This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adknowledge Malware Removal?

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :regfind
    BrowserSeek
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt




Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.
SystemLook 30.07.11 by jpshortstuff Log created at 22:53 on 01/07/2013 by David Administrator - Elevation successful ========== regfind ========== Searching for "BrowserSeek" No data found. -= EOF =-
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-07-2013
Ran by [removed] (administrator) on 01-07-2013 23:07:12
Running from C:\Documents and Settings\[removed]\Desktop
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(QUALCOMM, Inc.) C:\QUALCOMM\QDLService\QDLService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastUI.exe
(Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Intel Corporation) C:\WINDOWS\system32\igfxext.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Realtek Semiconductor Corp.) C:\DOCUME~1\David\LOCALS~1\Temp\RtkBtMnt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [182808 2008-09-12] (Intel Corporation)
HKLM\…\Run: [RTHDCPL] RTHDCPL.EXE [x]
HKLM\…\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe [53248 2006-07-17] (Realtek Semiconductor Corp.)
HKLM\…\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe [817672 2009-02-19] (Dritek System Inc.)
HKLM\…\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled [294544 2008-10-02] (Carbonite, Inc.)
HKLM\…\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 [208952 2008-04-14] (Microsoft Corporation)
HKLM\…\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC [59392 2008-04-14] ()
HKLM\…\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC [455168 2008-04-14] (Microsoft Corporation)
HKLM\…\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName [455168 2008-04-14] (Microsoft Corporation)
HKLM\…\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1422632 2009-01-22] (Synaptics Incorporated)
HKLM\…\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM\…\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4858968 2013-05-09] (AVAST Software)
HKLM\…\RunOnce: [A0] cmd /c "C:\Documents and Settings\David\Desktop\mbar-1.06.0.1004\mbar\mbar.exe" /r /s [769096 2013-06-28] (Malwarebytes Corporation)
HKCU\…\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [1695232 2008-04-14] (Microsoft Corporation)
HKCU\…\Policies\system: [disableregistrytools] 0
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler: ipp - No CLSID Value -
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchURL: (Conduit) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR DefaultSuggestURL: (Conduit) - "suggest_url": ""
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\25.0.1364.152\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\25.0.1364.152\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\25.0.1364.152\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Extension: (Google Drive) - C:\Documents and Settings\David\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Documents and Settings\David\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Documents and Settings\David\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Gmail) - C:\Documents and Settings\David\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 QDLService; C:\QUALCOMM\QDLService\QDLService.exe [345336 2008-11-10] (QUALCOMM, Inc.)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [237568 2008-11-27] (Acer Incorporated)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
S3 gusvc; "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" [x]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [x]

==================== Drivers (Whitelisted) ====================

R3 AR5416; C:\Windows\System32\DRIVERS\athw.sys [1346464 2008-12-30] (Atheros Communications, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software)
R1 AswRdr; C:\Windows\System32\Drivers\AswRdr.sys [49760 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-06-27] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-06-27] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [175176 2013-06-27] ()
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-14] (Windows ® Server 2003 DDK provider)
R3 L1e; C:\Windows\System32\DRIVERS\l1e51x86.sys [38400 2009-02-23] (Atheros Communications, Inc.)
R3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [35144 2013-06-28] ()
S3 NABTSFEC; C:\Windows\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-13] (Microsoft Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 QCFilterGAD; C:\Windows\System32\DRIVERS\qcfilterGAD.sys [5248 2008-11-10] (QUALCOMM Incorporated)
S3 qcusbnetGAD; C:\Windows\System32\DRIVERS\qcusbnetGAD.sys [115200 2008-11-10] (QUALCOMM Incorporated)
S3 qcusbserGAD; C:\Windows\System32\DRIVERS\qcusbserGAD.sys [103680 2008-11-10] (QUALCOMM Incorporated)
S3 SLIP; C:\Windows\System32\DRIVERS\SLIP.sys [11136 2008-04-13] (Microsoft Corporation)
S3 streamip; C:\Windows\System32\DRIVERS\StreamIP.sys [15232 2008-04-13] (Microsoft Corporation)
S3 WSTCODEC; C:\Windows\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-13] (Microsoft Corporation)
S3 catchme; \??\C:\DOCUME~1\David\LOCALS~1\Temp\catchme.sys [x]
S3 int15.sys; \??\c:\acernb\int15.sys [x]
S3 Rts516xIR; system32\DRIVERS\Rts516xIR.sys [x]
U3 TlntSvr;
S3 USBCCID; system32\DRIVERS\Rts5161ccid.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-01 23:07 - 2013-07-01 23:07 - 00000000 ____D C:\FRST
2013-07-01 23:06 - 2013-07-01 23:06 - 01372429 ____A (Farbar) C:\Documents and Settings\David\Desktop\FRST.exe
2013-07-01 22:52 - 2013-07-01 22:51 - 00139264 ____A C:\Documents and Settings\David\Desktop\SystemLook (1).exe
2013-06-28 17:59 - 2013-06-28 19:17 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2013-06-28 17:58 - 2013-06-28 17:58 - 00035144 ____A C:\Windows\System32\Drivers\mbamchameleon.sys
2013-06-28 17:57 - 2013-06-28 17:57 - 00000000 ____D C:\Documents and Settings\David\Desktop\mbar-1.06.0.1004
2013-06-28 17:56 - 2013-06-28 17:56 - 13399154 ____A C:\Documents and Settings\David\Desktop\mbar-1.06.0.1004.zip
2013-06-27 18:16 - 2013-06-27 18:16 - 00000175 ____A C:\Windows\System32\Drivers\aswVmm.sys.sum
2013-06-26 19:32 - 2013-06-27 18:16 - 00000175 ____A C:\Windows\System32\Drivers\aswSP.sys.sum
2013-06-26 19:32 - 2013-06-27 18:16 - 00000175 ____A C:\Windows\System32\Drivers\aswSnx.sys.sum
2013-06-24 18:05 - 2013-07-01 22:53 - 00000422 ____A C:\Documents and Settings\David\Desktop\SystemLook.txt
2013-06-24 18:04 - 2013-06-24 18:03 - 00139264 ____A C:\Documents and Settings\David\Desktop\SystemLook.exe
2013-06-23 19:28 - 2013-06-23 19:28 - 00000904 ____A C:\AdwCleaner[S2].txt
2013-06-23 19:27 - 2013-06-23 19:27 - 00648201 ____A C:\Documents and Settings\David\Desktop\adwcleaner (1).exe
2013-06-23 19:11 - 2013-06-23 19:12 - 00000856 ____A C:\AdwCleaner[S1].txt
2013-06-23 09:27 - 2013-07-01 22:27 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-21 06:45 - 2013-06-21 20:00 - 00087016 ____A C:\Documents and Settings\David\Desktop\OTL.Txt
2013-06-21 06:34 - 2013-06-21 06:34 - 00602112 ____A (OldTimer Tools) C:\Documents and Settings\David\Desktop\OTL (2).exe
2013-06-20 23:49 - 2013-06-20 23:49 - 00000000 ____D C:\_OTL
2013-06-20 20:33 - 2013-06-20 20:33 - 00000000 ____D C:\Documents and Settings\David\Application Data\Malwarebytes
2013-06-20 20:31 - 2013-06-20 20:31 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-06-20 20:31 - 2013-06-20 20:31 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2013-06-20 20:31 - 2013-04-04 14:50 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-06-20 20:09 - 2013-06-30 20:09 - 00000314 ___AH C:\Windows\Tasks\avast! Emergency Update.job
2013-06-20 20:09 - 2013-06-27 18:16 - 00770344 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2013-06-20 20:09 - 2013-06-27 18:16 - 00369584 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2013-06-20 20:09 - 2013-06-27 18:16 - 00175176 ____A C:\Windows\System32\Drivers\aswVmm.sys
2013-06-20 20:09 - 2013-06-20 20:09 - 00001693 ____A C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
2013-06-20 20:09 - 2013-05-09 01:59 - 00066336 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2013-06-20 20:09 - 2013-05-09 01:59 - 00056080 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2013-06-20 20:09 - 2013-05-09 01:59 - 00049760 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr.sys
2013-06-20 20:09 - 2013-05-09 01:59 - 00049376 ____A C:\Windows\System32\Drivers\aswRvrt.sys
2013-06-20 20:09 - 2013-05-09 01:59 - 00029816 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2013-06-20 20:09 - 2013-05-09 01:58 - 00229648 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
2013-06-20 20:08 - 2013-06-20 20:08 - 00000000 ____D C:\Program Files\AVAST Software
2013-06-20 20:08 - 2013-05-09 01:58 - 00041664 ____A (AVAST Software) C:\Windows\avastSS.scr
2013-06-20 20:07 - 2013-06-20 20:08 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\AVAST Software
2013-06-20 19:33 - 2013-06-20 19:33 - 00001821 ____A C:\DelFix.txt
2013-06-20 19:33 - 2013-06-20 19:33 - 00000000 ____D C:\Windows\ERUNT
2013-06-20 19:30 - 2013-06-20 19:30 - 00000000 ___SD C:\uninstall
2013-06-20 19:19 - 2013-06-20 19:19 - 00001738 ____A C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
2013-06-19 22:15 - 2013-06-19 22:15 - 00000000 ____D C:\Program Files\ESET
2013-06-19 06:40 - 2013-06-19 06:40 - 00000000 RASHD C:\cmdcons
2013-06-19 06:40 - 2013-06-15 23:53 - 00000245 ____A C:\Boot.bak
2013-06-19 06:40 - 2004-08-03 23:00 - 00260272 _RASH C:\cmldr
2013-06-19 06:38 - 2013-06-20 19:30 - 00000000 ____D C:\Windows\erdnt
2013-06-17 06:31 - 2013-06-15 22:59 - 00447129 ___RA C:\Windows\System32\Drivers\etc\hosts.20130617-063107.backup
2013-06-15 22:59 - 2013-05-10 15:41 - 00444734 ___RA C:\Windows\System32\Drivers\etc\hosts.20130615-225902.backup
2013-06-13 06:17 - 2013-06-13 06:17 - 00000000 __HDC C:\Windows\$NtUninstallKB2839229$
2013-06-13 06:12 - 2013-06-13 06:13 - 00011496 ____A C:\Windows\KB2838727-IE8.log
2013-06-12 06:31 - 2013-06-13 06:17 - 00014481 ____A C:\Windows\KB2839229.log
2013-06-08 19:29 - 2013-06-08 19:37 - 00017367 ____A C:\formatter.log

==================== One Month Modified Files and Folders ========

2013-07-01 23:07 - 2013-07-01 23:07 - 00000000 ____D C:\FRST
2013-07-01 23:06 - 2013-07-01 23:06 - 01372429 ____A (Farbar) C:\Documents and Settings\David\Desktop\FRST.exe
2013-07-01 22:53 - 2013-06-24 18:05 - 00000422 ____A C:\Documents and Settings\David\Desktop\SystemLook.txt
2013-07-01 22:51 - 2013-07-01 22:52 - 00139264 ____A C:\Documents and Settings\David\Desktop\SystemLook (1).exe
2013-07-01 22:34 - 2013-03-06 01:24 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-01 22:27 - 2013-06-23 09:27 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-01 18:12 - 2009-02-26 15:54 - 01407596 ____A C:\Windows\WindowsUpdate.log
2013-06-30 20:09 - 2013-06-20 20:09 - 00000314 ___AH C:\Windows\Tasks\avast! Emergency Update.job
2013-06-30 20:03 - 2013-03-12 20:04 - 00000620 ____A C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2013-06-28 19:17 - 2013-06-28 17:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2013-06-28 17:58 - 2013-06-28 17:58 - 00035144 ____A C:\Windows\System32\Drivers\mbamchameleon.sys
2013-06-28 17:57 - 2013-06-28 17:57 - 00000000 ____D C:\Documents and Settings\David\Desktop\mbar-1.06.0.1004
2013-06-28 17:56 - 2013-06-28 17:56 - 13399154 ____A C:\Documents and Settings\David\Desktop\mbar-1.06.0.1004.zip
2013-06-27 20:41 - 2013-05-10 15:06 - 00000000 ____D C:\Documents and Settings\David\Desktop\Originals
2013-06-27 20:41 - 2008-08-03 20:16 - 00000000 ____D C:\VALUEADD
2013-06-27 20:04 - 2013-03-06 01:24 - 00000880 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-27 20:04 - 2013-03-06 00:52 - 00000062 __ASH C:\Documents and Settings\David\Local Settings\desktop.ini
2013-06-27 20:04 - 2009-02-26 15:58 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2013-06-27 20:04 - 2009-02-26 15:58 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2013-06-27 20:04 - 2009-02-26 15:58 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-27 20:04 - 2009-02-26 07:52 - 00000159 ____A C:\Windows\wiadebug.log
2013-06-27 20:04 - 2009-02-26 07:52 - 00000049 ____A C:\Windows\wiaservc.log
2013-06-27 18:16 - 2013-06-27 18:16 - 00000175 ____A C:\Windows\System32\Drivers\aswVmm.sys.sum
2013-06-27 18:16 - 2013-06-26 19:32 - 00000175 ____A C:\Windows\System32\Drivers\aswSP.sys.sum
2013-06-27 18:16 - 2013-06-26 19:32 - 00000175 ____A C:\Windows\System32\Drivers\aswSnx.sys.sum
2013-06-27 18:16 - 2013-06-20 20:09 - 00770344 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2013-06-27 18:16 - 2013-06-20 20:09 - 00369584 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2013-06-27 18:16 - 2013-06-20 20:09 - 00175176 ____A C:\Windows\System32\Drivers\aswVmm.sys
2013-06-25 06:27 - 2009-02-26 15:58 - 00032510 ____A C:\Windows\SchedLgU.Txt
2013-06-24 18:03 - 2013-06-24 18:04 - 00139264 ____A C:\Documents and Settings\David\Desktop\SystemLook.exe
2013-06-23 19:33 - 2009-02-26 07:51 - 00511802 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-23 19:28 - 2013-06-23 19:28 - 00000904 ____A C:\AdwCleaner[S2].txt
2013-06-23 19:28 - 2013-03-12 20:04 - 00131072 ____A C:\Windows\System32\config\SpybotSD.evt
2013-06-23 19:28 - 2013-03-06 00:52 - 00000178 ___SH C:\Documents and Settings\David\ntuser.ini
2013-06-23 19:27 - 2013-06-23 19:27 - 00648201 ____A C:\Documents and Settings\David\Desktop\adwcleaner (1).exe
2013-06-23 19:12 - 2013-06-23 19:11 - 00000856 ____A C:\AdwCleaner[S1].txt
2013-06-23 09:28 - 2013-03-06 00:52 - 00000000 ____D C:\Documents and Settings\David\Application Data\Adobe
2013-06-23 09:28 - 2009-02-26 17:17 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR
2013-06-23 09:28 - 2009-02-26 17:16 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Adobe
2013-06-23 09:27 - 2013-04-07 10:28 - 00000000 ____D C:\Documents and Settings\David\Local Settings\Application Data\Adobe
2013-06-23 09:27 - 2013-03-06 21:32 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-23 09:27 - 2013-03-06 21:32 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-21 20:00 - 2013-06-21 06:45 - 00087016 ____A C:\Documents and Settings\David\Desktop\OTL.Txt
2013-06-21 06:34 - 2013-06-21 06:34 - 00602112 ____A (OldTimer Tools) C:\Documents and Settings\David\Desktop\OTL (2).exe
2013-06-20 23:49 - 2013-06-20 23:49 - 00000000 ____D C:\_OTL
2013-06-20 23:28 - 2013-05-01 18:41 - 00018432 ___AH C:\Documents and Settings\David\Desktop\photothumb.db
2013-06-20 20:33 - 2013-06-20 20:33 - 00000000 ____D C:\Documents and Settings\David\Application Data\Malwarebytes
2013-06-20 20:31 - 2013-06-20 20:31 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-06-20 20:31 - 2013-06-20 20:31 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2013-06-20 20:09 - 2013-06-20 20:09 - 00001693 ____A C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
2013-06-20 20:09 - 2009-02-26 15:56 - 00002577 ____A C:\Windows\System32\CONFIG.NT
2013-06-20 20:09 - 2009-02-26 07:51 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-06-20 20:08 - 2013-06-20 20:08 - 00000000 ____D C:\Program Files\AVAST Software
2013-06-20 20:08 - 2013-06-20 20:07 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\AVAST Software
2013-06-20 19:33 - 2013-06-20 19:33 - 00001821 ____A C:\DelFix.txt
2013-06-20 19:33 - 2013-06-20 19:33 - 00000000 ____D C:\Windows\ERUNT
2013-06-20 19:33 - 2009-02-26 15:54 - 00000000 ____D C:\Windows\System32\Restore
2013-06-20 19:30 - 2013-06-20 19:30 - 00000000 ___SD C:\uninstall
2013-06-20 19:30 - 2013-06-19 06:38 - 00000000 ____D C:\Windows\erdnt
2013-06-20 19:19 - 2013-06-20 19:19 - 00001738 ____A C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
2013-06-20 19:18 - 2009-02-26 17:16 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-06-20 19:18 - 2009-02-26 17:16 - 00000000 ____D C:\Program Files\Adobe
2013-06-19 22:15 - 2013-06-19 22:15 - 00000000 ____D C:\Program Files\ESET
2013-06-19 06:47 - 2009-02-26 15:40 - 00000227 ____A C:\Windows\system.ini
2013-06-19 06:40 - 2013-06-19 06:40 - 00000000 RASHD C:\cmdcons
2013-06-19 06:40 - 2009-02-26 15:43 - 00000355 _RASH C:\boot.ini
2013-06-17 06:32 - 2013-03-12 21:07 - 00002884 ____A C:\Windows\wininit.ini
2013-06-15 23:53 - 2013-06-19 06:40 - 00000245 ____A C:\Boot.bak
2013-06-15 22:59 - 2013-06-17 06:31 - 00447129 ___RA C:\Windows\System32\Drivers\etc\hosts.20130617-063107.backup
2013-06-15 22:51 - 2013-03-12 20:04 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2013-06-13 06:17 - 2013-06-13 06:17 - 00000000 __HDC C:\Windows\$NtUninstallKB2839229$
2013-06-13 06:17 - 2013-06-12 06:31 - 00014481 ____A C:\Windows\KB2839229.log
2013-06-13 06:17 - 2009-02-26 07:51 - 01061167 ____A C:\Windows\FaxSetup.log
2013-06-13 06:17 - 2009-02-26 07:51 - 00404685 ____A C:\Windows\tsoc.log
2013-06-13 06:17 - 2009-02-26 07:51 - 00215538 ____A C:\Windows\ntdtcsetup.log
2013-06-13 06:17 - 2009-02-26 07:51 - 00163314 ____A C:\Windows\iis6.log
2013-06-13 06:17 - 2009-02-26 07:51 - 00057999 ____A C:\Windows\ocmsn.log
2013-06-13 06:17 - 2009-02-26 07:51 - 00052474 ____A C:\Windows\msgsocm.log
2013-06-13 06:17 - 2008-08-03 20:17 - 00000000 ____D C:\i386
2013-06-13 06:13 - 2013-06-13 06:12 - 00011496 ____A C:\Windows\KB2838727-IE8.log
2013-06-13 06:13 - 2013-03-07 07:53 - 00000000 ____D C:\Windows\ie8updates
2013-06-13 06:13 - 2013-03-07 07:44 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-13 06:13 - 2009-02-26 16:03 - 00116840 ____A C:\Windows\updspapi.log
2013-06-13 06:13 - 2009-02-26 07:51 - 00001374 ____A C:\Windows\imsins.BAK
2013-06-08 19:37 - 2013-06-08 19:29 - 00017367 ____A C:\formatter.log

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02-07-2013 Ran by [removed] at 2013-07-01 23:09:01 Running from C:\Documents and Settings\[removed]\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 2007 Microsoft Office Suite Service Pack 1 (SP1) Acer 3G Connection Manager (Version: 1.00.143) Acer eRecovery Management (Version: 4.00.3002) Acer ScreenSaver (Version: 1.03.0216) Acer VCM (Version: 4.00.3004) Acrobat.com (Version: 0.0.0) Acrobat.com (Version: 1.1.377) Adobe AIR (Version: 3.7.0.2090) Adobe Flash Player 10 ActiveX (Version: 10.0.12.36) Adobe Flash Player 11 Plugin (Version: 11.7.700.224) Adobe Reader XI (11.0.03) (Version: 11.0.03) Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (Version: 1.0.0.7) Atheros for Acer Driver v7.6.1.221_Foxconn Installation Program (Version: 7.6.1.221) avast! Free Antivirus (Version: 8.0.1489.0) Carbonite Online Backup Setup (Version: 3.7.0) Choice Guard (Version: 1.2.87.0) Compatibility Pack for the 2007 Office system (Version: 12.0.4518.1014) ESET Online Scanner v3 eSobi v2 (Version: 2.0.3.000223) Google Chrome (Version: 27.0.1453.116) Google Update Helper (Version: 1.3.21.145) Intel® Graphics Media Accelerator Driver Intel® Matrix Storage Manager JMicron Flash Media Controller Driver (Version: 1.00.24.12) Junk Mail filter update (Version: 14.0.8050.1202) Launch Manager (Version: 2.0.01) Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300) Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729) Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft National Language Support Downlevel APIs Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6215.1000) Microsoft Office Home and Student 2007 (Version: 12.0.6215.1000) Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6215.1000) Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6215.1000) Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.4518.1014) Microsoft Office Proof (English) 2007 (Version: 12.0.6213.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6213.1000) Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6213.1000) Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014) Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6215.1000) Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6215.1000) Microsoft Office Suite Activation Assistant (Version: 2.9) Microsoft Office Word MUI (English) 2007 (Version: 12.0.6215.1000) Microsoft Software Update for Web Folders (English) 12 (Version: 12.0.6215.1000) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Works (Version: 9.7.0621) MSVCRT (Version: 14.0.1468.721) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) PhotoScape Qualcomm Gobi Driver Package (Version: 1.0.14) Qualcomm Gobi Images (Version: 1.0.19) Realtek High Definition Audio Driver (Version: 5.10.0.5780) SDFormatter (Version: 3.1.0) Segoe UI (Version: 14.0.4327.805) Spybot - Search & Destroy (Version: 2.0.12) Synaptics Pointing Device Driver (Version: 12.2.0.0) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Office 2007 (KB946691) Update for Windows Internet Explorer 8 (KB2598845) (Version: 1) Update for Windows XP (KB2345886) (Version: 1) Update for Windows XP (KB2467659) (Version: 1) Update for Windows XP (KB2661254-v2) (Version: 2) Update for Windows XP (KB2736233) (Version: 1) Update for Windows XP (KB2749655) (Version: 1) Update for Windows XP (KB898461) (Version: 1) Update for Windows XP (KB951072-v2) (Version: 2) Update for Windows XP (KB951978) (Version: 1) Update for Windows XP (KB955759) (Version: 1) Update for Windows XP (KB955839) (Version: 1) Update for Windows XP (KB968389) (Version: 1) Update for Windows XP (KB971029) (Version: 1) Update for Windows XP (KB973815) (Version: 1) USB2.0 Card Reader Software (Version: 6.0.6000.81) WebFldrs XP (Version: 9.50.7523) Windows Internet Explorer 7 (Version: 20070813.185237) Windows Internet Explorer 8 (Version: 20090308.140743) Windows Live Call (Version: 14.0.8050.1202) Windows Live Communications Platform (Version: 14.0.8050.1202) Windows Live Essentials (Version: 14.0.8050.1202) Windows Live Mail (Version: 14.0.8050.1202) Windows Live Messenger (Version: 14.0.8050.1202) Windows Live Photo Gallery (Version: 14.0.8051.1204) Windows Live Sign-in Assistant (Version: 5.000.817.1) Windows Live Sync (Version: 14.0.8050.1202) Windows Live Upload Tool (Version: 14.0.8014.1029) Windows Live Writer (Version: 14.0.8050.1202) Windows Media Format Runtime Windows Media Player 10 ==================== Restore Points ========================= 21-06-2013 02:33:11 System Checkpoint 21-06-2013 03:08:01 avast! Free Antivirus Setup 22-06-2013 14:26:20 System Checkpoint 23-06-2013 22:48:52 System Checkpoint 26-06-2013 03:33:13 System Checkpoint 28-06-2013 06:22:34 System Checkpoint 30-06-2013 15:35:12 System Checkpoint 02-07-2013 04:48:05 System Checkpoint ==================== Scheduled Tasks (whitelisted) ============= Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe Task: C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe Task: C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/15/2013 07:10:50 PM) (Source: CltMngSvc) (User: ) Description: CltMngSvcServiceInstall: Fail to Start serviceSearch Protect by Conduit Updater (Error: 1056) Error: (04/03/2013 06:54:37 AM) (Source: Application Error) (User: ) Description: Faulting application updater.exe, version 1.1.3.6, faulting module updater.exe, version 1.1.3.6, fault address 0x00002517. Processing media-specific event for [updater.exe!ws!] Error: (04/03/2013 06:27:47 AM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: The specified server cannot perform the requested operation. Error: (04/03/2013 06:27:47 AM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This operation returned because the timeout period expired. Error: (03/22/2013 07:37:25 PM) (Source: Application Hang) (User: ) Description: Hanging application msimn.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (03/20/2013 06:22:02 AM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: The specified server cannot perform the requested operation. Error: (03/20/2013 06:22:02 AM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: The specified server cannot perform the requested operation. Error: (03/20/2013 06:22:02 AM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: The specified server cannot perform the requested operation. Error: (03/20/2013 06:22:01 AM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This operation returned because the timeout period expired. Error: (03/13/2013 06:15:20 AM) (Source: crypt32) (User: ) Description: Failed auto update retrieval of third-party root list sequence number from: with error: This network connection does not exist. System errors: ============= Error: (06/27/2013 08:04:25 PM) (Source: Service Control Manager) (User: ) Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error: %%1053 Error: (06/27/2013 08:04:25 PM) (Source: Service Control Manager) (User: ) Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D; 2 Security Center Service service to connect. Error: (06/23/2013 07:29:39 PM) (Source: Service Control Manager) (User: ) Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error: %%1053 Error: (06/23/2013 07:29:39 PM) (Source: Service Control Manager) (User: ) Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D; 2 Security Center Service service to connect. Error: (06/23/2013 07:22:34 PM) (Source: Service Control Manager) (User: ) Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error: %%1053 Error: (06/23/2013 07:22:34 PM) (Source: Service Control Manager) (User: ) Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D; 2 Security Center Service service to connect. Error: (06/23/2013 07:15:32 PM) (Source: Service Control Manager) (User: ) Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error: %%1053 Error: (06/23/2013 07:15:32 PM) (Source: Service Control Manager) (User: ) Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D; 2 Security Center Service service to connect. Error: (06/20/2013 11:51:32 PM) (Source: Service Control Manager) (User: ) Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error: %%1053 Error: (06/20/2013 11:51:32 PM) (Source: Service Control Manager) (User: ) Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D; 2 Security Center Service service to connect. Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 70% Total physical RAM: 1011.88 MB Available physical RAM: 303.23 MB Total Pagefile: 2428.42 MB Available Pagefile: 1505.99 MB Total Virtual: 2047.88 MB Available Virtual: 1948.88 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:142.05 GB) (Free:128.65 GB) NTFS ==>[Drive with boot components (Windows XP)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149 GB) (Disk ID: 643360A4) Partition 1: (Not Active) - (Size=7 GB) - (Type=12) Partition 2: (Active) - (Size=142 GB) - (Type=07 NTFS) ==================== End Of Log ============================
Fix with FRST

  • Open notepad (Start =>All Programs => Accessories => Notepad).
  • Please copy the entire contents of the code box below.
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
  • Save it to the same direction as frst.exe (or frst64.exe) as fixlist.txt.

    CHR DefaultSearchURL: (Conduit) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
    oogle:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
    CHR DefaultSuggestURL: (Conduit) - "suggest_url": ""
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
  • Run frst.exe (on 64bit, run frst64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.

Reboot and tell me if something changed.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 02-07-2013 Ran by [removed] at 2013-07-03 06:33:15 Run:1 Running from C:\Documents and Settings\[removed]\Desktop Boot Mode: Normal ============================================== CHR DefaultSearchURL: (Conduit) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g ==> The Chrome "Settings" can be used to fix the entry. CHR DefaultSuggestURL: (Conduit) - "suggest_url": "" ==> The Chrome "Settings" can be used to fix the entry. ==== End of Fixlog ====
Please download HitmanPro to your desktop.
Press this link for the complete "User Manual" for HitmanPro.Kickstart.

  • Launch the program by double clicking on HitmanPro.exe. (Windows Vista/7 users right click on the HitmanPro icon and select run as administrator).
  • Click on the "HitmanPro.Kickstart button to create a bootable USB-stick with HitmanPro.Kickstart
    [external image: Posted Image]
  • Now insert the USB flash drive that will be used to write the HitmanPro.Kickstart files to.
    • As soon as one or more USB flash drives are detected, a selection screen will be presented.
  • Now select the USB flash drive on which you want to place the HitmanPro.Kickstart files and press the button Install Kickstart.
  • Importtant! Be aware that that all contents of the selected flash drive will be erased before the HitmanPro.Kickstart files are written.
  • If you press the ‘Yes’ button now, the selected USB flash drive will be formatted and all necessary HitmanPro.Kickstart files will be retrieved from the HitmanPro servers and written to the flash drive
  • Once the process is completed you can now remove the USB flash drive from the PC and use it to remove the malware from a ransomed PC.
  • Now insert the HitmanPro.Kickstart USB flash drive into a USB port of the ransomed PC and start the PC.
  • During the startup of the PC, enter the (BBS) Bios Boot Selector menu and select the USB flash drive that contains HitmanPro.Kickstart to boot from.
    • If it's not possible to enter the BBS go into the BIOS and set the USB option as your first boot-device by the boot-sequence.
  • The default way to boot is option 1, which skips the master boot record of your hard drive. If you do not press any key, the process will continue after 10 seconds using the default boot selection.
  • If you see a logon screen you can either select a user and logon, or if you wait approximately 15 seconds, HitmanPro will be started on your Windows logon screen.
  • Click on the next button. You must agree with the terms of EULA.
  • Check the box beside "No, I only want to perform a one-time scan to check this computer".
  • Click on the next button.
  • The program will start to scan the computer. The scan will typically take no more than 2-3 minutes.
  • Click on the next button and choose the option activate free license
  • Click on the next button and the infections where will be deleted.
  • Click now on the Save Log option and save this log to your desktop.
  • Click on the next button and restart the computer.
  • Copy the information of HitmanPro_20130116_1239.log in your next reply
Sorry. I finally printed the instructions for this fix (I don't have a printer at home) and now I need to come up with a USB drive. Hopefully, I'll get this done this weekend.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI