Possible malaware issue (maybe Trojon?)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #31
    FRST Fix.

    Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

    9-Lab Scan.

    [ul]
    [li]Download 9-Lab Removal Tool. [/li][li]CLICK HERE to determine whether you’re running 32-bit or 64-bit for Windows.[/li][li]Install the program onto your computer, then right click the icon run as administrator.[/li][li]Update the program and then run a full scan![/li][li]Make sure the program updates, might be better to install it update reboot and check for updates again.[/li][li]You need to make sure the database updates!!![/li][li]Upon Scan Completion Click on Show Results.[/li][li]Then Click On Clean [/li][li]Then Click on Save Log.[/li][li]Save it to your desktop, copy and paste the contents of the log here in your next reply.[/li][/ul]

    Security Check Scan.

    [ul]
    [li]Download Security Check to your desktop.[/li][li]Right click it run as administrator.[/li][li]When the program completes, the tool will automatically open a log file.[/li][li]Please post that log here in your next post.[/li][/ul]

    Comment

    • Dyvenge
      PCHF Member
      • Sep 2016
      • 33

      #32
      [HEADING=1]Fix result of Farbar Recovery Scan Tool (x64) Version: 28-09-2016
      Ran by garar (29-09-2016 20:48:15) Run:1
      Running from C:\Users\garar\Desktop
      Loaded Profiles: garar (Available Profiles: garar)
      Boot Mode: Normal[/HEADING]
      fixlist content:


      start
      CreateRestorePoint:
      CloseProcesses:
      HKLM-x32...\Run: =>
      Tcpip\Parameters: [DhcpNameServer] 216.104.96.22 216.104.98.222
      Tcpip..\Interfaces{8f0b84d4-3949-4ec3-a249-d64e72d570de}: [DhcpNameServer] 216.104.96.22 216.104.98.222
      ManualProxies:
      HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
      HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
      HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
      HKU\S-1-5-21-1963327732-3332141323-2774556287-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      SearchScopes: HKU\S-1-5-21-1963327732-3332141323-2774556287-1001 → {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
      FF Plugin HKU\S-1-5-21-1963327732-3332141323-2774556287-1001: torrents-time.com/TTPlugin → C:\Program Files (x86)\TorrentsTime Media Player\bin\npTTPlugin.dll [2016-02-25] (Torrents Time)
      R2 TTService; C:\Program Files (x86)\TorrentsTime Media Player\bin\TTService.exe [3312152 2016-03-02] (TorrentsTime)
      2016-09-19 18:00 - 2016-09-19 18:00 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsigne2575cf367 850c79
      2016-09-19 17:59 - 2016-09-19 17:59 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignb4e41b1902 82c97d
      2016-09-19 17:59 - 2016-09-19 17:59 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign758003a20a a1c633
      2016-09-19 17:59 - 2016-09-19 17:59 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign491f379cf2 187421
      2016-09-19 17:59 - 2016-09-19 17:59 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign2f5562a456 dca9ea
      2016-09-19 17:59 - 2016-09-19 17:59 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign0906545ef3 d2ccd4
      2016-09-15 20:13 - 2016-09-15 20:13 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign828a5b88b8 34b3ed
      2016-09-15 20:13 - 2016-09-15 20:13 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign7e0caaa4ff d45751
      2016-09-13 23:45 - 2016-09-13 23:45 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign4161003068 ac4071
      2016-09-13 23:45 - 2016-09-13 23:45 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign2fdcefa3f1 52120f
      2016-09-13 21:43 - 2016-09-13 21:43 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign89d28bea2e 1b652e
      2016-09-13 21:42 - 2016-09-13 21:42 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign8ee6a04b30 5059b6
      2016-09-13 21:42 - 2016-09-13 21:42 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign7730159777 d0a10a
      2016-09-13 21:42 - 2016-09-13 21:42 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign48e8adcdb1 b5ddf3
      2016-09-13 21:42 - 2016-09-13 21:42 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign1ac8100fe2 1f71a4
      2016-09-13 21:42 - 2016-09-13 21:42 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign19f79e399d 5f52cb
      2016-09-13 18:40 - 2016-09-13 18:40 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignac7a7447e0 072799
      2016-09-13 18:40 - 2016-09-13 18:40 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign8dae46f9de ad5d13
      2016-09-13 18:40 - 2016-09-13 18:40 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign8bd4dd28ce 8d93f2
      2016-09-13 18:40 - 2016-09-13 18:40 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign5b512d25f9 1a3f16
      2016-09-13 18:40 - 2016-09-13 18:40 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign4cff1cccd5 6b88e3
      2016-09-13 18:40 - 2016-09-13 18:40 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign39b6a2aae3 774712
      2016-09-11 23:03 - 2016-09-11 23:03 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign859c52ecad 9a3e45
      2016-09-11 22:36 - 2016-09-11 22:36 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsigndd1ccc74a6 8e6b3e
      2016-09-11 22:36 - 2016-09-11 22:36 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign814b895583 b16072
      2016-09-11 21:48 - 2016-09-11 21:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignf54767d6c6 32bf75
      2016-09-11 21:48 - 2016-09-11 21:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignc7e108b984 4aec90
      2016-09-11 21:48 - 2016-09-11 21:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignc0a414f071 833ea1
      2016-09-11 21:48 - 2016-09-11 21:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign77a50f516e 995d24
      2016-09-11 21:48 - 2016-09-11 21:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign52c32c3158 969642
      2016-09-11 21:48 - 2016-09-11 21:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign34897bc6d4 3910cb
      2016-09-10 11:15 - 2016-09-10 11:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TorrentsTime Media Player
      2016-09-10 11:15 - 2016-09-10 11:15 - 00000000 ____D C:\Program Files (x86)\TorrentsTime Media Player
      2016-09-08 23:02 - 2016-09-08 23:02 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignf2886709f4 cb0c3c
      2016-09-08 23:02 - 2016-09-08 23:02 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignd276861e06 5a71c6
      2016-09-08 23:02 - 2016-09-08 23:02 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign7e6bc0d203 611b51
      2016-09-08 23:02 - 2016-09-08 23:02 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign35ea1b58ff 410313
      2016-09-08 23:02 - 2016-09-08 23:02 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign1780ca78f1 945cfc
      2016-09-08 23:02 - 2016-09-08 23:02 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign0380f7e005 7a50e5
      2016-09-08 22:54 - 2016-09-08 22:54 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsigne3f1f7c670 161a4a
      2016-09-08 22:54 - 2016-09-08 22:54 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsigne1947cf282 63f752
      2016-09-08 22:54 - 2016-09-08 22:54 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign3453149ab2 c998dd
      2016-09-08 22:50 - 2016-09-08 22:50 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignf6ac6a50ba 439e8c
      2016-09-08 22:50 - 2016-09-08 22:50 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignc4ee34e789 1f1cc9
      2016-09-08 22:50 - 2016-09-08 22:50 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignc4458fe945 a03c22
      2016-09-08 22:50 - 2016-09-08 22:50 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign9efe8997fd 823d30
      2016-09-08 22:50 - 2016-09-08 22:50 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign7cbe4186f8 069071
      2016-09-08 22:50 - 2016-09-08 22:50 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign1135ea4cff 0fc7c6
      2016-09-08 21:34 - 2016-09-08 21:34 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignca377f48c0 81ae3f
      2016-09-08 21:34 - 2016-09-08 21:34 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignc9e9d4c8b6 b19eb9
      2016-09-08 21:34 - 2016-09-08 21:34 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignc4ed5537de 3c207a
      2016-09-08 21:34 - 2016-09-08 21:34 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign9f0479b90f a5b7a1
      2016-09-08 21:34 - 2016-09-08 21:34 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign5d5fb14c5e f3e9af
      2016-09-08 21:34 - 2016-09-08 21:34 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign509c06e4de 89eb99
      2016-09-08 21:34 - 2016-09-08 21:34 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign3d7ee335c3 70ea31
      2016-09-08 21:34 - 2016-09-08 21:34 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign34c068662f 768513
      2016-09-07 22:38 - 2016-09-07 22:38 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign96febe7c9d a1ec2a
      2016-09-07 22:37 - 2016-09-07 22:37 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign82f6be7bcf 18a03e
      2016-09-07 22:37 - 2016-09-07 22:37 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign38f309810d c8eb69
      2016-09-07 21:22 - 2016-09-07 21:22 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignbad14a18ab af6018
      2016-09-07 21:10 - 2016-09-07 21:10 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignf38d283361 cbe48f
      2016-09-07 21:09 - 2016-09-07 21:09 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignc7f13f5fd3 46d1f7
      2016-09-07 21:09 - 2016-09-07 21:09 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign1ee89d82de a5b667
      2016-09-07 21:08 - 2016-09-07 21:08 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignfa9c2a60a2 f06896
      2016-09-07 21:08 - 2016-09-07 21:08 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignd31094be9b ffc0cf
      2016-09-07 21:08 - 2016-09-07 21:08 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignc4a5fcc621 de0785
      2016-09-07 21:08 - 2016-09-07 21:08 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign1cd841854f 112558
      2016-09-07 21:08 - 2016-09-07 21:08 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign157c3d9942 191753
      2016-09-07 21:08 - 2016-09-07 21:08 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign14cd1da5ad 0a09de
      2016-09-07 20:48 - 2016-09-07 20:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign99878cab21 1dcc9b
      2016-09-07 20:48 - 2016-09-07 20:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign95a40fb5c7 41bc38
      2016-09-07 20:48 - 2016-09-07 20:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign7e7834b71f 748993
      2016-09-07 20:48 - 2016-09-07 20:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign72017d07e1 7706c0
      2016-09-07 20:48 - 2016-09-07 20:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign2a90ffca98 298e99
      2016-09-07 20:48 - 2016-09-07 20:48 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign0605ecb00c b695a5
      2016-09-07 20:18 - 2016-09-07 20:18 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign86711be6be a8f6d6
      2016-09-06 20:04 - 2016-09-06 20:04 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignb62f5c40c4 e6d177
      2016-09-06 20:04 - 2016-09-06 20:04 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign2879c30d9e af4035
      2016-09-05 22:08 - 2016-09-05 22:08 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign2f42856b4f 6cb846
      2016-09-05 22:07 - 2016-09-05 22:07 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign644ba8466a 8d77f7
      2016-09-05 22:07 - 2016-09-05 22:07 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign28bf1d258c e254d8
      2016-09-05 20:45 - 2016-09-05 20:45 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign449e2a49dc 99f333
      2016-09-05 20:45 - 2016-09-05 20:45 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign3bd21d1661 7eba6c
      2016-09-05 20:44 - 2016-09-05 20:44 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign29859784c4 d69297
      2016-09-05 20:43 - 2016-09-05 20:43 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsigneb6385cd98 9b46c5
      2016-09-05 20:43 - 2016-09-05 20:43 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignde322f5e97 dc508d
      2016-09-05 20:43 - 2016-09-05 20:43 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsignac56367ba6 e4454b
      2016-09-05 20:43 - 2016-09-05 20:43 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign7c14b48d67 39fa75
      2016-09-05 20:43 - 2016-09-05 20:43 - 00000000 ____D C:\Users\garar\AppData\Local\Tempzxpsign263178747e 9360ca
      C:\Users\garar\AppData\Roaming\settings.ini
      2016-09-05 20:43 - 2016-09-19 17:59 - 0000033 _____ () C:\Users\garar\AppData\Roaming\AdobeWLCMCache.dat
      2016-09-05 00:09 - 2016-09-07 22:37 - 0000000 _____ () C:\Users\garar\AppData\Roaming\settings.ini
      2016-09-19 21:36 - 2016-09-19 21:36 - 0026837 _____ () C:\ProgramData\agent.1474335373.bdinstall.bin
      CustomCLSID: HKU\S-1-5-21-1963327732-3332141323-2774556287-1001_Classes\CLSID{0E270DAA-1BE6-48F2-AC49-50903CC8184B}\InprocServer32 → %%systemroot%%\system32\shell32.dll => No File
      Task: {5F2401FF-5A8F-4F43-87DF-83ADD03F4A91} - System32\Tasks\MSIOSDx86_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe [2016-07-28] (Micro-Star INT’L CO., LTD.)
      Task: {6A6E8D7D-AB7A-4CDB-8630-BE73D75BCA9C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16] (Adobe Systems Incorporated)
      Task: {6DCB024B-B6F8-41BF-8325-57F442E978E4} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\garar\AppData\Local\Microsoft\OneDrive\17 .3.6517.0809\OneDriveStandaloneUpdater.exe [2016-09-01] (Microsoft Corporation)
      Task: {C0047965-CA8B-4E9A-BA04-0D6C657B69B5} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe [2016-09-13] (Adobe Systems Incorporated)
      Task: {C9646A87-8EA7-4300-B7FE-38BFE368DFC1} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-gararion@gmail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.e xe [2016-07-01] (Adobe Systems Incorporated)
      Task: {E0223F54-96A9-4DB9-B512-7E0C8F9D8155} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-09-15] (Overwolf LTD)
      Task: {E21AC619-0D98-425D-8029-9E1FBB45EC0E} - System32\Tasks\MSIOSDx64_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe [2016-07-28] (Micro-Star INT’L CO., LTD.)
      C:\Program Files (x86)\TorrentsTime Media Player
      AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq[ICODE]qsp[/ICODE]27hfm [0]
      AlternateDataStreams: C:\Users\garar\Desktop\Adware Removal Tool by TSA.exe:BDU [0]
      AlternateDataStreams: C:\Users\garar\Desktop\adwcleaner_6.020.exe:BDU [0]
      AlternateDataStreams: C:\Users\garar\Desktop\JRT.exe:BDU [0]
      AlternateDataStreams: C:\Users\garar\Desktop\ZHPCleaner.exe:BDU [0]
      AlternateDataStreams: C:\Users\garar\Desktop\zoek.exe:BDU [0]
      AlternateDataStreams: C:\Users\garar\Downloads\aswmbr.exe:BDU [0]
      AlternateDataStreams: C:\Users\garar\Downloads\mbam-setup-2.2.1.1043.exe:BDU [0]
      AlternateDataStreams: C:\Users\garar\Downloads\TeamSpeak3-Client-win64-3.0.19.4.exe:BDU [0]
      AlternateDataStreams: C:\Users\garar\Downloads\Zemana.AntiMalware.Setup. exe:BDU [0]
      RemoveProxy:
      Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Pol icy\Local /f
      Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Pol icy\Local /f
      CMD: bitsadmin /reset /allusers
      CMD: ipconfig /flushdns
      Emptytemp:
      reboot:
      end


      Restore point was successfully created.
      Processes closed successfully.
      HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\ => value removed successfully
      HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\DhcpNameServer => value removed successfully
      HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{8f0b84d4-3949-4ec3-a249-d64e72d570de}\DhcpNameServer => value removed successfully
      HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Para meters\Internet\ManualProxies\ => value removed successfully
      HKLM\Software\Microsoft\Internet Explorer\Main\Start Page => value restored successfully
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Start Page => value restored successfully
      HKLM\Software\Microsoft\Internet Explorer\Main\Default_Page_URL => value restored successfully
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Default_Page_URL => value restored successfully
      HKLM\Software\Microsoft\Internet Explorer\Main\Default_Search_URL => value restored successfully
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Default_Search_URL => value restored successfully
      HKU\S-1-5-21-1963327732-3332141323-2774556287-1001\Software\Microsoft\Internet Explorer\Main\Start Page => value restored successfully
      “HKU\S-1-5-21-1963327732-3332141323-2774556287-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{012E1000-F331-11DB-8314-0800200C9A66}” => key removed successfully
      HKCR\CLSID{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
      “HKU\S-1-5-21-1963327732-3332141323-2774556287-1001\Software\MozillaPlugins\torrents-time.com/TTPlugin” => key removed successfully
      C:\Program Files (x86)\TorrentsTime Media Player\bin\npTTPlugin.dll => moved successfully
      TTService => service removed successfully
      C:\Users\garar\AppData\Local\Tempzxpsigne2575cf367 850c79 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignb4e41b1902 82c97d => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign758003a20a a1c633 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign491f379cf2 187421 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign2f5562a456 dca9ea => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign0906545ef3 d2ccd4 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign828a5b88b8 34b3ed => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign7e0caaa4ff d45751 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign4161003068 ac4071 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign2fdcefa3f1 52120f => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign89d28bea2e 1b652e => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign8ee6a04b30 5059b6 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign7730159777 d0a10a => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign48e8adcdb1 b5ddf3 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign1ac8100fe2 1f71a4 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign19f79e399d 5f52cb => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignac7a7447e0 072799 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign8dae46f9de ad5d13 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign8bd4dd28ce 8d93f2 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign5b512d25f9 1a3f16 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign4cff1cccd5 6b88e3 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign39b6a2aae3 774712 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign859c52ecad 9a3e45 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsigndd1ccc74a6 8e6b3e => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign814b895583 b16072 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignf54767d6c6 32bf75 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignc7e108b984 4aec90 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignc0a414f071 833ea1 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign77a50f516e 995d24 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign52c32c3158 969642 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign34897bc6d4 3910cb => moved successfully
      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TorrentsTime Media Player => moved successfully
      C:\Program Files (x86)\TorrentsTime Media Player => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignf2886709f4 cb0c3c => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignd276861e06 5a71c6 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign7e6bc0d203 611b51 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign35ea1b58ff 410313 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign1780ca78f1 945cfc => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign0380f7e005 7a50e5 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsigne3f1f7c670 161a4a => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsigne1947cf282 63f752 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign3453149ab2 c998dd => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignf6ac6a50ba 439e8c => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignc4ee34e789 1f1cc9 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignc4458fe945 a03c22 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign9efe8997fd 823d30 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign7cbe4186f8 069071 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign1135ea4cff 0fc7c6 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignca377f48c0 81ae3f => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignc9e9d4c8b6 b19eb9 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignc4ed5537de 3c207a => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign9f0479b90f a5b7a1 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign5d5fb14c5e f3e9af => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign509c06e4de 89eb99 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign3d7ee335c3 70ea31 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign34c068662f 768513 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign96febe7c9d a1ec2a => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign82f6be7bcf 18a03e => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign38f309810d c8eb69 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignbad14a18ab af6018 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignf38d283361 cbe48f => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignc7f13f5fd3 46d1f7 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign1ee89d82de a5b667 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignfa9c2a60a2 f06896 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignd31094be9b ffc0cf => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignc4a5fcc621 de0785 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign1cd841854f 112558 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign157c3d9942 191753 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign14cd1da5ad 0a09de => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign99878cab21 1dcc9b => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign95a40fb5c7 41bc38 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign7e7834b71f 748993 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign72017d07e1 7706c0 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign2a90ffca98 298e99 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign0605ecb00c b695a5 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign86711be6be a8f6d6 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignb62f5c40c4 e6d177 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign2879c30d9e af4035 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign2f42856b4f 6cb846 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign644ba8466a 8d77f7 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign28bf1d258c e254d8 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign449e2a49dc 99f333 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign3bd21d1661 7eba6c => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign29859784c4 d69297 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsigneb6385cd98 9b46c5 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignde322f5e97 dc508d => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsignac56367ba6 e4454b => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign7c14b48d67 39fa75 => moved successfully
      C:\Users\garar\AppData\Local\Tempzxpsign263178747e 9360ca => moved successfully
      C:\Users\garar\AppData\Roaming\settings.ini => moved successfully
      C:\Users\garar\AppData\Roaming\AdobeWLCMCache.dat => moved successfully
      “C:\Users\garar\AppData\Roaming\settings.ini” => not found.
      C:\ProgramData\agent.1474335373.bdinstall.bin => moved successfully
      “HKU\S-1-5-21-1963327732-3332141323-2774556287-1001_Classes\CLSID{0E270DAA-1BE6-48F2-AC49-50903CC8184B}” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{5F2401F F-5A8F-4F43-87DF-83ADD03F4A91}” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{5F2401F F-5A8F-4F43-87DF-83ADD03F4A91}” => key removed successfully
      C:\WINDOWS\System32\Tasks\MSIOSDx86_Host => moved successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MSIOSDx8 6_Host” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{6A6E8D7 D-AB7A-4CDB-8630-BE73D75BCA9C}” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{6A6E8D7 D-AB7A-4CDB-8630-BE73D75BCA9C}” => key removed successfully
      C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task => moved successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{6DCB024 B-B6F8-41BF-8325-57F442E978E4}” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{6DCB024 B-B6F8-41BF-8325-57F442E978E4}” => key removed successfully
      C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task => moved successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Standalone Update Task” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{C004796 5-CA8B-4E9A-BA04-0D6C657B69B5}” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{C004796 5-CA8B-4E9A-BA04-0D6C657B69B5}” => key removed successfully
      C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater => moved successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{C9646A8 7-8EA7-4300-B7FE-38BFE368DFC1}” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{C9646A8 7-8EA7-4300-B7FE-38BFE368DFC1}” => key removed successfully
      C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-gararion@gmail.com => moved successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeAAMUpdater-1.0-MicrosoftAccount-gararion@gmail.com” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{E0223F5 4-96A9-4DB9-B512-7E0C8F9D8155}” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{E0223F5 4-96A9-4DB9-B512-7E0C8F9D8155}” => key removed successfully
      C:\WINDOWS\System32\Tasks\Overwolf Updater Task => moved successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Overwolf Updater Task” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{E21AC61 9-0D98-425D-8029-9E1FBB45EC0E}” => key removed successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{E21AC61 9-0D98-425D-8029-9E1FBB45EC0E}” => key removed successfully
      C:\WINDOWS\System32\Tasks\MSIOSDx64_Host => moved successfully
      “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MSIOSDx6 4_Host” => key removed successfully
      “C:\Program Files (x86)\TorrentsTime Media Player” => not found.
      C:\ProgramData\Reprise => “:wupeogjxldtlfudivq[ICODE]qsp[/ICODE]27hfm” ADS removed successfully.
      C:\Users\garar\Desktop\Adware Removal Tool by TSA.exe => “:BDU” ADS removed successfully.
      C:\Users\garar\Desktop\adwcleaner_6.020.exe => “:BDU” ADS removed successfully.
      C:\Users\garar\Desktop\JRT.exe => “:BDU” ADS removed successfully.
      C:\Users\garar\Desktop\ZHPCleaner.exe => “:BDU” ADS removed successfully.
      C:\Users\garar\Desktop\zoek.exe => “:BDU” ADS removed successfully.
      C:\Users\garar\Downloads\aswmbr.exe => “:BDU” ADS removed successfully.
      C:\Users\garar\Downloads\mbam-setup-2.2.1.1043.exe => “:BDU” ADS removed successfully.
      C:\Users\garar\Downloads\TeamSpeak3-Client-win64-3.0.19.4.exe => “:BDU” ADS removed successfully.
      C:\Users\garar\Downloads\Zemana.AntiMalware.Setup. exe => “:BDU” ADS removed successfully.

      ========= RemoveProxy: =========

      HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVers ion\Internet Settings\Connections\DefaultConnectionSettings => value removed successfully
      HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVers ion\Internet Settings\Connections\SavedLegacySettings => value removed successfully
      HKU\S-1-5-21-1963327732-3332141323-2774556287-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\DefaultConnectionSettings => value removed successfully
      HKU\S-1-5-21-1963327732-3332141323-2774556287-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\SavedLegacySettings => value removed successfully

      ========= End of RemoveProxy: =========

      ========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Pol icy\Local /f =========

      The operation completed successfully.

      ========= End of Reg: =========

      ========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Pol icy\Local /f =========

      The operation completed successfully.

      ========= End of Reg: =========

      ========= bitsadmin /reset /allusers =========

      BITSADMIN version 3.0 [ 7.8.10586 ]
      BITS administration utility.
      (C) Copyright 2000-2006 Microsoft Corp.

      BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
      Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

      0 out of 0 jobs canceled.

      ========= End of CMD: =========

      ========= ipconfig /flushdns =========

      Windows IP Configuration

      Successfully flushed the DNS Resolver Cache.

      ========= End of CMD: =========

      =========== EmptyTemp: ==========

      BITS transfer queue => 32768 B
      DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 6417352 B
      Java, Flash, Steam htmlcache => 21375593 B
      Windows/system/drivers => 404399508 B
      Edge => 51476523 B
      Chrome => 0 B
      Firefox => 384884809 B
      Opera => 0 B

      Temp, IE cache, history, cookies, recent:
      Default => 0 B
      ProgramData => 0 B
      Public => 0 B
      systemprofile => 128 B
      systemprofile32 => 0 B
      LocalService => 34250 B
      NetworkService => 8054 B
      garar => 4170413949 B

      RecycleBin => 0 B
      EmptyTemp: => 4.7 GB temporary data Removed.

      ================================

      The system needed a reboot.

      ==== End of Fixlog 20:48:40 ====

      Comment

      • Dyvenge
        PCHF Member
        • Sep 2016
        • 33

        #33
        9-lab Removal Tool 1.0.0.39 BETA

        [URL unfurl="true"]https://9-lab.com/[/URL]

        Database version: 142.43537

        Windows 8 (Version 6.2, Build 0, 64-bit Edition)
        Internet Explorer 9.11.10586.0
        garar :: DESKTOP-C5IISBO

        2016-09-29 9:01:07 PM
        9lab-log-2016-09-29 (21-01-07).txt

        Scan type: Full
        Objects scanned: 42662
        Time Elapsed: 8 m 50 s

        Registry Keys detected: 2
        PUP.RMPL.Baidu.vl [HKEY_CLASSES_ROOT\BDShellExt.BDMenu]
        PUP.RMPL.Baidu.vl [HKEY_CLASSES_ROOT\BDShellExt.BDMenu.1]

        Files detected: 14
        [B45F8BBB8580502550FB714DF5B7E19F] Trojan.FPL.Rotbrow.vl [c:\users\garar\appdata\roaming\ZHP\Quarantine\host s]
        [7D82D50DBC3AFDCEF5838A36B3296F86] Trojan.FPL.Rotbrow.vl [c:\users\garar\appdata\roaming\ZHP\Quarantine\oxy. exe]
        [133D724F0EE7C89525A0A604F1FC0B8A] Trojan.FPL.Rotbrow.vl [c:\users\garar\appdata\roaming\ZHP\Tempo.txt]
        [297AD30C1EB869E0008ECA7538327C37] Trojan.FPL.Rotbrow.vl [c:\users\garar\appdata\roaming\ZHP\Trace.txt]
        [BFF2A9A86983DC15846CE165F4321433] Trojan.FPL.Rotbrow.vl [c:\users\garar\appdata\roaming\ZHP\ZHPCleaner-[R]-26092016-23_05_22.txt]
        [2837F0060DE67AB6C742F9F332320E58] Trojan.FPL.Rotbrow.vl [c:\users\garar\appdata\roaming\ZHP\ZHPCleaner--26092016-23_03_22.txt]
        [EFFC998F0D2FF6AC21B9A8BDA5A8983D] Trojan.FPL.Rotbrow.vl [c:\users\garar\appdata\roaming\ZHP\ZHPCleaner.txt]
        [7B5E1D30E89E0EF1C86FECB977131673] Trojan.FPL.Rotbrow.vl [c:\users\garar\appdata\roaming\ZHP\ZHPCleaner_Quar antine.txt]
        [8F0EC74CA350B9B519DF0FC0A25BF824] Trojan.FPL.Rotbrow.vl [c:\users\garar\appdata\roaming\ZHP\ZHPCleaner_Temp o.txt]
        [78C647EE3F33D5E6DBADA0F5D4491099] Trojan.FPL.Rotbrow.vl [c:\users\garar\appdata\roaming\ZHP\ZHPQ_Files.txt]
        [7EA0260488F304D68067A50B33A23AC2] Malware.Win32.Gen.sm [C:\Users\garar\Desktop\zoek.exe]
        [E5CB3A4E25659BF053A4A18EC0504126] Malware.Win32.Gen.vb [C:\Windows\act_win_1339.exe]
        [1AA260EBDEF33846849287A11017DF80] Malware.Win32.Gen.cs0 [C:\Users\garar\AppData\Roaming\ZHP\ZHPCleaner.exe]
        [1AA260EBDEF33846849287A11017DF80] Malware.Win32.Gen.cs0 [C:\Users\garar\Desktop\ZHPCleaner.exe]

        Comment

        • Dyvenge
          PCHF Member
          • Sep 2016
          • 33

          #34
          SecurityCheck by glax24 & Severnyj v.1.4.0.46 [22.09.16]
          WebSite: www.safezone.cc
          DateLog: 29.09.2016 21:19:00
          Path starting: C:\Users\garar\AppData\Local\Temp\SecurityCheck\Se curityCheck.exe
          Log directory: C:\SecurityCheck
          IsAdmin: True
          User: garar
          VersionXML: 3.39is-26.09.2016


          Windows 10(6.3.10586) (x64) Core Lang: English(0409)
          Installation date OS: 01.09.2016 00:42:27
          LicenseStatus: Windows(R), Core edition The machine is permanently activated.
          Boot Mode: Normal
          Default Browser: Microsoft Edge (C:\WINDOWS\system32\LaunchWinApp.exe)
          SystemDrive: C: FS: [NTFS] Capacity: [111.7 Gb] Used: [34.9 Gb] Free: [76.8 Gb]
          ------------------------------- [ Windows ] -------------------------------
          Internet Explorer 11.589.10586.0
          User Account Control enabled

          Windows Update (wuauserv) - The service has stopped
          Security Center (wscsvc) - The service is running
          Remote Registry (RemoteRegistry) - The service has stopped
          SSDP Discovery (SSDPSRV) - The service is running
          Remote Desktop Services (TermService) - The service has stopped
          Windows Remote Management (WS-Management) (WinRM) - The service has stopped
          ---------------------------- [ Antivirus_WMI ] ----------------------------
          Windows Defender (disabled and up to date)
          Bitdefender Antivirus (enabled and up to date)
          ---------------------------- [ Firewall_WMI ] -----------------------------
          Bitdefender Firewall (enabled)
          --------------------------- [ AntiSpyware_WMI ] ---------------------------
          Bitdefender Antispyware (enabled and up to date)
          Windows Defender (disabled and up to date)
          ---------------------- [ AntiVirusFirewallInstall ] -----------------------
          Bitdefender Internet Security 2016 v.20.0.29.1517
          Bitdefender Agent v.20.0.29.1517
          -------------------------- [ SecurityUtilities ] --------------------------
          Malwarebytes Anti-Malware version 2.2.1.1043 v.2.2.1.1043
          Zemana AntiMalware v.2.50.72
          --------------------------- [ OtherUtilities ] ----------------------------
          WinRAR 5.40 (64-bit) v.5.40.0
          --------------------------- [ AdobeProduction ] ---------------------------
          Adobe Flash Player 23 NPAPI v.23.0.0.162
          Adobe Acrobat Reader DC v.15.017.20053
          ------------------------------- [ Browser ] -------------------------------
          Mozilla Firefox 48.0.2 (x86 en-US) v.48.0.2 Warning! Download Update
          --------------------------- [ RunningProcess ] ----------------------------
          C:\Program Files (x86)\Mozilla Firefox\firefox.exe v.48.0.2.6079
          ------------------ [ AntivirusFirewallProcessServices ] -------------------
          C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe v.20.0.28.1515
          ProductAgentService (ProductAgentService) - The service is running
          C:\Program Files\Bitdefender Agent\ProductAgentService.exe v.20.0.20.179
          Bitdefender Desktop Update Service (UPDATESRV) - The service is running
          C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe v.20.0.28.1507
          Bitdefender Virus Shield (VSSERV) - The service is running
          C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe v.20.0.28.1515
          D:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe v.2.3.173.0
          MBAMScheduler (MBAMScheduler) - The service is running
          D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe v.3.1.7.0
          MBAMService (MBAMService) - The service is running
          D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe v.3.2.21.0
          Windows Defender Service (WinDefend) - The service has stopped
          Windows Defender Network Inspection Service (WdNisSvc) - The service has stopped
          ZAM Controller Service (ZAMSvc) - The service is running
          C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe v.0.0.0.0
          ---------------------------- [ UnwantedApps ] -----------------------------
          TorrentsTime Media Player v.1.1.9.5 Warning! Suspected Adware! If this program is not familiar to you it is recommended to uninstall it and execute PC scanning using Malwarebytes Anti-Malware and AdwCleaner (by ToolsLib). Before uninstallation and scanning it is necessary to consult in the forum where cure is provided for you!!!
          ----------------------------- [ End of Log ] ------------------------------

          Comment

          • Malnutrition
            PCHF Moderator
            • Jul 2016
            • 7041

            #35
            Any issues to speak of?

            Comment

            • Dyvenge
              PCHF Member
              • Sep 2016
              • 33

              #36
              Haven’t had a chance to fully inspect things as of yet but computer is now staying asleep. Will give it a look about tomorrow after work. Side note, of all the programs/files that have now been downloaded/installed/placed on desktop, if everything is fine is there anything I can remove? Mainly asking as one of the last reports mentioned ZHP having Trojans and such, though it did say it cleaned them. Also kinda aiming to have my desktop rather clean if possible this time around.

              Comment

              • Malnutrition
                PCHF Moderator
                • Jul 2016
                • 7041

                #37
                Glad to have helped!! Please tell a friend … or two about us. https://forum.windowsinstructed.com/...cons/smile.png

                suggest the following in place of adblock.
                Alternate DNS Server. Ad Blocking DNS.
                Ublock Origin.
                Anti Ad Block Killer.

                Also, keep your browsing private with these tools:

                Self Destructing Cookies.
                Self Destructing Cookies Chrome.

                Some items to keep you safe on the internet.

                VooDoo Shield. control of what is running on your machine
                Qualys BrowserCheck To update plugins.
                Web Of Trust To Avoid Shady Websites.
                Unchecky To Avoid Bundled Software.
                Privazer To Clean up your mahcine.

                Now Lets Clean up the tools we used and remove old restore points.

                Download DelFix by “Xplode” to your Desktop.
                Right Click the tool and Run as Admin ( Xp Users Double Click)
                Put a check mark next the items below:

                Remove disinfection tools
                Create registry backup
                Purge System Restore

                Now click on “Run” button.
                allow the program to complete its work.
                all the tools we used will be removed.
                Tool will create and open a log report (DelFix.txt)
                Note: The report can be located at the following location C:\DelFix.txt
                Originally posted by Dyvenge
                Mainly asking as one of the last reports mentioned ZHP having Trojans and such, though it did say it cleaned them
                That last tool detected items that were in ZHP Quarantine… By running Del Fix you will clean all the tools we used in this thread.

                Comment

                • Dyvenge
                  PCHF Member
                  • Sep 2016
                  • 33

                  #38
                  Sorry, just getting a chance to do t he last steps you mentioned. So far the computer is running great.

                  Tried to download that DelFix f lie but getting a server not found error.

                  Comment

                  • jmarket
                    PCHF Owner
                    • Jan 2015
                    • 7634

                    #39
                    Downloads - DelFix - Download Now - ToolsLib

                    There you go

                    Comment

                    • Dyvenge
                      PCHF Member
                      • Sep 2016
                      • 33

                      #40
                      okay, thanks. That worked. Though on my desktop I still have the following:
                      Zemana AntiMalware
                      Adware Remaoval Tool by TSA
                      Removal Tool

                      Which one of those can I simply delete and which ones should be removed by either another method or Add/Remove programs uninstall?

                      Comment

                      • Malnutrition
                        PCHF Moderator
                        • Jul 2016
                        • 7041

                        #41
                        Originally posted by Dyvenge
                        okay, thanks. That worked. Though on my desktop I still have the following:
                        Zemana AntiMalware
                        Adware Remaoval Tool by TSA
                        Removal Tool

                        Which one of those can I simply delete and which ones should be removed by either another method or Add/Remove programs uninstall?
                        Simply delete the adware removal tool. Keep Zemana if you wish and scan with it from time to time to keep your machine malware free.

                        Comment

                        • Dyvenge
                          PCHF Member
                          • Sep 2016
                          • 33

                          #42
                          Thanks for your help and I will defiantly be keeping you sin mind if I know of anyone else having computer issues.

                          Comment

                          Working...