ok, i will check later, because i'm outside home and i can't right now, but i will check it in the afternoon, and i will post what happened, and about my first computer, asus windows 8.1, i found something else with rkill:
* HOSTS file entries found:
127.0.0.1 localhost
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
20 out of 35 HOSTS entries shown.
Please review HOSTS file for further entries.
and rouge killer found that two,
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 8 ¤¤¤
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-401314101-946683506-2006832327-1001\Software\Microsoft\Internet Explorer\Main | Start Page :
http://asus13.msn.com/?pc=ASJB -> Not selected
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-401314101-946683506-2006832327-1001\Software\Microsoft\Internet Explorer\Main | Start Page :
http://asus13.msn.com/?pc=ASJB -> Not selected
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-401314101-946683506-2006832327-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://asus13.msn.com/?pc=ASJB -> Not selected
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-401314101-946683506-2006832327-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://asus13.msn.com/?pc=ASJB -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 200.94.160.248 ([MEXICO (MX)]) -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 200.94.160.248 ([MEXICO (MX)]) -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{EEF98F8E-5F9D-4000-8E8A-75D19401AA9D} | DhcpNameServer : 200.94.160.248 ([X]) -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{EEF98F8E-5F9D-4000-8E8A-75D19401AA9D} | DhcpNameServer : 200.94.160.248 ([MEXICO (MX)]) -> Not selected
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 34 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomalyDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 tracking.opencandy.com.s3.amazonaws.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 media.opencandy.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.opencandy.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 tracking.opencandy.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 api.opencandy.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 installer.betterinstaller.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 installer.filebulldog.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.netDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 inno.bisrv.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 nsis.bisrv.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.file2desktop.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.goateastcach.usDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.guttastatdk.usDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.inskinmedia.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.insta.oibundles2.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.insta.playbryte.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.llogetfastcach.usDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.montiera.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.msdwnld.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.mypcbackup.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.ppdownload.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.riceateastcach.usDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.shyapotato.usDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.solimba.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.tuto4pc.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.appround.bizDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.bigspeedpro.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.bispd.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.bisrv.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.cdndp.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.download.sweetpacks.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.dpdownload.comDeleted
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.visualbee.netDeleted
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABF050 +++++
--- User ---
[MBR] 7566e601fc37fb011a6524949b91cc9c
[BSP] eefd9bcaf155d5eba732930c97cdddcb : Empty|VT.Unknown MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 100 MB
1 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 206848 | Size: 900 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 2050048 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 2312192 | Size: 455321 MB
4 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 934809600 | Size: 20490 MB
User = LL1 ... OK
User = LL2 ... OK
i choose to delete them, but after the restart the host entries are still there
i run MBAM and found nothing