Hi capnkrunch,
sorry about the logs I will paste future ones to the end of my posts
step 1 I have enabled resident shield although it looked active already. When I deactivated it I got a warning about no antivirus. I re enabled it
Step 2 complete
Step 3 complete
Step 4 complete log at end of post
Step 5 do not recognise Shockwave, I don't remember installing it
instructions were clear and easy to follow
I believe I have enabled AVG Resident Shield
I will not be using registry cleaners in the future
after selecting Normal Boot and removing the programs it took a very long time to complete the restart on both occasions
# AdwCleaner v5.029 - Logfile created 14/01/2016 at 01:17:26
# Updated 11/01/2016 by Xplode
# Database : 2016-01-12.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : stephen - MAGGIE
# Running from : C:\Users\stephen\Desktop\adwcleaner_5.029.exe
# Option : Scan
# Support :
http://toolslib.net/forum***** [ Services ] *****
Service Found : vToolbarUpdater40.2.4
***** [ Folders ] *****
Folder Found : C:\Program Files (x86)\myfree codec
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files\Common Files\AVG Secure Search
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\AVG Security Toolbar
Folder Found : C:\Users\Public\Documents\Guid
Folder Found : C:\Users\stephen\AppData\Roaming\WTools
Folder Found : C:\Users\stephen\AppData\Roaming\RPEng
Folder Found : C:\Users\stephen\AppData\Roaming\RunDir
***** [ Files ] *****
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
File Found : C:\Users\stephen\AppData\Roaming\Mozilla\Firefox\Profiles\iqn7ummx.default-1449965770414\Extensions\Avg@toolbar.xpi
File Found : C:\WINDOWS\SysNative\drivers\netmon_wfp.sys
File Found : C:\WINDOWS\SysWOW64\lavasofttcpservice.dll
***** [ DLL ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
Key Found : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKCU\Software\WEBAPP
Key Found : HKCU\Software\Microsoft\Tinstalls
Key Found : HKLM\SOFTWARE\NtSvcHandler
Key Found : [x64] HKLM\SOFTWARE\WebBar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CB7EA2A8-C0FB-4CF7-96AF-EA19779A4793}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CB7EA2A8-C0FB-4CF7-96AF-EA19779A4793}
***** [ Web browsers ] *****
[C:\Users\stephen\AppData\Roaming\Mozilla\Firefox\Profiles\iqn7ummx.default-1449965770414\prefs.js] [Preference] Found : user_pref("browser.safebrowsing.appRepURL", "hxxps://sb-ssl.google.com/safebrowsing/clientreport/download?key=%GOOGLE_API_KEY%");
[C:\Users\maggi_000\AppData\Roaming\Mozilla\Firefox\Profiles\c4sleunq.default-1443162559677\prefs.js] [Preference] Found : user_pref("browser.search.hiddenOneOffs", "Yahoo.co.uk,Bing,Amazon.co.uk,Chambers (UK),DuckDuckGo,eBay.co.uk,Twitter,Wikipedia (en),YourSearchResults");
[C:\Users\cmcga_000\AppData\Roaming\Mozilla\Firefox\Profiles\xdbengq.default\prefs.js] [Preference] Found : user_pref("browser.search.hiddenOneOffs", "Yahoo,Bing,Amazon.com,DuckDuckGo,eBay,Twitter,Wikipedia (en),YourSearchResults");
[C:\Users\cmcga_000\AppData\Roaming\Mozilla\Firefox\Profiles\xdbengq.default\prefs.js] [Preference] Found : user_pref("extensions.Rh8zKb8NHQqON7Ss.scode", "(function(){try{if(window.location.href.indexOf(\"rjYFrTg6qHkHrTr5rdYGpjaGqTC\")>-1){return;}}catch(e){}try{var d=[[\"cryptogmail.com\",\"bancdebinary.c[...]
[C:\Users\cmcga_000\AppData\Roaming\Mozilla\Firefox\Profiles\xdbengq.default\prefs.js] [Preference] Found : user_pref("extensions.ZRmQXG9lKe7tmzii.scode", "(function(){try{if(window.location.href.indexOf(\"rjYFrTg6qHkHrTr5rdYGpjaGqTC\")>-1){return;}}catch(e){}try{var d=[[\"cryptogmail.com\",\"bancdebinary.c[...]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [5778 bytes] ##########