Hi bobbyscot,
Sorry for the delay.
Ooops. I meant to provide the instructions for you to change the download default location for IE and Firefox. Do you know how to do that? If not, just let me know and I'll provide instructions for you.
Didn't mean to post the instructions for Google Chrome (which is not installed on your computer). Firefox is installed, though, and it would be best if you leave it installed even though you don't use it. There may come a time when you need a second, back up browser, and it will be there. It's not hurting anything being there.
This is a longer post than I had expected, so please read all the way through. As I pointed out before, if you have any questions what so ever, please ask.
I see you have
360 Total Security by Qihoo installed as your resident anti virus program. Personally, I would uninstall this AV product and install a more trust worthy AV software. You can read more about why I wouldn't let that software touch my system
here.
It appears that you have downloaded a few other programs trying to fix your problems yourself.
Clean Master
Should I Remove It
The above 2 programs are very shady. We call them snake oil.
They are system optimizers that can cause more harm than good and should be uninstalled.
Ccleaner is also installed. Though it is a good temp file cleaner, please don't use the registry cleaner that is included. Modifying registry keys incorrectly can cause Windows instability, or make Windows unbootable. No registry cleaner is completely safe and the potential is ever present to cause more problems than they claim to fix.
If you would like to uninstall Ccleaner, a good safe temp file cleaner to replace it with would be
TFC-Temporary File (TFC) Cleaner by OldTimer.
To uninstall the above programs, please click on your
Start > Control Panel > Programs and Features, look for those 2 programs, right click and uninstall.
You also have
µTorrent installed which is a
P2P program. I must warn you that this type of program is of the highest nature that infections are invited into your Computer. I suggest that you remove it as well. Though the programs themselves are not malicious, the chance of downloading a malicious file is like playing russian roullette. Any file could be the one that will turn your computer into a very expensive door stop.
P2P Programs can invite spyware, viruses, Trojan horses, or worms into your computer. When the files are downloaded, your computer becomes infected. If you share these files with others, their computer becomes infected as well. You also invite the possibilities of others stealing your personal information such as passwords, online banking accounts, personal files, etc.
Once you uninstall the 3 above programs, please go to the following locations and delete the
folder associated with them:
C:\Program Files (x86)\
Reason
Next:
Were you able to move FRST64.exe to your desktop? I need you to save the following as
fxilist.txt in the same location or the fix will not work.
I don't see any serious infection on your system. Did the other forum help ypou remove anything? Please provide a link to that other forum in your next post so I can what they did.
Let's remove the residual files I did find on your system.
Please do the following:
- Open notepad (Start > type notepad into Start Search > chose notepad from list.
- Please copy the entire contents of the code box below from start to end.
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
- Save it to the same directory as frst64.exe as fixlist.txt.
Code:
start
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4215804292-628602006-1330011759-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4215804292-628602006-1330011759-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4215804292-628602006-1330011759-1000 -> {EB4CD3B2-2900-4FB9-9A42-56DF1566A752} URL =
SearchScopes: HKU\S-1-5-21-4215804292-628602006-1330011759-1000 -> {F129081D-9B7A-45B8-B5F9-E42FF30508CD} URL =
FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\w4dp2k90.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-01-28] ()
S4 cmcore; c:\program files (x86)\cmcm\Clean Master\cmcore.exe [315240 2015-01-24] (Kingsoft Corporation)
S3 ksapi64; C:\Windows\system32\drivers\ksapi64.sys [56680 2015-01-24] (Kingsoft Corporation)
S4 cpuz134; \??\C:\Users\Robert\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S4 IpInIp; system32\DRIVERS\ipinip.sys [X]
S4 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20081126.003\ENG64.SYS [X]
S4 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20081126.003\EX64.SYS [X]
S4 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S4 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S4 SRTSP; \??\C:\Windows\system32\drivers\NISx64\1000000.07D\SRTSP64.SYS [X]
S4 SRTSPX; \??\C:\Windows\system32\drivers\NISx64\1000000.07D\SRTSPX64.SYS [X]
2015-04-04 18:30 - 2015-04-04 18:30 - 02178048 _____ (Reason Software Company Inc.) C:\Users\Robert\ShouldIRemoveIt_Setup.exe
2015-04-04 18:30 - 2015-04-04 18:30 - 00001070 _____ () C:\Users\Robert\Desktop\Should I Remove It.lnk
2015-04-04 18:30 - 2015-04-04 18:30 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin
2015-04-04 18:30 - 2015-04-04 18:30 - 00000000 ____D () C:\Program Files (x86)\Reason
C:\Users\Robert\disk-defrag-setup.exe
C:\Users\Robert\FRST64.exe
C:\Users\Robert\Intel Driver Update Utility Installer.exe
C:\Users\Robert\Nero_DiscSpeed_3p.exe
C:\Users\Robert\setup.exe
C:\Users\Robert\ShouldIRemoveIt_Setup.exe
C:\Users\Robert\vlc-2.2.0-win32.exe
C:\Users\Robert\vlc-2.2.0-win64.exe
C:\Users\Robert\AppData\Local\Temp\SSEInternetUpdaterX.exe
EmptyTemp:
Hosts:
end
NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system
- Run frst.exe (on 64bit, run frst64.exe) and press the Fix button just once and wait.
- The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.
Logs I need to see in your next reply:
Fixlog.txt
Thank you,
Donna