Could you let me know what problems remain after this
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
HKU\S-1-5-21-1551321902-3525539811-1481564533-1002\...\Run: [UXmedia] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Chewy\AppData\Local\ATworks\stormPadcuda.dll
HKLM-x32\...\Run: [Secured Net] => "C:\WINDOWS\che_020716\netsafe.exe"
ShellIconOverlayIdentifiers: [FpPop] -> {A5662DF9-0C2E-4A56-9FE1-BACFF6966D88} => No File
ShellIconOverlayIdentifiers: [FunOverlay] -> {A5662DF9-0C2E-4A56-9FE1-BACFF6966D88} => No File
R2 Amazon 1Button App Service; C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe [436032 2016-02-17] (Amazon Inc.)
2016-07-04 06:40 - 2016-07-04 06:40 - 00000000 ____D C:\Users\Chewy\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence
2016-07-04 06:40 - 2016-07-04 06:40 - 00000000 _____ C:\Users\Chewy\AppData\Roaming\1.txt
2016-07-04 06:39 - 2016-07-04 06:39 - 00003624 _____ C:\WINDOWS\System32\Tasks\{33ACF9EE-FBBA-4BEF-A12A-2981D1BD5E7F}
2016-07-03 20:33 - 2016-07-03 20:33 - 00002375 _____ C:\Users\Chewy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium.lnk
2016-07-03 20:32 - 2016-07-04 21:32 - 00000946 _____ C:\WINDOWS\Tasks\Yahoo! Powered mirer.job
2016-07-03 20:32 - 2016-07-04 06:39 - 00000000 ____D C:\Users\Chewy\AppData\Roaming\{A50A93B1-8058-FEC7-EB6E-D91537BC242B}
2016-07-03 20:32 - 2016-07-04 06:32 - 00000000 ____D C:\ProgramData\{CC150976-4657-83B0-C091-1DF25AD3963C}
2016-07-03 20:32 - 2016-07-03 20:32 - 00004024 _____ C:\WINDOWS\System32\Tasks\Yahoo! Powered mirer
2016-07-03 20:30 - 2016-07-04 06:59 - 00000000 ____D C:\Users\Chewy\AppData\Local\ATworks
2016-07-03 20:28 - 2016-07-04 06:58 - 00000000 ____D C:\Users\Chewy\AppData\Roaming\ssn
2016-07-03 20:28 - 2016-07-03 20:28 - 00000000 ____D C:\WINDOWS\che_020716
2016-07-03 20:28 - 2016-07-02 08:58 - 00000133 _____ C:\WINDOWS\ie.vbs
Task: {000E0CD8-C7E5-4BBE-9BBE-DD4E37265873} - System32\Tasks\Funshion\FsLibraryLogonUpdate => C:\Program Files (x86)\Funshion Online\3.0.3.68\FsLibrary.exe
Task: {9E943153-1999-4D1F-9A26-5850568417E6} - System32\Tasks\DistromaticUpdater-periodic => C:\Program Files (x86)\Amazon Browser Settings\updater.exe [2016-04-03] (Distromatic) <==== ATTENTION
Task: {9FA8A741-EFD2-468E-B127-3ACE8D5AEC22} - System32\Tasks\DistromaticSearchProtect-logon => C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe [2016-04-03] (Distromatic) <==== ATTENTION
Task: {A5F731A4-1B28-4CEC-BDC0-DD6D1DA6C54B} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {A8B5112D-3309-484D-8E9B-B18667D25623} - System32\Tasks\DistromaticSearchProtect-hourly => C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe [2016-04-03] (Distromatic) <==== ATTENTION
Task: {BC778488-C85D-4920-8570-07F0C36C86FE} - System32\Tasks\DistromaticUpdater-logon => C:\Program Files (x86)\Amazon Browser Settings\updater.exe [2016-04-03] (Distromatic) <==== ATTENTION
Task: C:\WINDOWS\Tasks\Yahoo! Powered mirer.job => C:\ProgramData\{CC150976-4657-83B0-C091-1DF25AD3963C}\cimo.txt <==== ATTENTION
C:\Users\Chewy\AppData\Local\ATworks
C:\WINDOWS\che_020716
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your Desktop.
- Close all open programs and internet browsers.
- Double click on AdwCleaner.exe to run the tool
- Click the Scan button and wait for the process to complete.
- Click the logfile button and the log will open in Notepad
- Click on the Clean button follow the prompts.
- A log file will automatically open after the scan has finished and the PC has rebooted
- Please post the content of that log file with your next answer.
- The report will be saved in the C:\AdwCleaner folder.