This thread's last reply is from March 21, 2018, 5:53 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Gary R
Looking over your logs, I'll be back once I've looked them over.
reddog1992000
It is much faster at startup. What should I tell her about using for antivirus software? Do you have a preference?
Fix result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018
Ran by [removed] (19-03-2018 21:53:48) Run:2
Running from C:\Users\[removed]\Downloads
[removed]
Boot Mode: Normal
==============================================
fixlist content:
*****************
CreateRestorePoint:
SearchScopes: HKU\.DEFAULT -> DefaultScope {2f23ab71-4ac6-41f2-a955-ea576e553146} URL =
SearchScopes: HKU\S-1-5-21-1580677906-789884366-343230679-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1580677906-789884366-343230679-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
Toolbar: HKLM-x32 - iYogiPMToolbar - {CF729B85-4F13-45E7-A1EF-75A32EDBD532} - C:\Program Files (x86)\iYogi\iYogiPasswordManager\iYogiPMToolbar.dll No File
Toolbar: HKU\S-1-5-21-1580677906-789884366-343230679-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\iYogi\iYogiPasswordManager\iYogiPassMgr.xpi => not found
CHR HKLM-x32\...\Chrome\Extension: [fpeifmajolhnfocdndkhkpbdiaohpnmg] - C:\Program Files (x86)\iYogi\iYogiPasswordManager\ChromeExtension\ChromeToolBar.crx <not found>
S3 scan; C:\Program Files (x86)\iYogi\TechGenie\scan.dll [X] <==== ATTENTION
2018-03-19 10:20 - 2015-03-02 13:26 - 000000000 ____D C:\Program Files (x86)\TechGenie
2018-03-19 10:20 - 2014-08-14 19:28 - 000000000 ____D C:\Program Files (x86)\iYogi Support Dock
2015-06-25 07:53 - 2015-06-25 07:53 - 000026936 _____ (TuneUp Software) C:\Users\Terri\AppData\Local\Temp\DseShExt-x64.dll
2015-06-25 07:53 - 2015-06-25 07:53 - 000028984 _____ (TuneUp Software) C:\Users\Terri\AppData\Local\Temp\DseShExt-x86.dll
2015-06-25 07:53 - 2015-06-25 07:53 - 000032568 _____ (TuneUp Software) C:\Users\Terri\AppData\Local\Temp\SDShelEx-win32.dll
2015-06-25 07:53 - 2015-06-25 07:53 - 000032056 _____ (TuneUp Software) C:\Users\Terri\AppData\Local\Temp\SDShelEx-x64.dll
2018-03-19 10:10 - 2012-03-09 02:57 - 001682432 _____ (iYogi Inc) C:\Users\Terri\AppData\Local\Temp\uninst000.exe
2015-05-20 14:06 - 2013-01-14 09:34 - 000007680 _____ () C:\Users\Terri\AppData\Local\Z@!-2a809d76-88be-40fd-9c2f-7bee87f7c434.tmp
2015-05-20 14:06 - 2013-01-14 09:34 - 000007168 _____ () C:\Users\Terri\AppData\Local\Z@S!-e299fa99-8280-4e84-b0e0-eb18fdd0b8a0.tmp
Task: {08CCDD46-CF49-4EF3-913D-2BB7686910BB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {0BC9BB65-94FF-4F2F-B2ED-2FEBC5977F2E} - System32\Tasks\TweakBit\PCSpeedUp\Start PCSpeedUp ?n logon => C:\Program Files (x86)\TweakBit\PCSpeedUp\PCSpeedUp.exe [2018-01-11] (TweakBit) <==== ATTENTION
Task: {248143D8-7A4E-40B7-AD1F-574BC97B50C5} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {2AD822BA-8A77-4176-B125-62FBCC0CF9EE} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {2E73D1A2-E7F8-48E8-9549-F87F63A76A2D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {36E57232-1B61-4D11-803A-25A45464CAD2} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {440CE6DF-561A-401F-991F-476367205404} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {47240613-99BF-4652-8890-929296A4E99F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {8D340956-A06E-46A1-AE5C-4F4ECF069894} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {A191CEC6-88FE-4615-9A7F-086801D83407} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {A8E7AC82-1018-4527-B623-E060D2BDF1FE} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {BD9D7621-8E92-4682-A91F-C5B5A975C7D5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {C0DC343E-7DBA-4AD9-8B02-C4FCEEEFA943} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
HKLM\...\StartupApproved\StartupFolder: => "Microsoft Office.lnk"
HKLM\...\StartupApproved\StartupFolder: => "TechGenie.lnk"
HKLM\...\StartupApproved\StartupFolder: => "WinZip Preloader.lnk"
HKLM\...\StartupApproved\StartupFolder: => "Update Notifier.lnk"
HKLM\...\StartupApproved\Run32: => "iYogi Support Dock"
HKLM\...\StartupApproved\Run32: => "TechGenieRealTime"
HKLM\...\StartupApproved\Run32: => "AntivirusUpdateApp"
HKLM\...\StartupApproved\Run32: => "InboxAce EPM Support"
HKLM\...\StartupApproved\Run32: => "DivXMediaServer"
HKU\S-1-5-21-1580677906-789884366-343230679-1001\...\StartupApproved\Run: => "OneDrive"
EmptyTemp:
Hosts:
CMD: ipconfig /flushdns
*****************
Restore point was successfully created.
"HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
"HKU\S-1-5-21-1580677906-789884366-343230679-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => removed successfully
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
"HKU\S-1-5-21-1580677906-789884366-343230679-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => removed successfully
HKLM\Software\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{CF729B85-4F13-45E7-A1EF-75A32EDBD532}" => removed successfully
"HKLM\Software\Wow6432Node\Classes\CLSID\{CF729B85-4F13-45E7-A1EF-75A32EDBD532}" => removed successfully
"HKU\S-1-5-21-1580677906-789884366-343230679-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => removed successfully
HKLM\Software\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => not found
"HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\[removed]" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fpeifmajolhnfocdndkhkpbdiaohpnmg" => removed successfully
"HKLM\System\CurrentControlSet\Services\scan" => removed successfully
scan => service removed successfully
C:\Program Files (x86)\TechGenie => moved successfully
C:\Program Files (x86)\iYogi Support Dock => moved successfully
C:\Users\Terri\AppData\Local\Temp\DseShExt-x64.dll => moved successfully
C:\Users\Terri\AppData\Local\Temp\DseShExt-x86.dll => moved successfully
C:\Users\Terri\AppData\Local\Temp\SDShelEx-win32.dll => moved successfully
C:\Users\Terri\AppData\Local\Temp\SDShelEx-x64.dll => moved successfully
C:\Users\Terri\AppData\Local\Temp\uninst000.exe => moved successfully
C:\Users\Terri\AppData\Local\Z@!-2a809d76-88be-40fd-9c2f-7bee87f7c434.tmp => moved successfully
C:\Users\Terri\AppData\Local\Z@S!-e299fa99-8280-4e84-b0e0-eb18fdd0b8a0.tmp => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{08CCDD46-CF49-4EF3-913D-2BB7686910BB}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{08CCDD46-CF49-4EF3-913D-2BB7686910BB}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0BC9BB65-94FF-4F2F-B2ED-2FEBC5977F2E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BC9BB65-94FF-4F2F-B2ED-2FEBC5977F2E}" => removed successfully
Could not move "C:\WINDOWS\System32\Tasks\TweakBit\PCSpeedUp\Start PCSpeedUp ?n logon" => Scheduled to move on reboot.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TweakBit\PCSpeedUp\Start PCSpeedUp ?n logon => could not remove. Access Denied.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{248143D8-7A4E-40B7-AD1F-574BC97B50C5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{248143D8-7A4E-40B7-AD1F-574BC97B50C5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2AD822BA-8A77-4176-B125-62FBCC0CF9EE}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AD822BA-8A77-4176-B125-62FBCC0CF9EE}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2E73D1A2-E7F8-48E8-9549-F87F63A76A2D}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2E73D1A2-E7F8-48E8-9549-F87F63A76A2D}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{36E57232-1B61-4D11-803A-25A45464CAD2}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36E57232-1B61-4D11-803A-25A45464CAD2}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{440CE6DF-561A-401F-991F-476367205404}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{440CE6DF-561A-401F-991F-476367205404}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47240613-99BF-4652-8890-929296A4E99F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47240613-99BF-4652-8890-929296A4E99F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8D340956-A06E-46A1-AE5C-4F4ECF069894}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D340956-A06E-46A1-AE5C-4F4ECF069894}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A191CEC6-88FE-4615-9A7F-086801D83407}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A191CEC6-88FE-4615-9A7F-086801D83407}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A8E7AC82-1018-4527-B623-E060D2BDF1FE}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8E7AC82-1018-4527-B623-E060D2BDF1FE}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD9D7621-8E92-4682-A91F-C5B5A975C7D5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD9D7621-8E92-4682-A91F-C5B5A975C7D5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C0DC343E-7DBA-4AD9-8B02-C4FCEEEFA943}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0DC343E-7DBA-4AD9-8B02-C4FCEEEFA943}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\Microsoft Office.lnk" => removed successfully
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TechGenie.lnk" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\TechGenie.lnk" => removed successfully
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\WinZip Preloader.lnk" => removed successfully
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Notifier.lnk" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\Update Notifier.lnk" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\iYogi Support Dock" => removed successfully
"HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\iYogi Support Dock" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\TechGenieRealTime" => removed successfully
"HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\TechGenieRealTime" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\AntivirusUpdateApp" => removed successfully
"HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AntivirusUpdateApp" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\InboxAce EPM Support" => removed successfully
"HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\InboxAce EPM Support" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\DivXMediaServer" => removed successfully
"HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\DivXMediaServer" => not found
"HKU\S-1-5-21-1580677906-789884366-343230679-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\OneDrive" => removed successfully
"HKU\S-1-5-21-1580677906-789884366-343230679-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\OneDrive" => not found
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 6053888 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 48814906 B
Java, Flash, Steam htmlcache => 3895 B
Windows/system/drivers => 435605 B
Edge => 7995076 B
Chrome => 84586374 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 7859 B
LocalService => 18010 B
NetworkService => 56976 B
Terri => 13253852 B
RecycleBin => 45275 B
EmptyTemp: => 153.8 MB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 19-03-2018 21:57:55)
C:\WINDOWS\System32\Tasks\TweakBit\PCSpeedUp\Start PCSpeedUp ?n logon => Could not move
Result of scheduled keys to remove after reboot:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TweakBit\PCSpeedUp\Start PCSpeedUp ?n logon => could not remove. Access Denied.
==== End of Fixlog 21:57:55 ====
reddog1992000
Thank you for that. Are we pretty much finished up then?
Gary R
Unless you've got any further problems, I'm finished.
I don't see any signs of infection in the logs you've supplied, and the symptoms you described do not lead me to believe your machine is infected, however if you wish we can run an online scan to make sure.
The choice is up to you.