Welcome.
Running from E:\Documents and Settings\Roger\
Desktop\SaferNetworking
Is this where you downloaded and run FRST?(Farbar Recovery Scan Tool)
It really needs to be on desktop.
Please go to your
Desktop\SaferNetworking downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.
Please open
Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as
fixlist.txt
NOTE. It's important that both files,
FRST/FRST64 and
fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)
start
CreateRestorePoint:
CloseProcesses:
HKLM\...\Run: [] => [X]
HKLM\...\Run: [YTDownloader] => "E:\Program Files\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-1644491937-813497703-682003330-1003\...\Run: [YTDownloader] => "E:\Program Files\YTDownloader\YTDownloader.exe" /boot
CHR HKU\S-1-5-21-1644491937-813497703-682003330-1003\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
URLSearchHook: [S-1-5-21-1644491937-813497703-682003330-500] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\S-1-5-21-1644491937-813497703-682003330-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
S2 BrsHelper; E:\PROGRA~1\YTDOWN~1\BROWSE~2.EXE [X]
U2 CertPropSvc; no ImagePath
S4 IntelIde; no ImagePath
S3 MFE_RR; \??\E:\DOCUME~1\Roger\LOCALS~1\Temp\mfe_rr.sys [X]
S1 sbmntr; \??\E:\PROGRA~1\YTDOWN~1\sbmntr.sys [X]
2015-09-24 21:44 - 2015-09-28 10:23 - 00000358 _____ E:\WINDOWS\Tasks\YTDownloader.job
2015-09-24 21:44 - 2015-09-28 10:23 - 00000348 _____ E:\WINDOWS\Tasks\YTDownloaderUpd.job
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> E:\Documents and Settings\Roger\Application Data\Dropbox\bin\Dropbox.exe /autoplay => No File
Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{08613A51-6E3E-43CC-9ECF-DD58B5837341}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{153EDC41-A2CC-4BEB-9EC8-008242389E50}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{188028B8-D91D-4BE2-BABA-68E32BDE4420}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{28E74F15-18C2-465E-B545-6CC738121C68}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{2BF6042B-B9B1-46D9-A3F8-9C987FADD4C6}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{40A222E2-93B1-45F9-9B07-0D1160A31A6C}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{6325A84C-E746-4007-A9C5-E4C1A50ED61F}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{92B0265C-B929-4D42-BA54-75AA39C99198}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{9BCA87A0-5B8F-4500-A5AF-EA1279714FDF}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{BB17DE65-B548-48C2-AC73-1FD1996C7261}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{C77D3EEF-FDCA-4D37-B0D2-5FF650E07825}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}\InprocServer32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{EA70EB31-CBAD-4862-AFDA-DCFCC32722ED}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{EC9100F8-5918-4F1B-9CC1-4D34A64E0FE0}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
CustomCLSID: HKU\S-1-5-21-1644491937-813497703-682003330-1003_Classes\CLSID\{F1A1ABE3-F454-4DD9-B520-01F2EEC5F0DD}\localserver32 -> "E:\Documents and Settings\Roger\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelper.exe" (the data entry has 10 more characters).
Task: E:\WINDOWS\Tasks\SpeedyPC Pro_sch_55147764-2E24-11E4-A89E-001FD08F1F5B.job => E:\Program Files\SpeedyPC Software\SpeedyPC\SpeedyPC.exe <==== ATTENTION
Task: E:\WINDOWS\Tasks\SpeedyPC Update Version3_triggeronce.job => e:\program files\common files\speedypc software\uus3\SpeedyPC_Update3.exe <==== ATTENTION
Task: E:\WINDOWS\Tasks\YTDownloader.job => E:\Program Files\YTDownloader\YTDownloader.exe <==== ATTENTION
Task: E:\WINDOWS\Tasks\YTDownloaderUpd.job => E:\Program Files\YTDownloader\Updater.exe <==== ATTENTION
CMD: ipconfig /flushdns
EmptyTemp:
End
Open
FRST/FRST64 and press the
> Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
~~~~~~~~~~~~~~~~~~~~~
AdwCleaner
- Please download AdwCleaner and save the file to your Desktop.
- Right-Click AdwCleaner.exe and select Run as administrator to run the programme.
- Follow the prompts.
- Click Scan.
- Upon completion, click Report. A log (AdwCleaner[SX].txt) will open. Briefly check the log for anything you know to be legitimate.
- Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
- Follow the prompts and allow your computer to reboot.
- After rebooting, a log (AdwCleaner[SX].txt) will open. Copy the contents of the log and paste in your next reply.
-- File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please download
Junkware Removal Tool
or from here
http://downloads.malwarebytes.org/file/jrt
to your desktop.
- Shut down your protection software now to avoid potential conflicts.
- Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
- The tool will open and start scanning your system.
- Please be patient as this can take a while to complete depending on your system's specifications.
- On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
- Post the contents of JRT.txt into your next message.
~~~`
please post
Fixlog.txt
AdwCleaner[CX].txt
JRT.txt