Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Windows Process Manager 32 bit Virus, Maybe More


  • Please log in to reply

#106
Kirballer

Kirballer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 67 posts

My laptop is running much better already. The Windows Process Manager (32 bit) is no longer using memory or cpu space. :thumbsup:

 

There are a couple things I'd like to ask about, but after you've finished looking over everything in case you answer my questions along the way.


  • 0

Advertisements


#107
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 139 posts

I see you didn't uninstall uTorrent as I asked you to ....
 

µTorrent (HKU\S-1-5-21-2127724220-2420722970-824995399-1001\...\uTorrent) (Version: 3.5.0.44090 - BitTorrent Inc.)


I strongly advise you to unistall this program.

Use of torrent programs is one of the prime ways that people get infected. By using a torrent you are bypassing the protection provided by your firewall and AV, so it is not surprising that malware purveyors use torrents as their delivery method of preferance. A great many torrent downloads contain things other than what you expect, and in the 14 years or so that I've been helping people on this and other forums, the vast majority of people I've helped, have had torrent programs installed.

It's not coincidental.

If you choose to uninstall uTorrent, and once again I strongly advise that you do ..... reboot your computer once it's uninstalled.

Next ....

Surprise, surprise, there's some orphans left from the programs you've just uninstalled. So let's get rid of them .....
 

  • Start FRST and when it opens ....
  • Press Ctrl+y (Ctrl and y keys at the same time)
  • A blank notepad file named fixlist.txt will open.
  • Copy and paste the following into it (don't include Code: Select all) ....
ShortcutTarget: Registry Updater.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (No File)
Startup: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registry Updater.lnk [2018-01-05]
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2018-01-15] (Zemana Ltd.)
C:\WINDOWS\System32\drivers\zamguard64.sys
S3 MBAMWebProtection; \SystemRoot\system32\DRIVERS\mwac.sys [X]
C:\Windows\system32\DRIVERS\mwac.sys
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
C:\WINDOWS\System32\drivers\zam64.sys
2018-01-17 00:37 - 2018-01-17 00:39 - 000031380 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2018-01-16 16:33 - 2018-01-17 00:30 - 000183077 _____ C:\WINDOWS\ZAM.krnl.trace
2018-01-15 01:36 - 2018-01-15 01:36 - 000055232 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2018-01-15 01:35 - 2018-01-15 01:59 - 000000000 ____D C:\ProgramData\HitmanPro
2018-01-15 00:51 - 2018-01-17 00:32 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-01-15 00:51 - 2018-01-15 00:51 - 000203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2018-01-15 00:50 - 2018-01-15 00:50 - 000000000 ____D C:\Users\Kirby\AppData\Local\Zemana
2018-01-13 13:32 - 2018-01-13 13:32 - 000000000 ____D C:\Users\Kirby\AppData\Local\ESET
2018-01-11 11:22 - 2018-01-11 11:40 - 000000000 ____D C:\Users\Kirby\Desktop\mbar
2018-01-11 11:21 - 2018-01-11 11:22 - 014178840 _____ (Malwarebytes Corp.) C:\Users\Kirby\Desktop\mbar-1.10.3.1001.exe
2018-01-07 22:50 - 2018-01-07 22:50 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\3131252F.sys
2018-01-07 22:48 - 2018-01-07 22:48 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\5355870F.sys
2018-01-07 22:18 - 2018-01-17 00:30 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-01-07 22:18 - 2018-01-07 22:18 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\2E740B26.sys
2018-01-07 22:15 - 2018-01-11 11:40 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
CustomCLSID: HKU\S-1-5-21-2127724220-2420722970-824995399-1001_Classes\CLSID\{c31ca596-532d-a36f-e223-ce16b9ac70a56}\InprocServer32 -> 0xA05E04E4A077D2013B2205E4A077D201010000000100000000000000 => No File
MSCONFIG\Services: DellDataVault => 2
MSCONFIG\Services: DellDataVaultWiz => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: HomeNetSvc => 2
MSCONFIG\Services: McBootDelayStartSvc => 2
MSCONFIG\Services: McNaiAnn => 2
MSCONFIG\Services: McODS => 3
MSCONFIG\Services: mcpltsvc => 2
MSCONFIG\Services: McProxy => 2
MSCONFIG\Services: MSK80Service => 3
MSCONFIG\Services: NvStreamNetworkSvc => 3
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: Stereo Service => 2
HKU\S-1-5-21-2127724220-2420722970-824995399-1001\...\StartupApproved\Run: => "BlueStacks Agent"
HKU\S-1-5-21-2127724220-2420722970-824995399-1001\...\StartupApproved\Run: => "iFunBox"
DeleteQuarantine:
  • Press Ctrl+s to save fixlist.txt

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system


  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log

 

 


  • 0

#108
Kirballer

Kirballer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 67 posts
Interesting, I did uninstall it but it still says its there? Ill try again. I wont be able to reply with anything else until later this afternoon my time. Ill let you know then.
  • 0

#109
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 139 posts

If you've uninstalled it, then the log entry is probably just an orphan, and we can deal with it (and any other uTorrent orphans) once you've run the FRST fix in my last post.

 

Talk to you again once you've run the fix. 


  • 0

#110
Kirballer

Kirballer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 67 posts

I had enough extra time to run the fix this morning:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 17.01.2018
Ran by Kirby (17-01-2018 06:51:06) Run:10
Running from C:\Users\Kirby\Desktop
Loaded Profiles: Kirby (Available Profiles: Kirby)
Boot Mode: Normal
==============================================

fixlist content:
*****************
ShortcutTarget: Registry Updater.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (No File)
Startup: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registry Updater.lnk [2018-01-05]
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2018-01-15] (Zemana Ltd.)
C:\WINDOWS\System32\drivers\zamguard64.sys
S3 MBAMWebProtection; \SystemRoot\system32\DRIVERS\mwac.sys [X]
C:\Windows\system32\DRIVERS\mwac.sys
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
C:\WINDOWS\System32\drivers\zam64.sys
2018-01-17 00:37 - 2018-01-17 00:39 - 000031380 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2018-01-16 16:33 - 2018-01-17 00:30 - 000183077 _____ C:\WINDOWS\ZAM.krnl.trace
2018-01-15 01:36 - 2018-01-15 01:36 - 000055232 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2018-01-15 01:35 - 2018-01-15 01:59 - 000000000 ____D C:\ProgramData\HitmanPro
2018-01-15 00:51 - 2018-01-17 00:32 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-01-15 00:51 - 2018-01-15 00:51 - 000203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2018-01-15 00:50 - 2018-01-15 00:50 - 000000000 ____D C:\Users\Kirby\AppData\Local\Zemana
2018-01-13 13:32 - 2018-01-13 13:32 - 000000000 ____D C:\Users\Kirby\AppData\Local\ESET
2018-01-11 11:22 - 2018-01-11 11:40 - 000000000 ____D C:\Users\Kirby\Desktop\mbar
2018-01-11 11:21 - 2018-01-11 11:22 - 014178840 _____ (Malwarebytes Corp.) C:\Users\Kirby\Desktop\mbar-1.10.3.1001.exe
2018-01-07 22:50 - 2018-01-07 22:50 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\3131252F.sys
2018-01-07 22:48 - 2018-01-07 22:48 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\5355870F.sys
2018-01-07 22:18 - 2018-01-17 00:30 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-01-07 22:18 - 2018-01-07 22:18 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\2E740B26.sys
2018-01-07 22:15 - 2018-01-11 11:40 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
CustomCLSID: HKU\S-1-5-21-2127724220-2420722970-824995399-1001_Classes\CLSID\{c31ca596-532d-a36f-e223-ce16b9ac70a56}\InprocServer32 -> 0xA05E04E4A077D2013B2205E4A077D201010000000100000000000000 => No File
MSCONFIG\Services: DellDataVault => 2
MSCONFIG\Services: DellDataVaultWiz => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: HomeNetSvc => 2
MSCONFIG\Services: McBootDelayStartSvc => 2
MSCONFIG\Services: McNaiAnn => 2
MSCONFIG\Services: McODS => 3
MSCONFIG\Services: mcpltsvc => 2
MSCONFIG\Services: McProxy => 2
MSCONFIG\Services: MSK80Service => 3
MSCONFIG\Services: NvStreamNetworkSvc => 3
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: Stereo Service => 2
HKU\S-1-5-21-2127724220-2420722970-824995399-1001\...\StartupApproved\Run: => "BlueStacks Agent"
HKU\S-1-5-21-2127724220-2420722970-824995399-1001\...\StartupApproved\Run: => "iFunBox"
DeleteQuarantine:
*****************

"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" => not found
C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registry Updater.lnk => moved successfully
ZAM_Guard => Unable to stop service.
"HKLM\System\CurrentControlSet\Services\ZAM_Guard" => removed successfully
ZAM_Guard => service removed successfully
C:\WINDOWS\System32\drivers\zamguard64.sys => moved successfully
"HKLM\System\CurrentControlSet\Services\MBAMWebProtection" => removed successfully
MBAMWebProtection => service removed successfully
"C:\Windows\system32\DRIVERS\mwac.sys" => not found
"HKLM\System\CurrentControlSet\Services\ZAM" => removed successfully
ZAM => service removed successfully
"C:\WINDOWS\System32\drivers\zam64.sys" => not found
C:\WINDOWS\ZAM_Guard.krnl.trace => moved successfully
C:\WINDOWS\ZAM.krnl.trace => moved successfully
C:\WINDOWS\system32\Drivers\hitmanpro37.sys => moved successfully
C:\ProgramData\HitmanPro => moved successfully
C:\Program Files (x86)\Zemana AntiMalware => moved successfully
"C:\WINDOWS\system32\Drivers\zamguard64.sys" => not found
C:\Users\Kirby\AppData\Local\Zemana => moved successfully
C:\Users\Kirby\AppData\Local\ESET => moved successfully
C:\Users\Kirby\Desktop\mbar => moved successfully
C:\Users\Kirby\Desktop\mbar-1.10.3.1001.exe => moved successfully
C:\WINDOWS\system32\Drivers\3131252F.sys => moved successfully
C:\WINDOWS\system32\Drivers\5355870F.sys => moved successfully
C:\ProgramData\Malwarebytes => moved successfully
C:\WINDOWS\system32\Drivers\2E740B26.sys => moved successfully
C:\ProgramData\Malwarebytes' Anti-Malware (portable) => moved successfully
"HKU\S-1-5-21-2127724220-2420722970-824995399-1001_Classes\CLSID\{c31ca596-532d-a36f-e223-ce16b9ac70a56}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\DellDataVault" => removed successfully
HKLM\System\CurrentControlSet\Services\DellDataVault => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\DellDataVaultWiz" => removed successfully
HKLM\System\CurrentControlSet\Services\DellDataVaultWiz => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdate" => removed successfully
HKLM\System\CurrentControlSet\Services\gupdate => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdatem" => removed successfully
HKLM\System\CurrentControlSet\Services\gupdatem => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\HomeNetSvc" => removed successfully
"HKLM\System\CurrentControlSet\Services\HomeNetSvc" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McBootDelayStartSvc" => removed successfully
"HKLM\System\CurrentControlSet\Services\McBootDelayStartSvc" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McNaiAnn" => removed successfully
"HKLM\System\CurrentControlSet\Services\McNaiAnn" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McODS" => removed successfully
"HKLM\System\CurrentControlSet\Services\McODS" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\mcpltsvc" => removed successfully
"HKLM\System\CurrentControlSet\Services\mcpltsvc" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McProxy" => removed successfully
"HKLM\System\CurrentControlSet\Services\McProxy" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\MSK80Service" => removed successfully
"HKLM\System\CurrentControlSet\Services\MSK80Service" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\NvStreamNetworkSvc" => removed successfully
HKLM\System\CurrentControlSet\Services\NvStreamNetworkSvc => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\nvsvc" => removed successfully
HKLM\System\CurrentControlSet\Services\nvsvc => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Stereo Service" => removed successfully
HKLM\System\CurrentControlSet\Services\Stereo Service => key not found
"HKU\S-1-5-21-2127724220-2420722970-824995399-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\BlueStacks Agent" => removed successfully
"HKU\S-1-5-21-2127724220-2420722970-824995399-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\BlueStacks Agent" => not found
"HKU\S-1-5-21-2127724220-2420722970-824995399-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\iFunBox" => removed successfully
"HKU\S-1-5-21-2127724220-2420722970-824995399-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\iFunBox" => not found
could not remove "C:\FRST\Quarantine\C\WINDOWS\system32\Drivers\zamguard64.sys.xBAD" => Scheduled to remove on reboot.
could not remove "C:\FRST\Quarantine" => Scheduled to remove on reboot.
"C:\FRST\Quarantine" => could not remove

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 17-01-2018 06:54:50)

"C:\FRST\Quarantine\C\WINDOWS\system32\Drivers\zamguard64.sys.xBAD" => removed successfully
"C:\FRST\Quarantine" => removed successfully

==== End of Fixlog 06:54:50 ====


  • 0

#111
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 139 posts

OK, now let's see if we can find the uTorrent orphans so that we can remove them.

  • Double click Frst64.exe to launch it.
  • FRST will start to run.
  • When the tool opens click Yes to the disclaimer.
  • Copy/Paste or Type the following line into the Search: box.

SearchAll:µTorrent;utorrent;torrent

  • Press the Search Files button.
  • When finished searching a log will open on your Desktop ... Search.txt
  • Please post it in your next reply.



 
  • 0

#112
Kirballer

Kirballer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 67 posts
My laptop cant open any websites because it says the DNS server isnt responding. Illpost the log here but Ill have to save the file to a usb and transfer it to my clean computer.

Edited by Kirballer, Yesterday, 05:06 PM.

  • 0

#113
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 139 posts

Please try the following ...
 

  • Start FRST and when it opens ....
  • Press Ctrl+y (Ctrl and y keys at the same time)
  • A blank notepad file named fixlist.txt will open.
  • Copy and paste the following into it ....

cmd: ipconfig /registerdns
  • Press Ctrl+s to save fixlist.txt

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system


  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log and let me know if that resolves things.

 

If this doesn't work, try re-booting your computer, and see if this resolves your DNS problem.


  • 0

#114
Kirballer

Kirballer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 67 posts
It's still giving me the same error. 
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 17.01.2018
Ran by Kirby (17-01-2018 17:27:35) Run:11
Running from C:\Users\Kirby\Desktop
Loaded Profiles: Kirby (Available Profiles: Kirby)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
cmd: ipconfig /registerdns
*****************
 
 
========= ipconfig /registerdns =========
 
 
Windows IP Configuration
 
Registration of the DNS resource records for all adapters of this computer has been initiated. Any errors will be reported in the Event Viewer in 15 minutes.
 
========= End of CMD: =========
 
 
==== End of Fixlog 17:27:38 ====

  • 0

#115
Kirballer

Kirballer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 67 posts

Sorry that we're kind of doing two things at once. I just thought it was odd about the internet issue. If you like, we can fix that later and continue on the other programs and cleanup.

 

For uTorrent, I deleted it and it still shows up when I click on uninstall applications. It won't let me uninstall again because it can't find the file location.

 

Here is the search.txt:

 

Farbar Recovery Scan Tool (x64) Version: 17.01.2018
Ran by Kirby (17-01-2018 17:42:19)
Running from C:\Users\Kirby\Desktop
Boot Mode: Normal
 
================== Search Files: "SearchAll:µTorrent;utorrent;torrent" =============
 
File:
========
C:\Windows\Prefetch\UTORRENT.EXE-D5021709.pf
[2018-01-05 14:08][2018-01-17 00:29] 000031323 _____ () D69957F11E062DA84FC5CE70210C4A80 [File not signed]
 
C:\Users\Kirby\Downloads\SPORE - [PC-DVD].torrent
[2017-11-03 22:09][2017-11-03 22:09] 000012120 _____ () 28653C1AB41E86B45A5F4299216C2C72 [File not signed]
 
C:\Users\Kirby\AppData\LocalLow\uTorrent\uTorrent_13956_00D07698_2142462829
[2017-11-03 22:11][2017-11-03 22:11] 000016384 _____ () 679672A5004E0AF50529F33DB5469699 [File not signed]
 
C:\Users\Kirby\AppData\LocalLow\uTorrent\uTorrent_13956_00D077C8_1036381570
[2017-11-03 22:11][2017-11-03 22:11] 000016384 _____ () 679672A5004E0AF50529F33DB5469699 [File not signed]
 
C:\Users\Kirby\AppData\LocalLow\uTorrent\uTorrent_16588_061499D0_1464353291
[2018-01-05 14:07][2018-01-05 14:07] 000016384 _____ () 679672A5004E0AF50529F33DB5469699 [File not signed]
 
C:\Users\Kirby\AppData\LocalLow\uTorrent\uTorrent_16588_06149C30_734337964
[2018-01-05 14:07][2018-01-05 14:07] 000016384 _____ () 679672A5004E0AF50529F33DB5469699 [File not signed]
 
C:\Users\Kirby\AppData\LocalLow\uTorrent\uTorrent_6108_03D14348_95402464
[2017-11-03 22:17][2017-11-03 22:17] 000016384 _____ () 679672A5004E0AF50529F33DB5469699 [File not signed]
 
C:\Users\Kirby\AppData\LocalLow\uTorrent\uTorrent_6108_03D149D0_200783180
[2017-11-03 22:17][2017-11-03 22:17] 000016384 _____ () 679672A5004E0AF50529F33DB5469699 [File not signed]
 
 
folder:
========
2017-11-03 22:11 - 2018-01-05 14:07 _____ C:\Users\Kirby\AppData\LocalLow\uTorrent
 
Registry:
========
 
===================== Search result for "µTorrent" ==========
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"DisplayName"="µTorrent"
 
 
===================== Search result for "utorrent" ==========
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\509f665f_0]
""="{2}.\\?\hdaudio#func_01&ven_1102&dev_0011&subsys_10280685&rev_1009#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\lineouttopo/00010001|\Device\HarddiskVolume7\Users\Kirby\AppData\Roaming\uTorrent\updates\3.5.0_44090\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"utorrentie.exe"="11000"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION]
"utorrentie.exe"="0"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION]
"utorrentie.exe"="1"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"Applications\uTorrent.exe_.torrent"="0"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"uTorrent_.torrent"="0"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithList]
"a"="uTorrent.exe"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithProgids]
"uTorrent"=""
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"DisplayIcon"=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe",0"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"DisplayName"="µTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"UninstallString"=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" /UNINSTALL"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"InstallLocation"="C:\Users\Kirby\AppData\Roaming\uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"URLInfoAbout"="http://www.utorrent.com"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"Publisher"="BitTorrent Inc."
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe"="0x5341435001000000000000000700000028000000C04D1E009D951E0001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000500000000000000000000040000000000000000000000000000000004F410000000000000100000001000000000000000000000000000000000000000000000000000000FF3BD70D000000000600000000000000"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btapp]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btinstall]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btkey]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch\OpenWithProgids]
"uTorrent"=""
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btskin]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent\OpenWithProgids]
"uTorrent"=""
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe\shell\open\command]
""=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\DefaultIcon]
""="C:\Users\Kirby\AppData\Roaming\uTorrent\maindoc.ico"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\shell\open\command]
""=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\DefaultIcon]
""="C:\Users\Kirby\AppData\Roaming\uTorrent\maindoc.ico"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\shell\open\command]
""=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent\Content Type]
""="application/x-bittorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent\DefaultIcon]
""="C:\Users\Kirby\AppData\Roaming\uTorrent\maindoc.ico"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent\shell\open\command]
""=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
 
===================== Search result for "torrent" ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-bittorrent]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-bittorrent]
"Extension"=".torrent"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-bittorrent-app]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-bittorrent-appinst]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-bittorrent-key]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-bittorrent-skin]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-bittorrentsearchdescription+xml]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\509f665f_0]
""="{2}.\\?\hdaudio#func_01&ven_1102&dev_0011&subsys_10280685&rev_1009#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\lineouttopo/00010001|\Device\HarddiskVolume7\Users\Kirby\AppData\Roaming\uTorrent\updates\3.5.0_44090\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"utorrentie.exe"="11000"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION]
"utorrentie.exe"="0"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION]
"utorrentie.exe"="1"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"Applications\uTorrent.exe_.torrent"="0"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"uTorrent_.torrent"="0"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithList]
"a"="uTorrent.exe"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithProgids]
"uTorrent"=""
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"DisplayIcon"=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe",0"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"DisplayName"="µTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"UninstallString"=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" /UNINSTALL"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"InstallLocation"="C:\Users\Kirby\AppData\Roaming\uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"URLInfoAbout"="http://www.utorrent.com"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"Publisher"="BitTorrent Inc."
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe"="0x5341435001000000000000000700000028000000C04D1E009D951E0001000000000000000000000A00210000DB80FDAC2839D301000000000000000002000000500000000000000000000040000000000000000000000000000000004F410000000000000100000001000000000000000000000000000000000000000000000000000000FF3BD70D000000000600000000000000"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btapp]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btapp]
"Content Type"="application/x-bittorrent-app"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btinstall]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btinstall]
"Content Type"="application/x-bittorrent-appinst"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btkey]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btkey]
"Content Type"="application/x-bittorrent-key"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch]
"Content Type"="application/x-bittorrentsearchdescription+xml"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch\OpenWithProgids]
"uTorrent"=""
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btskin]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btskin]
"Content Type"="application/x-bittorrent-skin"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent]
""="uTorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent]
"Content Type"="application/x-bittorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent\OpenWithProgids]
"uTorrent"=""
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe\shell\open\command]
""=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent]
""="bittorrent URI"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent]
"Content Type"="application/x-bittorrent-protocol"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\DefaultIcon]
""="C:\Users\Kirby\AppData\Roaming\uTorrent\maindoc.ico"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\shell\open\command]
""=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\DefaultIcon]
""="C:\Users\Kirby\AppData\Roaming\uTorrent\maindoc.ico"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\shell\open\command]
""=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\MIME\Database\Content Type\application/x-bittorrent]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\MIME\Database\Content Type\application/x-bittorrent]
"Extension"=".torrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\MIME\Database\Content Type\application/x-bittorrent-app]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\MIME\Database\Content Type\application/x-bittorrent-appinst]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\MIME\Database\Content Type\application/x-bittorrent-key]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\MIME\Database\Content Type\application/x-bittorrent-skin]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\MIME\Database\Content Type\application/x-bittorrentsearchdescription+xml]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent]
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent\Content Type]
""="application/x-bittorrent"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent\DefaultIcon]
""="C:\Users\Kirby\AppData\Roaming\uTorrent\maindoc.ico"
 
[HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent\shell\open\command]
""=""C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
 
====== End of Search ======

Edited by Kirballer, Yesterday, 05:49 PM.

  • 0

Advertisements


#116
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 139 posts
  • Start FRST and when it opens ....
  • Press Ctrl+y (Ctrl and y keys at the same time)
  • A blank notepad file named fixlist.txt will open.
  • Copy and paste the following into it  ....
C:\Windows\Prefetch\UTORRENT.EXE-D5021709.pf
C:\Users\Kirby\AppData\LocalLow\uTorrent

[-HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
[-HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe]
[-HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent]
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION | utorrentie.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION | utorrentie.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION | utorrentie.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts | Applications\uTorrent.exe_.torrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts | uTorrent_.torrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithList | a
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store | C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btapp |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btinstall |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btkey |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btskin |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe\shell\open\command |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\DefaultIcon |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\shell\open\command |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\DefaultIcon |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\shell\open\command |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\509f665f_0 |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION | utorrentie.exe
DeleteValue:  DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION | utorrentie.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION | utorrentie.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts | Applications\uTorrent.exe_.torrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts | uTorrent_.torrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithList | a
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store |   C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btapp |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btinstall |
DeleteValue: DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btkey |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btskin |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe\shell\open\command |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\DefaultIcon |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\shell\open\command |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\DefaultIcon |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\shell\open\command |
  • Press Ctrl+s to save fixlist.txt

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system


  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log

  • 0

#117
Kirballer

Kirballer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 67 posts
Fix result of Farbar Recovery Scan Tool (x64) Version: 17.01.2018
Ran by Kirby (17-01-2018 19:07:34) Run:12
Running from C:\Users\Kirby\Desktop
Loaded Profiles: Kirby (Available Profiles: Kirby)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
C:\Windows\Prefetch\UTORRENT.EXE-D5021709.pf
C:\Users\Kirby\AppData\LocalLow\uTorrent
 
[-HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
[-HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe]
[-HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent]
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION | utorrentie.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION | utorrentie.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION | utorrentie.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts | Applications\uTorrent.exe_.torrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts | uTorrent_.torrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithList | a
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store | C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btapp |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btinstall |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btkey |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btskin |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe\shell\open\command |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\DefaultIcon |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\shell\open\command |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\DefaultIcon |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\shell\open\command |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\509f665f_0 |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION | utorrentie.exe
DeleteValue:  DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION | utorrentie.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION | utorrentie.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts | Applications\uTorrent.exe_.torrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts | uTorrent_.torrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithList | a
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store |   C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btapp |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btinstall |
DeleteValue: DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btkey |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btskin |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent\OpenWithProgids | uTorrent
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe\shell\open\command |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\DefaultIcon |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\shell\open\command |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\DefaultIcon |
DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\shell\open\command |
*****************
 
C:\Windows\Prefetch\UTORRENT.EXE-D5021709.pf => moved successfully
C:\Users\Kirby\AppData\LocalLow\uTorrent => moved successfully
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent" => removed successfully
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe" => removed successfully
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent" => removed successfully
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION \\ utorrentie.exe" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION \\ utorrentie.exe" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION \\ utorrentie.exe" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts \\ Applications\uTorrent.exe_.torrent" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts \\ uTorrent_.torrent" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithList \\ a" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithProgids \\ uTorrent" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store \\ C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btapp \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btinstall \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btkey \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch\OpenWithProgids \\ uTorrent" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btskin \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent\OpenWithProgids \\ uTorrent" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe\shell\open\command \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\DefaultIcon \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\shell\open\command \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\DefaultIcon \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\shell\open\command \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\uTorrent \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\509f665f_0 \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION \\ utorrentie.exe" => not found
"DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION \\ utorrentie.exe" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION \\ utorrentie.exe" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts \\ Applications\uTorrent.exe_.torrent" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts \\ uTorrent_.torrent" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithList \\ a" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithProgids \\ uTorrent" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store \\   C:\Users\Kirby\AppData\Roaming\uTorrent\uTorrent.exe" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btapp \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btinstall \\" => not found
"DeleteValue: HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btkey \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btsearch\OpenWithProgids \\ uTorrent" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.btskin \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\.torrent\OpenWithProgids \\ uTorrent" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Applications\uTorrent.exe\shell\open\command \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\DefaultIcon \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\bittorrent\shell\open\command \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\DefaultIcon \\" => not found
"HKEY_USERS\S-1-5-21-2127724220-2420722970-824995399-1001\Software\Classes\Magnet\shell\open\command \\" => not found
 
==== End of Fixlog 19:07:36 ====

  • 0

#118
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 139 posts

How is your computer running now ?

 

Are you still having problems with opening websites ?

 

If you are, then please run a new scan with FRST, and post me both the FRST.txt and Addition.txt logs.


  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users


    Google (1)

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP