Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

I have malware on PC after downloading free software [Solved]


  • This topic is locked This topic is locked

#16
Nas

Nas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

ACtually it seems that because my Chrome was reset and I was logged out of it, my pop up blocker extension wasnt working, I assume these pop ups were always there. 

 

So no difference really, although it seems as though the frequency of these adverts have increased.


  • 0

Advertisements


#17
ruggie_uk

ruggie_uk

    Trusted Helper

  • Malware Removal
  • 2,083 posts

Ok, let's take a fresh look using FRST to see what's lurking now.
 
Initial FRST Scan

Please download Farbar Recovery Scan Tool and save it to your Desktop. There will be 2 versions offered, if you know which version is the one you need, download that one, if not, download both, only one will work on your computer, that is the one you need.

  • Right click frst.png to run as administrator. When the tool opens click Yes to the disclaimer.
  • Ensure that the following are ticked as in the image below
    Addition.txt
    frst-addition.png
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • This will also generate another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

  • 0

#18
Nas

Nas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-02-2015 01
Ran by Manraj at 2015-02-19 19:34:22
Running from C:\Users\Manraj\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-2917843931-2079053167-3573301051-1001\...\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
AAS - Lounge Lizard EP-4 (HKLM-x32\...\Lounge Lizard EP-4) (Version:  - Applied Acoustics Systems)
AMD Catalyst Install Manager (HKLM\...\{00957033-C081-5235-665A-A014A6E2FF7B}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.11 Beta2 - Michael Tippach)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform)
Command & Conquer Generals (HKLM-x32\...\InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}) (Version: 0.50.0000 - Electronic Arts)
Command & Conquer Generals (x32 Version: 0.50.0000 - Electronic Arts) Hidden
Command and ConquerTM Generals Zero Hour (HKLM-x32\...\InstallShield_{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}) (Version: 1.00.0000 - Electronic Arts)
Command and ConquerTM Generals Zero Hour (x32 Version: 1.00.0000 - Electronic Arts) Hidden
CPUID HWMonitor 1.26 (HKLM\...\CPUID HWMonitor_is1) (Version:  - )
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Dropbox (HKU\S-1-5-21-2917843931-2079053167-3573301051-1001\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.)
EA SPORTS™ FIFA 15 (HKLM-x32\...\{3D4ADA2B-F028-4307-ADF4-6F9AA44725DA}) (Version: 1.4.0.0 - Electronic Arts)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
Far Cry 4 - Gold Edition version Far Cry 4 - Gold Edition (HKLM-x32\...\Far Cry 4 - Gold Edition_is1) (Version: Far Cry 4 - Gold Edition - )
FL Studio 11 (HKLM-x32\...\FL Studio 11) (Version:  - Image-Line)
FlowStone FL 3.0 (HKLM-x32\...\FlowStone) (Version:  - )
Fraps (HKLM-x32\...\Fraps) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.111 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
HeavyLoad V3.3 (64 bit) (HKLM\...\HeavyLoad_is1) (Version: 3.3 - JAM Software)
IL Shared Libraries (HKLM-x32\...\IL Shared Libraries) (Version:  - Image-Line)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
LUXONIX Purity (HKLM-x32\...\LUXONIX_Purity) (Version: 1.2.4 - LUXONIX)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
MetalGearSolid2 Substance (HKLM-x32\...\{2184D9EA-4E5B-43FD-914E-4563CF028C94}) (Version: 1.00.000 - )
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Native Instruments Massive (HKLM-x32\...\Native Instruments Massive) (Version:  - Native Instruments)
Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version:  - Native Instruments)
NBA 2K15 (HKLM-x32\...\TkJBMksxNQ==_is1) (Version: 1 - )
NVIDIA 3D Vision Controller Driver 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 344.48 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.48 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.2 - NVIDIA Corporation)
NVIDIA Graphics Driver 344.48 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.48 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA Miracast Virtual Audio 344.48 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 344.48 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
SampleMoog (HKLM-x32\...\{218AA20E-F016-4385-9F74-04FF8E596FB2}) (Version: 1.0.0 - IK Multimedia)
SHIELD Streaming (Version: 3.1.200 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.13.42 - NVIDIA Corporation) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version:  - Valve)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29947 - TeamViewer)
TP-LINK TL-WN881ND Driver (HKLM-x32\...\{FDA7E907-6539-42C1-9721-0239C281B336}) (Version: 1.3.1 - TP-LINK)
VCE Exam Simulator Demo (HKLM-x32\...\VCE Exam Simulator Demo_is1) (Version:  - Avanset)
VirtualDJ PRO Full (HKLM-x32\...\{4769E972-2E92-49C5-B6F9-465EFD0C4D94}) (Version: 7.0.5 - Atomix Productions)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
 
==================== Restore Points  =========================
 
05-02-2015 20:02:42 Windows Update
07-02-2015 11:18:38 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
07-02-2015 11:18:43 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
09-02-2015 17:28:33 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
11-02-2015 18:57:53 Windows Modules Installer
17-02-2015 17:40:08 zoek.exe restore point
19-02-2015 18:55:48 Restore Point Created by FRST
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 13:25 - 2013-08-22 13:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {177C0DEB-2629-4D62-8994-989A36D37F67} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-11-28] ()
Task: {19E5F2CF-FD67-4DBD-A7EC-1DCE5044F381} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-26] (Google Inc.)
Task: {32A91CC4-2D42-40FF-B09A-BCEF7B3A6613} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {3CF21216-D91D-4D8D-B44A-C5A048458AE2} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-02-11] (Microsoft Corporation)
Task: {691C3EA5-2BA0-4F64-9AA8-13E3B6453234} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {7CF4AABE-A672-4BBF-B3B7-7C2E1F43E18B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-26] (Google Inc.)
Task: {A25BF94D-F693-44EE-9935-A97103EB9BE2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {AAAFE167-022E-42AE-874A-56AA902E9997} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-09-26] (Piriform Ltd)
Task: {C11FDC3E-050E-4266-B0C1-2B50527CC693} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {DFC25972-F30D-4AFD-B550-69ED5ED2FA11} - System32\Tasks\{DB370E97-219D-4E6F-86F6-1017C7BCCB2D} => pcalua.exe -a "C:\Users\Manraj\Desktop\Luxonix Purity VSTi v1.1.2\Setup.exe" -d "C:\Users\Manraj\Desktop\Luxonix Purity VSTi v1.1.2"
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) ==============
 
2013-07-10 19:31 - 2013-07-10 19:31 - 08865448 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-07-31 11:16 - 2014-07-31 11:16 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-07-31 11:16 - 2014-07-31 11:16 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-02-10 21:00 - 2015-02-10 21:00 - 00750080 _____ () C:\Users\Manraj\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-02-19 19:06 - 2015-02-19 19:06 - 00043008 _____ () c:\users\manraj\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpillicc.dll
2015-02-10 21:00 - 2015-02-10 21:00 - 00047616 _____ () C:\Users\Manraj\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-02-12 22:23 - 2015-02-10 21:00 - 00865280 _____ () C:\Users\Manraj\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-02-12 22:23 - 2015-02-10 21:00 - 00200704 _____ () C:\Users\Manraj\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2015-02-06 18:53 - 2015-02-04 09:02 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\libglesv2.dll
2015-02-06 18:53 - 2015-02-04 09:02 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\libegl.dll
2015-02-06 18:53 - 2015-02-04 09:02 - 09170760 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\pdf.dll
2015-02-06 18:53 - 2015-02-04 09:02 - 14965064 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\Users\Manraj\SkyDrive:ms-properties
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2917843931-2079053167-3573301051-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Manraj\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.0.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2917843931-2079053167-3573301051-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2917843931-2079053167-3573301051-500 - Administrator - Disabled)
Guest (S-1-5-21-2917843931-2079053167-3573301051-501 - Limited - Disabled)
Manraj (S-1-5-21-2917843931-2079053167-3573301051-1001 - Administrator - Enabled) => C:\Users\Manraj
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (02/19/2015 06:55:47 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {95716301-3e4e-4d95-bc07-274919d7775a}
 
Error: (02/19/2015 09:53:24 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14609
 
Error: (02/19/2015 09:53:24 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 14609
 
Error: (02/19/2015 09:53:24 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (02/19/2015 01:54:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15578
 
Error: (02/19/2015 01:54:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15578
 
Error: (02/19/2015 01:54:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (02/18/2015 09:30:51 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15000
 
Error: (02/18/2015 09:30:51 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15000
 
Error: (02/18/2015 09:30:51 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
System errors:
=============
Error: (02/19/2015 07:05:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The UAC File Virtualization service failed to start due to the following error: 
%%1275
 
Error: (02/19/2015 06:56:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The UAC File Virtualization service failed to start due to the following error: 
%%1275
 
Error: (02/18/2015 06:50:38 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 70. The Windows SChannel error state is 105.
 
Error: (02/18/2015 00:51:54 AM) (Source: DCOM) (EventID: 10010) (User: MANRAJPC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (02/18/2015 00:51:54 AM) (Source: DCOM) (EventID: 10010) (User: MANRAJPC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (02/17/2015 11:49:14 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
 
Error: (02/17/2015 08:26:44 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
 
Error: (02/17/2015 07:29:29 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
 
Error: (02/17/2015 06:25:54 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
 
Error: (02/17/2015 05:46:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The UAC File Virtualization service failed to start due to the following error: 
%%1275
 
 
Microsoft Office Sessions:
=========================
Error: (02/19/2015 06:55:47 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {95716301-3e4e-4d95-bc07-274919d7775a}
 
Error: (02/19/2015 09:53:24 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14609
 
Error: (02/19/2015 09:53:24 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 14609
 
Error: (02/19/2015 09:53:24 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (02/19/2015 01:54:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15578
 
Error: (02/19/2015 01:54:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15578
 
Error: (02/19/2015 01:54:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (02/18/2015 09:30:51 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15000
 
Error: (02/18/2015 09:30:51 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15000
 
Error: (02/18/2015 09:30:51 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-02-17 18:02:44.547
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-02-17 18:02:44.469
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-02-17 18:02:44.282
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-02-17 18:02:44.204
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-02-17 18:02:13.982
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-02-17 18:02:13.919
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-02-17 18:02:13.685
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-02-17 18:02:13.607
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-02-17 18:02:13.404
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-02-17 18:02:13.326
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-3570K CPU @ 3.40GHz
Percentage of memory in use: 22%
Total physical RAM: 8136.76 MB
Available physical RAM: 6276.61 MB
Total Pagefile: 9416.76 MB
Available Pagefile: 7302.08 MB
Total Virtual: 131072 MB
Available Virtual: 131071.83 MB
 
==================== Drives ================================
 
Drive a: (HDD) (Fixed) (Total:931.51 GB) (Free:586.55 GB) NTFS
Drive c: (SSD) (Fixed) (Total:111.45 GB) (Free:46.87 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: A55CB605)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.4 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 10B05F6F)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================
 
 
 
 
 
 
 
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2015 01
Ran by Manraj (administrator) on MANRAJPC on 19-02-2015 19:34:03
Running from C:\Users\Manraj\Desktop
Loaded Profiles: Manraj (Available profiles: Manraj)
Platform: Windows 8.1 Pro (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Dropbox, Inc.) C:\Users\Manraj\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2461504 2014-09-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-2917843931-2079053167-3573301051-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2917843931-2079053167-3573301051-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6482200 2014-09-26] (Piriform Ltd)
Startup: C:\Users\Manraj\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Manraj\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Manraj\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-2917843931-2079053167-3573301051-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.uk.msn.com/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2917843931-2079053167-3573301051-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.co...q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.co.uk/", "hxxp://uk.search.yahoo.com?type=714647&fr=spigot-yhp-ch", "https://www.google.co.uk/"
CHR Profile: C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Angry Birds) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2015-02-19]
CHR Extension: (Google Drive) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-19]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-02-09]
CHR Extension: (Please enter your password) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2015-02-19]
CHR Extension: (YouTube) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-19]
CHR Extension: (Google Search) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-19]
CHR Extension: (Inline Youtube) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehebapamcfpaadhjagimnbohggikmlpc [2015-02-19]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2015-02-19]
CHR Extension: (Hola Better Internet) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-02-19]
CHR Extension: (Lone Tree) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfmkllfplegemejikoabfpjdaoncphip [2015-02-19]
CHR Extension: (Streamus) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbnkffmindojffecdhbbmekbmkkfpmjd [2015-02-19]
CHR Extension: (Evernote Web) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2015-02-19]
CHR Extension: (ShiftEdit) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcgmndephhjcabhhjfcmncnhbmgbkpij [2015-02-19]
CHR Extension: (Google Maps) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-02-19]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-02-19]
CHR Extension: (Google Wallet) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-26]
CHR Extension: (Adblock Pro) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-02-19]
CHR Extension: (Evernote Web Clipper) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2015-02-19]
CHR Extension: (Gmail) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-19]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-09-17] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-09-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-09-17] (NVIDIA Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-22] (Advanced Micro Devices, Inc.)
R3 athr; C:\Windows\system32\DRIVERS\athwnx.sys [3680256 2013-06-18] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-09-24] (Advanced Micro Devices)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-05-26] (Disc Soft Ltd)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-09-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
S3 usbrndis6; C:\Windows\System32\drivers\usb80236.sys [20992 2013-08-22] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
R3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-19 19:22 - 2015-02-19 19:22 - 00144792 _____ () C:\Users\Manraj\Desktop\cc_20150219_192205.reg
2015-02-19 18:58 - 2015-02-19 19:06 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-19 18:58 - 2015-02-19 18:58 - 00001121 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-19 18:58 - 2015-02-19 18:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-19 18:58 - 2015-02-19 18:58 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-19 18:58 - 2015-02-19 18:58 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-19 18:58 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-19 18:58 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-19 18:58 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-18 18:02 - 2015-02-16 13:13 - 300227129 _____ () C:\Users\Manraj\Desktop\5.Solja VS Row D.m4v
2015-02-18 18:02 - 2015-02-16 12:40 - 380747777 _____ () C:\Users\Manraj\Desktop\4. Shorty D VS Geckz.m4v
2015-02-18 18:02 - 2015-02-16 12:29 - 273665371 _____ () C:\Users\Manraj\Desktop\3.Sparx VS Sin Ceer.m4v
2015-02-18 18:02 - 2015-02-16 12:21 - 441518619 _____ () C:\Users\Manraj\Desktop\2.Cadell VS Novelist.m4v
2015-02-18 18:02 - 2015-02-16 12:15 - 432952863 _____ () C:\Users\Manraj\Desktop\1.Jayeye VS Eyez.m4v
2015-02-17 17:46 - 2015-02-17 17:39 - 00024064 _____ () C:\Windows\zoek-delete.exe
2015-02-17 17:40 - 2015-02-17 17:46 - 00054650 _____ () C:\zoek-results.log
2015-02-17 17:39 - 2015-02-17 17:44 - 00000000 ____D () C:\zoek_backup
2015-02-17 17:39 - 2015-02-17 17:39 - 01304576 _____ () C:\Users\Manraj\Desktop\zoek.exe
2015-02-16 23:26 - 2015-02-16 23:26 - 00000000 ____D () C:\Users\Manraj\Desktop\Sour Soul Bundle
2015-02-15 19:48 - 2015-02-19 19:34 - 00016712 _____ () C:\Users\Manraj\Desktop\FRST.txt
2015-02-15 19:48 - 2015-02-19 18:53 - 00000000 ____D () C:\Users\Manraj\Desktop\FRST-OlderVersion
2015-02-13 18:00 - 2015-02-13 18:44 - 00000000 ____D () C:\AdwCleaner
2015-02-13 16:54 - 2015-02-19 19:34 - 00000000 ____D () C:\FRST
2015-02-13 16:54 - 2015-02-19 18:53 - 02086912 _____ (Farbar) C:\Users\Manraj\Desktop\FRST64.exe
2015-02-13 06:02 - 2015-02-13 06:07 - 00000000 ____D () C:\Users\Manraj\Desktop\Drake - If You're Reading This It's Too Late (Album) [mp3]
2015-02-12 22:52 - 2015-02-12 22:53 - 00000000 ____D () C:\Users\Manraj\Desktop\Windows 8
2015-02-12 22:47 - 2015-02-12 22:47 - 00001908 _____ () C:\Windows\diagwrn.xml
2015-02-12 22:47 - 2015-02-12 22:47 - 00001908 _____ () C:\Windows\diagerr.xml
2015-02-12 22:47 - 2015-02-12 22:47 - 00000000 ___HD () C:\$WINDOWS.~BT
2015-02-12 22:12 - 2015-02-12 22:12 - 00000000 ____D () C:\Users\Manraj\AppData\Roaming\ImgBurn
2015-02-12 22:11 - 2015-02-12 22:11 - 00000000 ____D () C:\Program Files (x86)\ImgBurn
2015-02-11 18:57 - 2015-02-11 18:57 - 00000151 _____ () C:\Users\Manraj\AppData\Roaming\KB8888239.log
2015-02-11 18:56 - 2014-09-10 09:58 - 00514560 _____ () C:\Windows\SysWOW64\Launcher.exe
2015-02-11 18:56 - 2014-09-03 02:18 - 00894071 _____ () C:\Windows\SysWOW64\Tools.exe
2015-02-11 18:29 - 2015-01-23 04:41 - 06041600 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-11 18:29 - 2015-01-23 03:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-02-11 00:24 - 2015-01-10 07:00 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-11 00:24 - 2015-01-10 06:38 - 00359424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-02-11 00:23 - 2015-02-03 23:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-11 00:23 - 2015-02-03 23:08 - 00761856 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-11 00:23 - 2015-02-03 23:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-11 00:23 - 2015-02-02 23:11 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-11 00:23 - 2015-02-02 23:11 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-11 00:23 - 2015-02-02 23:11 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 00:23 - 2015-01-19 18:42 - 01487976 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2015-02-11 00:23 - 2015-01-15 22:43 - 00563504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-11 00:23 - 2015-01-15 22:43 - 00177984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-11 00:23 - 2015-01-14 04:22 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-02-11 00:23 - 2015-01-14 03:53 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-02-11 00:23 - 2015-01-13 22:11 - 01762840 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-11 00:23 - 2015-01-13 22:04 - 01489072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-02-11 00:23 - 2015-01-12 03:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-11 00:23 - 2015-01-12 02:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-11 00:23 - 2015-01-12 02:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-11 00:23 - 2015-01-12 02:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-11 00:23 - 2015-01-12 02:34 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-02-11 00:23 - 2015-01-12 02:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-02-11 00:23 - 2015-01-12 02:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-11 00:23 - 2015-01-12 02:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-02-11 00:23 - 2015-01-12 02:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-11 00:23 - 2015-01-12 02:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-02-11 00:23 - 2015-01-12 02:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-02-11 00:23 - 2015-01-12 01:58 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-02-11 00:23 - 2015-01-12 01:55 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-02-11 00:23 - 2015-01-12 01:51 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-02-11 00:23 - 2015-01-12 01:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-11 00:23 - 2015-01-12 01:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-11 00:23 - 2015-01-12 01:48 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-11 00:23 - 2015-01-12 01:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-11 00:23 - 2015-01-12 01:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-02-11 00:23 - 2015-01-12 01:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-11 00:23 - 2015-01-12 01:34 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-02-11 00:23 - 2015-01-12 01:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-02-11 00:23 - 2015-01-12 01:27 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-02-11 00:23 - 2015-01-12 01:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-11 00:23 - 2015-01-12 01:25 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-02-11 00:23 - 2015-01-12 01:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-02-11 00:23 - 2015-01-12 01:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-02-11 00:23 - 2015-01-12 01:23 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-02-11 00:23 - 2015-01-12 01:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-02-11 00:23 - 2015-01-12 01:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-11 00:23 - 2015-01-12 01:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-11 00:23 - 2015-01-12 01:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-02-11 00:23 - 2015-01-12 00:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-02-11 00:23 - 2015-01-12 00:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-02-11 00:23 - 2015-01-10 09:10 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-11 00:23 - 2015-01-10 09:10 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-02-11 00:23 - 2015-01-10 08:28 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-02-11 00:23 - 2015-01-10 08:22 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-11 00:23 - 2014-12-19 08:57 - 00788680 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-11 00:23 - 2014-12-19 08:25 - 00602776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-02-11 00:23 - 2014-12-09 03:45 - 00393728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-02-11 00:23 - 2014-12-09 01:56 - 00538624 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-11 00:23 - 2014-12-08 23:12 - 00391526 _____ () C:\Windows\system32\ApnDatabase.xml
2015-02-11 00:23 - 2014-10-29 02:51 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-11 00:23 - 2014-10-29 02:50 - 00736768 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-11 00:23 - 2014-10-29 02:06 - 00736768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-02-11 00:23 - 2014-10-29 02:06 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-02-11 00:23 - 2014-10-29 02:02 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-02-11 00:23 - 2014-10-29 02:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-02-11 00:23 - 2014-10-29 01:57 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-02-11 00:23 - 2014-10-29 01:31 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-11 00:23 - 2014-10-29 01:15 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-02-11 00:23 - 2014-10-29 01:15 - 00005632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-02-11 00:23 - 2014-10-29 01:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-02-11 00:23 - 2014-10-29 01:13 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-02-11 00:23 - 2014-10-29 01:13 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-02-07 11:18 - 2015-02-07 11:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 15
2015-02-06 19:07 - 2015-02-06 19:07 - 00000000 ____D () C:\Users\Manraj\Desktop\MC Eiht - Compton 2 Vienna Vol. 1
2015-01-24 15:12 - 2015-01-24 15:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Far Cry 4 - Gold Edition
2015-01-22 19:36 - 2015-01-22 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2015-01-22 19:36 - 2015-01-22 19:36 - 00000000 ____D () C:\Fraps
2015-01-20 22:55 - 2015-01-20 22:55 - 00000381 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NBA 2K15.lnk
2015-01-20 19:17 - 2015-01-20 19:17 - 00000000 ____D () C:\Users\Manraj\AppData\Roaming\ATI
2015-01-20 19:17 - 2015-01-20 19:17 - 00000000 ____D () C:\Users\Manraj\AppData\Local\ATI
2015-01-20 19:17 - 2015-01-20 19:17 - 00000000 ____D () C:\ProgramData\ATI
2015-01-20 19:16 - 2015-01-20 19:16 - 00060601 _____ () C:\Windows\SysWOW64\CCCInstall_201501201916279863.log
2015-01-20 19:16 - 2015-01-20 19:16 - 00060328 _____ () C:\Windows\SysWOW64\CCCInstall_201501201916119009.log
2015-01-20 19:16 - 2015-01-20 19:16 - 00000000 ____D () C:\Users\Default\AppData\Roaming\ATI
2015-01-20 19:16 - 2015-01-20 19:16 - 00000000 ____D () C:\Users\Default\AppData\Local\ATI
2015-01-20 19:16 - 2015-01-20 19:16 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\ATI
2015-01-20 19:16 - 2015-01-20 19:16 - 00000000 ____D () C:\Users\Default User\AppData\Local\ATI
2015-01-20 19:16 - 2015-01-20 19:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-01-20 19:15 - 2015-01-20 19:15 - 00000000 ____D () C:\Program Files\AMD
2015-01-20 19:13 - 2015-02-17 17:44 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2015-01-20 19:13 - 2015-01-20 19:16 - 00000000 ____D () C:\AMD
2015-01-20 19:13 - 2015-01-20 19:13 - 00061173 _____ () C:\Windows\SysWOW64\CCCInstall_201501201913420094.log
2015-01-20 19:13 - 2015-01-20 19:13 - 00000000 ____D () C:\ProgramData\AMD
2015-01-20 19:13 - 2015-01-20 19:13 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2015-01-20 19:13 - 2015-01-20 19:13 - 00000000 _____ () C:\Windows\ativpsrm.bin
2015-01-20 19:13 - 2013-09-24 14:54 - 00222720 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdWB6.sys
2015-01-20 19:13 - 2013-09-24 14:54 - 00141312 _____ (Windows ® Win 7 DDK provider) C:\Windows\system32\Drivers\amdacpksl.sys
2015-01-20 19:13 - 2013-09-24 14:51 - 00110080 _____ (TODO: <Company name>) C:\Windows\system32\DelayAPO.dll
2015-01-20 19:13 - 2013-09-12 02:26 - 01187342 _____ () C:\Windows\system32\amdocl_as64.exe
2015-01-20 19:13 - 2013-09-12 02:26 - 01061902 _____ () C:\Windows\system32\amdocl_ld64.exe
2015-01-20 19:13 - 2013-09-12 02:26 - 00995342 _____ () C:\Windows\SysWOW64\amdocl_as32.exe
2015-01-20 19:13 - 2013-09-12 02:26 - 00798734 _____ () C:\Windows\SysWOW64\amdocl_ld32.exe
2015-01-20 19:13 - 2013-09-12 02:26 - 00129536 _____ (AMD) C:\Windows\system32\coinst_13.20.dll
2015-01-20 19:13 - 2013-09-12 01:26 - 00204952 _____ () C:\Windows\SysWOW64\ativvsvl.dat
2015-01-20 19:13 - 2013-09-12 01:26 - 00204952 _____ () C:\Windows\system32\ativvsvl.dat
2015-01-20 19:13 - 2013-09-12 01:26 - 00157144 _____ () C:\Windows\SysWOW64\ativvsva.dat
2015-01-20 19:13 - 2013-09-12 01:26 - 00157144 _____ () C:\Windows\system32\ativvsva.dat
2015-01-20 19:13 - 2011-09-12 22:06 - 00003917 _____ () C:\Windows\SysWOW64\atipblag.dat
2015-01-20 19:13 - 2011-09-12 22:06 - 00003917 _____ () C:\Windows\system32\atipblag.dat
2015-01-20 19:12 - 2015-01-20 19:16 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2015-01-20 19:12 - 2012-09-22 23:17 - 00021160 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\amdkmafd.sys
2015-01-20 19:11 - 2015-01-20 19:16 - 00000000 ____D () C:\Program Files\ATI Technologies
2015-01-20 19:11 - 2015-01-20 19:11 - 00000000 ____D () C:\Program Files\ATI
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-19 19:21 - 2014-05-28 08:49 - 00000000 ____D () C:\Users\Manraj\AppData\Roaming\uTorrent
2015-02-19 19:12 - 2014-05-25 07:32 - 00863592 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-19 19:10 - 2014-05-25 07:33 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2917843931-2079053167-3573301051-1001
2015-02-19 19:06 - 2014-11-28 22:31 - 00003758 _____ () C:\Windows\System32\Tasks\AutoKMS
2015-02-19 19:06 - 2014-05-28 04:13 - 00000000 ___DO () C:\Users\Manraj\SkyDrive
2015-02-19 19:06 - 2014-05-28 03:52 - 00000000 ____D () C:\Users\Manraj\AppData\Roaming\Dropbox
2015-02-19 19:06 - 2014-05-26 09:21 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-19 19:05 - 2014-05-26 03:25 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-02-19 19:05 - 2013-08-22 14:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-19 19:05 - 2013-08-22 13:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-02-19 19:02 - 2013-08-22 15:36 - 00000000 ____D () C:\Windows\system32\sru
2015-02-19 18:55 - 2014-05-26 02:42 - 00003930 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{79ECBCEF-EE26-487F-8DE4-490C964862E6}
2015-02-19 09:53 - 2014-09-28 14:06 - 00000000 ____D () C:\Users\Manraj\AppData\Roaming\vlc
2015-02-19 09:52 - 2014-05-26 09:21 - 00000924 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-15 21:15 - 2013-08-22 15:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-02-13 16:40 - 2014-12-27 18:21 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-13 16:40 - 2014-05-26 02:41 - 00000000 ____D () C:\Users\Manraj\AppData\Roaming\DAEMON Tools Lite
2015-02-12 18:11 - 2013-08-22 15:36 - 00000000 ____D () C:\Windows\rescache
2015-02-11 19:00 - 2013-08-22 15:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-02-11 19:00 - 2013-08-22 15:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-02-11 19:00 - 2013-08-22 15:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-02-11 18:21 - 2013-08-22 14:44 - 00484416 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-11 00:28 - 2014-05-28 04:01 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-11 00:26 - 2014-12-10 08:57 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-11 00:26 - 2014-07-10 21:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-11 00:26 - 2014-05-28 04:01 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-06 18:47 - 2014-05-26 09:21 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-06 18:47 - 2014-05-26 09:21 - 00003660 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-05 02:31 - 2015-01-08 21:30 - 00000000 ____D () C:\Users\Manraj\Desktop\Powerpnt
2015-02-03 19:31 - 2013-08-22 15:38 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-03 19:31 - 2013-08-22 15:38 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-30 01:27 - 2014-05-25 07:26 - 00000000 ____D () C:\Users\Manraj
2015-01-24 15:12 - 2014-10-15 23:12 - 00000000 ____D () C:\ProgramData\Orbit
2015-01-24 02:52 - 2014-05-26 12:22 - 00000000 ____D () C:\Windows\SysWOW64\directx
 
==================== Files in the root of some directories =======
 
2015-02-11 18:57 - 2015-02-11 18:57 - 0000151 _____ () C:\Users\Manraj\AppData\Roaming\KB8888239.log
 
Some content of TEMP:
====================
C:\Users\Manraj\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpillicc.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-02-13 19:30
 
==================== End Of Log ============================

  • 0

#19
ruggie_uk

ruggie_uk

    Trusted Helper

  • Malware Removal
  • 2,083 posts

Is this problem only happening in Chrome?


  • 0

#20
Nas

Nas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

It seems so, ive just been browsing on IE for a while and experienced no problems


  • 0

#21
ruggie_uk

ruggie_uk

    Trusted Helper

  • Malware Removal
  • 2,083 posts
I have a feeling its one of the extensions that is not what it says it is as your logs look good.
Please try disabling all chrone extensions and seeing how it goes.
Then enable one at a time.
  • 0

#22
Nas

Nas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

I only have two extensions, one is adblock pro which is making the pop ups more bareable, and google dictionary which made no difference,


  • 0

#23
ruggie_uk

ruggie_uk

    Trusted Helper

  • Malware Removal
  • 2,083 posts

According to the logs there are quite a few.

CHR Extension: (Angry Birds) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2015-02-19]
CHR Extension: (Google Drive) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-19]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-02-09]
CHR Extension: (Please enter your password) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2015-02-19]
CHR Extension: (YouTube) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-19]
CHR Extension: (Google Search) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-19]
CHR Extension: (Inline Youtube) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehebapamcfpaadhjagimnbohggikmlpc [2015-02-19]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2015-02-19]
CHR Extension: (Hola Better Internet) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-02-19]
CHR Extension: (Lone Tree) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfmkllfplegemejikoabfpjdaoncphip [2015-02-19]
CHR Extension: (Streamus) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbnkffmindojffecdhbbmekbmkkfpmjd [2015-02-19]
CHR Extension: (Evernote Web) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2015-02-19]
CHR Extension: (ShiftEdit) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcgmndephhjcabhhjfcmncnhbmgbkpij [2015-02-19]
CHR Extension: (Google Maps) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-02-19]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-02-19]
CHR Extension: (Google Wallet) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-26]
CHR Extension: (Adblock Pro) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-02-19]
CHR Extension: (Evernote Web Clipper) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2015-02-19]
CHR Extension: (Gmail) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-19]

 
I think that this is where the crux of the problem lies.
I think we should clear them all and see how it looks. You can add the ones you require back afterwards.
 
FRST Fix

If FRST.exe/FRST64.exe is not on your desktop, please download Farbar Recovery Scan Tool and save it to your desktop.

  • Download the attached Attached File  fixlist.txt   2.89KB   226 downloads and save it to your desktop <<< very important - it must be in the same location as FRST.exe/FRST64.exe
  • Right click frst.png and run as administrator. When the tool opens click Yes to the disclaimer.
  • Press the Fix button.
  • It will produce a log called fixlog.txt on your Desktop.
  • Please copy and paste the contents of that log back here.

    NOTICE: This script was written specifically for this user, for use on that particular machine, at this point in time. Running this on another machine may cause damage to your operating system.

  • 0

#24
Nas

Nas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

OK I have removed all extensions from chrome and problem still persists

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-02-2015 01
Ran by Manraj at 2015-02-20 16:14:26 Run:2
Running from C:\Users\Manraj\Desktop
Loaded Profiles: Manraj (Available profiles: Manraj)
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
start
CHR Extension: (Angry Birds) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2015-02-19]
CHR Extension: (Google Drive) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-19]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-02-09]
CHR Extension: (Please enter your password) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2015-02-19]
CHR Extension: (YouTube) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-19]
CHR Extension: (Google Search) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-19]
CHR Extension: (Inline Youtube) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehebapamcfpaadhjagimnbohggikmlpc [2015-02-19]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2015-02-19]
CHR Extension: (Hola Better Internet) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-02-19]
CHR Extension: (Lone Tree) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfmkllfplegemejikoabfpjdaoncphip [2015-02-19]
CHR Extension: (Streamus) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbnkffmindojffecdhbbmekbmkkfpmjd [2015-02-19]
CHR Extension: (Evernote Web) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2015-02-19]
CHR Extension: (ShiftEdit) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcgmndephhjcabhhjfcmncnhbmgbkpij [2015-02-19]
CHR Extension: (Google Maps) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-02-19]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-02-19]
CHR Extension: (Google Wallet) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-26]
CHR Extension: (Adblock Pro) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-02-19]
CHR Extension: (Evernote Web Clipper) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2015-02-19]
CHR Extension: (Gmail) - C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-19]
end
*****************
 
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj => Moved successfully.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf => Moved successfully.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn => Moved successfully.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn directory not found.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo => Moved successfully.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf => Moved successfully.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehebapamcfpaadhjagimnbohggikmlpc directory not found.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi directory not found.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio directory not found.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfmkllfplegemejikoabfpjdaoncphip => Moved successfully.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbnkffmindojffecdhbbmekbmkkfpmjd directory not found.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol => Moved successfully.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcgmndephhjcabhhjfcmncnhbmgbkpij => Moved successfully.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh => Moved successfully.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja directory not found.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => Moved successfully.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch directory not found.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc directory not found.
C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia => Moved successfully.
 
==== End of Fixlog 16:14:26 ====

  • 0

#25
Nas

Nas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

Actually, after browsing a little while later it seems as though the problem has been sorted


  • 0

Advertisements


#26
ruggie_uk

ruggie_uk

    Trusted Helper

  • Malware Removal
  • 2,083 posts

That's good.

 

Lets check for any residual malware and if it's all good, we can proceed to clean up.

 

Anti-Virus Scan
Please run a free online scan with the ESET Online Scanner

<< Please disable any existing anti virus product before performing the following. >>

  • Click Run Eset Online Scanner


Runscan.png


Note: You will need to use Internet Explorer or Firefox (You will be prompted to install a helper program if you use firefox)for this scan.
Important: Please disable your existing AV software for the duration of the scan

  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the option Enable detection of potentially unwanted applications is checked
  • Next click on Advanced Settings and select:

eset-selections.png

  • Make sure that the option Remove found threats is NOT checked
  • Scan archives
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology


eset-selections.png

  • Click Start, the virus database will update, this may take a while depending on your internet connection.
  • Once updated, the online scan will begin. (This scan can take several hours, so please be patient)
  • Once the scan is completed, click Finish
  • Use Notepad to open the logfile located at C:\Program Files (x86)\ESET\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic


  • 0

#27
Nas

Nas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=5dcb41751fe4254aba584ff59eb1d860
# engine=22581
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-02-21 12:39:47
# local_time=2015-02-21 12:39:47 (+0000, GMT Standard Time)
# country="United Kingdom"
# lang=1033
# osver=6.2.9200 NT 
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 4259 14826706 0 0
# scanned=246224
# found=1
# cleaned=0
# scan_time=480
sh=176F6D39C3643EA4AA11CA1ACFF86DFF8448937B ft=1 fh=074c4388ae890b5f vn="Win32/InstallMate potentially unwanted application" ac=I fn="A:\Music\Songs\FastDownload.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=5dcb41751fe4254aba584ff59eb1d860
# engine=22581
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2015-02-21 01:14:42
# local_time=2015-02-21 01:14:42 (+0000, GMT Standard Time)
# country="United Kingdom"
# lang=1033
# osver=6.2.9200 NT 
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 6354 14828801 0 0
# scanned=246236
# found=34
# cleaned=0
# scan_time=1728
sh=90D0C5A8F93AA2DC2789CDF58EFD55E7D2687368 ft=0 fh=0000000000000000 vn="MSIL/HackTool.IdleKMS.C potentially unsafe application" ac=I fn="A:\Windows_8.1_Pro_X64_Activated.iso"
sh=0333BDB5B657B0442D938793D830730582D01889 ft=1 fh=32f80367e4872969 vn="a variant of Win32/AdWare.MultiPlug.AP application" ac=I fn="A:\Downloads\Brandy - Two Eleven (Deluxe Edition) (Album).exe"
sh=F69F5B71A6FA94B71504EF184913BCF428D43899 ft=1 fh=6c8257ade2556f83 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application" ac=I fn="A:\Downloads\ccsetup418.exe"
sh=D368C0ABFB11F519F7A5A2C174CCBECBA655F0BD ft=1 fh=ecd33b65aaf31e72 vn="a variant of Win32/Amonetize.CH potentially unwanted application" ac=I fn="A:\Downloads\Document Id 237614 Zip Downloader__3687_i1418441173_il1001390.exe"
sh=A888C43C2D64BE516CD8F1486D8D88FD73E955DF ft=1 fh=c71c0011595faf88 vn="Win32/InstallCore.OH potentially unwanted application" ac=I fn="A:\Downloads\download-net-framework-35.exe"
sh=7909371332EF9D8A0AF804E5F7E301D8F67F0F3A ft=1 fh=6572b2bd954a1547 vn="a variant of Win32/Adware.MultiPlug.ES application" ac=I fn="A:\Downloads\Fifa_15___Only_v2.rar.exe"
sh=527DBDB7E31AAD1B48FE29EE578DF1AAA13E8926 ft=1 fh=c30c5368f81549e4 vn="Win32/Somoto.J potentially unwanted application" ac=I fn="A:\Downloads\FLVPlayerSetup.exe"
sh=A20ADE7E19C2F6F45034544132C04F85768A3EEE ft=1 fh=1c3b405f45b7852d vn="Win32/Somoto.G potentially unwanted application" ac=I fn="A:\Downloads\mathematik_-_on_top_downloader-I3knYGnbE.exe"
sh=3DC8141138927F3034351FBA1D15091AFEA462FF ft=1 fh=4b5a756d5930c7a8 vn="a variant of Win32/Amonetize.AD potentially unwanted application" ac=I fn="A:\Downloads\MediaCenter__4406_il643.exe"
sh=2A67427157AA30F08DBA77DD15B13227733693AF ft=1 fh=4b97057aea4308e9 vn="a variant of Win32/PSWTool.ophCrack.A potentially unsafe application" ac=I fn="A:\Downloads\ophcrack-win32-installer-3.6.0.exe"
sh=D8F050D333A3DA7656A6A7F005D85D48EC997D35 ft=0 fh=0000000000000000 vn="a variant of Win32/InstallMonstr.FF potentially unwanted application" ac=I fn="A:\Downloads\rusfolder_downloader.zip"
sh=5CA96A0C243390C378DEE1A629684EA261E2CFC4 ft=1 fh=a717dcd23690f0a7 vn="Win32/OpenCandy potentially unsafe application" ac=I fn="A:\Downloads\SetupImgBurn_2.5.8.0.exe"
sh=BD7012A6453D959EF309B18F3A3E8196CC759DFA ft=0 fh=0000000000000000 vn="a variant of Win32/Keygen.CL potentially unsafe application" ac=I fn="A:\Downloads\Applied Acoustics Lounge Lizard EP-4 v4.0.3 WIN OSX Incl. Keygen AiR - [deepstatus][h33t][1337x]\a-ll403.rar"
sh=5AB2729DF7DDADEBA5B623004D427170EBAAA69F ft=1 fh=5faceca7b95ee3bc vn="a variant of Win32/HackTool.Crack.CS potentially unsafe application" ac=I fn="A:\Far Cry 4 - Gold Edition\bin\steam_api.dll"
sh=B45806F85A8EFA8AA923A09B28B26EE1FCFD97BA ft=1 fh=021ef04e4af54844 vn="Win32/Bundled.Toolbar.Google.E potentially unsafe application" ac=I fn="A:\Music\Songs\ccsetup309.exe"
sh=176F6D39C3643EA4AA11CA1ACFF86DFF8448937B ft=1 fh=074c4388ae890b5f vn="Win32/InstallMate potentially unwanted application" ac=I fn="A:\Music\Songs\FastDownload.exe"
sh=A5503351E5F9790C288798D2DC1A724323F36429 ft=1 fh=b731be6c2c02754f vn="a variant of Win32/Toolbar.SearchSuite.Z potentially unwanted application" ac=I fn="A:\Music\Songs\iLividSetupV1.exe"
sh=F4E1A0B30C2633EC3585AEDEB8E3164CF1D0694F ft=0 fh=0000000000000000 vn="Win32/HackTool.Crack.BQ potentially unsafe application" ac=I fn="A:\The.Elder.Scrolls.V.Skyrim.Dragonborn.Addon.DLC-RELOADED\rld-tesvskdb.iso"
sh=657843A11DDE9F64DB3FE87C72143FFA37C3DCAC ft=1 fh=dab6bd18636d9576 vn="a variant of Win32/BrowseFox.AF potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\updater.bak.vir"
sh=AAB5F615BB4253E0F103D1EE606581C9DB431753 ft=1 fh=c2d008a2f8c8b46d vn="a variant of Win32/BrowseFox.AF potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\updater.exe.vir"
sh=C4DAC4796C8EF049AFF460CB8206DFD63795B2C8 ft=1 fh=2c11c2f3084a7f02 vn="a variant of Win32/Toolbar.CrossRider.AV potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SuperPlusRadio v2.1\e70a7c0c-00c2-4d3e-9c19-f7fd5a0d6a3d-1-6.exe.vir"
sh=C186B9F5AA1C36DF061A127F9A5F223A1D9A06A4 ft=1 fh=68caf27907e41d26 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SuperPlusRadio v2.1\e70a7c0c-00c2-4d3e-9c19-f7fd5a0d6a3d-10.exe.vir"
sh=6F4663CBC736268A09BFB42A963D21F0187E7C26 ft=1 fh=cf0f9ef41fec5ca4 vn="a variant of Win32/Toolbar.CrossRider.BZ potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SuperPlusRadio v2.1\e70a7c0c-00c2-4d3e-9c19-f7fd5a0d6a3d-6.exe.vir"
sh=F33DC76E720F3CC6DEDAA26F975D48A8047DE882 ft=1 fh=94e96382a3f88d88 vn="a variant of Win32/BrowseFox.AF potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer.bak.vir"
sh=C21AAC7F201EC119D5B879EAB16525D76E75FA61 ft=1 fh=4c07350428b83a2f vn="a variant of Win32/BrowseFox.AF potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer.exe.vir"
sh=1B289FB2E1B7BB0301B0FEFF3725F6ED4836E417 ft=1 fh=da53bfbe220ad3e6 vn="a variant of Win32/BrowseFox.AF potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\3\Plugin.exe.vir"
sh=ED1059DA162FF39C8E833556BC9C8C913CFD8CFD ft=1 fh=ddb26ada8e4ae02c vn="a variant of Win32/BrowseFox.AF potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\5\Plugin.exe.vir"
sh=5FE758345D51B9E8208852BFC4875D69F4BB920B ft=1 fh=fa412084b2bcf095 vn="a variant of Win32/BrowseFox.AF potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\8\Plugin.exe.vir"
sh=A20ADE7E19C2F6F45034544132C04F85768A3EEE ft=1 fh=1c3b405f45b7852d vn="Win32/Somoto.G potentially unwanted application" ac=I fn="C:\Users\Manraj\AppData\Local\Google\Chrome\User Data\Default\File System\009\t\00\00000000"
sh=B554C22F5C32BD884277F2E2E91716CB4FCFE7DE ft=1 fh=2ba75dedb1b48fd7 vn="MSIL/HackTool.IdleKMS.C potentially unsafe application" ac=I fn="C:\Users\Manraj\Desktop\Windows 8\sources\$OEM$\$$\Setup\Scripts\KMSpico_setup.exe"
sh=21F5C96F000B6B182F13BEBBAB5C8B89FC3A4A85 ft=1 fh=f47f8fde390ebec3 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\zoek_backup\C_Program Files (x86)_AMD AVT_69012486-ccc8-4510-98aa-6d0389889b90.dll.vir"
sh=9DA8B4F1449D426477FC796EE6E38D53CD193563 ft=1 fh=2375031f3dd99637 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\zoek_backup\C_Program Files (x86)_AMD AVT_d7f95f05-ac86-42d5-bce2-11792a3afe92.dll.vir"
sh=21F5C96F000B6B182F13BEBBAB5C8B89FC3A4A85 ft=1 fh=f47f8fde390ebec3 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\zoek_backup\C_PROGRA~2_69012486-ccc8-4510-98aa-6d0389889b90\8ae23e98-fed3-43a1-ab05-d93a47056d0f.dll"
sh=9DA8B4F1449D426477FC796EE6E38D53CD193563 ft=1 fh=2375031f3dd99637 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\zoek_backup\C_PROGRA~2_69012486-ccc8-4510-98aa-6d0389889b90\e18ce507-7508-4c24-9699-20e012ba14ac.dll"

  • 0

#28
ruggie_uk

ruggie_uk

    Trusted Helper

  • Malware Removal
  • 2,083 posts

Hi, sorry for the delay, things get a bit hectic at the weekend.

 

There are quite a few suspect programs in your downloads folder. Judging by what they are, I presume you know they are all there, but they are bundled with various adware programs etc.

 

The main ones to be concerned about are:

A:\Downloads\Brandy - Two Eleven (Deluxe Edition) (Album).exe
A:\Downloads\Document Id 237614 Zip Downloader__3687_i1418441173_il1001390.exe
A:\Downloads\download-net-framework-35.exe
A:\Downloads\Fifa_15___Only_v2.rar.exe
A:\Downloads\FLVPlayerSetup.exe
A:\Downloads\mathematik_-_on_top_downloader-I3knYGnbE.exe
A:\Downloads\MediaCenter__4406_il643.exe
A:\Downloads\ophcrack-win32-installer-3.6.0.exe
A:\Downloads\rusfolder_downloader.zip
A:\Downloads\Applied Acoustics Lounge Lizard EP-4 v4.0.3 WIN OSX Incl. Keygen AiR - [deepstatus][h33t][1337x]\a-ll403.rar
A:\Music\Songs\FastDownload.exe
A:\Music\Songs\iLividSetupV1.exe

I won't create a fixlist for them, but please look through them carefully and delete the ones you know you don't need.

 

After that then we can clean up.

Good news, it looks like your system is now clean. A good workman cleans up after himself so let's now attend to that :D

Tool Removal

We need to remove the tools we've used during cleaning your machine

  • Download Delfix from here
  • Ensure Remove disinfection tools is ticked
    Also tick:
    • Activate UAC
    • Create registry backup
    • Purge system restore
    • Reset System Settings

    delfix-select.png
  • Click Run

The program will run for a few moments and then notepad will open with a log. Please paste the log in your next reply

We need to uninstall a program
Open Programs and Features by clicking the Start button, clicking Control Panel, clicking Programs, and then clicking Programs and Features.
Select the following programs from the list below, one at a time and click Uninstall.
  • ESET Online Scanner

Delete the following Files and Folders (If Present):
C:\Program Files (x86)\ESET
Delete any other .bat, .log, .reg, .txt, and any other files created during this process, and left on the desktop and empty the Recycle Bin.



Keep your machine updated

Due to the ever-present tide of malware, it is important to ensure your computer is kept up-to-date to minimize the risk of future infection. An important step is to ensure that automatic updates are enabled.


To enable automatic updates:

Windows 7
To turn on Automatic Updates yourself, follow these steps:
  • Click Start, type Windows update in the search box, and then click Windows Update in the Programs list.
  • In the left pane, click Change settings.
  • Select the option that you want.
  • Under Recommended updates, select the Give me recommended updates the same way I receive important updates or Include recommended updates when downloading, installing, or notifying me about updates check box, and then click OK.



It is recommended to install an anti-malware to help prevent reinfection.
Below are some free ones that can help keep you clean.

Malwarebytes AntiMalware

As you have installed Malwarebytes, I recommend that you keep this program and use it to help you stay clean.

The free version will scan your computer and fix the problems it finds but will not provide real-time protection. You must scan regularly to find any threats.
Consider purchasing the full version for active monitoring of threats.

JAVA Advice
WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article and this article.
I would recommend that you completely uninstall Java unless you need it to run an important software or need it to play games on-line.
In that instance I would recommend that you only use Firefox or Chrome to visit those sites and do the following:
  • For Firefox, install the NoScript add-on.
  • For Chrome, install the ScriptSafe add-on.
    -->IMPORTANT<--: After installing the add-ons you will need to tell them that the site you are visiting is allowed to run Javascript. If you don't, the sites won't work properly. Or not at all. You can go to the NoScript home page here to learn how to use the add-on.
  • Disable Java in your browsers until you need it for that software and then enable it. (See How to disable Java in your web browser or How to unplug Java from the browser)

If you still want to update your Java, follow the instructions below:

A.
Your version of Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older versions of Java components and update:
  • Download the latest version of the Java Runtime Environment (JRE) Version from Here and save it to your desktop.
  • Look for "Java Platform, Standard Edition". You will see the current Java version and update number under listed under the heading. Example: The newest update is Java SE 8u25
  • Click the "Download button under "JRE".
  • On the Java SE Runtime Environment page, click the button to "Accept License Agreement".
  • Under the Java SE Runtime Environment 8u25 heading:
    To install the version for your system:
    • For Windows 64bit systems, look for Windows x64 - 88.37MB, click the jre-8u25-windows-64.exe file and save it to your desktop. Do Not run it from the Java site.

  • Close any programs you may have running - especially your web browser.

B.
Uninstall all versions of Java
  • Click Start > Control Panel > Add/Remove Programs. The list of installed programs will populate.
  • Click the Start Orb, then Control Panel. Under the Programs or Programs and Features section click Uninstall a program. The list of installed programs will populate.
  • Remove all older versions of Java. These may call themselves: Java Runtime, Runtime Environment, Runtime, JRE, Java Virtual Machine, Virtual Machine, Java VM, JVM, VM, J2RE or J2SE
    The versions I see on the computer are:
    • Java 7 Update
    • Java 8 (64-bit)
    • Java SE Development Kit 8

  • Right click each program and click Uninstall and follow the on screen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.

C.
Install the latest JAVA

Back on your desktop:
  • Right click the  jre-8u25-windows-x64.exe file, click Run as Administrator and OK the UAC prompt to install the newest version.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.

[Note:] The Java Quick Starter (JQS.exe) adds a service to improve the initial start up time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > You will have to be in Classic View to see Java(It looks like a coffee cup). Double-click on Java click the Advanced Tab click Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.


Update Adobe Flash Player

NOTE: Depending on your settings, you may have to temporarily disable your antivirus software and firewall.
  • Please click here to go to the FlashPlayer Installation page.
  • In the first column, Adobe Flash Player, make sure the system version (64bit) and the browser are correct.
    • Note: If you use IE and other browsers you will need to install both Flash Player for IE and Flash Player for Other Browsers.

  • In the middle column, Optional offer:, UNCHECK the box next to Yes, install free McAfee Security Scan Plus
  • Click the Install now button. A download window for the install_flashplayer15x64_mssd_aaa_aih.exe file will open. Save it to the desktop.
  • Close the browser and all open windows.
  • Back on the desktop, right click the install_flashplayer15x64_mssd_aaa_aih.exe file and click Run as Administrator to install Flash Player.


Cryptolocker Warning
Go here for information about CryptoLocker Ransomeware.
The main thing with this infection is ~ Backup.
If you're using an external hard drive, keep it unplugged from the computer when you're not backing up files or using it. This will prevent the infection from getting to your backed up files if you ever do come across it.

Recommended Programs
Unchecky is a small service that runs in the background to help keep those "extra toolbars" and tag along search engines from automatically installing. By automatically directing you to a custom install with all the options unchecked, only what you manually choose and confirm gets installed.
is a free program that prevents CryptoLocker / ransomware from infecting your PC by locking down the OS so the malware can not get a grip on your system.
Web Of Trust is a free program that prevents CryptoLocker / ransomware from infecting your PC by locking down the OS so the malware can not get a grip on your system.
Web Of Trust is a browser add-on designed to alert the user before interacting with a potentially malicious website. It will highlight green if a site is known to be safe.

[url=https://adblockplus.org/en/firefox]Adblock is a firefox browser add-on that blocks annoying banners, pop-ups and video ads.

General Advice
  • When browsing the internet, look closely at the links you click on. Some aren't always what they seem
  • Avoid Peer to Peer file sharing utilities, these are a minefield of malware infections.
  • Don't open email attachments unless you are expecting them. Even an email from your best friend can be infected, they might not have sent it.
  • Pay attention when installing a program to your computer, particularly to any check boxes that may appear during installation, it is common for unwanted software to be installed in this way.


  • 0

#29
Nas

Nas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts
# DelFix v10.8 - Logfile created 26/02/2015 at 23:02:13
# Updated 29/07/2014 by Xplode
# Username : Manraj - MANRAJPC
# Operating System : Windows 8.1 Pro  (64 bits)
 
~ Activating UAC ... OK
 
~ Removing disinfection tools ...
 
Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\Users\Manraj\Desktop\FRST-OlderVersion
Deleted : C:\zoek-results.log
Deleted : C:\Users\Manraj\Desktop\Fixlog.txt
Deleted : C:\Users\Manraj\Desktop\FRST64.exe
Deleted : C:\Users\Manraj\Desktop\zoek.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
 
~ Cleaning system restore ...
 
Deleted : RP #44 [Windows Modules Installer | 02/11/2015 18:57:53]
Deleted : RP #45 [zoek.exe restore point | 02/17/2015 17:40:08]
Deleted : RP #47 [Restore Point Created by FRST | 02/19/2015 18:55:48]
Deleted : RP #48 [Windows Update | 02/25/2015 01:11:33]
 
New restore point created !
 
~ Resetting system settings ... OK
 
########## - EOF - ##########
 
 
 
 
Thank you so much for your help guys :)
 

  • 0

#30
ruggie_uk

ruggie_uk

    Trusted Helper

  • Malware Removal
  • 2,083 posts

You are welcome


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP