This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help. I think my laptop is infected. [Solved]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good morning. I was wondering if you could help me out with removing virus/malware from my laptop. Thanks.

 

Here is the log from HijackThis:

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:17:28, on 29.03.2016
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\SMART BRO\UIExec.exe
C:\Users\Adadu\AppData\Local\MalwareProtectionLive\MalwareProtectionClient.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe
C:\Program Files\McAfee Security Scan\3.11.292\SSScheduler.exe
C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe
C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Adadu\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://ph.search.yahoo.com/?type=635779&fr=spigot-yhp-ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [UIExec] "C:\Program Files\SMART BRO\UIExec.exe"
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [MalwareProtectionLive] C:\Users\Adadu\AppData\Local\MalwareProtectionLive\MalwareProtectionClient.exe
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_B39AB54E1CBAA3343BC9208D4A147D23] "C:\Program Files\Google\Chrome\Application\chrome.exe" –no-startup-window
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [KSS] "C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe" autorun
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.11.292\SSScheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-UpdaterService.exe
O23 - Service: Serviciul Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Serviciul Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kaspersky Security Scan Service (kss) - AO Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.292\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Windows\RtkAudioService.exe
O23 - Service: UI Assistant Service - Unknown owner - C:\Program Files\SMART BRO\AssistantServices.exe

–
End of file - 5585 bytes
 

Hello xxxerotech and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please follow these instructions in the order given.

===================================================


  • open HijackThis and click Do a system scan only.
  • place a check mark next to the following entry:


    C:\Users\Adadu\AppData\Local\MalwareProtectionLive\MalwareProtectionClient.exe
     

  • close all windows except for HijackThis and click Fix checked.

================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

AdwCleaner log
JRT.txt
Frst.txt
Addition.txt


Thanks

Satchfan

 

Thanks, Satchfan. Here are the logs that you requested.

 

ADWCLEANER

 

# AdwCleaner v5.107 - Logfile created 30/03/2016 at 16:53:31
# Updated 28/03/2016 by Xplode
# Database : 2016-03-30.1 [Server]
# Operating system : Windows 7 Ultimate  (x86)
# Username : Adadu - ADADU-PC
# Running from : C:\Users\Adadu\Downloads\adwcleaner_5.107.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Users\Adadu\AppData\Local\MalwareProtectionLive

***** [ Files ] *****

[-] File Deleted : C:\Users\Adadu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malware Protection Live.lnk
[-] File Deleted : C:\Users\Adadu\AppData\Roaming\Mozilla\Firefox\Profiles\9sdpg9pi.default-1450624626215\searchplugins\yahoo_ff.xml

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\14919ea49a8f3b4aa3cf1058d9a64cec
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.Protector
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.Protector.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MalwareProtectionLive
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{7AA57DF6-5CBB-481A-BE53-7C27B7326F7D}

***** [ Web browsers ] *****

[-] [C:\Users\Adadu\AppData\Roaming\Mozilla\Firefox\Profiles\9sdpg9pi.default-1450624626215\prefs.js] [Preference] Deleted : user_pref("keyword.URL", "hxxps://ph.search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=635779&p;=");
[-] [C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : utorrent.en.softonic.com

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [2277 bytes] - [30/03/2016 16:53:31]
C:\AdwCleaner\AdwCleaner[S1].txt - [2515 bytes] - [30/03/2016 16:48:42]
C:\AdwCleaner\AdwCleaner[S2].txt - [2588 bytes] - [30/03/2016 16:51:51]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2496 bytes] ##########
 

 

JRT

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 7 Ultimate x86
Ran by [removed] (Administrator) on 30.03.2016 at 17:10:09.07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 17

Successfully deleted: C:\Program Files\GUT8B60.tmp (File)
Successfully deleted: C:\Users\Adadu\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\191UFLB6 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Adadu\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\28AXC5A2 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Adadu\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5RA76TZJ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Adadu\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CGZGIGPH (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Adadu\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G8WFP9DY (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Adadu\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KK8RZI6Q (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Adadu\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q46L9SXS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Adadu\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VV55N2I4 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\191UFLB6 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\28AXC5A2 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5RA76TZJ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CGZGIGPH (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G8WFP9DY (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KK8RZI6Q (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q46L9SXS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VV55N2I4 (Temporary Internet Files Folder)



Registry: 1

Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_B39AB54E1CBAA3343BC9208D4A147D23 (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.03.2016 at 17:11:41.62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-03-2016 01
Ran by [removed] (administrator) on ADADU-PC (30-03-2016 17:23:22)
Running from C:\Users\[removed]\Downloads
[removed] Platform: Micro$hit MacOS X 7 Ultimate  (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Realtek Semiconductor) C:\Windows\RTKAUDIOSERVICE.EXE
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-UpdaterService.exe
() C:\Program Files\SMART BRO\AssistantServices.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [UIExec] => C:\Program Files\SMART BRO\UIExec.exe [139088 2011-04-02] ()
HKLM\…\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe [896632 2015-07-22] (BlueStack Systems, Inc.)
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Run: [KSS] => C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe [933856 2015-12-17] (AO Kaspersky Lab)
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\MountPoints2: {2b574cb8-c53b-11e2-93e2-00158307c969} - F:\Autorun.exe
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\MountPoints2: {de714692-81a2-11e4-887c-00158307c969} - F:\Autorun.exe
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\MountPoints2: {f4b13db3-c5de-11e2-bddb-00158307c969} - F:\Autorun.exe
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\MountPoints2: {f4b13dbf-c5de-11e2-bddb-00158307c969} - F:\Autorun.exe
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\MountPoints2: {f4b13dc8-c5de-11e2-bddb-00158307c969} - F:\Autorun.exe
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [10240 2009-07-14] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-02-23]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.292\SSScheduler.exe (McAfee, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 0.0.0.1    mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A8279C24-18BD-4C66-8A18-90C981C2330E}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-21] (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-21] (Google Inc.)
Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} -  No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Adadu\AppData\Roaming\Mozilla\Firefox\Profiles\9sdpg9pi.default-1450624626215
FF SelectedSearchEngine: Yahoo!
FF Homepage: hxxps://www.google.com.ph/?gfe_rd=cr&ei;=Ezt9VtG4LISg8wfit4u4CQ&gws;_rd=ssl
FF Keyword.URL: hxxps://ph.search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=635779&p;=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] ()
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll [2009-05-27] (Yahoo! Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin HKU\S-1-5-21-3559194677-4052321422-2392058216-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Adadu\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-02-20] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll [2009-12-02] (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-27] (Microsoft Corporation)
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-21] [not signed]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox-branding.js [2009-12-02]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox-l10n.js [2009-12-02]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox.js [2009-12-02]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\reporter.js [2009-12-02]

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxps://ph.search.yahoo.com/?type=635779&fr;=yo-yhp-ch
CHR StartupUrls: Default -> "hxxps://ph.search.yahoo.com/?type=635779&fr;=yo-yhp-ch"
CHR DefaultSearchURL: Default -> hxxps://ph.search.yahoo.com/search?fr=chr-yo_gc&ei;=utf-8&ilc;=12&type;=635779&p;={searchTerms}
CHR DefaultSearchKeyword: Default -> yahoo.com Search
CHR DefaultSuggestURL: Default -> hxxps://ff.search.yahoo.com/gossip?output=fxjson&command;={searchTerms}
CHR Profile: C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-07]
CHR Extension: (Google Docs) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-09]
CHR Extension: (Google Drive) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-20]
CHR Extension: (Trovi) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkppklolcafniedknpmhkncifhoamnd [2015-12-20]
CHR Extension: (YouTube) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-15]
CHR Extension: (Google Search) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-20]
CHR Extension: (Google Sheets) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-07]
CHR Extension: (Google Docs Offline) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-07]
CHR Extension: (Gmail) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-09]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [433784 2015-06-16] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [413304 2015-06-16] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [831096 2015-07-21] (BlueStack Systems, Inc.)
S2 kss; C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe [933856 2015-12-17] (AO Kaspersky Lab)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.292\McCHSvc.exe [239880 2016-02-06] (McAfee, Inc.)
R2 Themes; C:\Windows\system32\themeservice.dll [37376 2009-08-14] (Microsoft Corporation) [File not signed]
R2 UI Assistant Service; C:\Program Files\SMART BRO\AssistantServices.exe [253264 2011-01-24] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [131704 2015-06-16] (BlueStack Systems)
S3 massfilter; C:\Windows\System32\drivers\massfilter.sys [9216 2011-03-26] (MBB Incorporated)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2013-03-10] () [File not signed]
S3 ZTEusbvoice; C:\Windows\System32\DRIVERS\ZTEusbvoice.sys [107776 2011-03-26] (ZTE Incorporated)
U3 agmnptsw; C:\Windows\system32\Drivers\agmnptsw.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
U4 ehRecvr; no ImagePath
U4 ehSched; no ImagePath
U4 Fax; no ImagePath
U4 Mcx2Svc; no ImagePath
U4 TabletInputService; no ImagePath
U4 WMPNetworkSvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-30 17:23 - 2016-03-30 17:23 - 00010815 _____ C:\Users\Adadu\Downloads\FRST.txt
2016-03-30 17:20 - 2016-03-30 17:23 - 00000000 ____D C:\FRST
2016-03-30 17:20 - 2016-03-30 17:20 - 01725440 _____ (Farbar) C:\Users\Adadu\Downloads\FRST.exe
2016-03-30 17:11 - 2016-03-30 17:17 - 00003384 _____ C:\Users\Adadu\Desktop\JRT.txt
2016-03-30 16:58 - 2016-03-30 16:58 - 01610352 _____ (Malwarebytes) C:\Users\Adadu\Downloads\JRT.exe
2016-03-30 16:55 - 2016-03-30 16:55 - 00002575 _____ C:\Users\Adadu\Desktop\AdwCleaner[C1].txt
2016-03-30 16:47 - 2016-03-30 16:53 - 00000000 ____D C:\AdwCleaner
2016-03-30 16:47 - 2016-03-30 16:47 - 03102208 _____ C:\Users\Adadu\Downloads\adwcleaner_5.107.exe
2016-03-30 16:43 - 2016-03-30 16:43 - 00000000 ____D C:\Users\Adadu\Downloads\backups
2016-03-30 16:36 - 2016-03-30 16:36 - 00388608 _____ (Trend Micro Inc.) C:\Users\Adadu\Downloads\HiJackThis(1).exe
2016-03-29 13:32 - 2016-03-29 13:32 - 00000000 ____D C:\Users\Adadu\AppData\Roaming\.mono
2016-03-29 13:32 - 2016-03-29 13:32 - 00000000 ____D C:\ProgramData\.mono
2016-03-29 09:18 - 2016-03-29 09:18 - 00005586 _____ C:\Users\Adadu\Desktop\hijackthis 1.txt
2016-03-29 09:16 - 2016-03-29 09:16 - 00388608 _____ (Trend Micro Inc.) C:\Users\Adadu\Downloads\HiJackThis.exe
2016-03-25 03:47 - 2016-03-25 03:47 - 00000000 ____D C:\Users\Adadu\Documents\10 Cloverfield Lane 2016 CAM SUBBED-VOSE
2016-03-21 13:29 - 2016-03-21 15:49 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-03-16 09:48 - 2016-03-16 09:48 - 01503872 _____ (Skype Technologies S.A.) C:\Users\Adadu\Downloads\SkypeSetup(1).exe
2016-03-16 08:41 - 2016-03-16 08:41 - 01503872 _____ (Skype Technologies S.A.) C:\Users\Adadu\Downloads\SkypeSetup.exe
2016-03-09 15:21 - 2016-03-09 15:21 - 00000000 ____D C:\Users\Adadu\Documents\Ant-Man 2015 1080p BluRay x264 DTS-JYK
2016-03-07 05:36 - 2016-03-07 05:36 - 00000188 _____ C:\Windows\system32\ConnectLog.txt
2016-03-05 09:16 - 2016-03-05 09:16 - 00001025 _____ C:\Users\Public\Desktop\Kaspersky Security Scan.lnk
2016-03-05 09:16 - 2016-03-05 09:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
2016-03-05 09:16 - 2016-03-05 09:16 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2016-03-05 09:16 - 2016-03-05 09:16 - 00000000 ____D C:\Program Files\Kaspersky Lab
2016-03-05 09:09 - 2016-03-05 09:09 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2016-03-05 08:38 - 2016-03-05 08:38 - 00000000 ____D C:\KVRT_Data
2016-03-05 08:27 - 2016-03-05 08:28 - 04914720 _____ (Facebook Inc.) C:\Users\Adadu\Downloads\Kaspersky_T10208603781829221T_.exe
2016-03-04 12:22 - 2016-03-04 12:22 - 00000000 ____D C:\Users\Adadu\AppData\Roaming\Unity
2016-03-04 12:16 - 2016-03-04 12:16 - 00000000 ____D C:\Users\Adadu\AppData\LocalLow\Unity
2016-03-04 12:16 - 2016-03-04 12:16 - 00000000 ____D C:\Users\Adadu\AppData\Local\Unity
2016-03-04 12:15 - 2016-03-04 12:15 - 01091016 _____ (Unity Technologies ApS) C:\Users\Adadu\Downloads\UnityWebPlayer.exe
2016-03-02 08:53 - 2016-03-02 08:53 - 00000000 ____D C:\Users\Adadu\Documents\Blindspot.S01E03.HDTV.x264-LOL[ettv]

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-30 17:09 - 2013-03-10 16:02 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-03-30 16:59 - 2009-07-14 12:34 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-03-30 16:59 - 2009-07-14 12:34 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-03-30 16:58 - 2013-03-10 00:42 - 00717892 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-30 16:58 - 2009-07-14 10:37 - 00000000 ____D C:\Windows\inf
2016-03-30 16:54 - 2013-03-10 16:03 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-30 16:54 - 2009-07-14 12:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-03-30 16:38 - 2015-08-07 11:51 - 00002141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-30 16:38 - 2015-08-07 11:51 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-30 16:38 - 2013-03-10 16:03 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-29 18:00 - 2015-12-29 08:21 - 00000000 ____D C:\Users\Adadu\AppData\Local\Battle.net
2016-03-29 16:08 - 2015-12-29 08:18 - 00000000 ____D C:\Program Files\Battle.net
2016-03-29 09:47 - 2015-12-29 08:53 - 00000000 ____D C:\Program Files\Hearthstone
2016-03-28 16:39 - 2013-03-10 16:18 - 00000000 ____D C:\Users\Adadu\AppData\Roaming\vlc
2016-03-28 09:53 - 2015-12-21 03:58 - 00000000 ____D C:\Users\Adadu\AppData\Roaming\Azureus
2016-03-27 22:39 - 2015-12-21 03:58 - 00000000 ____D C:\Users\Adadu\Documents\Vuze Downloads
2016-03-26 15:35 - 2015-08-07 09:19 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2016-03-24 10:10 - 2013-03-10 16:02 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-03-24 10:10 - 2013-03-10 16:02 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-03-22 07:44 - 2015-07-05 14:41 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-03-21 18:18 - 2014-06-18 18:03 - 00000000 ____D C:\Users\Adadu\Desktop\Warcraft III
2016-03-20 19:24 - 2013-11-22 21:56 - 00000000 ____D C:\Users\Adadu\AppData\Roaming\dvdcss
2016-03-19 09:08 - 2009-07-14 12:53 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-03-12 17:28 - 2013-11-20 20:33 - 00000000 ____D C:\Users\Adadu\Desktop\VIDS

Some files in TEMP:
====================
C:\Users\Adadu\AppData\Local\Temp\GLF480B.EXE
C:\Users\Adadu\AppData\Local\Temp\GLFD29E.EXE
C:\Users\Adadu\AppData\Local\Temp\GLFD58B.EXE
C:\Users\Adadu\AppData\Local\Temp\ipclog.exe
C:\Users\Adadu\AppData\Local\Temp\libeay32.dll
C:\Users\Adadu\AppData\Local\Temp\msvcr120.dll
C:\Users\Adadu\AppData\Local\Temp\sqlite3.dll
C:\Users\Adadu\AppData\Local\Temp\vs60wiz.exe
C:\Users\Adadu\AppData\Local\Temp\{20F8852F-6D50-4D86-B75F-63FCD2BAECF5}-49.0.2618.8_49.0.2612.0_chrome_updater_3stage.exe
C:\Users\Adadu\AppData\Local\Temp\{95384514-D470-4A51-9B8D-994950D7D2EF}-50.0.2633.3_chrome_installer.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe
[2009-07-14 07:41] - [2009-09-03 13:51] - 2417664 ____A (Microsoft Corporation) 850AC6E1690E59DF6E6F37D076DD7443

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2013-11-20 22:10

==================== End of FRST.txt ============================

 

ADDITION

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version:05-03-2016 01
Ran by [removed] (2016-03-30 17:23:57)
Running from C:\Users\[removed]\Downloads
Micro$hit MacOS X 7 Ultimate  (X86) (2013-03-09 16:32:21)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Adadu (S-1-5-21-3559194677-4052321422-2392058216-1000 - Administrator - Enabled) => C:\Users\Adadu
Administrator (S-1-5-21-3559194677-4052321422-2392058216-500 - Administrator - Disabled)
Guest (S-1-5-21-3559194677-4052321422-2392058216-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 4.65 (HKLM\…\7-Zip) (Version:  - )
Adobe Flash Player 21 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 21.0.0.197 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated)
Adobe Reader 9.2 Lite (HKLM\…\{AC76BA86-7AD7-1033-7B44-A92000000001}) (Version: 9.2.0 - Adobe Systems Incorporated)
Advertising Center (Version: 0.0.0.1 - Nero AG) Hidden
AIMP2 (HKLM\…\AIMP2) (Version:  - AIMP DevTeam)
Battle.net (HKLM\…\Battle.net) (Version:  - Blizzard Entertainment)
Bejeweled Deluxe 1.862 (HKLM\…\Bejeweled Deluxe 1.862) (Version:  - )
BlueStacks App Player (HKLM\…\BlueStacks App Player) (Version: 0.9.30.9239 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM\…\{3792811C-832F-4392-B44A-24092901EDDC}) (Version: 0.9.30.9239 - BlueStack Systems, Inc.)
CDisplayEx 1.10.29 (HKLM\…\CDisplayEx_is1) (Version:  - Progdigy Software S.A.R.L.)
Combo Chaos Deluxe (HKLM\…\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7}) (Version:  - HALFPiNT Games)
Cool Timer 5.1.3.0 (HKLM\…\Cool Timer_is1) (Version:  - Harmony Hollow Software)
DolbyFiles (Version: 2.0 - Nero AG) Hidden
Google Chrome (HKLM\…\Google Chrome) (Version: 51.0.2693.2 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.21.135 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.29.5 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.1872 - Intel Corporation)
Kaspersky Security Scan (HKLM\…\InstallWIX_{D1282694-0693-41A8-ABC1-6D1FFC1F65C5}) (Version: 15.0.0.761 - Kaspersky Lab)
Kaspersky Security Scan (Version: 15.0.0.761 - Kaspersky Lab) Hidden
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.11.292.3 - McAfee, Inc.)
Microsoft Office Enterprise 2007 (HKLM\…\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual Basic 6.0 Professional Edition (HKLM\…\Visual Basic 6.0 Professional Edition) (Version:  - )
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Web Publishing Wizard 1.53 (HKLM\…\WebPost) (Version:  - )
Mozilla Firefox 45.0.1 (x86 en-US) (HKLM\…\Mozilla Firefox 45.0.1 (x86 en-US)) (Version: 45.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 45.0.1.5918 - Mozilla)
Nero 9 (HKLM\…\{8d2871f6-e558-40bf-81ec-6808343d09bf}) (Version:  - Nero AG)
Program4Pc DJ Music Mixer (HKLM\…\{8C6B8ECF-C649-46D9-A8ED-5BE2921F9ECD}) (Version: 5.5 - Program4Pc Inc.)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5653 - Realtek Semiconductor Corp.)
RKLauncher 0.43 Custom (HKLM\…\{40636246-26E3-4471-894D-B3940117ED36}_is1) (Version:  - ArG, Inc.)
Skype™ 4.1 (HKLM\…\{5C474A83-A45F-470C-9AC8-2BD1C251BF9A}) (Version: 4.1.141 - Skype Technologies S.A.)
SMART BRO (HKLM\…\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.1 - ZTE)
Unity Web Player (HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\UnityWebPlayer) (Version: 5.3.3f1 - Unity Technologies ApS)
VLC media player 1.0.3 (HKLM\…\VLC media player) (Version: 1.0.3 - VideoLAN Team)
Vuze (HKLM\…\8461-7759-5462-8226) (Version: 5.7.0.0 - Azureus Software, Inc.)
WinRAR archiver (HKLM\…\WinRAR archiver) (Version:  - )
Yahoo! Messenger (HKLM\…\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Y'z Dock 1.01 (HKLM\…\{B96F3609-1472-45CF-93FD-54743FD9FB61}_is1) (Version:  - ArG, Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3559194677-4052321422-2392058216-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Adadu\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0F851277-EB24-46C6-83FD-0965D17D37F3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-06-13] (Google Inc.)
Task: {2375F586-1009-41FB-B54E-30D8AF2B781D} - System32\Tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary => C:\Program Files\Windows Media Player\wmpnscfg.exe
Task: {4DFA292C-7CE9-4EB6-8CCC-CA58531187C3} - System32\Tasks\{4B6191D7-2F13-490E-BC8D-22FA730F99A9} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=7.18.0.112&LastError;=12002
Task: {A095C9DC-988E-4AF4-ADDB-38472EF9B3EA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-24] (Adobe Systems Incorporated)
Task: {B2210200-6478-40EE-9C9B-BE78008EE12C} - System32\Tasks\{EA3CB214-0F14-4B6A-8444-7AA5A289BE26} => Firefox.exe hxxp://ui.skype.com/ui/0/7.18.0.112/en/abandoninstall?source=lightinstaller&page;=tsInstall
Task: {D9BC0A1A-2CE5-4CC3-A444-1B088E1E4C06} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-06-13] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2014-12-12 10:09 - 2011-01-24 20:29 - 00253264 _____ () C:\Program Files\SMART BRO\AssistantServices.exe
2013-03-10 00:43 - 2008-09-17 02:18 - 00132608 _____ () C:\Program Files\WinRAR\rarext.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 10:04 - 2016-02-23 09:53 - 00000858 ____A C:\Windows\system32\Drivers\etc\hosts

0.0.0.1    mssplus.mcafee.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Adadu\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 0) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RKLauncher.lnk => C:\Windows\pss\RKLauncher.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Y'z Dock.lnk => C:\Windows\pss\Y'z Dock.lnk.CommonStartup
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: Messenger (Yahoo!) => "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: RtHDVCpl => RtHDVCpl.exe
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{4B2807DB-1DF1-4BAA-96A5-DC2EAED24D24}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{D9C3FBAD-7CDD-400E-8965-754B24CEF9D6}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{0A554C7A-9475-4C33-875F-CCC7635A253D}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{24B9BAF7-AD86-4D8F-B113-5E28E087B653}C:\users\adadu\desktop\warcraft iii\war3.exe] => (Block) C:\users\adadu\desktop\warcraft iii\war3.exe
FirewallRules: [UDP Query User{CA626E8D-4878-48CB-941E-FB15D120AE83}C:\users\adadu\desktop\warcraft iii\war3.exe] => (Block) C:\users\adadu\desktop\warcraft iii\war3.exe
FirewallRules: [{36AA861F-A8A2-403E-B884-F2DACC2767C0}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{ABEAA39D-FE67-48CD-BFC9-CAA1ACB8614D}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{B5AFE642-E302-4C1C-909D-D180CED95C8F}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [{0F2350B0-17E8-4050-A230-FF297DF7CD58}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [TCP Query User{06454344-5098-4587-AD60-8951019278DA}C:\program files\hearthstone\hearthstone.exe] => (Allow) C:\program files\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{858A25EE-52CC-461C-97A8-4552C54AE1AE}C:\program files\hearthstone\hearthstone.exe] => (Allow) C:\program files\hearthstone\hearthstone.exe
FirewallRules: [{DB625FA1-7C1B-49D7-864A-5A40369E3D21}] => (Block) C:\program files\hearthstone\hearthstone.exe
FirewallRules: [{13CC22F4-031B-4A21-8C97-B347D8251324}] => (Block) C:\program files\hearthstone\hearthstone.exe
FirewallRules: [{1C1A6F45-3531-4223-8BAA-8ADDEBAB292F}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

09-03-2013 22:51:30 Windows Update
09-03-2013 23:03:08 Windows Update
09-03-2013 23:06:15 Removed Microsoft Office Professional Edition 2003
09-03-2013 23:17:35 Installed Microsoft Office Enterprise 2007
10-03-2013 00:38:32 SPTD setup V1.62
10-03-2013 00:43:01 Installed Microsoft Office Professional Edition 2003
10-03-2013 15:52:53 Windows Update
12-04-2013 18:20:56 Scheduled Checkpoint
09-05-2013 04:04:36 Scheduled Checkpoint
25-05-2013 21:03:27 Installed SMART BRO
26-05-2013 16:40:20 Removed SMART BRO
26-05-2013 16:45:52 Installed SMART BRO
26-05-2013 16:50:46 Removed SMART BRO
26-05-2013 16:51:57 Installed SMART BRO
26-05-2013 17:02:13 Removed SMART BRO
06-07-2013 10:04:00 Scheduled Checkpoint
10-07-2013 06:18:30 Installed SMART BRO
28-07-2013 13:17:01 Removed SMART BRO
07-09-2013 22:07:12 Installed SMART BRO
24-09-2013 21:17:05 Scheduled Checkpoint
14-11-2013 21:04:53 Scheduled Checkpoint
12-12-2013 02:48:35 Removed SMART BRO
12-12-2013 02:51:07 Installed SMART BRO
12-12-2013 02:56:09 Removed SMART BRO
12-12-2014 10:08:56 Installed SMART BRO
07-08-2015 11:31:27 Installed Program4Pc DJ Music Mixer.
30-03-2016 17:10:16 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Base System Device
Description: Base System Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Could not start eventlog service, could not read events.

The Windows Event Log service is starting.
The Windows Event Log service could not be started.

A system error has occurred.

The system cannot find message text for message number 0x1069 in the message file for (null).

More help is available by typing NET HELPMSG 4201.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
Percentage of memory in use: 33%
Total physical RAM: 2911.04 MB
Available physical RAM: 1935.65 MB
Total Virtual: 5818.29 MB
Available Virtual: 4810.2 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.79 GB) (Free:86.1 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: C706724C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

P2P - I see you have P2P software, (Vuze (formerly Azureus), installed on your machine.

We are not here to pass judgment on file-sharing as a concept but we will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection.

If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.

Please see this topic for more information:

P2P File Sharing Risks.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

================================================

Antivirus

You have no resident antivirus, (AV), installed on your computer. If you use the Internet without an antivirus your computer will certainly become infected.

I’ll advise you about a couple of good, free AVs when we’re finished but meanwhile I suggest that you don’y use the Internet except for replying to this topic and for downloading any tools I ask you to run.

================================================

Uninstall Chrome
 

CHR dev: Chrome dev build detected! <======= ATTENTION


Unless you did this yourself, malware has changed your Chrome version into the Development Build. Among other things, this allows malware to install any extension it wants. Chrome needs to be uninstalled so we can deal with the infections present on your computer. After your computer is clean, Chrome can be reinstalled

First save all your bookmarks/favourites.

  • open Chrome, click on the 3 bars in the top right hand corner, select Bookmarks and then Bookmarks Manager
  • click on Organise and then select Export Bookmarks to HTML file, then choose Desktop to save it
  • again, click on the three bars in the top right hand corner and select Settings
  • in the list of Settings under “Sign in” click on Disconnect your Google Account – (if “Disconnect your Google Account” is not there, you will have to sign in using your Chrome username and password first to make it visible)
  • in the text of the next window click on “Google Dashboard” then, at the “Chrome sync” screen, click on Stop and Clear at the bottom
  • a box will open and ask for confirmation, click on OK (wait for this to complete before doing the next step)
  • when confirmation appears close that page and then click on Disconnect account
  • shut Google Chrome, then uninstall it from Control panel > programs and features
  • also remove Google Toolbar for Internet Explorer, (all versions) – see this.

Reboot the system and then reinstall Google Chrome from here

Repeat the process to reinstate your bookmarks by going to Bookmarks > Bookmarks Manager > Organise and select Import Bookmarks.

================================================

You need to move Farbar Recovery Scan Tool to your desktop otherwise fixes will not work.

  • go to your Downloads folder and locate Farbar Recovery Scan Tool
  • right click and select Cut
  • go to an empty spot on your desktop, right click and select Paste

Farbar Recovery Scan Tool should now be on your desktop.

================================================

Run Farbar Recovery Scan Tool

Open notepad (Start >All Programs > Accessories > Notepad). Please copy the entire contents of the code box below and paste it into Notepad.

HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [NoInternetOpenWith] 1
Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} -  No File
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Extension: (Trovi) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkppklolcafniedknpmhkncifhoamnd [2015-12-20]
CHR Extension: (Trovi) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkppklolcafniedknpmhkncifhoamnd [2015-12-20]
U3 agmnptsw; C:\Windows\system32\Drivers\agmnptsw.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
U4 ehRecvr; no ImagePath
U4 ehSched; no ImagePath
U4 Fax; no ImagePath
U4 Mcx2Svc; no ImagePath
U4 TabletInputService; no ImagePath
U4 WMPNetworkSvc; no ImagePath
C:\Users\Adadu\AppData\Local\Temp\GLF480B.EXE
C:\Users\Adadu\AppData\Local\Temp\GLFD29E.EXE
C:\Users\Adadu\AppData\Local\Temp\GLFD58B.EXE
C:\Users\Adadu\AppData\Local\Temp\ipclog.exe
C:\Users\Adadu\AppData\Local\Temp\libeay32.dll
C:\Users\Adadu\AppData\Local\Temp\msvcr120.dll
C:\Users\Adadu\AppData\Local\Temp\sqlite3.dll
C:\Users\Adadu\AppData\Local\Temp\vs60wiz.exe
C:\Users\Adadu\AppData\Local\Temp\{20F8852F-6D50-4D86-B75F-63FCD2BAECF5}-49.0.2618.8_49.0.2612.0_chrome_updater_3stage.exe
C:\Users\Adadu\AppData\Local\Temp\{95384514-D470-4A51-9B8D-994950D7D2EF}-50.0.2633.3_chrome_installer.exe
EmptyTemp:

NOTE: this script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

================================================

Download Malwarebytes-Anti-Malware

Click here

  • double-click mbam-setup.exe and follow the prompts to install the program – (Note: Vista & Windows 7, 8, 10 users, please right-click and select “Run as Administrator”)
  • select the “Scan” tab at the top
  • there are three scan types; choose Threat Scan, then click on Scan
  • when the scan is complete, if no malicious items are found you can close the program
  • if malicious items are found be sure that everything is checked and click Quarantine
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.

NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Logs to include with the next post:

Fixlog.txt
Mbam.txt


Satchfan

Let me get back to you to you with the MBAM. It's still updating its database.

 

FRST fix log

 

Fix result of Farbar Recovery Scan Tool (x86) Version:05-03-2016 01
Ran by [removed] (2016-03-31 08:47:51) Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal

==============================================

fixlist content:
*****************
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\…\Policies\Explorer: [NoInternetOpenWith] 1
Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} -  No File
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Extension: (Trovi) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkppklolcafniedknpmhkncifhoamnd [2015-12-20]
CHR Extension: (Trovi) - C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkppklolcafniedknpmhkncifhoamnd [2015-12-20]
U3 agmnptsw; C:\Windows\system32\Drivers\agmnptsw.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
U4 ehRecvr; no ImagePath
U4 ehSched; no ImagePath
U4 Fax; no ImagePath
U4 Mcx2Svc; no ImagePath
U4 TabletInputService; no ImagePath
U4 WMPNetworkSvc; no ImagePath
C:\Users\Adadu\AppData\Local\Temp\GLF480B.EXE
C:\Users\Adadu\AppData\Local\Temp\GLFD29E.EXE
C:\Users\Adadu\AppData\Local\Temp\GLFD58B.EXE
C:\Users\Adadu\AppData\Local\Temp\ipclog.exe
C:\Users\Adadu\AppData\Local\Temp\libeay32.dll
C:\Users\Adadu\AppData\Local\Temp\msvcr120.dll
C:\Users\Adadu\AppData\Local\Temp\sqlite3.dll
C:\Users\Adadu\AppData\Local\Temp\vs60wiz.exe
C:\Users\Adadu\AppData\Local\Temp\{20F8852F-6D50-4D86-B75F-63FCD2BAECF5}-49.0.2618.8_49.0.2612.0_chrome_updater_3stage.exe
C:\Users\Adadu\AppData\Local\Temp\{95384514-D470-4A51-9B8D-994950D7D2EF}-50.0.2633.3_chrome_installer.exe
EmptyTemp:
*****************

HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => value removed successfully.
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\LinkResolveIgnoreLinkInfo => value removed successfully.
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully.
HKU\S-1-5-21-3559194677-4052321422-2392058216-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInternetOpenWith => value removed successfully.
"HKCR\PROTOCOLS\Handler\dvd" => key removed successfully.
HKCR\CLSID\{12D51199-0DB5-46FE-A120-47A3D7D937CC} => key not found.
CHR dev: Chrome dev build detected! <======= ATTENTION => Error: No automatic fix found for this entry.
C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkppklolcafniedknpmhkncifhoamnd => not found.
C:\Users\Adadu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkppklolcafniedknpmhkncifhoamnd => not found.
agmnptsw => service not found.
ehRecvr => service removed successfully.
ehSched => service removed successfully.
Fax => service removed successfully.
Mcx2Svc => service removed successfully.
TabletInputService => service removed successfully.
WMPNetworkSvc => service removed successfully.
C:\Users\Adadu\AppData\Local\Temp\GLF480B.EXE => moved successfully
C:\Users\Adadu\AppData\Local\Temp\GLFD29E.EXE => moved successfully
C:\Users\Adadu\AppData\Local\Temp\GLFD58B.EXE => moved successfully
C:\Users\Adadu\AppData\Local\Temp\ipclog.exe => moved successfully
C:\Users\Adadu\AppData\Local\Temp\libeay32.dll => moved successfully
C:\Users\Adadu\AppData\Local\Temp\msvcr120.dll => moved successfully
C:\Users\Adadu\AppData\Local\Temp\sqlite3.dll => moved successfully
C:\Users\Adadu\AppData\Local\Temp\vs60wiz.exe => moved successfully
C:\Users\Adadu\AppData\Local\Temp\{20F8852F-6D50-4D86-B75F-63FCD2BAECF5}-49.0.2618.8_49.0.2612.0_chrome_updater_3stage.exe => moved successfully
C:\Users\Adadu\AppData\Local\Temp\{95384514-D470-4A51-9B8D-994950D7D2EF}-50.0.2633.3_chrome_installer.exe => moved successfully
EmptyTemp: => 6.5 GB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 08:48:23 ====

I think I messed up with the MBAM. Per your instruction, it should produce a log after the scan but it didn't. I also can't find the log tab from MBAM. I had to do the scan again and click on save results to get the log. I hope this is the log that you are looking for. The first scan found something and it quarantined it. (PUP.Optional.Spigot).

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 31.03.2016
Scan Time: 18:32
Logfile: mbam.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.03.31.02
Rootkit Database: v2016.03.30.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7
CPU: x86
File System: NTFS
User: Adadu

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 291147
Time Elapsed: 7 min, 39 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

I think I messed up with the MBAM. Per your instruction, it should produce a log after the scan but it didn't. I also can't find the log tab from MBAM. I had to do the scan again and click on save results to get the log.

Apologies. I'll have to check and update that.

I’d like to see the previous log

 

  • open Malwarebytes and click on the “History” tab
  • on the left click on Application Logs
  • locate the log from the first run and click on it to open it
  • click on Export and choose .txt file
  • please copy and paste the results in your reply.

Can you tell me what remaining problems there are.

Thanks

Satchfan

The icons in my desktop are not showing. I think it's because of the Bluestack app that have been installed. Someone is addicted with Clash of Clans here. I keep getting that captcha to almost all the websites that I visit.

 

I have uninstalled Chrome already but I haven't removed the Google Toolbar for Internet Explorer yet. I have no plans of installing Chrome. Is that alright? I'm fine using Mozilla Firefox.

 

Anyway, here is the previous log from MBAM.

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 31.03.2016
Scan Time: 18:20
Logfile: mbam.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.03.31.02
Rootkit Database: v2016.03.30.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7
CPU: x86
File System: NTFS
User: Adadu

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 291236
Time Elapsed: 7 min, 57 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
PUP.Optional.Spigot, C:\Users\Adadu\AppData\Roaming\Mozilla\Firefox\Profiles\9sdpg9pi.default-1450624626215\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "https://ph.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=635779&p=");),Replaced,[a8a6e2ac99005dd9a57bbb9427de7789]

Physical Sectors: 0
(No malicious items detected)


(end)

I have no plans of installing Chrome. Is that alright? I'm fine using Mozilla Firefox.

 

Apart from being "alright", I'd say that it's a sensible move. I wouldn't touch Chrome and the sooner others get wise to it and stop using it the better.

 

Apparently this “captcha” is a Clash of Clans safeguard against “bots” but I’m unsure about why it keeps appearing even when you’re not visiting their site.

We’ll run a tool to clear up your browsers and see if that solves the problem.

Download zoek.exe to your Desktop:

Important: Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here

  • on Windows Vista, 7, and 8, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:

    autoclean;
    emptyalltemp;
    emptyclsid;
    FFdefaults;
    iedefaults;
    
  • close any open programs
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

Let me know if there is any improvement.

Satchfan

Wow! Now I'm curious. Is Chrome really that bad?

 

I ran zoek.exe and I got a pop-up/system message/warning. I don't know what to call it. It just popped up. I can't seem to paste/attach the screenshot, so I'll just type the message:

 

To run this application, you first must install one of the following versions of the .NET framework:

v4.0.30319

Contact your application publisher for instructions about obtaining the appropriate version of the .NET framework.

 

I didn't click OK, instead I closed it by clicking the X button.

 

 

 

Zoek.exe continued running. It asked me to reboot my laptop, and here is the log that I got.

 

Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Adadu on 02.04.2016 at 17:04:58.67.
Micro$hit MacOS X 7 Ultimate  6.1.7600  x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Adadu\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

02.04.2016 17:07:01 Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\Program Files\Common Files\Services deleted successfully
C:\Users\Adadu\AppData\Roaming\DAEMON Tools Lite deleted successfully
C:\Users\Adadu\AppData\Roaming\WinRAR deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Adadu\AppData\Roaming\Mozilla\Firefox\Profiles\9sdpg9pi.default-1450624626215\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.com.ph/?gfe_rd=cr&ei=Ezt9VtG4LISg8wfit4u4CQ&gws_rd=ssl");
user_pref("browser.search.selectedEngine", "Yahoo!");
user_pref("keyword.URL", "https://ph.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=635779&p=");

Added to C:\Users\Adadu\AppData\Roaming\Mozilla\Firefox\Profiles\9sdpg9pi.default-1450624626215\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Adadu\AppData\Roaming\Mozilla\Firefox\Profiles\9sdpg9pi.default-1450624626215

user.js not found
—- FireFox user.js and prefs.js backups —-

prefs__1721_.backup

==== Deleting Files \ Folders ======================

C:\Program Files\GUM8B5F.tmp deleted
C:\Program Files\Yahoo! deleted
C:\PROGRA~2\Yahoo! deleted
C:\Users\Adadu\AppData\Local\Unity deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
"C:\Users\Adadu\AppData\LocalLow\Unity" deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Adadu\AppData\Roaming\Mozilla\Firefox\Profiles\9sdpg9pi.default-1450624626215
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

AppDir: C:\Program Files\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\Adadu\AppData\Roaming\Mozilla\Firefox\Profiles\9sdpg9pi.default-1450624626215
28D2C5CE5944E1B027CF5C8004CF89A1    - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll -    Adobe Acrobat
AF8A94BCB98C299C49B28CC12EBC0ED2    - C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll -    Google Update
7C67580DFE143EF19E7418B0F054B5F6    - C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_197.dll -    Shockwave Flash


==== Chromium Look ======================


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

==== Deleting Registry Keys ======================

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\UnityWebPlayer deleted successfully

==== Empty IE Cache ======================

C:\Users\Adadu\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Adadu\AppData\Local\Mozilla\Firefox\Profiles\9sdpg9pi.default-1450624626215\cache2 emptied successfully

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=318 folders=71 777527896 bytes)

==== Empty Temp Folders ======================

C:\Users\Adadu\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Adadu\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Adadu\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted

==== EOF on 02.04.2016 at 17:36:50.47 ======================
 

Wow! Now I'm curious. Is Chrome really that bad?

Some people have had problems with updated versions of Chrome but there is no option to go back to a previous version, (Google monitors the Internet and forbids anyone from offering old versions of Chrome to download). It’s auto-update is uncontrollable even if you change your registry settings because they regularly change the way they are delivered.

Another reason is that for some time now you have been unable to install extensions from a location other than the Chrome Web Store, (well it is possible but a bit of a phaff).

Also, your extension can be taken down for any reason and you can do nothing about it. You won’t be given a reason for the removal and you are not provided with a way to ask Google why your extension was removed – there is no way of contacting these morons that think they’re untouchable.

The main reason for me though is the fact that if an extension is bad, with other browsers we can give a “fix” but with Chrome you will have to uninstall/re-install Chrome plus all your bookmarks etc. Google have been aware of this flaw for 8 years now and have chosen to do nothing about it.

I could go on and on as there is more but I’ve already given Google enough of my time and besides, most people are like sheep and follow any new trend without heeding advice. :wall:

Suffice to say I will have nothing to do with Google.

==========================================

Can you tell me if you are still having problems.

Satchfan

I didn't know that Chrome has that many issues. I'm pretty much satisfied with Firefox for the silly reason that I like their logo. :) It reminds me of this manga I like, Naruto.

 

Anyway, other than the captcha I get, I don't think I have any more problem with laptop. This is one of the sites I get the captcha from.

 

http://thewatchseries.to/episode/ash_vs_evil_dead_s1_e8.html

 

I am really addicted to watching these TV series. I don't have cable so this is the only source I got to get my daily fix. :) Since my Internet connection isn't that great, I get buffer a lot of times while watching these series online, so that's why sometimes I prefer downloading it from torrent sites. Thanks for all your help Satchfan.

I'm not quite sure why there appear to be two web page addresses in one. When I copied and pasted the link it redirected me to a site that says “Access to the websites listed on this page has been blocked pursuant to orders of the High Court” and gives a list of the blocked sites. It is the ispcourtorders website. I'm afraid if you indulge in the habit of using torrent sites that circumvent this you may have to live with it.

 

You could try the first suggestion here and see if that clears it up, (better than uninstalling/re-installing Firefox). This will likely be a temporary solution as I expect the situation will soon re-appear..


Let’s run an online scan to be sure nothing is left.

Run ESET Online Scan

Note: This may take a long time so please be patient.

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use Internet Explorer, FireFox or Chrome for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan

  • click the Run Eset online Scanner button
  • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o    click on esetinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    o    double click on the Eset installer icon on your desktop.
     

  • check Yes, I accept the Terms of Use
  • click the Start button
  • accept any security warnings from your browser
  • check Enable detection of potentially unwanted applications
  • click Advanced settings and select the following:


    o    scan archives
    o    scan for potentially unsafe applications
    o    enable Anti-Stealth technology


    Note: Do not check Remove found threats:
     

  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • when the scan completes, push List of found threats
  • push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.


    Note - if ESET doesn't find any threats, no report will be created.
     

  • push the back button.
  • push Finish

When the scan is complete:

If no threats were found:


o    put a checkmark in "Uninstall application on close"
o    close program
o    report to me that nothing was found.
 

If threats were found:


o    click on "list of threats found"
o    click on "export to text file" and save it as ESET results and save to the desktop
o    click on back
o    put a checkmark in "Uninstall application on close"
o    click on finish
o    close program
o    copy and paste the report here.
 

Thanks

Satchfan

Thanks for checking the link out. Wow, that sounded serious. I guess I'll have to search for another website to watch my series.

 

Here's the log from ESET

 

C:\Users\Adadu\Downloads\VuzeLeapSetup.exe    a variant of Win32/Toolbar.Widgi.W potentially unwanted application
 

that sounded serious. I guess I'll have to search for another website to watch my series.

 

Good idea. ^_^

 

 

Let’s get rid of what Eset found.

Please copy all text in the code box below and paste it into Notepad:
 

@echo off
del /f /s /q " C:\Users\Adadu\Downloads\VuzeLeapSetup.exe"
del %0
  • save the Notepad file to your desktop and name it delfiles.bat
  • save type as "All Files"
  • on your desktop, double-click on delfiles.bat to run it, (a black CMD window will flash, then disappear - this is normal).

Can you tell me if there are any remaining problems: if not, I’ll send instructions later to tidy up.

Satchfan

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI