I have my farber report ready for some help

Status
Not open for further replies.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\YouTube Accelerator\ipc.dll.vir a variant of Win32/SBWatchman.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\YouTube Accelerator\xmldb.dll.vir a variant of Win32/SBWatchman.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe.vir a variant of Win32/SBWatchman.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\windows\System32\drivers\webinstrNewH.sys.vir Win64/Adware.AddLyrics.E application
C:\FRST\Quarantine\C\Users\chuckanddona\AppData\Local\Temp\tu17p84.exe.xBAD a variant of Win32/SBWatchman.D potentially unwanted application
C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\hstart.exe a variant of Win32/HiddenStart.A potentially unsafe application
C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\Backup\DBRUpdate\hstart.exe.bak a variant of Win32/HiddenStart.A potentially unsafe application
C:\Users\chuckanddona\AppData\Local\nsl2CE3.tmp Win32/VOPackage.BC potentially unwanted application
C:\Users\chuckanddona\AppData\Local\Installer\Installyta_28091\ytai.exe a variant of Win32/SpeedBit.C potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\1zn72r9z.default-1414768909077\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\4of6rxmx.default-1416144829817\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\d1s22mmj.default-1414766510453\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\ec5k3vxz.default-1415286555222\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\eda6lsm0.default-1414089807006\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\g52sn5dt.default-1416052739247\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\h8tl7ddn.default-1416066202480\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\llg2redq.default\extensions\64ffxtbr@TelevisionFanatic.com\plugins\NativeMessagingDispatcher.dll Win32/Toolbar.MyWebSearch.AO potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\llg2redq.default\extensions\KUS@VbT0.org\content\bg.js JS/Kryptik.ATB trojan
C:\Users\chuckanddona\Desktop\Old Firefox Data\nfpxpldb.default-1416668850496\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\q0wider0.default-1415364493713\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\rg31oeqe.default-1415302381270\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Desktop\Old Firefox Data\st93mqs1.default-1416873200958\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application
C:\Users\chuckanddona\Downloads\WeatherBugSetup(1).msi a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
C:\Users\chuckanddona\Downloads\WeatherBugSetup.msi a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
C:\Windows.old\Users\chuckanddona\AppData\Local\Temp\ApnStub.exe a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\Windows.old\Users\chuckanddona\AppData\Local\Temp\Offercast2802_WBV5_.exe a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application
 
Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

start
CloseProcesses:
C:\Users\chuckanddona\AppData\Local\nsl2CE3.tmp
C:\Users\chuckanddona\AppData\Local\Installer\Installyta_28091\ytai.exe
C:\Users\chuckanddona\Desktop\Old Firefox Data\1zn72r9z.default-1414768909077\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\4of6rxmx.default-1416144829817\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\d1s22mmj.default-1414766510453\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\ec5k3vxz.default-1415286555222\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\eda6lsm0.default-1414089807006\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\g52sn5dt.default-1416052739247\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\h8tl7ddn.default-1416066202480\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\llg2redq.default\extensions\64ffxtbr@TelevisionFanatic.com\plugins\NativeMessagingDispatcher.dll
C:\Users\chuckanddona\Desktop\Old Firefox Data\llg2redq.default\extensions\KUS@VbT0.org\content\bg.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\nfpxpldb.default-1416668850496\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\q0wider0.default-1415364493713\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\rg31oeqe.default-1415302381270\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\st93mqs1.default-1416873200958\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Downloads\WeatherBugSetup(1).msi
C:\Users\chuckanddona\Downloads\WeatherBugSetup.msi
C:\Windows.old\Users\chuckanddona\AppData\Local\Temp\ApnStub.exe
C:\Windows.old\Users\chuckanddona\AppData\Local\Temp\Offercast2802_WBV5_.exe
EmptyTemp:
End

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


How is the computer now?
 
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-01-2015 03
Ran by chuckanddona at 2015-01-05 08:58:59 Run:2
Running from C:\Users\chuckanddona\Desktop
Loaded Profile: chuckanddona (Available profiles: chuckanddona & Administrator)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CloseProcesses:
C:\Users\chuckanddona\AppData\Local\nsl2CE3.tmp
C:\Users\chuckanddona\AppData\Local\Installer\Installyta_28091\ytai.exe
C:\Users\chuckanddona\Desktop\Old Firefox Data\1zn72r9z.default-1414768909077\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\4of6rxmx.default-1416144829817\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\d1s22mmj.default-1414766510453\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\ec5k3vxz.default-1415286555222\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\eda6lsm0.default-1414089807006\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\g52sn5dt.default-1416052739247\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\h8tl7ddn.default-1416066202480\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\llg2redq.default\extensions\64ffxtbr@TelevisionFanatic.com\plugins\NativeMessagingDispatcher.dll
C:\Users\chuckanddona\Desktop\Old Firefox Data\llg2redq.default\extensions\KUS@VbT0.org\content\bg.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\nfpxpldb.default-1416668850496\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\q0wider0.default-1415364493713\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\rg31oeqe.default-1415302381270\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Desktop\Old Firefox Data\st93mqs1.default-1416873200958\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js
C:\Users\chuckanddona\Downloads\WeatherBugSetup(1).msi
C:\Users\chuckanddona\Downloads\WeatherBugSetup.msi
C:\Windows.old\Users\chuckanddona\AppData\Local\Temp\ApnStub.exe
C:\Windows.old\Users\chuckanddona\AppData\Local\Temp\Offercast2802_WBV5_.exe
EmptyTemp:
End
*****************

Processes closed successfully.
C:\Users\chuckanddona\AppData\Local\nsl2CE3.tmp => Moved successfully.
C:\Users\chuckanddona\AppData\Local\Installer\Installyta_28091\ytai.exe => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\1zn72r9z.default-1414768909077\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\4of6rxmx.default-1416144829817\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\d1s22mmj.default-1414766510453\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\ec5k3vxz.default-1415286555222\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\eda6lsm0.default-1414089807006\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\g52sn5dt.default-1416052739247\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\h8tl7ddn.default-1416066202480\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\llg2redq.default\extensions\64ffxtbr@TelevisionFanatic.com\plugins\NativeMessagingDispatcher.dll => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\llg2redq.default\extensions\KUS@VbT0.org\content\bg.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\nfpxpldb.default-1416668850496\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\q0wider0.default-1415364493713\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\rg31oeqe.default-1415302381270\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Desktop\Old Firefox Data\st93mqs1.default-1416873200958\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js => Moved successfully.
C:\Users\chuckanddona\Downloads\WeatherBugSetup(1).msi => Moved successfully.
C:\Users\chuckanddona\Downloads\WeatherBugSetup.msi => Moved successfully.
C:\Windows.old\Users\chuckanddona\AppData\Local\Temp\ApnStub.exe => Moved successfully.
C:\Windows.old\Users\chuckanddona\AppData\Local\Temp\Offercast2802_WBV5_.exe => Moved successfully.
EmptyTemp: => Removed 185.7 MB temporary data.


The system needed a reboot.

==== End of Fixlog 08:59:14 ====
 
Seems okay... not sure if it is related but I had to reboot because my key board wouldnt function? Wouldnt let me type anything?
 
Also please download Windows Repair (all in one) from here

step-4-tab.jpg

Install the program then go to step 4 and create a new system restore point and new registry backup.

Go to Step 2 and allow it to run CheckDisk by clicking on Do It button:
p22001645.gif




NEXT
On the the Start Repairs tab => Click the Start
start-repairs-tab.jpg



Please ensure that ONLY items seen in the image below are ticked as indicated (they're all checked by default):
p22001647.gif


Click on box next to the Restart System when Finished. Then click on Start.
 
At this time Avast is wrong, temporarily disable it so it can be downloaded to desktop.
 
I am on a different machine. Now when I boot my computer, there is no pointer on the screen and I also get a message that Microsoft does not recognize my USB mouse! I am able to use my arrow buttons to open Firefox but after that I cannot make any moves at all? Is there anything I can do? something in safe mode or anything?
 
Let's try some troubleshooting tips

pressed the "hide the pointer" key (fn F7), next to the "two screens" key (fn + F6). After press "fn" + F7 again.
http://answers.microsoft.com/en-us/...h-screen/1d5491f9-dbac-4d8d-ac34-a1b1d2d9aee9

could try this

Goto Start > Control Panel > Mouse
Click on the Pointer Options tab
Ensure that the checkbox for Show location of pointer when I press the CTRL key is checked
Click on the Apply button


Now when you press the CTRL key, you will be able to find the exact location of your mouse

http://www.tomshardware.com/forum/43107-63-missing-mouse-pointer


Try to boot into safemode with networking, if it works then go to the below microsoft link

http://support.microsoft.com/kb/871233
Unplug the USB device, and then plug the device back into the computer or hub. If your computer still does not recognize the device, go to the next

Method 1: Initiate recognition of the USB device by using Device Manager
To initiate recognition of the USB device by using Device Manager, follow these steps:

Click Start, click Run, type Devmgmt.msc, and then click OK. The Device Manager window opens.
Click to select your computer as the location for the scan.
On the Action menu, click Scan for hardware changes.

Close the Device Manager window.

If this method resolves the issue, you are finished.

If this method does not resolve the issue, go to method 2.
Method 2: Disable power management of the USB hub
Note If you perform the following procedure, you may also reduce the battery life on a portable computer.

Use this method if method 1 does not work. To disable power management of the USB hub, follow these steps:

Click Start, click Run, type Devmgmt.msc, and then click OK. The Device Manager window opens.
Expand Universal Serial Bus controllers.
Right-click a USB Root Hub in the list, and then click Properties. The USB Root Hub Properties dialog box is displayed.
Click the Power Management tab.
Click to clear the Allow the computer to turn off this device to save power check box, and then click OK.
Repeat steps 3 through 6 for each USB Root Hub in the list.
On the Action menu, click Scan for hardware changes.
Close the Device Manager window.
 
I have tried using fn f7 key, doesn't seem to do anything. I can get into the control panel and to the mouse using only the arrow keys but from there it won't let me do anything with arrow keys alone and there is still no pointer. I am trying to go into safe mode, I shut down unplugged and took out battery. When I rebooted it skipped right passed the page that has the f2 and f12 option for a boot into safe mode. I am going to give this another try. When I get in safe mode not sure exactly which option I am going for? Thanks for all the advice and time!
 
I am in boot mode now. Says boot mode is set to uefi secure boot on. Other options diagnostic or enter set up or peripheral device settings or change boot mode?
 
change boot mode?
if anything I would see if safemode with networking is available?
if not don't boot into uefi secure boot.

ANother way to get into safemode, then into safe mode with networking is

hold the power button down on the computer and count to 5, then wait a minute, then power back on.
Sometimes this brings up the option for safemode with networking.
 
Not sure what I did exactly, have been rebooting and trying to get into safe mode, turns out it is different with windows 8. Anyway, all of a sudden it booted with the pointer and full function of my touch pad. I had been using the USB mouse as a work around for my touch pad not working properly. I am now hoping that whatever the problem with my touch pad was fixed with whatever you did with me. Its too soon to tell if this is permanent or if it will glitch again with a re boot or just stop working for whatever reason. I am going to play around and hopefully report back that all seems fine. Is there anything you want me to do? Run another scan or anything to see if all is well?
 
Spoke too soon. Was surfing the web and the pointer just disappeared. Tried plugging in USB mouse. Says the last USB device you connected to this computer malfunctioned, and windows does not recognize it. I am going to keep trying to get in under safe mode again. Will keep checking here to see if any of this new info has given us a new course. If I have progress will let you know. :(
 
Not sure what I did exactly, have been rebooting and trying to get into safe mode, turns out it is different with windows 8. Anyway, all of a sudden it booted with the pointer and full function of my touch pad. I had been using the USB mouse as a work around for my touch pad not working properly. I am now hoping that whatever the problem with my touch pad was fixed with whatever you did with me. Its too soon to tell if this is permanent or if it will glitch again with a re boot or just stop working for whatever reason. I am going to play around and hopefully report back that all seems fine. Is there anything you want me to do? Run another scan or anything to see if all is well?

I have no idea what you had attempted when it rebooted so I'm not sure what to say.
I had been using the USB mouse as a work around for my touch pad not working properly.
I have a feeling it has something to do with this.
Could be drivers needed to be updated or one was corrupt....bad USB port,

We had removed all the malware and were at a point to remove the tools with quarantine folders. After that I would post preventive tips.
 
Status
Not open for further replies.
Back
Top