Completed above steps. Requested logs will be pasted at the bottom of this post.
After completing previous steps, I ran Malwarebytes' Anti-Malware. It showed, then removed 3 threats it listed as trojans.
I then ran Microsoft Security Essentials. It opened and ran successfully. THANK YOU! Updated MSE and ran a complete scan. It came up with a few (less than 5) threats, which were then removed. Restarted Windows and re-ran Malwarebytes. Results were clean. Downloaded and Ran: Spybot-seek and destroy. results were clean.
I will re-run Security Check after posting this, and paste the updated checkup.txt.
:::Fixlog:::
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-08-2014
Ran by David Hurley at 2014-08-15 07:39:43 Run:1
Running from C:\Users\David Hurley\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
HKLM-x32\...\Run: [{0d46ffa6-6f79-f5af-81ac-2441fc43a414}] => C:\ProgramData\Microsoft\{0d46ffa6-6f79-f5af-81ac-2441fc43a414}\{0d46ffa6-6f79-f5af-81ac-2441fc43a414}.exe [255524 2014-08-11] ()
HKLM Group Policy restriction on software: C:\Program Files\Windows Defender <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\Microsoft Security Client <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware <====== ATTENTION
HKLM\...\Policies\Explorer\Run: [{0d46ffa6-6f79-f5af-81ac-2441fc43a414}] => C:\ProgramData\Microsoft\{0d46ffa6-6f79-f5af-81ac-2441fc43a414}\{0d46ffa6-6f79-f5af-81ac-2441fc43a414}.exe [255524 2014-08-11] ( ())
SearchScopes: HKLM-x32 - {8fe8d013-c3fd-4802-af48-79274e9f969e} URL =
http://search.mywebs...r={searchTerms}SearchScopes: HKCU - {8fe8d013-c3fd-4802-af48-79274e9f969e} URL =
http://search.mywebs...r={searchTerms}FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
S3 cpusat64; \??\C:\Program Files (x86)\Intel Corporation\Power Thermal Utility for SandyBridgeE Processor Rev 2.0\cpusat64.sys [X]
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X]
C:\Users\David Hurley\AppData\Local\Temp\sbllerf.dll
C:\Users\David Hurley\AppData\Local\Temp\_isED4F.exe
C:\ProgramData\Microsoft\{0d46ffa6-6f79-f5af-81ac-2441fc43a414}\{0d46ffa6-6f79-f5af-81ac-2441fc43a414}.exe
End
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\{0d46ffa6-6f79-f5af-81ac-2441fc43a414} => value deleted successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\{0d46ffa6-6f79-f5af-81ac-2441fc43a414} => value deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{8fe8d013-c3fd-4802-af48-79274e9f969e}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{8fe8d013-c3fd-4802-af48-79274e9f969e}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8fe8d013-c3fd-4802-af48-79274e9f969e}" => Key deleted successfully.
"HKCR\CLSID\{8fe8d013-c3fd-4802-af48-79274e9f969e}" => Key not found.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"FF Plugin: @microsoft.com/GENUINE -> disabled No File" => not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File not found.
cpusat64 => Service deleted successfully.
cpuz135 => Service deleted successfully.
C:\Users\David Hurley\AppData\Local\Temp\sbllerf.dll => Moved successfully.
C:\Users\David Hurley\AppData\Local\Temp\_isED4F.exe => Moved successfully.
Could not move "C:\ProgramData\Microsoft\{0d46ffa6-6f79-f5af-81ac-2441fc43a414}\{0d46ffa6-6f79-f5af-81ac-2441fc43a414}.exe" => Scheduled to move on reboot.
=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-08-15 07:41:26)<=
C:\ProgramData\Microsoft\{0d46ffa6-6f79-f5af-81ac-2441fc43a414}\{0d46ffa6-6f79-f5af-81ac-2441fc43a414}.exe => Is moved successfully.
==== End of Fixlog ====
:::Checkup.txt:::
Results of screen317's Security Check version 0.99.87
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````Windows Security Center service is not running! This report may not be accurate!Windows Firewall Enabled!
Microsoft Security Essentials
(On Access scanning
disabled!)
Error obtaining update status for antivirus!`````````Anti-malware/Other Utilities Check:`````````````````Process Check: objlist.exe by Laurent````````Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````Total Fragmentation on Drive C: 18%
Defragment your hard drive soon! (Do NOT defrag if SSD!)````````````````````End of Log``````````````````````