[external image: goGMWSt.gif]P2P Warningββββββββββ
I see you have peer-to-peer (P2P) file sharing software installed on your computer (
uTorrent). I advise you avoid P2P file sharing programmes; they are a security risk which can
make your computer susceptible to malware. File sharing networks are thoroughly infected and infested with malware - worms, backdoor Trojans, IRCBots, and rootkits propagate via P2P file sharing networks, gaming, and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can
trigger pop-up ads and malicious Flash ads that
install viruses, Trojans, and spyware. The best way to reduce the risk of infection is to
avoid these types of web sites and not use P2P applications. Please read the following articles for more information.
- Risks of File-Sharing Technology
- P2P Software User Advisories
- More malware is traveling on P2P networks these days
Your P2P software can be removed by following the instructions below.
- Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
- Search for the aforementioned programme(s), right-click and click Uninstall.
If you choose not to, please refrain from using the programme(s) during this process.
**
Running from C:\Users\[removed]\
DownloadsPlease go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.
Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as
fixlist.txtNOTE. It's important that both files,
FRST/FRST64 and
fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)
[external image: FRSTfix.JPG] start
CloseProcesses:
() C:\ProgramData\webzoom\1.1.0.29\cozahost.exe
() C:\ProgramData\webzoom\1.1.0.29\cozwdhost.exe
() C:\ProgramData\webzoom\1.1.0.29\cozaghost.exe
() C:\ProgramData\webzoom\1.1.0.29\coz32host.exe
() C:\ProgramData\webzoom\1.1.0.29\coz64host.exe
() C:\ProgramData\webzoom\1.1.0.29\cozahost.exe
R2 cozaghost; C:\ProgramData\webzoom\1.1.0.29\cozaghost.exe [481776 2015-02-05] ()
R2 cozwdhost; C:\ProgramData\webzoom\1.1.0.29\cozwdhost.exe [247280 2015-02-05] ()
HKLM-x32\β¦\RunOnce: [Import FF:0] => "C:\Users\Josh\AppData\Local\browser extensions\Resources\certutil.exe" -A -n "DO_NOT_TRUST_FiddlerRoot" -t "TCu,TCu,TCu" -i "C:\Users\Josh\AppData\Local\browser extensions\TrustedRoot.cer" -d "C:\Use (the data entry has 66 more characters).
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM\β¦\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
CHR HKLM-x32\β¦\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
CHR HKLM-x32\β¦\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
2015-02-06 20:52 - 2015-02-06 20:52 - 01513574 _____ () C:\Windows\shost.bin
C:\Users\Josh\AppData\Local\Temp\Quarantine.exe
C:\Users\Josh\AppData\Local\Temp\sqlite3.dll
C:\Users\Josh\AppData\Local\Temp\{92622AAD-05E8-4459-B256-765CE1E929FB}_NST_11551.exe
2015-02-05 06:18 - 2015-02-05 06:18 - 00247280 _____ () C:\ProgramData\webzoom\1.1.0.29\cozwdhost.exe
2015-02-05 06:19 - 2015-02-05 06:19 - 00481776 _____ () C:\ProgramData\webzoom\1.1.0.29\cozaghost.exe
2015-02-05 06:19 - 2015-02-05 06:19 - 00073728 _____ () C:\ProgramData\webzoom\1.1.0.29\coz32host.exe
2015-02-05 06:19 - 2015-02-05 06:19 - 00081920 _____ () C:\ProgramData\webzoom\1.1.0.29\coz64host.exe
2015-02-05 06:19 - 2015-02-05 06:19 - 00106496 _____ () C:\ProgramData\webzoom\1.1.0.29\cozahost.exe
EmptyTemp:
Hosts:
End
Open
FRST/FRST64 and press the
Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
~~~~~~~~~~~~~~~~~~~
[external image: BY4dvz9.png]AdwCleaner- Please download AdwCleaner and save the file to your Desktop.
- Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Follow the prompts.
- Click Scan.
- Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
- Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
- Follow the prompts and allow your computer to reboot.
- After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
- β File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.
~~~~~~~~~~~~~~~~~~`
Download Malwarebytes' Anti-Malware to your desktop.- Windows XP : Double click on the icon to run it.
- Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
[external image: MBAMDashboard_zpsddef9b5f.gif]- On the Dashboard click on Update Now
- Go to the Setting Tab
- Under Setting go to Detection and Protection
- Under PUP and PUM make sure both are set to show Treat Dections as Malware
- Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
- Then on the Dashboard click on Scan
- Make sure to select THREAT SCAN
- Then click on Scan
- When the scan is finished and the log pops upβ¦select Copy to Clipboard
- Please paste the log back into this thread for review
- Exit Malwarebytes
- ***************************************
Please post
fixlist.txt
AdwCleaner.txt
Malwarebytes log