a log was not created, it said that it was fixed, and needed to reboot the computer. after reboot no log appeared. nvm i found the fixlog in the FRST folder.
Edited by jseyuin, 25 June 2014 - 11:57 PM.
Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
a log was not created, it said that it was fixed, and needed to reboot the computer. after reboot no log appeared. nvm i found the fixlog in the FRST folder.
Edited by jseyuin, 25 June 2014 - 11:57 PM.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-06-2014
Ran by Justin at 2014-06-26 01:52:56 Run:1
Running from C:\Users\Justin\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
C:\Users\Justin\AppData\Roaming\Adobe\Flash Player\SpeedCache\IDMan.exe
Reboot:
End
*****************
C:\Users\Justin\AppData\Roaming\Adobe\Flash Player\SpeedCache\IDMan.exe => Moved successfully.
The system needed a reboot.
==== End of Fixlog ====
Cpu shows to run between 2-9%
Wasn't that easy? Let's check for remnantsCpu shows to run between 2-9%
trying a twitch stream right now and its going no higher that 30%. I opened 4 youtube channels , and two twitch channels, as well as a game of hearthstone ,and its below 50% :-D
Running malware scanner. I think it may take a while.
Edited by jseyuin, 26 June 2014 - 12:06 AM.
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 6/26/2014
Scan Time: 2:04:39 AM
Logfile: MbamLog.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.06.26.02
Rootkit Database: v2014.06.23.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Justin
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 280395
Time Elapsed: 3 min, 5 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 2
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035, , [47c3f7860c6f89adbc1b9afd00029070],
Files: 20
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\03dc1e50b634438b2b3439535f16e4ef, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\04938c177ebb9cb453d87b2b2e61f6f5, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\20133249a4819b59eedc890d3ecbea3b, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\2c5bb40fed401a1ba3a47fa6fa6f3183, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\355c13830b2b10319e09666596b903c3, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\4975fea9f6ac679b3b23754cd30d3159, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\4c535d174e60724e5459e1c8694467bc, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\4ca34f9b7ccf897c79f070b43a9f26ef, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\56104db0c4deb1778d8ab81fa5c0ca93, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\8546b02629f6906abe4dab3c43626548, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\9d3c1dea253fc011ee75ec848618774f, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\aa72d42e9ee0332c52b3a8d73d5a6b53, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\ac33c7cca1cadc79882c16e23326c28f, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\bed6e8a15788e109cee2268d3fa80537, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\c3a43239291502e5ee7043e339659ba5, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\cc94cdb252e9dd2338a096e332f4635b, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.FreeCauseTB.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\FCTB\{5835466c-49af-4cbe-b102-a8c8b6313749}\62035\eac5556352c27a7245384e50c443f51e, , [47c3f7860c6f89adbc1b9afd00029070],
PUP.Optional.Conduit.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\prefs.js, Good: (), Bad: (user_pref("CT3115642.SearchFromAddressBarUrl", "http://search.condui...archSource=2&q="), ,[c545ec91fc7ff93deaec8a2cfc086d93]
PUP.Optional.Conduit.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\prefs.js, Good: (), Bad: (user_pref("CT3115642.CT3115642.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"http://search.condui...&Lay=1&UM=UM_ID\"}"), ,[8d7d6e0f1c5f8bab766fd9dd2ed68878]
PUP.Optional.Conduit.A, C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\prefs.js, Good: (), Bad: (user_pref("CT3115642.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"http://search.condui...SSPV=&Lay=1&UM=\"}"), ,[be4c9be2c2b9aa8cfbea4c6a5aaa847c]
Physical Sectors: 0
(No malicious items detected)
(end)
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=3c270b669e6592488cc5f8a81808f48c
# engine=18891
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-06-26 07:34:32
# local_time=2014-06-26 03:34:32 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='AVG AntiVirus Free Edition 2014'
# compatibility_mode=1051 16777213 100 100 0 89962456 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 6707230 155311522 0 0
# scanned=399450
# found=6
# cleaned=0
# scan_time=4756
sh=3CD0AF1C27068B736BCFA96E484C8040DB35CC43 ft=1 fh=1c16b9d0a9498207 vn="a variant of Win32/BitCoinMiner.AK potentially unsafe application" ac=I fn="C:\FRST\Quarantine\C\Users\Justin\AppData\Roaming\Adobe\Flash Player\SpeedCache\IDMan.exe.xBAD"
sh=FA2F38133D10A9DEC9E4BE3AF8CB796441FDAEA7 ft=1 fh=b21e34b7daf343d1 vn="a variant of Win32/BitCoinMiner.AK potentially unsafe application" ac=I fn="C:\Users\Justin\Desktop\Xilisoft.Video.Converter.Ultimate.v7.7.2.20130508.Incl.Patch-TRH\x-video-converter-ultimate7.exe"
sh=CB8FA4F1C9B64D23D7DF0860396794F372980A61 ft=0 fh=0000000000000000 vn="Win32/AdWare.Adpeak.B application" ac=I fn="E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\bootstrap.js"
sh=AFF6026DD64A6AD95B73CD2D1EE61EAEBA192C4E ft=0 fh=0000000000000000 vn="Win32/AdWare.Adpeak.B application" ac=I fn="E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\bootstrap.js.old"
sh=3E96B9735719402FC4DF891275A3B0CEACABC6F1 ft=0 fh=0000000000000000 vn="Win32/AdWare.Adpeak.B application" ac=I fn="E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\manifest.json"
sh=C8CBA85BBAB2DB85E803CDCBDD7BB81223F62BDC ft=1 fh=ef5c9b08e8a9305e vn="a variant of Win32/Conduit.SearchProtect.N potentially unwanted application" ac=I fn="E:\Users\Beleg\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\extensions\{46a3135d-3683-48cf-b94c-82655cbc0e8a}\Plugins\npConduitFirefoxPlugin.dll"
Start C:\Users\Justin\Desktop\Xilisoft.Video.Converter.Ultimate.v7.7.2.20130508.Incl.Patch-TRH\ E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\bootstrap.js E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\bootstrap.js.old E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\manifest.json E:\Users\Beleg\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\extensions\{46a3135d-3683-48cf-b94c-82655cbc0e8a}\Plugins\npConduitFirefoxPlugin.dll End
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 27-06-2014
Ran by Justin at 2014-06-27 16:18:14 Run:2
Running from C:\Users\Justin\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
C:\Users\Justin\Desktop\Xilisoft.Video.Converter.Ultimate.v7.7.2.20130508.Incl.Patch-TRH\
E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\bootstrap.js
E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\bootstrap.js.old
E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\manifest.json
E:\Users\Beleg\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\extensions\{46a3135d-3683-48cf-b94c-82655cbc0e8a}\Plugins\npConduitFirefoxPlugin.dll
End
*****************
C:\Users\Justin\Desktop\Xilisoft.Video.Converter.Ultimate.v7.7.2.20130508.Incl.Patch-TRH => Moved successfully.
E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\bootstrap.js => Moved successfully.
E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\bootstrap.js.old => Moved successfully.
E:\Users\Beleg\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\manifest.json => Moved successfully.
E:\Users\Beleg\AppData\Roaming\Mozilla\Firefox\Profiles\3dfpt7i8.default\extensions\{46a3135d-3683-48cf-b94c-82655cbc0e8a}\Plugins\npConduitFirefoxPlugin.dll => Moved successfully.
==== End of Fixlog ====
Seems to be running super well, thats awesome!
♣ Removal of Tools and Quarantined Files ♣
♣ Prevention and Future Guidelines ♣
0 members, 0 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.