Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by Rick (administrator) on RICK-PC on 29-01-2015 12:25:42
Running from C:\Users\Rick\Downloads
Loaded Profiles: Rick (Available profiles: Rick)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

aswMBR version Copyright(c) 2014 AVAST Software
Run date: 2015-01-29 12:30:57
12:30:57.168 OS Version: Windows x64 6.1.7601 Service Pack 1
12:30:57.168 Number of processors: 2 586 0x170A
12:30:57.169 ComputerName: RICK-PC UserName: Rick
12:31:05.927 Initialize success
12:31:06.180 VM: initialized successfully
12:31:06.182 VM: Intel CPU virtualization not supported
12:59:35.261 AVAST engine defs: 15012900
13:00:54.883 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
13:00:54.883 Disk 0 Vendor: ST925031 0003 Size: 238475MB BusType: 3
13:00:55.445 Disk 0 MBR read successfully
13:00:55.445 Disk 0 MBR scan
13:00:55.601 Disk 0 Windows VISTA default MBR code
13:00:55.601 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 298 MB offset 63
13:00:55.632 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 19328 MB offset 612352
13:00:55.663 Disk 0 Boot: NTFS code=1
13:00:55.757 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 218847 MB offset 40196096
13:00:56.163 Disk 0 scanning C:\Windows\system32\drivers
13:01:32.620 Service scanning
13:03:17.421 Modules scanning
13:03:17.436 Disk 0 trace - called modules:
13:03:17.483 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
13:03:17.499 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031b03c0]
13:03:17.514 3 CLASSPNP.SYS[fffff880013bc43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8002e0d050]
13:03:38.294 AVAST engine scan C:\Windows
13:03:59.884 AVAST engine scan C:\Windows\system32
13:16:05.285 AVAST engine scan C:\Windows\system32\drivers
13:17:09.963 AVAST engine scan C:\Users\Rick
14:22:11.811 AVAST engine scan C:\ProgramData
14:39:32.317 Disk 0 statistics 4870938/0/0 @ 0.55 MB/s
14:39:32.333 Scan finished successfully
15:48:08.040 Disk 0 MBR has been saved successfully to "C:\Users\Rick\Contacts\Desktop\MBR.dat"
15:48:08.087 The log file has been saved successfully to "C:\Users\Rick\Contacts\Desktop\aswMBR.txt"

Tea Timer was not turned off during these runs, my error.

Please uninstall/remove through your programs list
Coupon Printer for Windows

Running from C:\Users\Rick\Downloads
It's best we move Farbar's to desktop.

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-318222819-587572666-1752428572-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-21-318222819-587572666-1752428572-1001 -> URL http://search.conduit.com/Results.aspx?gd=&ctid=CT3325291&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=58&CUI=&UM=2&UP=SP39810CDC-14A2-455C-A1EA-70910FD1C243&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-318222819-587572666-1752428572-1001 -> SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKU\S-1-5-21-318222819-587572666-1752428572-1001 -> {0ABF0D15-0D00-4695-BE91-44679E688D34} URL =
SearchScopes: HKU\S-1-5-21-318222819-587572666-1752428572-1001 -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_dnldstr_14_40_ff&cd=2XzuyEtN2Y1L1QzuyBtDtC0AtDyEtAtDzyyDyBtC0AtDtD0DtN0D0Tzu0StCtDtDyEtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1OtN1L1G1B1V1N2Y1L1Qzu2SyBtB0A0E0F0BzztCtG0CyCyDtAtG0EtCyCtCtGyB0C0F0DtGyCtB0F0D0DyE0A0F0E0CtA0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEzzzy0Azz0Dzy0AtG0CyD0F0DtGyEtByB0AtGzyyDtDyEtGzz0Ezy0DtB0CtC0D0E0FyEzy2Q&cr=1036207534&ir=
Toolbar: HKU\S-1-5-21-318222819-587572666-1752428572-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll (Coupons, Inc.)
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKU\S-1-5-21-318222819-587572666-1752428572-1001\...\Chrome\Extension: [lcnnhcneegeeojhgpfijnlnocjdmlaon] - C:\ProgramData\ValueApps\CH\ValueApps.crx [2014-01-10]
CHR HKLM-x32\...\Chrome\Extension: [lcnnhcneegeeojhgpfijnlnocjdmlaon] - C:\ProgramData\ValueApps\CH\ValueApps.crx [2014-01-10]
S4 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [176624 2014-02-13] (Coupons.com Inc.)
C:\Program Files (x86)\Coupons\CouponPrinterService.exe
CustomCLSID: HKU\S-1-5-21-318222819-587572666-1752428572-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Rick\AppData\Roaming\Dropbox\bin\Dropbox.exe No File
Task: {041D3E65-F357-4000-8192-9FAFEF68D56A} - \Security Center Update - 2153847654 No Task File <==== ATTENTION
Task: {0D43F909-9647-41E8-B5B3-260B159570A6} - System32\Tasks\pcreg => C:\Program Files\pcreg\service.exe <==== ATTENTION
Task: {182EB22D-E74A-4C88-8604-6296D5F18A3D} - System32\Tasks\UpdaterEX => C:\Users\Rick\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {1FDF6AE2-EEE6-4CBC-8B54-A786EEB97C05} - \Security Center Update - 3991425528 No Task File <==== ATTENTION
Task: {46F5A2D0-8C38-47DA-BF19-D66593086F95} - \Security Center Update - 1248866258 No Task File <==== ATTENTION
Task: {4B88AD02-49BC-4736-AA22-943DFFEC7D17} - \Security Center Update - 4071741768 No Task File <==== ATTENTION
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\Rick\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


http://i.imgur.com/BY4dvz9.png AdwCleaner

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) and save the file to your Desktop.
Right-Click AdwCleaner.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Follow the prompts.
Click Scan.
Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
Follow the prompts and allow your computer to reboot.
After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.

-- File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.


Download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) to your desktop.

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"

http://i1269.photobucket.com/albums/jj590/OCD-WTT/MBAMDashboard_zpsddef9b5f.gif (http://s1269.photobucket.com/user/OCD-WTT/media/MBAMDashboard_zpsddef9b5f.gif.html)

On the Dashboard click on Update Now
Go to the Setting Tab
Under Setting go to Detection and Protection
Under PUP and PUM make sure both are set to show Treat Dections as Malware
Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
Then on the Dashboard click on Scan
Make sure to select THREAT SCAN
Then click on Scan
When the scan is finished and the log pops up...select Copy to Clipboard
Please paste the log back into this thread for review
Exit Malwarebytes

please post
Malwarebytes log

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015
Ran by Rick at 2015-01-29 20:59:37 Run:1
Running from C:\Users\Rick\Contacts\Desktop
Loaded Profiles: Rick (Available profiles: Rick)
Boot Mode: Normal

Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt1" => Key deleted successfully.
HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt2" => Key deleted successfully.
HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt3" => Key deleted successfully.
HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4" => Key deleted successfully.
HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKU\S-1-5-21-318222819-587572666-1752428572-1001\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKU\S-1-5-21-318222819-587572666-1752428572-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value deleted successfully.
HKU\S-1-5-21-318222819-587572666-1752428572-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON => value deleted successfully.
"HKU\S-1-5-21-318222819-587572666-1752428572-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ABF0D15-0D00-4695-BE91-44679E688D34}" => Key deleted successfully.
HKCR\CLSID\{0ABF0D15-0D00-4695-BE91-44679E688D34} => Key not found.
"HKU\S-1-5-21-318222819-587572666-1752428572-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}" => Key deleted successfully.
HKCR\CLSID\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} => Key not found.
HKU\S-1-5-21-318222819-587572666-1752428572-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value deleted successfully.
HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found.
"C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll" => not found.
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-318222819-587572666-1752428572-1001\SOFTWARE\Google\Chrome\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon" => Key deleted successfully.
C:\ProgramData\ValueApps\CH\ValueApps.crx => Moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon" => Key deleted successfully.
"C:\ProgramData\ValueApps\CH\ValueApps.crx" => File/Directory not found.
CouponPrinterService => Service not found.
C:\Program Files (x86)\Coupons\CouponPrinterService.exe => Moved successfully.
"HKU\S-1-5-21-318222819-587572666-1752428572-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{041D3E65-F357-4000-8192-9FAFEF68D56A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{041D3E65-F357-4000-8192-9FAFEF68D56A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 2153847654" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0D43F909-9647-41E8-B5B3-260B159570A6}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D43F909-9647-41E8-B5B3-260B159570A6}" => Key deleted successfully.
C:\Windows\System32\Tasks\pcreg => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pcreg" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{182EB22D-E74A-4C88-8604-6296D5F18A3D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{182EB22D-E74A-4C88-8604-6296D5F18A3D}" => Key deleted successfully.
C:\Windows\System32\Tasks\UpdaterEX => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UpdaterEX" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1FDF6AE2-EEE6-4CBC-8B54-A786EEB97C05}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1FDF6AE2-EEE6-4CBC-8B54-A786EEB97C05}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 3991425528" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{46F5A2D0-8C38-47DA-BF19-D66593086F95}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{46F5A2D0-8C38-47DA-BF19-D66593086F95}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 1248866258" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4B88AD02-49BC-4736-AA22-943DFFEC7D17}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4B88AD02-49BC-4736-AA22-943DFFEC7D17}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 4071741768" => Key deleted successfully.
C:\Windows\Tasks\UpdaterEX.job => Moved successfully.
C:\Users\Rick\AppData\Roaming\Usyqise => Moved successfully.
"C:\Users\Rick\AppData\Roaming\Uvxaohe\etcyvun.exe" => File/Directory not found.
C:\Users\Rick\AppData\Roaming\Uvxaohe => Moved successfully.
"C:\Users\Rick\AppData\Roaming\Emfuzi\woehi.exe" => File/Directory not found.
C:\Users\Rick\AppData\Roaming\Emfuzi => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 14.2 GB temporary data.

The system needed a reboot.

==== End of Fixlog 21:02:26 ====

# AdwCleaner v4.109 - Report created 29/01/2015 at 21:33:46
# Updated 24/01/2015 by Xplode
# Database : 2015-01-26.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Rick - RICK-PC
# Running from : C:\Users\Rick\Downloads\AdwCleaner(1).exe
# Option : Clean

***** [ Services ] *****

Service Deleted : YahooAUService
[#] Service Deleted : pcregservice

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\ValueApps
Folder Deleted : C:\ProgramData\Yahoo! Companion
Folder Deleted : C:\Program Files (x86)\Bench
Folder Deleted : C:\Program Files (x86)\ValueApps
Folder Deleted : C:\Program Files\pcreg
Folder Deleted : C:\Users\Rick\AppData\LocalLow\Yahoo! Companion
Folder Deleted : C:\Users\Rick\AppData\Roaming\UpdaterEX
File Deleted : C:\Users\Rick\AppData\LocalLow\SkwConfig.bin
File Deleted : C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage

***** [ Scheduled Tasks ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F63AAEDC-3602-49EF-AA45-262380A98980}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}]
Key Deleted : HKCU\Software\BRS
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\PennyBee
Key Deleted : HKCU\Software\UpdaterEX
Key Deleted : HKLM\SOFTWARE\Bench
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496

-\\ Mozilla Firefox v35.0.1 (x86 en-US)

-\\ Google Chrome v40.0.2214.93

[C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
[C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3325291&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=58&CUI=&UM=2&UP=SP39810CDC-14A2-455C-A1EA-70910FD1C243&q={searchTerms}&SSPV=
[C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_dnldstr_14_40_ff&cd=2XzuyEtN2Y1L1QzuyBtDtC0AtDyEtAtDzyyDyBtC0AtDtD0DtN0D0Tzu0StCtDtDyEtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1OtN1L1G1B1V1N2Y1L1Qzu2SyBtB0A0E0F0BzztCtG0CyCyDtAtG0EtCyCtCtGyB0C0F0DtGyCtB0F0D0DyE0A0F0E0CtA0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEzzzy0Azz0Dzy0AtG0CyD0F0DtGyEtByB0AtGzyyDtDyEtGzz0Ezy0DtB0CtC0D0E0FyEzy2Q&cr=1036207534&ir=


AdwCleaner[R0].txt - [7336 octets] - [27/12/2013 13:59:53]
AdwCleaner[R1].txt - [4173 octets] - [29/01/2015 21:10:07]
AdwCleaner[R2].txt - [4233 octets] - [29/01/2015 21:27:35]
AdwCleaner[S0].txt - [6277 octets] - [27/12/2013 14:01:43]
AdwCleaner[S1].txt - [4047 octets] - [29/01/2015 21:33:46]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4107 octets] ##########

Malwarebytes Anti-Malware

Scan Date: 1/29/2015
Scan Time: 9:54:12 PM
Administrator: Yes

Malware Database: v2015.01.29.11
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Rick

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 369798
Time Elapsed: 30 min, 41 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


Thanks Juliet for your help!

Tell me what the computer is doing now?

2015-01-30, 15:37
Tell me what the computer is doing now?

Everything looks and is running "normal"..... Biggest concern I had was the video retrievals and playing online, slower than normal startups, and the search engine had switched in my Firefox browser. And as you could see in the threads, I had downloaded SpyHunter by mistake which screwed things up pretty good too. I was just worried about what was going on behind the keyboard.

What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.

Go here (http://www.eset.com/us/online-scanner/) to run an online scannner from ESET. Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator

For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
Turn off the real time scanner of any existing antivirus program while performing the online scan. Here's how (http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html).
Click the blue Run ESET Online Scanner button
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
Click on Advanced Settings
Make sure that the option Remove found threats is unticked.
Ensure these options are ticked

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

Click Start
Wait for the scan to finish
When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
Close the ESET online scan.


C:\AdwCleaner\Quarantine\C\Program Files\pcreg\pcreg.exe.vir Win32/Conduit.SearchProtect.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Windows\System32\roboot64.exe.vir a variant of Win64/Systweak.A potentially unwanted application
C:\Program Files (x86)\pcreginst\file_to_run.exe Win32/ChatZum.A potentially unwanted application
C:\Program Files (x86)\runonce\user\updater.exe multiple threats
C:\Users\Rick\Downloads\Adobe_Flash_Setup.exe a variant of Win32/InstallCore.OZ potentially unwanted application
C:\Users\Rick\Downloads\reginout_setup.exe multiple threats

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

C:\Program Files (x86)\pcreginst\file_to_run.exe
C:\Program Files (x86)\runonce\user\updater.exe

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

slower than normal startups, and the search engine had switched in my Firefox browser

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015
Ran by Rick at 2015-01-31 22:02:32 Run:2
Running from C:\Users\Rick\Contacts\Desktop
Loaded Profiles: Rick (Available profiles: Rick)
Boot Mode: Normal

Content of fixlist:
C:\Program Files (x86)\pcreginst\file_to_run.exe
C:\Program Files (x86)\runonce\user\updater.exe

C:\Program Files (x86)\pcreginst\file_to_run.exe => Moved successfully.
C:\Program Files (x86)\runonce\user\updater.exe => Moved successfully.
C:\Users\Rick\Downloads\Adobe_Flash_Setup.exe => Moved successfully.
C:\Users\Rick\Downloads\reginout_setup.exe => Moved successfully.
EmptyTemp: => Removed 381.3 MB temporary data.

The system needed a reboot.

==== End of Fixlog 22:03:16 ====

No to your last question. Seems to boot up just fine and after reading the copy of my note, (LOL) search engine is okay.

Good deal!

http://i.imgur.com/AFZxnZc.jpg DelFix

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix)
or from here http://www.bleepingcomputer.com/download/delfix/ and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools
Create registry backup
Purge system restore

Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7, MVP
How Malware Spreads - How did I get infected? (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7, MVP
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams, MVP
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes, MVP
How to backup and restore your data using Cobian Backup (http://www.bleepingcomputer.com/tutorials/backup-and-restore-data-with-cobian-backup/) by YourHighness
Slow Computer/browser? It May Not Be Malware (http://www.bleepingcomputer.com/forums/t/87058/slow-computerbrowser-check-here-first;-it-may-not-be-malware/) by quietman7, MVP

The following programmes come highly recommended in the security community.

http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpgAdBlock (https://adblockplus.org/en/firefox) is a browser add-on that blocks annoying banners, pop-ups and video ads.
http://i.imgur.com/E8I37RF.pngCryptoPrevent (https://www.foolishit.com/) places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
http://i.imgur.com/EG85Vjt.png Malwarebytes Anti-Exploit (https://www.malwarebytes.org/antiexploit/) (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpgMalwarebytes Anti-Malware Premium (https://www.malwarebytes.org/) (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xjv4nhMJ.png.pagespeed.ic.A5YbWn1eDO.png NoScript (http://noscript.net/) is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
http://i.imgur.com/3O8r9Uq.png (http://www.sandboxie.com/) Sandboxie (http://www.sandboxie.com/) isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/DgW1XL2.png.pagespeed.ce.v1OlJl_ZAS.png Secuina PSI (http://secunia.com/vulnerability_scanning/personal/) will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xj1OLIec.png.pagespeed.ic.k6hhwopU0q.jpg SpywareBlaster (https://www.brightfort.com/spywareblaster.html) is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xJEP5iWI.png.pagespeed.ic.4tmM1lM7DQ.pngWeb of Trust (https://www.mywot.com/) (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

Good deal!

http://i.imgur.com/AFZxnZc.jpg DelFix

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix)
or from here http://www.bleepingcomputer.com/download/delfix/ and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools
Create registry backup
Purge system restore

Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7, MVP
How Malware Spreads - How did I get infected? (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7, MVP
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams, MVP
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes, MVP
How to backup and restore your data using Cobian Backup (http://www.bleepingcomputer.com/tutorials/backup-and-restore-data-with-cobian-backup/) by YourHighness
Slow Computer/browser? It May Not Be Malware (http://www.bleepingcomputer.com/forums/t/87058/slow-computerbrowser-check-here-first;-it-may-not-be-malware/) by quietman7, MVP

The following programmes come highly recommended in the security community.

http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpgAdBlock (https://adblockplus.org/en/firefox) is a browser add-on that blocks annoying banners, pop-ups and video ads.
http://i.imgur.com/E8I37RF.pngCryptoPrevent (https://www.foolishit.com/) places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
http://i.imgur.com/EG85Vjt.png Malwarebytes Anti-Exploit (https://www.malwarebytes.org/antiexploit/) (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpgMalwarebytes Anti-Malware Premium (https://www.malwarebytes.org/) (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xjv4nhMJ.png.pagespeed.ic.A5YbWn1eDO.png NoScript (http://noscript.net/) is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
http://i.imgur.com/3O8r9Uq.png (http://www.sandboxie.com/) Sandboxie (http://www.sandboxie.com/) isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/DgW1XL2.png.pagespeed.ce.v1OlJl_ZAS.png Secuina PSI (http://secunia.com/vulnerability_scanning/personal/) will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xj1OLIec.png.pagespeed.ic.k6hhwopU0q.jpg SpywareBlaster (https://www.brightfort.com/spywareblaster.html) is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xJEP5iWI.png.pagespeed.ic.4tmM1lM7DQ.pngWeb of Trust (https://www.mywot.com/) (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

Just out of curiosity, why did it remove a downloaded report from my company?

# DelFix v10.8 - Logfile created 01/02/2015 at 16:05:31
# Updated 29/07/2014 by Xplode
# Username : Rick - RICK-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\Rick\Contacts\Desktop\FRST-OlderVersion
Deleted : C:\Users\Rick\Contacts\Desktop\AdwCleaner.exe
Deleted : C:\Users\Rick\Contacts\Desktop\aswMBR.txt
Deleted : C:\Users\Rick\Contacts\Desktop\Fixlog.txt
Deleted : C:\Users\Rick\Contacts\Desktop\FRST64.exe
Deleted : C:\Users\Rick\Contacts\Desktop\MBR.dat
Deleted : C:\Users\Rick\Downloads\Addition.txt
Deleted : C:\Users\Rick\Downloads\AdwCleaner(1).exe
Deleted : C:\Users\Rick\Downloads\AdwCleaner(2).exe
Deleted : C:\Users\Rick\Downloads\AdwCleaner(3).exe
Deleted : C:\Users\Rick\Downloads\AdwCleaner.exe
Deleted : C:\Users\Rick\Downloads\aswMBR.exe
Deleted : C:\Users\Rick\Downloads\esetsmartinstaller_enu.exe
Deleted : C:\Users\Rick\Downloads\FRST.txt
Deleted : C:\Users\Rick\Downloads\FSS.exe
Deleted : C:\Users\Rick\Downloads\FSS.txt
Deleted : C:\Users\Rick\Downloads\Report_from_J._M._Teague_Engineering_PLLC.pdf
Deleted : C:\Users\Rick\Downloads\SecurityCheck.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #739 [Windows Update | 01/17/2015 08:00:25]
Deleted : RP #740 [Windows Update | 01/22/2015 21:52:56]
Deleted : RP #741 [Windows Update | 01/25/2015 23:29:09]
Deleted : RP #742 [Installed SpyHunter | 01/27/2015 01:58:58]
Deleted : RP #743 [Removed SpyHunter | 01/27/2015 04:53:30]
Deleted : RP #744 [Removed SpyHunter | 01/27/2015 04:55:55]
Deleted : RP #745 [Removed SpyHunter | 01/27/2015 04:57:07]
Deleted : RP #746 [Windows Update | 01/29/2015 07:27:51]

New restore point created !

########## - EOF - ##########

wow, I do not know.
Wonder if it had anything to do with the name of the file?

I'll try to contact the developer of the tool to report the bug.

Sorry, I have not heard back from the developer.

Is there anything else I can help you with?

Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.