,\"type\":\"NO_DUPLEX\"},{\"type\":\"LONG_EDGE\"},{\"type\":\"SHORT_EDGE\"}]},\"media_size\":{\"option\":[{\"custom_display_name\":\"Letter\",\"height_microns\":279400,\"is_default\":true,\"name\":\"NA_LETTER\",\"vendor_id\":\"1\",\"width_microns\":215900},{\"custom_display_name\":\"4x6\",\"height_microns\":152400,\"name\":\"NA_INDEX_4X6\",\"vendor_id\":\"5139\",\"width_microns\":101600},{\"custom_display_name\":\"A4\",\"height_microns\":297000,\"name\":\"ISO_A4\",\"vendor_id\":\"9\",\"width_microns\":209900}]},\"page_orientation\":{\"option\":[{\"is_default\":true,\"type\":\"PORTRAIT\"},{\"type\":\"LANDSCAPE\"},{\"type\":\"AUTO\"}]},\"supported_content_type\":[{\"content_type\":\"application/pdf\"}]},\"version\":\"1.0\"},\"selectedDestinationName\":\"HP ePrint\",\"mediaSize\":{\"custom_display_name\":\"Letter\",\"height_microns\":279400,\"is_default\":true,\"name\":\"NA_LETTER\",\"vendor_id\":\"1\",\"width_microns\":215900},\"selectedDestinationExtensionId\":\"\"}"}},"profile":{"avatar_bubble_tutorial_shown":1,"avatar_index":13,"content_settings":{"clear_on_exit_migrated":true,"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{"https://www.youtube.com:443,https://www.youtube.com:443":{"setting":1}},"geolocation":{"http://www.wunderground.com:80,http://www.wunderground.com:80":{"last_used":1433531881.176794,"setting":1}},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"chrome-extension://njkkjobcechefaoknodniidfjapgfoco/,chrome-extension://njkkjobcechefaoknodniidfjapgfoco/":{"geolocation":1,"last_used":{"geolocation":1423610958.053427}},"http://krqr.tunegenie.com:80,http://krqr.tunegenie.com:80":{"geolocation":2},"http://photos.weatherbug.com:80,http://photos.weatherbug.com:80":{"geolocation":2},"http://wweather.co:80,http://wweather.co:80":{"geolocation":1,"last_used":{"geolocation":1423699288.706273}},"http://www.wunderground.com:80,http://www.wunderground.com:80":{"geolocation":1,"last_used":{"geolocation":1426633440.747668}},"https://mail.google.com:443,*":{"notifications":1},"https://www.google.com:443,https://www.google.com:443":{"geolocation":2},"https://www.youtube.com:443,https://www.youtube.com:443":{"fullscreen":1}},"plugin_whitelist":{"adobe-flash-player":true,"google-chrome-pdf":true,"java-runtime-environment":true,"npsitesafety":{"dll":true},"widevinecdmadapter":{"dll":true}},"pref_version":1},"created_by_version":"38.0.2125.122","default_content_settings":{},"exit_type":"Normal","exited_cleanly":true,"gaia_info_picture_url":"https://lh4.googleusercontent.com/-uTTcJ1rYSqE/AAAAAAAAAAI/AAAAAAAABB8/_HHxPAoJrig/s256-c/photo.jpg","gaia_info_update_time":"13078129134958334","icon_version":3,"managed":{"shared_settings":{"BA3Gmdnfqew=":{"chrome-avatar-index":{"acknowledged":true,"value":13}}}},"managed_user_id":"","managed_users":{"BA3Gmdnfqew=":{"acknowledged":true,"chromeAvatar":"chrome-avatar-index:13","chromeOsAvatar":"","masterKey":"","name":"angel","passwordEncryptionKey":"","passwordSignatureKey":""}},"migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"alien","per_host_zoom_levels":{},"using_default_avatar":false,"using_gaia_avatar":true},"protection":{"macs":{}},"reverse_autologin":{"enabled":false},"safebrowsing":{"extended_reporting_enabled":true},"savefile":{"default_directory":"C:\\Users\\pam\\Downloads"},"selectfile":{"last_directory":"C:\\Users\\pam\\Downloads"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13060579098373211"},"signin":{"signedin_time":"13060579176474015"},"sync":{"app_list":true,"app_settings":true,"apps":true,"autofill":true,"autofill_profile":true,"autofill_wallet":true,"bookmarks":true,"dictionary":true,"encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAf5WBv/kY/k+26+wl28E+wwAAAAACAAAAAAAQZgAAAAEAACAAAADzwcBjtx/GwqlUxlIeQPccZeDt67AWL8m9Tebity/vawAAAAAOgAAAAAIAACAAAADw0HzDeyJXrbloT6w09ydRInBhRgBHNY1tjqR2kt+azkAAAACpB8vWrgB1XFEhcv190hXo5MIGwGxxKrIyEIDzRc9droIbeyuG7WOtwprmF5QittpC9XTjozLoXpwex/UV7daqQAAAAFMqFq0Dvpf6YjsaMEdXcv2lOLu+WtyRIErLrZFogVrAenJCp3OqscpqQXAZm8BAeidMcnPJCSObfovl/npoIrc=","extension_settings":true,"extensions":true,"favicon_images":true,"favicon_tracking":true,"first_sync_time":"13060579176547015","has_auth_error":false,"has_setup_completed":true,"history_delete_directives":true,"keystore_encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAf5WBv/kY/k+26+wl28E+wwAAAAACAAAAAAAQZgAAAAEAACAAAACdK6smKkul7oOZLrO/j87pO9lbAq5hMFmSf2Ktq+RBJAAAAAAOgAAAAAIAACAAAABzCpJoSZFDWPWMdoK0xksEhzvi/lduA0tWESiIpl7kVlAAAACFHoU2vp8MHQ2t2rcYPZv8CQbcpQ8su8SvRhJAkkB3UwjEdltn64dl/r7B1zYckl6vSwMKOmwGIj/cgyuSK9BOvAfofn/PnC90bUcEx+JEO0AAAAA/Q4sR99s2+dUrll/Xz+gMnwOjVDzrga3j0b+FaBCVWInGxRP2fLNWga5fSkl6e1ZkeNbdOSaINuXFufGmwakj","last_synced_time":"13078179548355326","managed_user_settings":true,"managed_user_shared_settings":true,"managed_user_whitelists":true,"managed_users":true,"passwords":true,"preferences":true,"priority_preferences":true,"search_engines":true,"session_sync_guid":"session_syncnSYMFUK5ntIp1YoKXjp2Sw==","sessions":true,"suppress_start":false,"tabs":true,"themes":true,"typed_urls":true},"sync_promo":{"startup_count":1},"translate_accepted_count":{"ar":0,"bg":1,"cs":1,"da":1,"de":0,"el":0,"en":0,"es":0,"fa":1,"fi":2,"fr":2,"hr":1,"hu":2,"id":0,"it":6,"ja":1,"ko":0,"lv":1,"ms":2,"nl":1,"pl":4,"pt":6,"ro":1,"ru":2,"th":0,"tr":1,"zh-CN":1},"translate_blocked_languages":[],"translate_denied_count":{"ar":1,"bg":0,"cs":0,"da":0,"de":2,"el":1,"en":3,"es":2,"fa":0,"fi":0,"fr":0,"hr":0,"hu":0,"id":1,"it":0,"ja":0,"ko":1,"lv":0,"ms":0,"nl":0,"pl":0,"pt":0,"ro":0,"ru":0,"th":2,"tr":0,"zh-CN":0},"translate_language_blacklist":[],"translate_site_blacklist":[],"translate_too_often_denied":true,"translate_whitelists":{"hu":"en","pt":"en"},"webkit":{"webprefs":{"uses_universal_detector":true}},"zerosuggest":{"cachedresults":""}}
7","mhjfbmdgcfjbbpaeojofohoefgiehjai":"8969E9560348FA46539143EBE702A0ED1B7079D983D687FC6230546CDAA9136B","mkaliidbdemijhjchoaoomhfifplapmi":"2B2715D2D916C95E9F00164142F76ABFEF02053239109318CD09BACF8A6B7082","nbpagnldghgfoolbancepceaanlmhfmd":"1B97B6F8EAB58C330F587308CA632AD1A72D260F465095A11CDC9DA890DE8B21","neajdppkdcdipfabeoofebfddakdcjhd":"8ABEA4D145303010154A16158E4472A1599FE0D75F2C77443997616714F083A6","njkkjobcechefaoknodniidfjapgfoco":"F83687ABC258EDC11D313F6AAB2D11ACFDE21CEBF515BF5B8EB2AA6F22D18D9C","nkeimhogjdpnpccoofpliimaahmaaome":"2B34667B90ADD62606F80448871481226942A848D3A5ECEBC25E161D8F15C4FC","nmmhkkegccagdldgiimedpiccmgmieda":"A5AD1902908B4D6F3BB7C4D8A3FDAF0F453C4D9FE558CBF05C96247B22C0D51A","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"EC4BEF646CC5C2EAC6EB977E3C3D7A137FD8CC60821335934ECB430963279A8C","pjejbgheonogbpfkkjigbmahaljipoej":"582A50A59802E2FE552B530AE53FE5FD57FAD511840FE39E46C6D7087E84850D","pjkljhegncpnkpknbcohdijeoejaedia":"5B0C07E3CCFBB11EDD8254BACEF1836399414CFD5BFB6CBA3461770ACD1F7F14"}},"google":{"services":{"last_username":"869C0C0E3351F962F630AF3D032F37A0A633EEB94F3220F3A851E7B6947678D0","username":"888C816DE0D7B9096378A07E2A884249FFDA3F0516937A10E236430797119641"}},"homepage":"0F968E9E7D6BD92D6E144BE66560EDBC59EF7EA3CC05E1C239A859680E6DF90C","homepage_is_newtabpage":"D68AC1FBADAB34E51CF224B9141B2F19143484A21E71A81F40A8D884BFC5AD00","pinned_tabs":"E53A11FD280278F528200DA090D68BF5350CDA3DC873DECC59D1B76C45E51368","prefs":{"preference_reset_time":"BF1BA7DECF79DEB5AEFF3321D5F5CAC94D09BDE9DEE58D546906942628C04ED0"},"profile":{"reset_prompt_memento":"BBEAE423DF50CBBA6963DAF0B60982F2701AE430D8D2CF5B27F3033094E73CBA"},"safebrowsing":{"incidents_sent":"A1414C9ECACD4AE4CC97F07027E45CF5801750A7542B2758311F407ECA7C8D4B"},"search_provider_overrides":"4BBD4B51390975E2579B55900411A1E932296030E29D36DCA4F095DE5E7C5A82","session":{"restore_on_startup":"9CDEA9794D1678BA554A0F65C278398FC42A88C09B30973D9A1A1A0A3783F0E9","startup_urls":"653195A15EC6E34C3C3A770A33C89C7909CE8B72DACF7F000921542BBEEA9D57"},"software_reporter":{"prompt_reason":"ED017B1627377EE8BEDC7BDFA779A058F4733F423BDDE20F739A302C22F8DDB2","prompt_seed":"82AB5A03D2A3068CF7F90E4AC190D9091BB64FA54F9D5C1184EFF58269C5B3B9","prompt_version":"E80E12CEC75368EA08D5660794086310C9F0700098FB3C1AD39F66476DFAD0A2"},"sync":{"remaining_rollback_tries":"A1727D7BF594232C324DDC48DEE7309E015DFC6C862A4F2FCDFFF6A7F5A8D424"}},"super_mac":"1197EAE3A2203865E233617AAE65EE4563B7DA4BF6AA036BEDDD48A29DE7B504"},"session":{"restore_on_startup":5,"startup_urls":["http://www.google.com/","http://yahoo.genieo.com/?v=w3i8","http://mysearch.avg.com?cid={B74061FB-D9EC-4C13-AD37-28B5B6A546AE}&mid=f03055a1d84f47d08281d16f2ae9dd91-0b56751693a1a6eef81875233f858dde1af65aff&lang=en&ds=ts019&coid=avgtbdists&cmpid=&pr=sa&d=2014-04-04 21:17:05&v=18.0.5.292&pid=safeguard&sg=&sap=hp","http://mysearch.avg.com?cid={B74061FB-D9EC-4C13-AD37-28B5B6A546AE}&mid=f03055a1d84f47d08281d16f2ae9dd91-0b56751693a1a6eef81875233f858dde1af65aff&lang=en&ds=ts019&coid=avgtbdists&cmpid=&pr=sa&d=2014-04-04 21:17:05&v=18.1.0.443&pid=safeguard&sg=&sap=hp","http://homepage-web.com/?s=hp&m=start"]},"sync":{"remaining_rollback_tries":0}}
 
 
==== Chromium Fix ======================
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Local Storage\http_www.azlyrics.com_0.localstorage deleted successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Local Storage\http_www.azlyrics.com_0.localstorage-journal deleted successfully
 
==== Set IE to Default ======================
 
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.google.com"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
 
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
 
==== All HKCU SearchScopes ======================
 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Goo  Url="http://www.google.com/search?q={sear"
 
==== Reset Google Chrome ======================
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Secure Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Secure Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Secure Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 5\Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 5\Secure Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Secure Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Secure Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Web Data was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Web Data was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Web Data was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 5\Web Data was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Web Data was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Web Data was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Web Data-journal was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Web Data.tmp was reset successfully
 
==== Empty IE Cache ======================
 
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\pam\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\pam\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\pam\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\pam\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
 
==== Empty FireFox Cache ======================
 
C:\Users\pam\AppData\Local\Mozilla\Firefox\Profiles\3nh7ww8g.default\cache2 emptied successfully
 
==== Empty Chrome Cache ======================
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 5\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Cache emptied successfully
 
==== Empty All Flash Cache ======================
 
Flash Cache Emptied Successfully
 
==== Empty All Java Cache ======================
 
Java Cache cleared successfully
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=1103 folders=162 246069634 bytes)
 
==== Empty Temp Folders ======================
 
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\pam\AppData\Local\Temp will be emptied at reboot
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
 
==== After Reboot ======================
 
==== Empty Temp Folders ======================
 
C:\windows\Temp successfully emptied
C:\Users\pam\AppData\Local\Temp successfully emptied
 
==== Empty Recycle Bin ======================
 
C:\$RECYCLE.BIN successfully emptied
 
==== EOF on Sun 06/07/2015 at 14:17:36.78 ======================
 
 
 
 
# AdwCleaner v4.206 - Logfile created 07/06/2015 at 15:32:47
# Updated 01/06/2015 by Xplode
# Database : 2015-06-05.1 [Server]
# Operating system : Windows 8.1 Connected  (x64)
# Username : pam - MINE
# Running from : C:\Users\pam\Desktop\adwcleaner_4.206.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17416
 
 
-\\ Mozilla Firefox v38.0.1 (x86 en-US)
 
 
-\\ Google Chrome v43.0.2357.81
 
 
*************************
 
AdwCleaner[R0].txt - [4338 bytes] - [01/06/2015 11:03:12]
AdwCleaner[R1].txt - [4397 bytes] - [01/06/2015 11:49:06]
AdwCleaner[R2].txt - [4456 bytes] - [01/06/2015 12:34:46]
AdwCleaner[R3].txt - [1009 bytes] - [07/06/2015 14:26:00]
AdwCleaner[R4].txt - [1068 bytes] - [07/06/2015 15:16:02]
AdwCleaner[S0].txt - [4212 bytes] - [01/06/2015 12:42:25]
AdwCleaner[S1].txt - [995 bytes] - [07/06/2015 15:32:47]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1053  bytes] ##########
 
 


#4 satchfan

satchfan

  • Malware Response Team
  • 2,857 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:06:02 AM

Posted 08 June 2015 - 01:44 AM

Thanks for the logs and you did fine.


Run AVG removal tool

There are some remnants of AVG on your computer so please download and run AVG Removal Tool from here.

Can you then run FRST again and send the new log.

Also, can you tell me how your computer is now and if the problem is still there.

Thanks

Satchfan


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#5 Angel White

Angel White
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Arizona Bay
  • Local time:10:02 PM

Posted 08 June 2015 - 02:59 AM

HI! I downloaded and opened the avg removal tool and got the following error:  

 

2015-06-08 07:25:27,489 ERROR Wrong application platform. Use corresponding application version for 32bit or 64bit systems

 

 

As for how my system is running now, comes up slow, then seems to be ok once its up. No about:blank while surfing.  and only  couple browser crashes (could be Chrome?).   BTW, if i click on something in those log reports i posted (clickable links), it redirects to the about:blank and then on to the page, so it still seems to be there, but not for very long, it doesnt seem to 'hang there'. 

 

So, anyway i didnt run the FRST since the avg thing didnt work. Did you still want me to run that one? Thank you :)



#6 satchfan

satchfan

  • Malware Response Team
  • 2,857 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:06:02 AM

Posted 08 June 2015 - 08:47 AM

Forget AVG as I think Zoek might have dealt with it.

Google Chrome is infamous for this kind of behaviour. Let’s see if we can get rid of this nuisance entry.

Run Zoek

Please run Zoek again.

Important : Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe.

  • on Windows Vista, 7, and 8, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    
    chrdefaults;
    emptyalltemp;
    emptyclsid;
    autoclean;
    
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

Thanks

Satchfan
 

 


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#7 Angel White

Angel White
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Arizona Bay
  • Local time:10:02 PM

Posted 08 June 2015 - 02:57 PM

It's weird, after rebooting the machine, and opening browser, i clicked on facebook to make sure all the settings were working and at first it said 'facebook dot com' in the addr bar, then the about:blank showed up, like it was going to redirect, but then went back to facebook address lol.. but didn't really slow down the process too much. Also, still have it when i click an external link.  I'm probably just cursed with this stupid thing!  If this is taking too much time away from others who have more severe problems, let me know.. i could always come back if it starts causing more of an issue, it's not a problem. :)
 
 
 
 
Here is the Zoek log:
 
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by pam on Mon 06/08/2015 at 11:14:39.08.
Microsoft Windows 8.1 with Bing 6.3.9600  x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\pam\Desktop\zoek.exe [Scan all users] [Script inserted] 
 
==== Older Logs ======================
 
C:\zoek-results2015-06-07-211736.log 27770 bytes
 
==== Deleting CLSID Registry Keys ======================
 
 
==== Deleting CLSID Registry Values ======================
 
 
==== Deleting Services ======================
 
 
==== Firefox Extensions Registry ======================
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [04/23/2015 11:17 PM]
 
==== Firefox Extensions ======================
 
ProfilePath: C:\Users\pam\AppData\Roaming\Mozilla\Firefox\Profiles\3nh7ww8g.default
- WOT - %ProfilePath%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
 
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
==== Firefox Plugins ======================
 
Profilepath: C:\Users\pam\AppData\Roaming\Mozilla\Firefox\Profiles\3nh7ww8g.default
2E661988463BCFA1B95D4DAAB9B0B6FA - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll - Shockwave Flash
08ACECEB47FAF053C468D8AFE44709AD - C:\Users\pam\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll - Google Update
 
 
==== Chromium Look ======================
 
Google Chrome Version: 43.0.2357.81
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[03/20/2015 11:04 AM]
 
Avast Online Security - pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Hotword Shared Module - pam\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
Google Voice Search Hotword (Beta) - pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Webroot Filtering Extension - pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kjeghcllfecehndceplomkocgfbklffd
Webroot Password Manager - pam\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab
Google Voice Search Hotword (Beta) - pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Webroot Filtering Extension - pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\kjeghcllfecehndceplomkocgfbklffd
Webroot Password Manager - pam\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab
Google Voice Search Hotword (Beta) - pam\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Google Voice Search Hotword (Beta) - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
WOT - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\bhmmomiinigofkjcapegjjndpbikblnp
Scroll Button - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fbkobdcckhcgleanepepnfaficicaogg
Spaaze - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\hofabcapkmnnhhccplipkecnjbmgoegl
Arcane Legends - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ibmlkgieigeddcedpbijnpojheoddido
Social Fixer for Facebook - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb
WeatherBug (Legacy App) - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak
Deadmau5 Green Edition - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\iphfjhmkmdjocaaopmgpeikabebejihc
International Internet TV - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\jpfaflofhdeeaikcajgalgbpgejbmihk
Scroll to Top - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\khnloieeghjghmpjeaopaenibbneljpk
Unfriend Alerts - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\lgbeldbnadmemecalekdfnffgobkpafc
WeatherBug - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\mekeaeklopjambfhgndcddmpfbinkdpb
WeatherBug - pam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\njkkjobcechefaoknodniidfjapgfoco
Google Voice Search Hotword (Beta) - pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Avast SafePrice - pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - pam\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\gomekmidlodglbbmalcneegieacbdmki
WOT - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\bhmmomiinigofkjcapegjjndpbikblnp
Tampermonkey - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo
Bookmark Manager - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\gmlllbghnfkpflemihljekbapjopfjik
Avast Online Security - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\gomekmidlodglbbmalcneegieacbdmki
Spaaze - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\hofabcapkmnnhhccplipkecnjbmgoegl
Arcane Legends - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\ibmlkgieigeddcedpbijnpojheoddido
Social Fixer for Facebook - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb
Deadmau5 Green Edition - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\iphfjhmkmdjocaaopmgpeikabebejihc
Scroll to Top - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\khnloieeghjghmpjeaopaenibbneljpk
Chrome Hotword Shared Module - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\lccekmodgklaepjeofjdjpbminllajkg
WeatherBug - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\mekeaeklopjambfhgndcddmpfbinkdpb
Fairshare - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\mkaliidbdemijhjchoaoomhfifplapmi
WeatherBug - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\njkkjobcechefaoknodniidfjapgfoco
Weather Underground - pam\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\pjejbgheonogbpfkkjigbmahaljipoej
 
==== Chromium Startpages ======================
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Preferences
s":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false}}},"google":{"services":{"last_username":"angelwhite300@gmail.com","username":"angelwhite300@gmail.com"}},"homepage":"http://www.facebook.com/","homepage_is_newtabpage":false,"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"6717AD43262C60D0D3F0BD1AD5175E25BF131BB78A91153D68B76F82C5D86214"},"default_search_provider":{"keyword":"42ACBEFE26FBD901EDC8E56B0AC87210572E5046C07C37EA52C4A4899149FB7D","name":"773C3E1E7F4EE33E9311569ED6445C521E0A7C60434588B65FFB4F96F7E6AB14","search_url":"4E2947CBC0CCB9F7791F1628833BE0F248DC0D64EFD2F6DF445E5193F53BB390"},"default_search_provider_data":{"template_url_data":"0682D66A4C4A8EFE2B45BE75F260DBFB218172AD09A61C7E395BC27E04A7D192"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"FF5D40E9521DF3BECDE7073E6E447CCE9909F19EC3C26FC2DA3AFE0289CBC8E7","aohghmighlieiainnegkcijnfilokake":"3C55DA89F803B69CF7C5F0F297C5C96F776F77487FCDE7A5DFC42F1B680E89D3","apdfllckaahabafndbhieahigkjlhalf":"FED42AF397ABF585CA218719888BE5B61C13535429DBFCCE58997CA297038502","bepbmhgboaologfdajaanbcjmnhjmhfn":"D329578314A24240DF2099D222ABE45141201CF0E9CFD8A574D16CE627329498","bhmmomiinigofkjcapegjjndpbikblnp":"0CD2283DF71EA106175BB14ED2250C9A73BF964E258471DF383AD168AC990E02","blpcfgokakmgnkcojhhkbfbldkacnbeo":"462D825A3D30A24FCBA7B6C6DC78B66957DE93A195537B9A74B2822590EAC69C","cfhdojbkjhnklbpkdaibdccddilifddb":"219D410BCCB954A29AC1B55DA3BE9E559D93E15AFD1A82EF7679EA6C6EB35B15","chiikmhgllekggjhdfjhajkfdkcngplp":"09C2FDDBA33EC8511B224A0A3D583BA640FD6F5074A43B166E6FE96E744A1F02","coobgpohoikkiipiblmjeljniedjpjpf":"7F3EC659A05833FB1B9FA26216A3B8AA0A773444797501028AA303995CF68853","ddcihbboebboehpkkdfdkhbodacmmfkk":"AFC5CB6381A29ADE8E8CC743D68A1C5F1DCEBCC05C5913C527BB383FCFA70428","dhdgffkkebhmkfjojejmpbldmpobfkfo":"598F8DF8F5D27087FD9FC092E1BB48DC92FE9D0E5B0EE0FCAF3441617C4D59BD","eemcgdkfndhakfknompkggombfjjjeno":"FC153537B60A1D850D297D0B2E9AA1B94FC94A4B53B5D2850E4FA925B2B57343","ennkphjdgehloodpbhlhldgbnhmacadg":"3EFC55DA92574F972DC12623C50398CEDAE4BA8EED3F354FA917C7B10FF9F935","felcaaldnbdncclmgdcncolpebgiejap":"0EB1AF527E11B9C5BF14554FA139E36F907B9D5AE0774AA005988C6C1E53FD91","gdhhajdfefljnoihedjgannejglblohb":"9D6804FFF9045954A1B89099977B6F83875598A237D5B988F709B18FBB5FB73F","gfdkimpbcpahaombhbimeihdjnejgicl":"246CD64EB58BBB48D9E1745F4BDA928D03A981F95129F62A2EBEFDB8F94E5EE0","gmlllbghnfkpflemihljekbapjopfjik":"A1BD3FD150752C635AE405444AB9038EA62C534A2A482EFDDC85991969A32353","gomekmidlodglbbmalcneegieacbdmki":"697A55DA838B21F4AE6CA193036D1F00767287D50643D9A13544CA5C9C8398BA","gpdjojdkbbmdfjfahjcgigfpmkopogic":"C00899E4327362B2F8844BE22CADD073B2356F17BFC3B27D82F745A4A8644878","haomkemhnjlojfjklokcbkjkdanghlic":"7E173284D47A3B095E38812234B9BE17AC4E253D26AA0824A6FC4BBCDBD56780","hofabcapkmnnhhccplipkecnjbmgoegl":"73D9C465FB3429ED90A454AFFD3863BDF09D59BE25ED5F96642CD055F10C811C","iaiicjbbkmidkdnmebipdidclcfdpakk":"F1072BD3B4151BB11C2F73E7F8039C60B776CA4E13799D2EE36478E775149DC8","ibmlkgieigeddcedpbijnpojheoddido":"BB0D48BDD02291536254753CB06DB95F7626673BD5240E0493B53FFDD6C15A77","ifmhoabcaeehkljcfclfiieohkohdgbb":"E52A022E7B89B5F8BD2D031B3748FC4FEDC5C1802AF7FDCA342898A26255C1E5","iphfjhmkmdjocaaopmgpeikabebejihc":"2BC9B954AAFF046C657FFEFF2ED2D0E52EADCD8117F24CB1CFDB1EFDE705DC6A","jpfaflofhdeeaikcajgalgbpgejbmihk":"9A2003EDFE2CE4522518754EB57FF0088B10DF16ADDCB87FF7B1161FF550BDAC","khnloieeghjghmpjeaopaenibbneljpk":"02C1CDC65197B03C36275EBF0444F2112C65371581E3B7C006CBE248BD3DF777","kmendfapggjehodndflmmgagdbamhnfd":"C15E61D5EA89D599C23F2D25969A322273C87438B94212AEA98348540C57816E","lccekmodgklaepjeofjdjpbminllajkg":"0DB7066CA2F4EFC8BB1C46E633FFCDCB6AB98577D2E78524069BB9D46402C472","lneaknkopdijkpnocmklfnjbeapigfbh":"76E7D35537047606C3F9643B8883B02A9B1D1B5ADC5354606721206AA6CC89BB","mekeaeklopjambfhgndcddmpfbinkdpb":"FDC0CE3EB2529BFD28ABC7FE5FC635AC4AB150BF9853FF040C8F31BADF7E60C7","mfehgcgbbipciphmccgaenjidiccnmng":"9B9FCFDF56A42F1AF77A3C0A8A406940E57AE6ADA90F7128B737CD4B20AC196E","mfffpogegjflfpflabcdkioaeobkgjik":"D62C59ADFA23A98E2003B7D7CD6912EEBE0C59179E9B84CAB4FD1D00E86F4ADD","mgndgikekgjfcpckkfioiadnlibdjbkf":"A6F9A0DC5744A6D28C6D005F19DBF3FD82D7B953E1A3A94FE8FF1D581524EBEF","mhjfbmdgcfjbbpaeojofohoefgiehjai":"D7FCDEFBF710A534F72800AC5E67DEE96AEAB3106DE93C3A95A95B5A5A5D9675","mkaliidbdemijhjchoaoomhfifplapmi":"AA6595E6A1017638FF5B7D8928D67E41F286EEDD958CCE8813F3C14D1E5F9E07","nbpagnldghgfoolbancepceaanlmhfmd":"C3811085324BD2CA449BDBE87EC86F299E410D335751B817405D994AB027C164","neajdppkdcdipfabeoofebfddakdcjhd":"4F27BF91142BCCB073D74AB83F27E7A3842975F978831BCB9897E7525F039211","njkkjobcechefaoknodniidfjapgfoco":"42FD137A7721BD09CEB56616D416D8D8BADE782F1A0041989A6547507C419AE2","nkeimhogjdpnpccoofpliimaahmaaome":"22C1F1D0F4913F4B0E3C8D86F568E010B66366D0C12457E0DCF31EBDCBD710EE","nmmhkkegccagdldgiimedpiccmgmieda":"1DB93DFF7A912D2FFD847E7394C32F057048CD64C08D74C2D928F0F882DFC42D","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"DF275CBF65D0CEDC1DD83EBDE2B39302A46AEDCEBB82C5C7A5ABC738DC0A2094","pjejbgheonogbpfkkjigbmahaljipoej":"310411BF8CCEBBE793F20CE83E71A7232871A975E78A50B822A03E38505407EB","pjkljhegncpnkpknbcohdijeoejaedia":"BA6E9C0CA333E0F3A5C8F1B01683FBCFE8B439342E08FBDDD27123C32CC97D3C"}},"google":{"services":{"last_username":"869C0C0E3351F962F630AF3D032F37A0A633EEB94F3220F3A851E7B6947678D0","username":"888C816DE0D7B9096378A07E2A884249FFDA3F0516937A10E236430797119641"}},"homepage":"0F968E9E7D6BD92D6E144BE66560EDBC59EF7EA3CC05E1C239A859680E6DF90C","homepage_is_newtabpage":"D68AC1FBADAB34E51CF224B9141B2F19143484A21E71A81F40A8D884BFC5AD00","pinned_tabs":"E53A11FD280278F528200DA090D68BF5350CDA3DC873DECC59D1B76C45E51368","prefs":{"preference_reset_time":"BF1BA7DECF79DEB5AEFF3321D5F5CAC94D09BDE9DEE58D546906942628C04ED0"},"profile":{"reset_prompt_memento":"BBEAE423DF50CBBA6963DAF0B60982F2701AE430D8D2CF5B27F3033094E73CBA"},"safebrowsing":{"incidents_sent":"A1414C9ECACD4AE4CC97F07027E45CF5801750A7542B2758311F407ECA7C8D4B"},"search_provider_overrides":"4BBD4B51390975E2579B55900411A1E932296030E29D36DCA4F095DE5E7C5A82","session":{"restore_on_startup":"9CDEA9794D1678BA554A0F65C278398FC42A88C09B30973D9A1A1A0A3783F0E9","startup_urls":"653195A15EC6E34C3C3A770A33C89C7909CE8B72DACF7F000921542BBEEA9D57"},"software_reporter":{"prompt_reason":"ED017B1627377EE8BEDC7BDFA779A058F4733F423BDDE20F739A302C22F8DDB2","prompt_seed":"82AB5A03D2A3068CF7F90E4AC190D9091BB64FA54F9D5C1184EFF58269C5B3B9","prompt_version":"E80E12CEC75368EA08D5660794086310C9F0700098FB3C1AD39F66476DFAD0A2"},"sync":{"remaining_rollback_tries":"A1727D7BF594232C324DDC48DEE7309E015DFC6C862A4F2FCDFFF6A7F5A8D424"}},"super_mac":"B54EFE56BF3A1699182E0BD2117DE24B4887BB398A3281980D8943F45467638F"},"session":{"restore_on_startup":5,"startup_urls":["http://www.google.com/","http://yahoo.genieo.com/?v=w3i8","http://mysearch.avg.com?cid={B74061FB-D9EC-4C13-AD37-28B5B6A546AE}&mid=f03055a1d84f47d08281d16f2ae9dd91-0b56751693a1a6eef81875233f858dde1af65aff&lang=en&ds=ts019&coid=avgtbdists&cmpid=&pr=sa&d=2014-04-04 21:17:05&v=18.0.5.292&pid=safeguard&sg=&sap=hp","http://mysearch.avg.com?cid={B74061FB-D9EC-4C13-AD37-28B5B6A546AE}&mid=f03055a1d84f47d08281d16f2ae9dd91-0b56751693a1a6eef81875233f858dde1af65aff&lang=en&ds=ts019&coid=avgtbdists&cmpid=&pr=sa&d=2014-04-04 21:17:05&v=18.1.0.443&pid=safeguard&sg=&sap=hp","http://homepage-web.com/?s=hp&m=start"]},"sync":{"remaining_rollback_tries":0}}
 
 
==== Set IE to Default ======================
 
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
 
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
 
==== All HKCU SearchScopes ======================
 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Goo  Url="http://www.google.com/search?q={sear"
 
==== Reset Google Chrome ======================
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Secure Preferences was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Web Data was reset successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Web Data-journal was reset successfully
 
==== Empty IE Cache ======================
 
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\pam\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\pam\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\pam\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\pam\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
 
==== Empty FireFox Cache ======================
 
C:\Users\pam\AppData\Local\Mozilla\Firefox\Profiles\3nh7ww8g.default\cache2 emptied successfully
 
==== Empty Chrome Cache ======================
 
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 2\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 3\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 4\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 5\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 6\Cache emptied successfully
C:\Users\pam\AppData\Local\Google\Chrome\User Data\Profile 7\Cache emptied successfully
 
==== Empty All Flash Cache ======================
 
Flash Cache Emptied Successfully
 
==== Empty All Java Cache ======================
 
Java Cache cleared successfully
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=1103 folders=162 246069634 bytes)
 
==== Empty Temp Folders ======================
 
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\pam\AppData\Local\Temp will be emptied at reboot
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
 
==== After Reboot ======================
 
==== Empty Temp Folders ======================
 
C:\windows\Temp successfully emptied
C:\Users\pam\AppData\Local\Temp successfully emptied
 
==== Empty Recycle Bin ======================
 
C:\$RECYCLE.BIN successfully emptied
 
==== EOF on Mon 06/08/2015 at 12:25:04.00 ======================
 
 
Again, Thanks! :)


#8 satchfan

satchfan

  • Malware Response Team
  • 2,857 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:06:02 AM

Posted 08 June 2015 - 03:16 PM

If this is taking too much time away from others who have more severe problems, let me know.

Everyone's problems here are taken as equally important so let's deal with it!


Unfortunalely, you cannot remove some bad stuff except with an uninstall/re-install of Chrome, (even though Google have been aware of this since 2008 and haven't bothered to do anything about it).

I suggest you do the following as this is the quickest solution:

Uninstall/Reinstall Google Chrome

First save all your bookmarks/favourites.

  • open Chrome, click on the 3 bars in the top right hand corner, select Bookmarks and then Bookmarks Manager
  • click on Organise and then select Export Bookmarks to HTML file, then choose Desktop to save it
  • again, click on the three bars in the top right hand corner and select Settings
  • in the list of Settings under “Sign in” click on Disconnect your Google Account
  • in the text of the next window click on “Google Dashboard” then, at the “Chrome sync” screen, click on Stop and Clear at the bottom
  • a box will open and ask for confirmation, click on OK (wait for this to complete before doing the next step)
  • when confirmation appears close that page and then click on Disconnect account
  • shut Google Chrome, click on Start > Control Panel > Programs and Features (or Add/Remove Programs in XP) and uninstall Google Chrome. Select Everything for removal if asked.

Reboot the system and then reinstall Google Chrome from here

Repeat the process to reinstate your bookmarks by going to Bookmarks > Bookmarks Manager > Organise and select Import Bookmarks.

 

Please tell me how things are and if that has resolved the problem,

 

Satchfan


Edited by satchfan, 08 June 2015 - 03:17 PM.

My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#9 Angel White

Angel White
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Arizona Bay
  • Local time:10:02 PM

Posted 08 June 2015 - 06:27 PM

hmm well, i did those steps, although i couldnt find where it said "Disconnnect Google Acct", when i was done with the bookmarks thing i was signed out of google. i uninstalled, and rebooted, reinstalled google, and all my bookmarks and google extensions were intact. Just had to sign back into Google.. lol dont know if it worked.

 

Youre right about google, how bad it performs. Firefox is a lot faster, i only changed because it seemed to crash more than Google. And, the about:blank is there, with google and firefox, and when i click an external link. Took Chrome page a really long time to load, Firefox came right up, tho its started with the about:blank.  Lol!  

 

 

Everyone's problems here are taken as equally important so let's deal with it!

 

 

Lol thanks, but im sure this one is going to drive everyone crazy.  And maybe its not the about:blank thats causing the problems, lol maybe its just Chrome? took 20 seconds for Youtube to even respond and 10 to load (in Chrome) --no about:blank.. 


Edited by Angel White, 08 June 2015 - 11:45 PM.


#10 satchfan

satchfan

  • Malware Response Team
  • 2,857 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:06:02 AM

Posted 09 June 2015 - 04:41 AM

I’ve just looked at your thread from the other forum and it seems you’ve had this problem with other laptops which makes me wonder about your router so let’s try something else.

Reset the Router

Let’s try to reset the router to its default configuration.

  • this can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labelled "reset" located on the back of the router.
  • press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
  • if you don’t know the router's default password, you can look it up. here
  • you also need to reconfigure any security settings you had in place prior to the reset.
  • you may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

Note: After resetting your router, it is important to set a non-default password, and if possible, username, on the router. This will assist in eliminating the possibility of the router being hijacked again.

Flush the DNS

Now lets flush the DNS on the computer:

  • hold down your Windows key and press R
  • a “run” window will appear
  • type in cmd and press Enter
  • a black window will open
  • please enter the following text into that window and then press Enter:


ipconfig /flushdns

 

Check the router


  • open Notepad and copy/paste the entire contents of the codebox below, into Notepad:
    
    @echo off
    >Log1.txt (
    ipconfig /all
    nslookup google.com
    nslookup yahoo.com
    ping -n 2 google.com
    ping -n 2 yahoo.com
    route print
    )
    start Log1.txt
    del %0
  • save this as router.bat
  • choose to Save type as - All Files and where to save – Desktop - then close the Notepad file.
  • double-click on router.bat to run it. it will open notepad when done please post back the results.

Satchfan

 


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#11 Angel White

Angel White
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Arizona Bay
  • Local time:10:02 PM

Posted 09 June 2015 - 02:50 PM

I already reset the router about 4 or 5 months ago. Did it on accident actually and took it to my provider who is also my tech guy. Also it has a non-default password. Called him up and he's not in for couple days. But i did the next steps; Flushed the dns and here is the router.bat results:

 

 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : MINE
   Primary Dns Suffix  . . . . . . . : 
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
 
Wireless LAN adapter Local Area Connection* 2:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
   Physical Address. . . . . . . . . : 1A-EE-65-A7-F1-A0
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Ethernet adapter Ethernet:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Realtek PCIe FE Family Controller
   Physical Address. . . . . . . . . : 40-A8-F0-4A-3E-D6
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::8c34:d044:a0bf:559%4(Preferred) 
   IPv4 Address. . . . . . . . . . . : 192.168.0.105(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Monday, June 8, 2015 3:35:27 PM
   Lease Expires . . . . . . . . . . : Tuesday, June 9, 2015 1:35:29 PM
   Default Gateway . . . . . . . . . : 192.168.0.1
   DHCP Server . . . . . . . . . . . : 192.168.0.1
   DHCPv6 IAID . . . . . . . . . . . : 161499164
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1B-13-22-AA-40-A8-F0-4A-3E-D6
   DNS Servers . . . . . . . . . . . : 192.168.0.1
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Wireless LAN adapter Wi-Fi:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Qualcomm Atheros AR9485 802.11b/g/n WiFi Adapter
   Physical Address. . . . . . . . . : B8-EE-65-A7-F1-A0
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter isatap.{A0AC277F-5897-47E0-81AD-1ED090AE6CC3}:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Teredo Tunneling Pseudo-Interface:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:9d38:6abd:3c75:3f7f:3f57:ff96(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::3c75:3f7f:3f57:ff96%7(Preferred) 
   Default Gateway . . . . . . . . . : ::
   DHCPv6 IAID . . . . . . . . . . . : 335544320
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1B-13-22-AA-40-A8-F0-4A-3E-D6
   NetBIOS over Tcpip. . . . . . . . : Disabled
Server:  UnKnown
Address:  192.168.0.1
 
Name:    google.com
Addresses:  2607:f8b0:4005:803::200e
 216.58.192.46
 
Server:  UnKnown
Address:  192.168.0.1
 
Name:    yahoo.com
Addresses:  98.138.253.109
 206.190.36.45
 98.139.183.24
 
 
Pinging google.com [216.58.192.46] with 32 bytes of data:
Reply from 216.58.192.46: bytes=32 time=13ms TTL=53
Reply from 216.58.192.46: bytes=32 time=18ms TTL=53
 
Ping statistics for 216.58.192.46:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 13ms, Maximum = 18ms, Average = 15ms
 
Pinging yahoo.com [206.190.36.45] with 32 bytes of data:
Reply from 206.190.36.45: bytes=32 time=99ms TTL=49
Reply from 206.190.36.45: bytes=32 time=35ms TTL=49
 
Ping statistics for 206.190.36.45:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 35ms, Maximum = 99ms, Average = 67ms
===========================================================================
Interface List
  5...1a ee 65 a7 f1 a0 ......Microsoft Wi-Fi Direct Virtual Adapter
  4...40 a8 f0 4a 3e d6 ......Realtek PCIe FE Family Controller
  3...b8 ee 65 a7 f1 a0 ......Qualcomm Atheros AR9485 802.11b/g/n WiFi Adapter
  1...........................Software Loopback Interface 1
  6...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
  7...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================
 
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.0.1    192.168.0.105     20
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.0.0    255.255.255.0         On-link     192.168.0.105    276
    192.168.0.105  255.255.255.255         On-link     192.168.0.105    276
    192.168.0.255  255.255.255.255         On-link     192.168.0.105    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link     192.168.0.105    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link     192.168.0.105    276
===========================================================================
Persistent Routes:
  None
 
IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  7    306 ::/0                     On-link
  1    306 ::1/128                  On-link
  7    306 2001::/32                On-link
  7    306 2001:0:9d38:6abd:3c75:3f7f:3f57:ff96/128
                                    On-link
  4    276 fe80::/64                On-link
  7    306 fe80::/64                On-link
  7    306 fe80::3c75:3f7f:3f57:ff96/128
                                    On-link
  4    276 fe80::8c34:d044:a0bf:559/128
                                    On-link
  1    306 ff00::/8                 On-link
  4    276 ff00::/8                 On-link
  7    306 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None

Edited by Angel White, 09 June 2015 - 02:52 PM.


#12 satchfan

satchfan

  • Malware Response Team
  • 2,857 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:06:02 AM

Posted 09 June 2015 - 05:08 PM

I may need to refer you to another of our forums that deals with networking issues but before that, I’d like you to run another scan.

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop

  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.
Please post the contents of the RKreport.txt in your next reply.

Thanks

Satchfan

 


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#13 Angel White

Angel White
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Arizona Bay
  • Local time:10:02 PM

Posted 09 June 2015 - 11:15 PM

Hi, sorry, got called to work.  Here is the scan log:

 

RogueKiller V10.8.2.0 [Jun  9 2015] by Adlice Software
 
Operating System : Windows 8.1 (6.3.9200 ) 64 bits version
Started in : Normal mode
User : pam [Administrator]
Started from : C:\Users\pam\Desktop\RogueKiller.exe
Mode : Scan -- Date : 06/09/2015  21:09:41
 
¤¤¤ Processes : 1 ¤¤¤
[Suspicious.Path] Google+ Auto Backup.exe(2532) -- C:\Users\pam\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe[7] VT(1) -> Killed [TermProc]
 
¤¤¤ Registry : 2 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1548870796-431023125-660753347-1001\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\pam\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart [7][x] -> Found
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1548870796-431023125-660753347-1001\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\pam\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart [7][x] -> Found
 
¤¤¤ Tasks : 0 ¤¤¤
 
¤¤¤ Files : 0 ¤¤¤
 
¤¤¤ Hosts File : 0 ¤¤¤
 
¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤
 
¤¤¤ Web browsers : 0 ¤¤¤
 
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD50 00AAKX-60U6AA0 SATA Disk Device +++++
--- User ---
[MBR] 2a3e202a1c1746b9aac5f35172b7c744
[BSP] e92708f516d98b366b72e2c6aaf66335 : Empty MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 1023 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2097152 | Size: 360 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 2834432 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 3096576 | Size: 461024 MB
4 - [SYSTEM] Basic data partition | Offset (sectors): 947273728 | Size: 14399 MB
User = LL1 ... OK
User = LL2 ... OK


#14 satchfan

satchfan

  • Malware Response Team
  • 2,857 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:06:02 AM

Posted 10 June 2015 - 03:56 AM

There is almost certainly no malware on your computer.

You said at the beginning in the other forum:

 

i looked it up again and finally someone had a blog about it.. that it wasnt a malware just a blank page microsoft or someone came up with and it was completely safe, it was default. whatever, i want it gone! 

“About:Blank” is the default setting but most users choose a favourite Home Page, eg Google or Yahoo. I assume your home page is OK but I’m unsure what your exact problem is.
 

 

it doesnt come up when i open a new tab or the bring the browser up, just when i go to a new webpage

Please explain that a bit more as it seems unclear to me. If it’s OK when you open your browser, then when does “About:Blank” appear - what the difference is between “a new tab” and “a new web page” if bringing up your browser doesn't cause it to appear - isn't that a new web page? :unsure:


Edited by satchfan, 10 June 2015 - 03:56 AM.

My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#15 Angel White

Angel White
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Arizona Bay
  • Local time:10:02 PM

Posted 10 June 2015 - 11:47 AM

Well i guess because i've had it on just about every machine ive owned, it seemed to lag everything or hang up searches.  I dint think its a malware either just a nuisance. But that's why i didn't go to the malware forum lol...I just wanted to know if there's a way to get rid of it. Maybe stop it from trying to load. I think when you choose a home page, it still tries to start up then goes to whatever page you have set.. My problem? It drives me nuts!

 

So far, the about:blank appears whenever i am on a website and click an external link. For example.. in the RK log report i posted, theres an external link to a blog by Adlice, i click on it and it goes to that blog. In the addr bar, it first shows about:blank, then www.adlice.com.  So, its not a real horrible problem, just wanted to know how to stop that from happening. it seems to hang on the about:blank before continuing onto the site i was aiming for. lol

 

I guess a lot of times, this issue is with the home page as a hijack, but i tried to say that a couple of times it wasn't and my home page was fine. I guess it didn't make sense as to what i was saying..Sorry bout that!  I guess there is probably no way to get rid of this annoyance, and the lag could have been a Chrome problem anyway...it seems to be running extra fast this morning.

 

Thanks again 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users