Hi OCD,
Here's the Security check:
Results of screen317's Security Check version 0.99.86
Windows Vista Service Pack 1 x86
(UAC is disabled!)
Out of date service pack!!
Internet Explorer 7
Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
HijackThis 2.0.2
AVG PC Tuneup 2011
Java 7 Update 45
Java(TM) SE Runtime Environment 6
Java version out of Date!
Adobe Flash Player 14.0.0.145
Adobe Reader 8
Adobe Reader out of Date!
Mozilla Firefox 18.0
Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 5 %
Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
And here's the Farbar scan:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:23-07-2014 01
Ran by Holly Chapman (administrator) on THE-BEAST on 23-07-2014 22:16:17
Running from C:\Users\Holly Chapman\Downloads
Platform: Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 7
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgwdsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(iolo technologies, LLC) C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
(Eastman Kodak Company) C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
(Eastman Kodak Company) C:\Program Files\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe
(IDT, Inc.) C:\Windows\System32\stacsv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgnsx.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgchsvx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgcsrvx.exe
(Uniblue Systems Limited) C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe
(RealNetworks, Inc.) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(CyberLink Corp.) C:\Program Files\Dell\MediaDirect\PCMService.exe
(Creative Technology Ltd.) C:\Windows\OEM02Mon.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(iolo technologies, LLC) C:\Program Files\iolo\System Mechanic\ioloGovernor.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Spigot, Inc.) C:\Users\Holly Chapman\AppData\Roaming\Search Protection\SearchProtection.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Avanquest Software ) C:\Program Files\Digital Line Detect\DLG.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
() C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winamp.exe
==================== Registry (Whitelisted) ==================
HKLM\...\InprocServer32: [Default-wbemess] ATTENTION! ====> ZeroAccess?
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\.DEFAULT\...\Run: [msnmsgr] => C:\Program Files\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Run: [DriverScanner] => C:\Program Files\Uniblue\DriverScanner\launcher.exe [338296 2011-05-16] (Uniblue Systems Limited)
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Run: [Xvid] => C:\Program Files\Xvid\CheckUpdate.exe [8192 2011-01-17] ()
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Run: [VeohPlugin] => C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe [3558136 2009-02-24] (Veoh Networks)
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Run: [uTorrent] => C:\Users\Holly Chapman\AppData\Roaming\uTorrent\uTorrent.exe [1329744 2014-07-21] (BitTorrent Inc.)
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Run: [SearchProtection] => C:\Users\Holly Chapman\AppData\Roaming\Search Protection\SearchProtection.EXE [873832 2014-07-17] (Spigot, Inc.)
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-18] (Microsoft Corporation)
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Policies\system: [HideLegacyLogonScripts] 0
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Policies\system: [HideLogoffScripts] 0
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Policies\system: [RunLogonScriptSync] 1
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Policies\system: [RunStartupScriptSync] 0
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\Policies\system: [HideStartupScripts] 0
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\MountPoints2: {1e30d2f0-96c3-11dd-83db-001e4cdc4ef0} - F:\setupSNK.exe
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\MountPoints2: {bea08218-13f7-11df-a7dd-001e4cdc4ef0} - G:\LaunchU3.exe -a
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\MountPoints2: {c03f2a25-14b1-11df-bab4-001e4cdc4ef0} - wd_windows_tools\setup.exe
HKU\S-1-5-21-1025113376-2626304966-3518894149-1000\...\MountPoints2: {cbf9d7f6-b1bb-11dd-9902-001e4cdc4ef0} - F:\setupSNK.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\Users\Holly Chapman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
ShortcutTarget: ERUNT AutoBackup.lnk -> C:\Program Files\ERUNT\AUTOBACK.EXE ()
BootExecute:
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://uk.search.yahoo.com/?type=282369&fr=spigot-yhp-ie
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=2080117
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=2080117
URLSearchHook: HKCU - (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File
SearchScopes: HKLM - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
SearchScopes: HKLM - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms}
SearchScopes: HKCU - DefaultScope {FD36FFE4-BFE5-485E-8954-BF293DDC790E} URL = https://uk.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=282369&p={searchTerms}
SearchScopes: HKCU - {105E99FF-8B9A-4492-B155-06194B9056D2} URL = http://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
SearchScopes: HKCU - {C0197584-7E91-4454-8177-07E01E8098A6} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
SearchScopes: HKCU - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://search.avg.com/route/?d=4d4acdad&v=6.11.25.1&i=26&tp=chrome&q={searchTerms}&lng={language}&iy=&ychte=us
SearchScopes: HKCU - {DCDBBF03-BC10-457D-911F-EFB0321D22BE} URL = ${SRCH_SCP_URL}
SearchScopes: HKCU - {E72EEF90-4393-4B8E-9DCF-9FDFDB659A30} URL = http://internetsearchservice.com/search?q={searchTerms}
SearchScopes: HKCU - {FD36FFE4-BFE5-485E-8954-BF293DDC790E} URL = https://uk.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=282369&p={searchTerms}
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: No Name -> {A3BC75A2-1F87-4686-AA43-5347D756017C} -> No File
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
BHO: No Name -> {FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C} -> No File
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll ()
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [147456] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\Profiles\7lqvfta1.default
FF NewTab: hxxp://search.conduit.com/?gd=&ctid=CT3324790&octid=EB_ORIGINAL_CTID&ISID=MBAEA6744-D857-4CE3-8A2A-712EF60CAE3F&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SP7D9A60B4-EE90-48AB-ABC1-F7FAB62519F6
FF SearchEngineOrder.1: Search the web (Softonic)
FF Homepage: google.co.uk
FF Keyword.URL:
https://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=282369&p=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.46 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.46 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.46 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @veoh.com/VeohTVPlugin - C:\Program Files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll (Veoh Networks )
FF Plugin: @veoh.com/VeohWebPlayer - C:\Program Files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll (Veoh)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF user.js: detected! => C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\Profiles\7lqvfta1.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdnu.dll (AOL LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdnupdater2.dll (AOL LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\Profiles\7lqvfta1.default\searchplugins\softonic.xml
FF SearchPlugin: C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\Profiles\7lqvfta1.default\searchplugins\yahoo_ff.xml
FF Extension: No Name - C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions [2011-08-15]
FF Extension: No Name - C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\profiles\extensions\searchplugins [2014-07-21]
FF Extension: 2YourFace - C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\profiles\extensions\support@2yourface.com [2011-08-15]
FF Extension: vis - C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\Profiles\7lqvfta1.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM [2014-01-15]
FF Extension: Zotero Word for Windows Integration - C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\Profiles\7lqvfta1.default\Extensions\zoteroWinWordIntegration@zotero.org [2014-04-30]
FF Extension: Ghostery - C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\Profiles\7lqvfta1.default\Extensions\firefox@ghostery.com.xpi [2013-08-18]
FF Extension: MEGA - C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\Profiles\7lqvfta1.default\Extensions\firefox@mega.co.nz.xpi [2013-12-29]
FF Extension: Zotero - C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\Profiles\7lqvfta1.default\Extensions\zotero@chnm.gmu.edu.xpi [2013-08-12]
FF Extension: Adblock Plus - C:\Users\Holly Chapman\AppData\Roaming\Mozilla\Firefox\Profiles\7lqvfta1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-06]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\sotfone-tracker@sotfone.ru [2013-11-07]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-11-07]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-11-07]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-09-03]
FF HKLM\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] - C:\Program Files\AVG\AVG10\Firefox4
FF Extension: AVG Safe Search - C:\Program Files\AVG\AVG10\Firefox4 [2011-07-07]
FF HKLM\...\Firefox\Extensions: [crossriderapp435@crossrider.com] - C:\ProgramData\CodecCheck\firefox
FF Extension: Premiumplay Codec-C - C:\ProgramData\CodecCheck\firefox [2011-08-15]
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-06-04]
FF HKCU\...\Firefox\Extensions: [web@veoh.com] - C:\Program Files\Veoh Networks\VeohWebPlayer\FFVideoFinder
FF Extension: Veoh Web Player Video Finder - C:\Program Files\Veoh Networks\VeohWebPlayer\FFVideoFinder [2008-11-26]
FF HKCU\...\Firefox\Extensions: [offerboxffx@offerbox.com] - C:\Users\Holly Chapman\AppData\Roaming\OfferBox\offerboxffx@offerbox.com
FF Extension: OfferBox - C:\Users\Holly Chapman\AppData\Roaming\OfferBox\offerboxffx@offerbox.com [2010-06-28]
Chrome:
=======
CHR HomePage: hxxp://search.softonic.com/MOY00002/tb_v1?SearchSource=48&cc=&mi=74965616000000000000001cbf915686&toi=16085
CHR RestoreOnStartup: "hxxp://search.softonic.com/MOY00002/tb_v1?SearchSource=48&cc=&mi=74965616000000000000001cbf915686&toi=16085"
CHR StartupUrls: "hxxp://search.softonic.com/MOY00002/tb_v1?SearchSource=48&cc=&mi=74965616000000000000001cbf915686&toi=16085"
CHR DefaultSearchProvider: Search the web (Softonic)
CHR DefaultSearchURL: http://search.softonic.com/MOY00002/tb_v1?q={searchTerms}&SearchSource=49&cc=&mi=74965616000000000000001cbf915686&toi=16085
CHR Extension: (No Name) - C:\Users\Holly Chapman\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab [2014-01-15]
CHR Extension: (AVG Safe Search) - C:\Users\Holly Chapman\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla [2011-07-10]
CHR Extension: (No Name) - C:\Users\Holly Chapman\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho [2012-03-24]
CHR Extension: (No Name) - C:\Users\Holly Chapman\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2011-01-24]
CHR HKLM\...\Chrome\Extension: [jmfkcklnlgedgbglfkkgedjfmejoahla] - C:\Program Files\AVG\AVG10\Chrome\safesearch.crx [2011-09-09]
CHR HKLM\...\Chrome\Extension: [jpnbdefcbnoefmmcpelplabbkfmfhlho] - C:\ProgramData\CodecCheck\chrome\codec_check.crx [2011-08-15]
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [7391072 2012-01-31] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG10\avgwdsvc.exe [269520 2011-02-08] (AVG Technologies CZ, s.r.o.)
R2 Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [229376 2007-07-24] (Apple Inc.) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 ioloSystemService; C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe [1168960 2013-12-03] (iolo technologies, LLC)
R2 Kodak AiO Network Discovery Service; C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe [395200 2012-10-19] (Eastman Kodak Company)
R2 Kodak AiO Status Monitor Service; C:\Program Files\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe [779200 2012-10-15] (Eastman Kodak Company)
S3 RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [880640 2006-11-05] (Sonic Solutions) [File not signed]
S2 RoxWatch9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [159744 2006-11-05] (Sonic Solutions) [File not signed]
S4 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3291008 2013-08-14] (Skype Technologies S.A.)
S4 stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [73728 2006-09-14] (MicroVision Development, Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
R3 AVGIDSDriver; C:\Windows\System32\DRIVERS\AVGIDSDriver.Sys [134480 2011-05-27] (AVG Technologies CZ, s.r.o. )
R0 AVGIDSEH; C:\Windows\System32\DRIVERS\AVGIDSEH.Sys [22992 2011-02-22] (AVG Technologies CZ, s.r.o. )
R3 AVGIDSFilter; C:\Windows\System32\DRIVERS\AVGIDSFilter.Sys [24144 2011-02-10] (AVG Technologies CZ, s.r.o. )
R3 AVGIDSShim; C:\Windows\System32\DRIVERS\AVGIDSShim.Sys [28624 2011-02-10] (AVG Technologies CZ, s.r.o. )
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [255968 2012-11-12] (AVG Technologies CZ, s.r.o.)
R1 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [34896 2011-03-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [32592 2011-03-16] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [297168 2011-04-05] (AVG Technologies CZ, s.r.o.)
R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [26248 2013-03-18] (EldoS Corporation)
R3 OXSDIDRV_x32; C:\Windows\System32\DRIVERS\OXSDIDRV_x32.sys [52656 2009-09-28] ()
S3 OXUDIDRV; C:\Windows\system32\Drivers\OXUDIDRV_X32.sys [24880 2010-05-25] ()
R2 PDFsFilter; C:\Windows\System32\DRIVERS\PDFsFilter.sys [68464 2013-03-18] (Raxco Software, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-18] (Microsoft Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 mcdbus; system32\DRIVERS\mcdbus.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 uafilter; System32\DRIVERS\uafilter.sys [X]
S3 USBAAPL; System32\Drivers\usbaapl.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-23 22:16 - 2014-07-23 22:16 - 00023551 _____ () C:\Users\Holly Chapman\Downloads\FRST.txt
2014-07-23 22:14 - 2014-07-23 22:14 - 01082368 _____ (Farbar) C:\Users\Holly Chapman\Downloads\FRST.exe
2014-07-22 21:17 - 2014-07-22 21:17 - 00854390 _____ () C:\Users\Holly Chapman\Downloads\SecurityCheck.exe
2014-07-22 17:39 - 2014-07-22 18:00 - 00000000 ____D () C:\Windows\pss
2014-07-21 18:14 - 2014-07-21 18:14 - 00000000 ____D () C:\Users\Holly Chapman\AppData\Roaming\Search Protection
2014-07-20 16:32 - 2014-07-20 16:38 - 365230920 _____ (Microsoft Corporation) C:\Users\Holly Chapman\Downloads\Windows6.0-KB948465-X86.exe
2014-07-15 17:21 - 2014-07-15 17:21 - 00000000 ____D () C:\ProgramData\Auslogics
2014-07-15 17:20 - 2014-07-15 17:20 - 00000924 _____ () C:\Users\Holly Chapman\Desktop\Auslogics DiskDefrag.lnk
2014-07-15 17:20 - 2014-07-15 17:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
2014-07-15 17:20 - 2014-07-15 17:20 - 00000000 ____D () C:\Program Files\Auslogics
2014-07-06 10:38 - 2014-07-06 10:38 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-THE-BEAST--(32-bit).dat
2014-07-06 10:36 - 2014-07-06 10:36 - 00000000 ____D () C:\RegBackup
2014-07-06 10:34 - 2014-07-12 13:15 - 00001914 _____ () C:\Users\Holly Chapman\Desktop\Tweaking.com - Windows Repair (All in One).lnk
2014-07-06 10:34 - 2014-07-06 10:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-06 10:33 - 2014-07-06 10:33 - 00000000 ____D () C:\Program Files\Tweaking.com
2014-06-28 20:39 - 2014-06-28 20:43 - 00000000 ____D () C:\b8b2c6ec9b2f9a90d7
2014-06-27 19:50 - 2014-07-23 22:17 - 00000000 ____D () C:\FRST
2014-06-26 17:58 - 2014-06-26 17:58 - 00000676 _____ () C:\Users\Holly Chapman\Desktop\ERUNT.lnk
2014-06-26 17:58 - 2014-06-26 17:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
==================== One Month Modified Files and Folders =======
2014-07-23 22:19 - 2014-07-23 22:16 - 00023551 _____ () C:\Users\Holly Chapman\Downloads\FRST.txt
2014-07-23 22:17 - 2014-06-27 19:50 - 00000000 ____D () C:\FRST
2014-07-23 22:14 - 2014-07-23 22:14 - 01082368 _____ (Farbar) C:\Users\Holly Chapman\Downloads\FRST.exe
2014-07-23 21:39 - 2008-01-16 23:18 - 01712956 _____ () C:\Windows\WindowsUpdate.log
2014-07-23 21:38 - 2013-08-04 19:42 - 00000000 ____D () C:\Users\Holly Chapman\AppData\Roaming\uTorrent
2014-07-23 21:36 - 2011-10-24 20:57 - 00000344 _____ () C:\Windows\Tasks\DriverScanner.job
2014-07-23 21:35 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-23 21:35 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-23 21:34 - 2013-01-16 18:12 - 00000000 ____D () C:\ProgramData\Kodak
2014-07-23 21:33 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-23 21:33 - 2006-11-02 13:37 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-07-23 18:17 - 2008-01-16 23:19 - 00000012 _____ () C:\Windows\bthservsdp.dat
2014-07-23 18:17 - 2006-11-02 14:01 - 00032644 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-23 17:28 - 2012-04-30 19:04 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-23 16:58 - 2012-04-26 19:09 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-07-23 16:58 - 2008-01-16 23:54 - 00142876 _____ () C:\Windows\PFRO.log
2014-07-22 22:36 - 2013-11-07 11:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-07-22 21:17 - 2014-07-22 21:17 - 00854390 _____ () C:\Users\Holly Chapman\Downloads\SecurityCheck.exe
2014-07-22 18:00 - 2014-07-22 17:39 - 00000000 ____D () C:\Windows\pss
2014-07-22 17:11 - 2011-02-03 16:40 - 00000000 ____D () C:\Windows\system32\Drivers\AVG
2014-07-21 18:14 - 2014-07-21 18:14 - 00000000 ____D () C:\Users\Holly Chapman\AppData\Roaming\Search Protection
2014-07-21 18:13 - 2013-09-05 14:21 - 00000788 _____ () C:\Users\Holly Chapman\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-07-20 20:58 - 2009-03-16 21:42 - 00000000 ____D () C:\Users\Holly Chapman\AppData\Roaming\vlc
2014-07-20 17:53 - 2010-12-04 12:27 - 00000490 ____H () C:\Windows\Tasks\Norton Security Scan for Holly Chapman.job
2014-07-20 16:38 - 2014-07-20 16:32 - 365230920 _____ (Microsoft Corporation) C:\Users\Holly Chapman\Downloads\Windows6.0-KB948465-X86.exe
2014-07-20 16:33 - 2013-10-26 18:06 - 00000000 ____D () C:\Users\Holly Chapman\Desktop\Philosophy
2014-07-15 17:21 - 2014-07-15 17:21 - 00000000 ____D () C:\ProgramData\Auslogics
2014-07-15 17:20 - 2014-07-15 17:20 - 00000924 _____ () C:\Users\Holly Chapman\Desktop\Auslogics DiskDefrag.lnk
2014-07-15 17:20 - 2014-07-15 17:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
2014-07-15 17:20 - 2014-07-15 17:20 - 00000000 ____D () C:\Program Files\Auslogics
2014-07-14 19:52 - 2014-04-24 15:22 - 00000000 ____D () C:\Program Files\MyPC Backup
2014-07-12 14:09 - 2011-01-07 14:02 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-07-12 13:15 - 2014-07-06 10:34 - 00001914 _____ () C:\Users\Holly Chapman\Desktop\Tweaking.com - Windows Repair (All in One).lnk
2014-07-10 16:31 - 2012-04-30 19:04 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-10 16:31 - 2011-12-13 19:31 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-10 16:05 - 2008-01-21 12:40 - 00000000 ____D () C:\Program Files\Windows Live
2014-07-07 19:31 - 2006-11-02 11:23 - 00000240 _____ () C:\Windows\win.ini
2014-07-07 19:28 - 2013-02-18 21:07 - 00000000 ___RD () C:\Program Files\Skype
2014-07-07 19:28 - 2013-02-18 21:07 - 00000000 ____D () C:\ProgramData\Skype
2014-07-07 19:23 - 2006-11-02 13:42 - 00000000 ____D () C:\Windows\WindowsMobile
2014-07-06 18:59 - 2011-06-29 19:30 - 00000000 ____D () C:\a29765fcbd92a1918a2ed2
2014-07-06 12:44 - 2008-01-21 12:32 - 00085416 _____ () C:\Users\Holly Chapman\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-06 11:17 - 2006-11-02 13:47 - 00332584 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-06 11:08 - 2006-11-02 11:33 - 00707392 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-06 10:38 - 2014-07-06 10:38 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-THE-BEAST--(32-bit).dat
2014-07-06 10:36 - 2014-07-06 10:36 - 00000000 ____D () C:\RegBackup
2014-07-06 10:34 - 2014-07-06 10:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-06 10:33 - 2014-07-06 10:33 - 00000000 ____D () C:\Program Files\Tweaking.com
2014-06-28 20:43 - 2014-06-28 20:39 - 00000000 ____D () C:\b8b2c6ec9b2f9a90d7
2014-06-26 17:59 - 2008-07-05 18:40 - 00000000 ____D () C:\Windows\erdnt
2014-06-26 17:58 - 2014-06-26 17:58 - 00000676 _____ () C:\Users\Holly Chapman\Desktop\ERUNT.lnk
2014-06-26 17:58 - 2014-06-26 17:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
2014-06-26 17:58 - 2011-01-02 20:45 - 00000000 ____D () C:\Program Files\ERUNT
2014-06-24 17:24 - 2008-03-11 17:04 - 00006540 _____ () C:\Users\Holly Chapman\AppData\Local\d3d9caps.dat
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-23 21:38
==================== End Of Log ============================