This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Vosteran Hijack help needed please

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello. I installed chrome on a new-to-me used pc and now have vosteran taking over everything. Can you help? Ive done the requested scans. 

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-02-19 18:06:39
—————————–
18:06:39.584    OS Version: Windows x64 6.1.7601 Service Pack 1
18:06:39.585    Number of processors: 4 586 0x3A09
18:06:39.585    ComputerName: MARK-PC  UserName: Mark
18:06:42.752    Initialze error C000010E - driver not loaded
18:08:08.566    AVAST engine defs: 15021901
18:08:12.061    Service scanning
18:08:21.352    Modules scanning
18:08:21.356    Disk 0 trace - called modules:
18:08:21.358    
18:08:24.510    AVAST engine scan C:\Windows
18:08:27.333    AVAST engine scan C:\Windows\system32
18:09:36.170    AVAST engine scan C:\Windows\system32\drivers
18:09:44.550    AVAST engine scan C:\Users\Mark
18:10:15.131    AVAST engine scan C:\ProgramData
18:10:19.841    Scan finished successfully
18:10:55.584    The log file has been saved successfully to "C:\Users\Mark\Desktop\aswMBR021915.txt"
 
 
can result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015 (ATTENTION: ====> FRST version is 22 days old and could be outdated)
Ran by [removed] (administrator) on MARK-PC on 19-02-2015 18:13:03
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.5383\Battle.net.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Spotify Ltd) C:\Users\Mark\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
(Google Inc.) C:\Users\Mark\AppData\Local\Google\Update\GoogleUpdate.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.3733\Agent.exe
(Spotify Ltd) C:\Users\Mark\AppData\Roaming\Spotify\spotify.exe
() C:\Users\Mark\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Mark\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Mark\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Mark\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Mark\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM-x32\…\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\…\Run: [RUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation)
HKLM-x32\…\RunOnce: [DelTr270303369] => cmd.exe /c rd /s /q  "C:\Users\Mark\AppData\Roaming\WSE_Vosteran"
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\Run: [Spotify] => C:\Users\Mark\AppData\Roaming\Spotify\Spotify.exe [6737976 2015-01-15] (Spotify Ltd)
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2015-01-15] (Google Inc.)
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\Run: [Google Update] => C:\Users\Mark\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2015-01-18] (Google Inc.)
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\Run: [Spotify Web Helper] => C:\Users\Mark\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-01-15] (Spotify Ltd)
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\RunOnce: [WSE_Vosteran] => [X]
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\RunOnce: [PriceFountain] => [X]
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\RunOnce: [DelTr270303369] => cmd.exe /c rd /s /q  "C:\Users\Mark\AppData\Roaming\WSE_Vosteran"
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg64.dll (Google Inc.)
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-4044005535-2863482562-1548477820-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 75.75.75.75 75.75.76.76
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-4044005535-2863482562-1548477820-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Mark\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-4044005535-2863482562-1548477820-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Mark\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
 
Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-15]
CHR Extension: (Google Docs) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-15]
CHR Extension: (Google Drive) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-15]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-15]
CHR Extension: (YouTube) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-15]
CHR Extension: (Google Cast) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2015-01-18]
CHR Extension: (Google Search) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-15]
CHR Extension: (Weather Forecast) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\daidbcgjmglbmccacppklkejkpcekill [2015-02-17]
CHR Extension: (Google Sheets) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-15]
CHR Extension: (Rambler News) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\jecpbjbmdpgfdnodellehmojlchichkf [2015-02-15]
CHR Extension: (Google Wallet) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-15]
CHR Extension: (Gmail) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-15]
CHR Extension: (savienShoap) - C:\ProgramData\pfmffafgdbaniofilhkiajcmjoaajiom\ [2015-01-15]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 c7522d84; c:\Program Files (x86)\Optimizer Pro 3.27\OptProMon.dll [2462800 2015-01-18] ()
S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [1461904 2012-08-09] (Realtek Semiconductor Corporation                           )
R1 {16a92140-918d-4afb-9edb-46f22437bb10}Gw64; C:\Windows\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}Gw64.sys [48792 2015-01-25] (StdLib)
R1 {915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64; C:\Windows\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64.sys [48792 2015-01-22] (StdLib)
R1 {ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64; C:\Windows\System32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64.sys [48792 2015-01-15] (StdLib)
R1 {ecd6aae4-019c-44b2-a0e5-570904275d66}Gw64; C:\Windows\System32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}Gw64.sys [48792 2015-01-16] (StdLib)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 aswMBR; \??\C:\Users\Mark\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Mark\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-19 18:13 - 2015-02-19 18:13 - 00013093 _____ () C:\Users\Mark\Downloads\FRST.txt
2015-02-19 18:13 - 2015-02-19 18:13 - 00000000 ____D () C:\FRST
2015-02-19 18:12 - 2015-02-19 18:12 - 02129920 _____ (Farbar) C:\Users\Mark\Downloads\FRST64.exe
2015-02-19 18:10 - 2015-02-19 18:10 - 00000947 _____ () C:\Users\Mark\Desktop\aswMBR021915.txt
2015-02-19 18:05 - 2015-02-19 18:05 - 05198336 _____ (AVAST Software) C:\Users\Mark\Downloads\aswMBR.exe
2015-02-17 21:40 - 2015-02-17 21:41 - 00000000 ____D () C:\ProgramData\bfa64d1d9bb35bfa
2015-02-17 21:36 - 2015-02-17 21:36 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2015-02-17 19:50 - 2015-02-17 21:40 - 00000000 ____D () C:\Program Files (x86)\SMaRRtComapare
2015-02-17 19:50 - 2015-02-17 19:50 - 00000000 ____D () C:\Program Files (x86)\Weather Forecast
2015-02-17 19:50 - 2015-02-17 19:50 - 00000000 ____D () C:\Program Files (x86)\surfikeeepiti
2015-02-15 11:30 - 2015-02-15 11:30 - 00000000 ____D () C:\ProgramData\pfmffafgdbaniofilhkiajcmjoaajiom
2015-02-15 11:30 - 2015-02-15 11:30 - 00000000 ____D () C:\Program Files (x86)\savienShoap
2015-02-15 11:30 - 2015-02-15 11:30 - 00000000 ____D () C:\Program Files (x86)\Rambler News
2015-02-13 19:46 - 2015-02-13 19:46 - 00000000 ____D () C:\Program Files (x86)\DisucounttLocator
2015-02-13 19:26 - 2015-02-17 21:37 - 00000020 _____ () C:\Users\Mark\AppData\Roaming\appdataFr3.bin
2015-02-08 20:09 - 2015-02-08 20:09 - 00000000 ____D () C:\ProgramData\CouponFactory
2015-02-06 13:07 - 2015-02-17 21:40 - 00000000 ____D () C:\Program Files (x86)\dEaal2deualit
2015-02-06 13:07 - 2015-02-17 21:40 - 00000000 ____D () C:\Program Files (x86)\CoOlSaLeCoupon
2015-02-06 13:07 - 2015-02-17 19:50 - 00000000 ____D () C:\ProgramData\13809810096939817978
2015-01-25 08:22 - 2015-01-25 05:44 - 00048792 _____ (StdLib) C:\Windows\system32\Drivers\{16a92140-918d-4afb-9edb-46f22437bb10}Gw64.sys
2015-01-22 17:42 - 2015-01-22 12:54 - 00048792 _____ (StdLib) C:\Windows\system32\Drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64.sys
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-19 18:13 - 2015-01-17 08:02 - 00000000 ____D () C:\Users\Mark\AppData\Local\Battle.net
2015-02-19 18:07 - 2015-01-15 17:25 - 00000000 ____D () C:\Users\Mark\AppData\Roaming\Spotify
2015-02-19 18:03 - 2015-01-18 08:56 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4044005535-2863482562-1548477820-1000UA.job
2015-02-19 18:03 - 2015-01-18 08:56 - 00000852 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4044005535-2863482562-1548477820-1000Core.job
2015-02-19 18:03 - 2015-01-15 17:29 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-19 18:03 - 2015-01-15 17:29 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-19 18:03 - 2015-01-15 17:26 - 00000000 ____D () C:\Users\Mark\AppData\Local\Spotify
2015-02-19 18:03 - 2015-01-12 20:08 - 00023561 _____ () C:\Windows\WindowsUpdate.log
2015-02-17 21:42 - 2015-01-18 17:11 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-02-08 19:30 - 2015-01-17 08:02 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-01-25 08:32 - 2015-01-15 18:25 - 00000153 _____ () C:\Users\Mark\AppData\Roaming\WB.CFG
2015-01-25 08:22 - 2009-07-13 21:34 - 00000580 _____ () C:\Windows\win.ini
 
==================== Files in the root of some directories =======
 
2015-02-13 19:26 - 2015-02-17 21:37 - 0000020 _____ () C:\Users\Mark\AppData\Roaming\appdataFr3.bin
2015-01-15 18:25 - 2015-01-25 08:32 - 0000153 _____ () C:\Users\Mark\AppData\Roaming\WB.CFG
2015-01-17 08:00 - 2015-01-17 08:00 - 0000001 _____ () C:\Users\Mark\AppData\Local\DSI.DAT
2015-01-17 08:00 - 2015-01-17 08:00 - 0022528 _____ () C:\Users\Mark\AppData\Local\dsisetup1390925812.exe
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-02-17 20:02
 
==================== End Of Log ============================
Theres quite a bit to do.

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

~~~

Please disable SpyBot TeaTimer.

SPYBOT TEATIMER

Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
On the left hand side, click on Tools, then click on the Resident Icon in the list.
Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
Click on the "System Startup" icon in the List
Uncheck the "TeaTimer" box and "OK" any prompts.
If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
Exit Spybot S&D when done and reboot your computer.
(When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]

~~~~~

Please download and install Revo Uninstaller Free
  • Double click Revo Uninstaller to run it.
  • From the list of programs double click on Google Chrome
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • when the built-in uninstaller is finished click on Next.
  • Once the program has searched for leftovers click Next.
  • Check/tick the bolded items only on the list then click Delete
  • when prompted click on Yes and then on next.
  • put a check on any folders that are found and select delete
  • when prompted select yes then on next
  • Once done click Finish.
Also please uninstall Optimizer Pro v3.2.

~~

Once uninstalled, download again from this link.
http://www.google.com/chrome/

~~~

Running from C:\Users\[removed]\Downloads

It's best we move Farbar's to desktop.

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CloseProcesses:
HKLM-x32\…\RunOnce: [DelTr270303369] => cmd.exe /c rd /s /q "C:\Users\Mark\AppData\Roaming\WSE_Vosteran"
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\RunOnce: [WSE_Vosteran] => [X]
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\RunOnce: [PriceFountain] => [X]
HKU\S-1-5-21-4044005535-2863482562-1548477820-1000\…\RunOnce: [DelTr270303369] => cmd.exe /c rd /s /q "C:\Users\Mark\AppData\Roaming\WSE_Vosteran"
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/…r=303474610&ir=
SearchScopes: HKU\S-1-5-21-4044005535-2863482562-1548477820-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/…r=303474610&ir=
CHR dev: Chrome dev build detected! <======= ATTENTION
R2 c7522d84; c:\Program Files (x86)\Optimizer Pro 3.27\OptProMon.dll [2462800 2015-01-18] ()
c:\Program Files (x86)\Optimizer Pro 3.27
R1 {16a92140-918d-4afb-9edb-46f22437bb10}Gw64; C:\Windows\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}Gw64.sys [48792 2015-01-25] (StdLib)
C:\Windows\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}Gw64.sys
R1 {915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64; C:\Windows\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64.sys [48792 2015-01-22] (StdLib)
R1 {ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64; C:\Windows\System32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64.sys [48792 2015-01-15] (StdLib)
R1 {ecd6aae4-019c-44b2-a0e5-570904275d66}Gw64; C:\Windows\System32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}Gw64.sys [48792 2015-01-16] (StdLib)
2015-01-25 08:22 - 2015-01-25 05:44 - 00048792 _____ (StdLib) C:\Windows\system32\Drivers\{16a92140-918d-4afb-9edb-46f22437bb10}Gw64.sys
2015-01-22 17:42 - 2015-01-22 12:54 - 00048792 _____ (StdLib) C:\Windows\system32\Drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64.sys
C:\Windows\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64.sys
C:\Windows\System32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64.sys
C:\Windows\System32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}Gw64.sys
2015-02-17 19:50 - 2015-02-17 21:40 - 00000000 ____D () C:\Program Files (x86)\SMaRRtComapare
2015-02-17 19:50 - 2015-02-17 19:50 - 00000000 ____D () C:\Program Files (x86)\surfikeeepiti
2015-02-15 11:30 - 2015-02-15 11:30 - 00000000 ____D () C:\ProgramData\pfmffafgdbaniofilhkiajcmjoaajiom
2015-02-15 11:30 - 2015-02-15 11:30 - 00000000 ____D () C:\Program Files (x86)\savienShoap
2015-02-15 11:30 - 2015-02-15 11:30 - 00000000 ____D () C:\Program Files (x86)\Rambler News
2015-02-13 19:46 - 2015-02-13 19:46 - 00000000 ____D () C:\Program Files (x86)\DisucounttLocator
2015-02-08 20:09 - 2015-02-08 20:09 - 00000000 ____D () C:\ProgramData\CouponFactory
2015-02-06 13:07 - 2015-02-17 21:40 - 00000000 ____D () C:\Program Files (x86)\dEaal2deualit
2015-02-06 13:07 - 2015-02-17 21:40 - 00000000 ____D () C:\Program Files (x86)\CoOlSaLeCoupon
EmptyTemp:
Hosts:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click Scan.
  • Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
  • Follow the prompts and allow your computer to reboot.
  • After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
  • – File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


    [external image: thisisujrt.gif]
    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    *****
    please post
    Fixlog.txt
    C:\AdwCleaner.txt
    JRT.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI