This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot install antivirus, Chrome/IE crashing immediately after opening

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    start
    CreateRestorePoint:
    () C:\ProgramData\openssl.exe
    () C:\ProgramData\aspnet_wp_64.exe
    () C:\ProgramData\igfxEM_32.exe
    (Microsoft Corporation) C:\Windows\System32\regsvr32.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
    
    S3 BS680067079; \??\C:\Users\Michael\AppData\Local\Temp\NTFS.sys [X]
    C:\Users\Michael\AppData\Local\Temp\NTFS.sys
    R3 WinRing0_1_2_0; \??\C:\Users\Michael\AppData\Local\Temp\tmp9E8F.tmp [X]
    C:\Users\Michael\AppData\Local\Temp\tmp9E8F.tmp
    2009-07-13 18:19 - 2009-07-13 20:14 - 0577536 _____ () C:\Users\Michael\AppData\Roaming\BackUp680067079.exe
    
    HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [RSA680067079] => C:\Windows\system32\rundll32.exe "C:\Users\Michael\AppData\Roaming\Microsoft\Crypto\RSA\RSA680067079.dll",DllInitialize <===== ATTENTION
    C:\Users\Michael\AppData\Roaming\Microsoft\Crypto\RSA\RSA680067079.dll
    HKLM\…\Run: [GheT3Z733AFC] => regsvr32.exe /s "C:\PROGRA~3\GheT3Z733AFC.dll"
    HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [IequGrufh] => regsvr32.exe "C:\ProgramData\Linpal\BufqOvba.dll"
    2015-10-31 05:49 - 2015-10-31 06:02 - 00000000 ____D C:\ProgramData\Linpal
    HKLM\…\Run: [openssl] => C:\ProgramData\openssl.exe [4096 2015-11-05] ()
    HKLM\…\Run: [igfxEM_32] => C:\ProgramData\igfxEM_32.exe [4096 2015-11-06] ()
    HKLM\…\Run: [aspnet_wp_64] => C:\ProgramData\aspnet_wp_64.exe [4096 2015-11-10] ()
    2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ C:\ProgramData\sessionmsg_32.dll
    2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ C:\ProgramData\igfxEM_32.exe
    2015-11-05 08:32 - 2015-11-05 08:32 - 00004096 _____ C:\ProgramData\openssl.exe
    2015-11-05 08:31 - 2015-11-05 08:31 - 00004096 _____ C:\ProgramData\TabTip32.dll
    2015-10-31 06:20 - 2015-10-31 06:20 - 00004096 _____ C:\ProgramData\GheT3Z733AFC.dll
    2015-10-31 06:17 - 2015-10-31 06:17 - 00004096 _____ C:\ProgramData\hTew6txG3AFC.dll
    2015-11-10 19:01 - 2015-11-10 19:01 - 00004096 _____ C:\ProgramData\aspnet_wp_64.exe
    2015-11-10 19:00 - 2015-11-10 19:00 - 00004096 _____ C:\ProgramData\wowreg_64.dll
    
    HKU\S-1-5-18\…\Run: [Chrome] => C:\ProgramData\taskhost.exe [5120 2015-10-31] ()
    2015-10-31 06:21 - 2015-10-31 06:21 - 00005120 _____ C:\ProgramData\taskhost.exe
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Chrome]
    
    2015-10-31 05:49 - 2015-10-31 05:50 - 00000000 ___HD C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}
    
    2015-11-06 08:43 - 2015-11-06 08:43 - 00090112 _____ C:\ProgramData\7B571D05.EX
    2015-10-31 06:16 - 2015-11-14 04:39 - 03474516 _____ C:\Windows\system32\CFG680067079
    2015-10-31 05:50 - 2015-10-31 05:50 - 00450102 _____ C:\Users\Michael\AppData\Roaming\lqnqtgzk.exe
    2015-11-14 22:04 - 2015-11-14 22:10 - 00037209 _____ C:\Windows\system32\DB680067079
    2015-11-12 08:10 - 2015-11-12 08:10 - 00065537 _____ C:\Users\Michael\AppData\Roaming\qlulctq.exe
    
    HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\MountPoints2: {d61fb579-c776-11e4-bcd3-bc5ff4abb4c9} - I:\Startme.exe
    Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
    Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
    EmptyTemp:
    end
  • Click File, Save As and type fixlist.txt as the File Name. 
  • Important: The file must be saved in the same location as FRST64.exe. 

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Double-Click FRST64.exe to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Attach the log in your next reply.

 

STEP 2
[external image: YARWD1t.png] TDSSKiller Scan

  • Right-Click TDSSKiller.exe (or iexplore.exe in your case) and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Change parameters. Place a checkmark next to Detect TDLFS file system and Verify file digital signatures.
  • ​Click Start Scan. Do not use the computer during the scan.
  • If objects are found, change the action to skip.
  • Click Continue and close the window.
  • A log will be created and saved to the root directory (usually C:\). Attach (not copy/paste) the file in your next reply.

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • Fixlog.txt by FRST
  • TDSSKiller log

Hi MisterCynic.

 

Yes the message pop-up is a result of our fix. We will take care of it eventually.

 

STEP 1
[external image: iAdP9bf.png] Malwarebytes Anti-Rootkit (MBAR)

  • Please download Malwarebytes Anti-Rootkit and save the file to your Desktop.
  • Right-Click MBAR.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the installer.
  • Select your Desktop as the location to extract the contents and click OK. The programme should open upon completion.
  • Click Next, followed by Update. Upon update completion, click Next.
  • Ensure Drivers, Sectors & System are checked and click Scan.
  • Note: Do not use your computer during the scan.
  • Upon completion:
    • If no malware is found, close the MBAR window.
    • If malware is found, ensure Create Restore Point is checked and click Cleanup. Reboot when prompted.
  • Two logs (mbar-log.txt and system-log.txt) will be created. Copy the contents of both logs and paste in your next reply. Both logs can be found in the MBAR folder.

 

STEP 2
[external image: GfiJrQ9.png] Malwarebytes Anti-Malware (MBAM)

  • Please download the Malwarebytes Anti-Malware setup file to your Desktop.
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme. 
  • Open Malwarebytes Anti-Malware and click Update Now.
  • Once updated, click the Settings tab, followed by Detection and Protection and tick Scan for rootkits.
  • Click the Scan tab, ensure Threat Scan is selected and click Start Scan.
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards. 
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs and double-click the Scan Log.
  • Attach the log in your next reply.

 

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs.

  • mbar-log.txt
  • system-log.txt
  • MBAM Scan log

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2015.11.20.05
  rootkit: v2015.11.14.01

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Michael :: YMIR [administrator]

11/20/2015 12:46:23
mbar-log-2015-11-20 (12-46-23).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 385652
Time elapsed: 31 minute(s), 55 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 1
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|RSA680067079 (Trojan.Agent.E) -> Data: C:\Windows\system32\rundll32.exe "C:\Users\Michael\AppData\Roaming\Microsoft\Crypto\RSA\RSA680067079.dll",DllInitialize -> Delete on reboot. [ac995d236328eb4b904e2a805ba8966a]

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
 

 

 

 

 

 

—————————————
Malwarebytes Anti-Rootkit BETA 1.09.3.1001

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7600 Windows 7 x64

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, I:\ DRIVE_FIXED
CPU speed: 3.400000 GHz
Memory total: 17057308672, free: 13016829952

Downloaded database version: v2015.11.20.05
Downloaded database version: v2015.11.14.01
Downloaded database version: v2015.11.20.01
=======================================
Initializing…
Driver version: 0.3.0.4
———— Kernel report ————
     11/20/2015 12:46:14
———— Loaded modules ———–
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\DRIVERS\ACPI.sys
\SystemRoot\system32\DRIVERS\WMILIB.SYS
\SystemRoot\system32\DRIVERS\msisadrv.sys
\SystemRoot\system32\DRIVERS\pci.sys
\SystemRoot\system32\DRIVERS\vdrvroot.sys
\SystemRoot\system32\DRIVERS\iusb3hcs.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\DRIVERS\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\DRIVERS\atapi.sys
\SystemRoot\system32\DRIVERS\ataport.SYS
\SystemRoot\system32\DRIVERS\msahci.sys
\SystemRoot\system32\DRIVERS\PCIIDEX.SYS
\SystemRoot\system32\DRIVERS\iaStorA.sys
\SystemRoot\system32\DRIVERS\storport.sys
\SystemRoot\system32\DRIVERS\asahci64.sys
\SystemRoot\system32\DRIVERS\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\ngvss.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\system32\DRIVERS\iaStorF.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\System32\Drivers\aswVmm.sys
\SystemRoot\System32\Drivers\aswRvrt.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\drivers\aswSnx.sys
\SystemRoot\system32\drivers\aswSP.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\aswRdr2.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\System32\drivers\truecrypt.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\nvlddmkm.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\iusb3xhc.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\HECIx64.sys
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\k57nd60a.sys
\SystemRoot\system32\DRIVERS\asmtxhci.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\wmiacpi.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\ISCTD64.sys
\SystemRoot\system32\DRIVERS\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\drivers\LGBusEnum.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\drivers\nvvad64v.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\nvhda64v.sys
\SystemRoot\system32\DRIVERS\iusb3hub.sys
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\DRIVERS\asmthub3.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_asahci64.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\imsevent.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\ikbevent.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\DRIVERS\sshid.sys
\SystemRoot\system32\DRIVERS\hidkmdf.sys
\SystemRoot\system32\drivers\usbaudio.sys
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\aswMonFlt.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\drivers\aswStm.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\aswHwid.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\drivers\WPRO_41_2001.sys
\??\C:\Users\Michael\AppData\Local\Temp\ALSysIO64.sys
\SystemRoot\system32\DRIVERS\WUDFRd.sys
\??\C:\Users\Michael\AppData\Local\Temp\tmp81CC.tmp
\??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
\SystemRoot\system32\drivers\LGVirHid.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\Program Files\PeerBlock\pbfilter.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\setupapi.dll
\Windows\System32\msctf.dll
\Windows\System32\clbcatq.dll
\Windows\System32\ole32.dll
\Windows\System32\nsi.dll
\Windows\System32\sechost.dll
\Windows\System32\urlmon.dll
\Windows\System32\normaliz.dll
\Windows\System32\usp10.dll
\Windows\System32\imm32.dll
\Windows\System32\user32.dll
\Windows\System32\shlwapi.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\psapi.dll
\Windows\System32\iertutil.dll
\Windows\System32\kernel32.dll
\Windows\System32\comdlg32.dll
\Windows\System32\imagehlp.dll
\Windows\System32\Wldap32.dll
\Windows\System32\ws2_32.dll
\Windows\System32\lpk.dll
\Windows\System32\difxapi.dll
\Windows\System32\advapi32.dll
\Windows\System32\gdi32.dll
\Windows\System32\msvcrt.dll
\Windows\System32\oleaut32.dll
\Windows\System32\shell32.dll
\Windows\System32\wininet.dll
\Windows\System32\devobj.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\crypt32.dll
\Windows\System32\KernelBase.dll
\Windows\System32\comctl32.dll
\Windows\System32\wintrust.dll
\Windows\System32\msasn1.dll
\Windows\SysWOW64\normaliz.dll
———– End ———–
Done!

Scan started
Database versions:
  main:    v2015.11.20.05
  rootkit: v2015.11.14.01

<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa800f86d060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xfffffa800f86db90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800f86d060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800da018d0, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa800d527680, DeviceName: \Device\Ide\IdeDeviceP0T0L0-0\, DriverName: \Driver\atapi\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers…
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: FFC0A867

Partition information:

    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 204800
    Partition is bootable
    Partition file system is NTFS

    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 206848  Numsec = 1953314816
    Partition is not bootable
    Partition file system is NTFS

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 1000204886016 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 4096
Drive: 1, DevicePointer: 0xfffffa8012de1060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xfffffa8012de1b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8012de1060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8012ba2c50, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa8011f1bb70, DeviceName: \Device\00000081\, DriverName: \Driver\USBSTOR\
———— End ———-
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 9A88295B

Partition information:

    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 976752597
    Partition is not bootable
    Partition file system is NTFS

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 4000787025920 bytes
Sector size: 4096 bytes

Done!
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xfffffa8013734690, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xfffffa8013823040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8013734690, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800ca6c040, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa80137cdb70, DeviceName: \Device\00000091\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xfffffa801373f790, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xfffffa80137f3680, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa801373f790, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa801384b850, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa801374ca70, DeviceName: \Device\00000092\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xfffffa801382f060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xfffffa801382fb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa801382f060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa801384cc50, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa8013737b70, DeviceName: \Device\00000093\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 5, DevicePointer: 0xfffffa801384c060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xfffffa801384b040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa801384c060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8013831c50, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa8013822060, DeviceName: \Device\00000094\, DriverName: \Driver\USBSTOR\
———— End ———-
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VF" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VE0" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VE0" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VE0" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VE0" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VE0" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VE0" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VE0" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VE0" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VE0" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1C47C7B9568A3BAE764D6D11F6615900BAA8980D.bin.VE1" is compressed (flags = 1)
Infected: HKU\S-1-5-21-711289349-3085500364-3229847752-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|RSA680067079 –> [Trojan.Agent.E]
Scan finished
Creating System Restore point…
Cleaning up…
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================

 

Hello MisterCynic.

 

Malwarebyte's Antimalware has removed entries related to a program called Driver Sweeper. There are two reasons for this.

 

1. It comes with an Open Candy installer and updater. This kind of installer bundles third-party software. These third-party offers are usually opt-out and decline options may be greyed out and look like they cannot be clicked. People often install unwanted programs this way.

 

2. Driver Sweeper can make dangerous changes to your system leading to instability. It also does not officially support the latest version of Windows 7, because it has not been updated in years. This article also explains, why this kind of software is not necessary anymore.

 

I highly suggest that you uninstall the programme if it is still in the program list. Tell me about your decision in your next reply.

 

 

STEP 1
[external image: EtQetiM.png] Uninstall Software

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for the following programmes, right-click and click Uninstall.
    • ​​​​YTD Video Downloader 3.9.6
  • Follow the prompts.
  • Note: If you are offered the choice to install additional software, ensure you decline.
  • You may also uninstall Driver Sweeper during this step if you decide to do so.
  • Reboot if necessary.

 

STEP 2
[external image: E3feWj5.png] Junkware Removal Tool (JRT)

  • Please download Junkware Removal Tool and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Right-Click JRT.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts and allow the scan to run uninterrupted. 
  • Upon completion, a log (JRT.txt) will open on your desktop.
  • Re-enable your anti-virus software.
  • Copy the contents of JRT.txt and paste in your next reply.
     

STEP 3

[external image: BY4dvz9.png] AdwCleaner

  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts. 
  • Click Scan. 
  • Upon completion, click Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate. 
  • Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab, and click Cleaning. 
  • Follow the prompts and allow your computer to reboot. 
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.

– File and folder backups are made for items removed using this tool. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[S1].txt.

 
======================================================

STEP 4
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs.

  • Did you successfully uninstall the programmes in Step 1?
  • JRT.txt
  • AdwCleaner[C1].txt

I decided to go with your advice and uninstall Driver Sweeper along with YTD Video Downloader.

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.0 (11.12.2015)
Operating System: Windows 7 Home Premium x64
Ran by [removed] (Administrator) on Mon 11/23/2015 at 10:20:13.13
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 5

Successfully deleted: C:\Users\Michael\AppData\Roaming\3909 (Folder)
Successfully deleted: C:\Users\Michael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\ytd video downloader.lnk (Shortcut)
Successfully deleted: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\user.js (File)
Successfully deleted: C:\Users\Michael\AppData\Roaming\system (Folder)
Successfully deleted: C:\Users\Michael\AppData\Roaming\wyupdate au (Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 11/23/2015 at 10:22:41.69
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

# AdwCleaner v5.022 - Logfile created 23/11/2015 at 11:32:50
# Updated 22/11/2015 by Xplode
# Database : 2015-11-22.2 [Server]
# Operating system : Windows 7 Home Premium  (x64)
# Username : Michael - YMIR
# Running from : C:\Users\Michael\Desktop\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi
[-] Folder Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\bohapeiooecafommnlaiccilacgmkaoc

***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\pc-mechanic
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CB139E9D-B946-4AD9-BA55-C992101CEA7C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CCAD7AF4-2975-4BFD-96A0-15F67DB62A78}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{CB139E9D-B946-4AD9-BA55-C992101CEA7C}
[-] Key Deleted : HKCU\Software\APN PIP
[-] Key Deleted : HKLM\SOFTWARE\PIP

***** [ Web browsers ] *****

[-] [C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\prefs.js] [Preference] Deleted : user_pref("keyword.URL", "hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=282369&p=");
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : netflix.com
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : driver-sweeper.en.softonic.com
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : yahoo.com Search
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : bohapeiooecafommnlaiccilacgmkaoc
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : mcbkbpnkkkipelfledbfocopglifcfmi

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2527 bytes] ##########
 

STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan

  • Double-Click FRST64.exe to run the programme.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Attach the logs in your next reply.

 

STEP 2
[external image: GzlsbnV.png] ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

  • Please download ESET Online Scan and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the programme. 
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Place a checkmark next to Enable detection of potentially unwanted applications.
  • Click Advanced settings. Place a checkmark next to:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Ensure Remove found threats is unchecked.
  • Click Start.
  • Wait for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points. 
  • Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
  • Push the Back button.
  • Place a checkmark next to [external image: KN1w2nv.png] and click [external image: SzOC1p0.png].
  • Re-enable your anti-virus software.
  • Attach the log in your next reply.
     

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs.

  • FRST.txt
  • Addition.txt
  • ESET Online Scan log
  • Are there any outstanding issues with your computer?

STEP 1
[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    start
    CreateRestorePoint:
    CloseProcesses:
    HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [IequGrufh] => regsvr32.exe "C:\ProgramData\Linpal\BufqOvba.dll"
    2015-11-19 11:09 - 2015-11-19 11:56 - 00000000 ____D C:\ProgramData\Linpal
    Folder: C:\Users\Michael\AppData\Roaming\3909
    EmptyTemp:
    end
    
  • Click File, Save As and type fixlist.txt as the File Name.
  • Important: The file must be saved in the same location as FRST64.exe.

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Double-Click FRST64.exe to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Attach the log in your next reply.

 

Please try the ESET scan again after the fix.

 

STEP 2
[external image: GzlsbnV.png] ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

  • Please download ESET Online Scan and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the programme. 
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Place a checkmark next to Enable detection of potentially unwanted applications.
  • Click Advanced settings. Place a checkmark next to:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Ensure Remove found threats is unchecked.
  • Click Start.
  • Wait for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points. 
  • Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
  • Push the Back button.
  • Place a checkmark next to [external image: KN1w2nv.png] and click [external image: SzOC1p0.png].
  • Re-enable your anti-virus software.
  • Attach the log in your next reply.
     

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs.

  • Fixlog.txt
  • ESET Online Scan log

Hello MisterCynic.

 

The malware is still on the system. Do you have a USB drive? If you do, please follow instructions below. Otherwise give me a note.

 

STEP 1
[external image: xlK5Hdb.png] FRST Recovery Environment Scan


Note: Please print off these instructions, or ensure you have access to them using a different device.

  • Please download Farbar Recovery Scan Tool (x64) to your USB drive.

Enter Recovery Environment (Windows 7/Vista)

  • Restart the infected computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until the Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select your the keyboard language settings, and then click Next.
  • Select the operating system you wish to repair, and then click Next.
  • Select your user account, and then click Next.

Advanced Boot Options Menu

  • Select Command Prompt.
  • In the command window type notepad and press Enter on your keyboard.
  • Notepad will open. Click File followed by Open. 
  • Click Computer, write down your USB drive letter on a piece of paper and close Notepad.
  • Type: x:\frst.exe or x:\frst64.exe in the command window. 
    • Note: Replace letter x with the drive letter of your USB drive you wrote down earlier.
  • Press Enter on your keyboard. The tool will start to run.
  • When the tool opens click Yes to the disclaimer.
  • Click Scan.
  • A log (FRST.txt) will be saved to your USB drive. Please attach the log in your next reply.
     

======================================================
 
STEP 2
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs.

  • FRST.txt

Here's the results.

 

Also, if this info is any help, the Chrome browser's now starting up properly though the steam browser is still failing to load anything and Opera gives an "out of memory" message.  The Avast installer also starts up now, but I haven't tried reinstalling it.  For now I'm just using Windows Defender.

Attachments:

Hello MisterCynic.

 

Thank you for your patience so far. The malware on your system is pretty persistent. It respawned after our fix, which is why we need to take more steps than usual to take care of it.

 

STEP 1

[external image: xlK5Hdb.png] FRST Recovery Environment Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    start
    HKU\Michael\…\Run: [IequGrufh] => regsvr32.exe "C:\ProgramData\Linpal\BufqOvba.dll"
    C:\ProgramData\Linpal
    C:\Users\All Users\Linpal
    end
    
  • Click File, Save As and type fixlist.txt as the File Name.
  • Save the file to your USB drive.

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Enter the Recovery Environment just as you did before.
  • Run FRST just as you did before.
  • Click the Fix button once.
  • A log (Fixlog.txt) will be created on your USB drive.
  • Attempt to boot normally into Windows. Does the PC boot normally?
  • Attach Fixlog.txt to your next reply.

 

After you have booted normally, reboot the computer again before you proceed with the next step. Ensure that your computer is connected to the Internet.

 

STEP 2
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan

  • Double-Click FRST64.exe to run the programme.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Attach the logs in your next reply.

 

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs.

  • Could you boot normally into Windows?
  • FRST.txt
  • Addition.txt

STEP 1
[external image: 9SN2ePL.png] ComboFix

  • Note: Please read through these instructions before running ComboFix. 
  • Please download ComboFix and save the file to your Desktop. << Important!
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Right-Click ComboFix.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts. 
     
  • Allow ComboFix to complete it's removal routine (please refer to Important Notes:).
  • Upon completion, a log (ComboFix.txt) will be created in the root directory (C:\). Copy the contents of the log and paste in your next reply.
  • Re-enable your anti-virus software.
     

Important Notes:

  • Do NOT mouse click ComboFix's window whilst it is running. This may cause the programme to stall.
  • Do NOT use your computer whilst ComboFix is running.
  • Your Desktop/taskbar may disappear whilst ComboFix is running; this is normal.
     
  • If you get the message Illegal operation attempted on registry key that has been marked for deletion please reboot your computer.
  • ComboFix will disconnect your machine from the Internet as soon as it starts.
  • Please do not attempt to re-connect your machine back to the Internet until ComboFix has completely finished.
  • If you are unable to access the Internet after running ComboFix, please reboot your computer. 
     

======================================================

STEP 2
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs.

  • ComboFix.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI