Hi,
I am having the same problem as Nanaki, Beh3 and Zel32. I have removed Spybot and run the FRST scan. I have attached my logs.
Thank you for the help.
Addition.txt 70.03KB
3 downloads
FRST.txt 46.13KB
4 downloads
Posted 05 March 2016 - 10:44 PM
Hi,
I am having the same problem as Nanaki, Beh3 and Zel32. I have removed Spybot and run the FRST scan. I have attached my logs.
Thank you for the help.
Addition.txt 70.03KB
3 downloads
FRST.txt 46.13KB
4 downloads
Posted 06 March 2016 - 08:34 AM
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Start CreateRestorePoint: EmptyTemp: CloseProcesses: ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File Toolbar: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [No File] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => not found FF HKLM\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn => not found CHR Plugin: (Native Client) - C:\Users\user\AppData\Local\Google\Chrome\Application\48.0.2564.116\ppGoogleNaClPluginChrome.dll => No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\user\AppData\Local\Google\Chrome\Application\48.0.2564.116\pdf.dll => No File CHR Plugin: (Shockwave Flash) - C:\Users\user\AppData\Local\Google\Chrome\Application\48.0.2564.116\gcswf32.dll => No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll => No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll => No File CHR Plugin: (Google Update) - C:\Users\user\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll => No File CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll => No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll => No File CHR HKU\S-1-5-21-1323538042-1961802298-2586452256-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\user\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx <not found> U3 idsvc; no ImagePath U3 wpcsvc; no ImagePath CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.135\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.99\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{0E55CBE1-B06A-49B6-AD8D-9EFAA0160C6F}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.57\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.25.5\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.27.5\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{218D2740-5A50-42A8-AB9F-62FF1B168782}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.69\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{29A96789-9595-4947-BEDB-0FCC776F7DB8}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.2.183.39\goopdate.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{320F0FDB-BE0A-4648-9D18-4A2C3448C007}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.79\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.23.9\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.28.1\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.145\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.123\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.153\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.28.13\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.24.15\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.149\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.22.3\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.165\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.26.9\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.115\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.29.2\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.25.11\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\user\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.28.15\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{DB25D157-76D4-41C1-97B5-359E4A4CECEB}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.65\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.22.5\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.21.111\psuser.dll => No File CustomCLSID: HKU\S-1-5-21-1323538042-1961802298-2586452256-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.24.7\psuser.dll => No File Task: {0865FF72-E36A-4581-98B5-ED47FC1A4855} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {35F1F4A2-4A72-4EA9-B703-03DC6AB9743D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {501958F8-96CC-452C-9A24-72344355DA30} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {59CA657C-3B3F-4DDA-B58C-8859732542C7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {96F1588E-9A94-4C86-B4E1-5A7E5BF2116A} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {A0F6B3E4-657B-4405-A1BE-EBC5E721D989} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {A89B276B-66C3-41AC-8A96-73B626FF7E44} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {CE774D9C-0DA7-45C9-87D7-0BEC5D58614A} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {E18A2E4A-5BB2-4E43-BC6F-2CF1C4EBA3F7} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {E60FF775-6145-4DBD-B06D-FDF6D8F116EB} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {EE1555B2-CB7B-480D-A964-1ADD6C29873B} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION EndSave the file as fixlist.txt in the same folder where the Farbar tool is running from.
Posted 06 March 2016 - 10:44 AM
Hi Nasdaq,
Thank you for the quick response. I was unable to remove the Vuze Toolbar. I received an error saying the file location was wrong.
I have attached the ADWCleaner log and the new FRST log.
I ran ESET and it found no threats.
Posted 06 March 2016 - 11:37 AM
I ran a scan with Spybot and it did not get held up this time. Looks to be good.
Thank you for the help and feedback.
Posted 06 March 2016 - 11:42 AM
Sorry one last problem. My Windows Defender will still not turn on. I receive the message below:
"This app has been turned off and isn't monitoring your computer. If you are using another app to check for malicious or unwanted software, use Security and Maintenance to check the app's status"
I got this message when trying to open Windows Defender from the Security and Maintenance section.
Posted 06 March 2016 - 02:11 PM
Sorry one last problem. My Windows Defender will still not turn on.
Posted 06 March 2016 - 04:00 PM
Posted 07 March 2016 - 07:15 AM
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=-
Edited by nasdaq, 10 March 2016 - 08:25 AM.
Posted 09 March 2016 - 10:07 PM
Posted 10 March 2016 - 08:25 AM
0 members, 0 guests, 0 anonymous users