Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I can't remove ads from "saleschecker" and constant pop-up's


  • This topic is locked This topic is locked
2 replies to this topic

#1 csrtio

csrtio

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:35 PM

Posted 04 February 2015 - 07:15 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2015
Ran by mikaela (administrator) on MIKAELA on 04-02-2015 00:39:48
Running from C:\Users\mikaela\Downloads
Loaded Profiles: mikaela & Administratör (Available profiles: mikaela & Administratör)
Platform: Microsoft Windows 8.1 (X86) OS Language: Svenska (Sverige)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ATK Package\ATK Hotkey\AsHidSrv.exe
(ASUS Cloud Corporation) C:\Program Files\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX86\officeclicktorun.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe
(Intel® Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer INC.) C:\ProgramData\AsTouchPanel\AsPatchTouchPanel.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(AsusTek) C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPLoader.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPCenter.exe
(AsusTek) C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe
(Spotify Ltd) C:\Users\mikaela\AppData\Roaming\Spotify\spotify.exe
(BitTorrent Inc.) C:\Users\mikaela\AppData\Roaming\uTorrent\uTorrent.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
() C:\Users\mikaela\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\mikaela\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\Users\mikaela\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\mikaela\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\mikaela\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Intel Corporation) C:\Program Files\Intel\TXE Components\DAL\jhi_service.exe
(ASUS Cloud Corporation) C:\Program Files\ASUS\WebStorage\2.0.3.226\AsusWSPanel.exe
(Trend Micro Inc.) C:\Users\mikaela\Downloads\HousecallLauncher.exe
(Trend Micro Inc.) C:\Users\mikaela\AppData\Local\Temp\7zS6F89.tmp\Setup.exe
(Microsoft Corporation) C:\Windows\FileManager\FileManager.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x86__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [ASUSPRP] => C:\Program Files\ASUS\APRP\APRP.EXE [3216032 2013-12-13] (ASUSTek Computer Inc.)
HKLM\...\Run: [WebStorage] => C:\Program Files\ASUS\WebStorage\2.0.3.226\ASUSWSLoader.exe [63296 2013-08-16] ()
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [73216 2013-11-02] (Intel Corporation)
HKLM\...\Run: [RtkNGUI] => C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe [2904064 2013-10-30] (Realtek Semiconductor)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKU\S-1-5-21-1776157182-2844987415-1046504066-1001\...\Run: [GoogleChromeAutoLaunch_8FC8C92AD5D5CF53A03E6829BDFF67F4] => C:\Program Files\Google\Chrome\Application\chrome.exe [856904 2014-12-06] (Google Inc.)
HKU\S-1-5-21-1776157182-2844987415-1046504066-1001\...\Run: [Spotify] => C:\Users\mikaela\AppData\Roaming\Spotify\Spotify.exe [6737976 2015-01-02] (Spotify Ltd)
HKU\S-1-5-21-1776157182-2844987415-1046504066-1001\...\Run: [uTorrent] => C:\Users\mikaela\AppData\Roaming\uTorrent\uTorrent.exe [1374032 2015-01-13] (BitTorrent Inc.)
HKU\S-1-5-21-1776157182-2844987415-1046504066-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6699800 2015-01-22] (SUPERAntiSpyware)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_BN] -> {CC5FC992-B0AA-47CD-9DC2-83445083CBB9} => C:\Program Files\Common Files\AWS\2.0.3.226\ASUSWSShellExt.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_ON] -> {618A47A2-528B-4D9A-AFC8-97D3233511E3} => C:\Program Files\Common Files\AWS\2.0.3.226\ASUSWSShellExt.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_UN] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files\Common Files\AWS\2.0.3.226\ASUSWSShellExt.dll (ASUS Cloud Corporation.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-1776157182-2844987415-1046504066-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com/?pc=ASJB
HKU\S-1-5-21-1776157182-2844987415-1046504066-500\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com/?pc=ASJB
HKU\S-1-5-21-1776157182-2844987415-1046504066-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com/?pc=ASJB
URLSearchHook: [S-1-5-21-1776157182-2844987415-1046504066-500_classes] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\S-1-5-21-1776157182-2844987415-1046504066-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1776157182-2844987415-1046504066-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.6
 
FireFox:
========
FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files\Intel\TXE Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\TXE Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
 
Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\mikaela\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Ask Search) - C:\Users\mikaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaajhmeplfccacopbgpfaibalfnhcb [2014-12-22]
CHR Extension: (Free Mp3 Music Search Downloads) - C:\Users\mikaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\aghgalahdhgjcpjhdeknpodognmmkgeh [2014-12-22]
CHR Extension: (Make a GIF) - C:\Users\mikaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\anhnbgabclnjfceopaladlmpfpgnpdjf [2015-01-13]
CHR Extension: (Dropmark sidebar) - C:\Users\mikaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\foiapgoppijipmmgkaibacckkhbngfhp [2015-01-05]
CHR Extension: (No Name) - C:\Users\mikaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-02-04]
CHR Extension: (Chainlove Countdown Timer) - C:\Users\mikaela\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljppcglljemjablfhgjdhndlpallobpl [2015-01-23]
CHR Extension: (WowCouponn) - C:\ProgramData\hahllkkcgmjblimbfkknnkkefcbkblna\ [2015-01-23]
CHR HKLM\...\Chrome\Extension: [aaaaajhmeplfccacopbgpfaibalfnhcb] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaajhmeplfccacopbgpfaibalfnhcb.crx [Not Found]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-23] (SUPERAntiSpyware.com)
R2 AsHidService; C:\Program Files\ASUS\ATK Package\ATK Hotkey\AsHidSrv.exe [103224 2013-09-09] (ASUSTek Computer Inc.)
R2 ASLDRService; C:\Program Files\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [111416 2013-09-09] (ASUSTek Computer Inc.)
R2 Asus WebStorage Windows Service; C:\Program Files\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe [71680 2013-08-16] (ASUS Cloud Corporation) [File not signed]
R2 ATKGFNEXSrv; C:\Program Files\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2011-11-21] (ASUS)
S2 BcmBtRSupport; C:\WINDOWS\system32\BtwRSupportService.exe [1677016 2014-03-14] (Broadcom Corporation.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe [1679536 2014-11-11] (Microsoft Corporation)
S3 cphs; C:\WINDOWS\system32\IntelCpHeciSvc.exe [279000 2013-11-13] (Intel Corporation)
R2 DptfParticipantProcessorService; C:\WINDOWS\system32\DptfParticipantProcessorService.exe [75264 2013-11-02] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\WINDOWS\system32\DptfPolicyCriticalService.exe [89088 2013-11-02] (Intel Corporation)
R2 DptfPolicyLpmService; C:\WINDOWS\system32\DptfPolicyLpmService.exe [82432 2013-11-02] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [586752 2013-07-01] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [637912 2013-07-01] (Intel® Corporation)
R2 jhi_service; C:\Program Files\Intel\TXE Components\DAL\jhi_service.exe [168216 2013-08-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 ScDeviceEnum; C:\WINDOWS\System32\ScDeviceEnum.dll [105472 2013-08-22] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [288128 2014-09-22] (Microsoft Corporation)
S3 WEPHOSTSVC; C:\WINDOWS\system32\wephostsvc.dll [20992 2013-08-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22192 2014-09-22] (Microsoft Corporation)
S3 workfolderssvc; C:\WINDOWS\system32\workfolderssvc.dll [1222144 2014-07-24] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ASMMAP; C:\Program Files\ASUS\ATK Package\ATKGFNEX\ASMMAP.sys [13880 2009-07-02] (ASUS)
R3 AsusHID; C:\WINDOWS\System32\drivers\AsusHID.sys [64792 2013-12-12] (ASUS Corporation)
R1 ATKWMIACPIIO; C:\Program Files\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi.sys [17720 2013-07-02] (ASUSTek Computer Inc.)
R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [25600 2014-02-22] (Microsoft Corporation)
R3 BCMSDH43XX; C:\WINDOWS\system32\DRIVERS\bcmdhd63.sys [304344 2013-10-03] (Broadcom Corp)
R3 BthLEEnum; C:\WINDOWS\System32\drivers\BthLEEnum.sys [186880 2013-12-04] (Microsoft Corporation)
R3 BthMini; C:\WINDOWS\System32\Drivers\BTHMINI.sys [24064 2013-08-22] (Microsoft Corporation)
S3 btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [144600 2014-03-14] (Broadcom Corporation.)
R3 BtwSerialBus; C:\WINDOWS\system32\DRIVERS\BtwSerialBus.sys [130776 2014-03-14] (Broadcom Corporation.)
R3 camera; C:\WINDOWS\system32\DRIVERS\camera.sys [345088 2013-12-02] (Intel Corporation)
R3 CM3218x; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [188416 2014-05-31] (Microsoft Corporation)
R3 CPLMACPI; C:\WINDOWS\system32\DRIVERS\CPLMACPI.sys [16488 2013-09-06] (Capella Microsystems, Inc.)
R3 DptfDevDBPT; C:\WINDOWS\system32\DRIVERS\DptfDevPower.sys [17408 2013-11-02] (Intel Corporation)
R3 DptfDevDisplay; C:\WINDOWS\system32\DRIVERS\DptfDevDisplay.sys [19968 2013-11-02] (Intel Corporation)
R3 DptfDevGen; C:\WINDOWS\system32\DRIVERS\DptfDevGen.sys [28160 2013-11-02] (Intel Corporation)
R3 DptfDevProc; C:\WINDOWS\system32\DRIVERS\DptfDevProc.sys [72704 2013-11-02] (Intel Corporation)
R3 DptfManager; C:\WINDOWS\system32\DRIVERS\DptfManager.sys [176640 2013-11-02] (Intel Corporation)
R3 GPIO; C:\WINDOWS\System32\drivers\iaiogpioe.sys [23552 2013-11-04] (Intel Corporation)
R3 GpioVirtual; C:\WINDOWS\System32\drivers\iaiogpiovirtual.sys [16896 2013-11-04] (Intel Corporation)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsHIDSwitch.sys [17720 2013-10-08] (ASUS)
R3 iaioi2c; C:\WINDOWS\System32\drivers\iaioi2ce.sys [58368 2013-11-15] (Intel Corporation)
R3 iaiouart; C:\WINDOWS\System32\drivers\iaiouart.sys [87552 2013-11-04] (Intel Corporation)
S0 iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [505192 2013-08-09] (Intel Corporation)
S3 intaud_WaveExtensible; C:\WINDOWS\system32\drivers\intelaud.sys [33176 2013-10-29] (Intel Corporation)
R3 IntelSST; C:\WINDOWS\system32\drivers\isstrtc.sys [252416 2013-11-04] (Intel® Corporation)
R3 INVN_MotionApps; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [188416 2014-05-31] (Microsoft Corporation)
R3 iwdbus; C:\WINDOWS\System32\drivers\iwdbus.sys [23448 2013-10-29] (Intel Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [114904 2015-02-03] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R0 MBI; C:\WINDOWS\System32\drivers\MBI.sys [21456 2013-11-02] (Intel Corporation)
R3 MT9M114; C:\WINDOWS\System32\drivers\MT9M114.sys [38912 2013-12-02] (Intel Corporation)
S3 NETwNs32; C:\WINDOWS\system32\DRIVERS\Netwsn00.sys [10372096 2013-06-18] (Intel Corporation)
R3 PMIC; C:\WINDOWS\System32\drivers\PMIC.sys [48128 2013-11-02] (Intel Corporation)
R3 rtii2sac; C:\WINDOWS\system32\DRIVERS\rtii2sac.sys [149720 2013-12-05] (Realtek Semiconductor Corp.)
S3 RTLU3E8023-W8-32; C:\WINDOWS\system32\DRIVERS\rtu30x86w8.sys [57856 2013-06-18] (Realtek                                            )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SensorsServiceDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [188416 2014-05-31] (Microsoft Corporation)
R3 TXEI; C:\WINDOWS\System32\drivers\TXEI.sys [76304 2013-11-02] (Intel Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [84800 2014-09-22] (Microsoft Corporation)
R0 Wof; C:\WINDOWS\system32\Drivers\Wof.sys [138584 2014-03-13] (Microsoft Corporation)
R3 WUDFSensorLP; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [188416 2014-05-31] (Microsoft Corporation)
U0 msahci; No ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-04 00:39 - 2015-02-04 00:40 - 00017600 _____ () C:\Users\mikaela\Downloads\FRST.txt
2015-02-04 00:39 - 2015-02-04 00:39 - 00000000 ____D () C:\FRST
2015-02-04 00:35 - 2015-02-04 00:38 - 01122304 _____ (Farbar) C:\Users\mikaela\Downloads\FRST.exe
2015-02-03 23:27 - 2015-02-03 23:45 - 00000000 ____D () C:\SUPERDelete
2015-02-03 23:25 - 2015-02-03 23:25 - 00000010 _____ () C:\Users\mikaela\AppData\Local\sponge.last.runtime.cache
2015-02-03 23:24 - 2015-02-03 23:24 - 00222339 _____ () C:\Users\mikaela\AppData\Local\census.cache
2015-02-03 23:24 - 2015-02-03 23:24 - 00152562 _____ () C:\Users\mikaela\AppData\Local\ars.cache
2015-02-03 23:22 - 2015-02-03 23:46 - 00000530 _____ () C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task ce9a5efe-4c75-417b-8dac-54b4100659aa.job
2015-02-03 23:22 - 2015-02-03 23:46 - 00000530 _____ () C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 2052b7d3-bd37-475e-b9aa-d4ccdab59456.job
2015-02-03 23:22 - 2015-02-03 23:22 - 00000000 ____D () C:\Users\mikaela\AppData\Roaming\SUPERAntiSpyware.com
2015-02-03 23:19 - 2015-02-03 23:47 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-02-03 23:19 - 2015-02-03 23:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-02-03 23:19 - 2015-02-03 23:19 - 00001979 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
2015-02-03 23:19 - 2015-02-03 23:19 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2015-02-03 23:13 - 2015-02-03 23:19 - 21172816 _____ (SUPERAntiSpyware) C:\Users\mikaela\Downloads\SUPERAntiSpyware.exe
2015-02-03 22:52 - 2013-09-28 03:56 - 00289352 _____ (Trend Micro Inc.) C:\WINDOWS\system32\Drivers\tmcomm.sys
2015-02-03 22:51 - 2015-02-03 22:51 - 00000036 _____ () C:\Users\mikaela\AppData\Local\housecall.guid.cache
2015-02-03 22:50 - 2015-02-03 22:50 - 02073512 _____ (Trend Micro Inc.) C:\Users\mikaela\Downloads\HousecallLauncher.exe
2015-02-03 21:31 - 2015-02-03 21:31 - 00002301 _____ () C:\Users\mikaela\Desktop\Startprogrammet för appar i Chrome.lnk
2015-02-03 21:31 - 2015-02-03 21:31 - 00000000 ____D () C:\Users\mikaela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-03 20:59 - 2015-02-03 23:46 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-02-03 20:58 - 2015-02-03 20:58 - 00001078 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-03 20:58 - 2015-02-03 20:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-03 20:58 - 2015-02-03 20:58 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-03 20:58 - 2015-02-03 20:58 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-02-03 20:58 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-02-03 20:58 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-02-03 20:58 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-02-03 20:45 - 2015-02-03 20:57 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\mikaela\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-03 19:59 - 2015-02-03 19:59 - 00000000 ____D () C:\Program Files\Savveron
2015-02-03 19:59 - 2015-02-03 19:59 - 00000000 ____D () C:\Program Files\QQueeenCouponn
2015-02-03 19:58 - 2015-02-03 19:58 - 00000000 ____D () C:\Program Files\FFianeDealSoft
2015-02-03 19:58 - 2015-02-03 19:58 - 00000000 ____D () C:\Program Files\dealpeAka
2015-02-03 19:57 - 2015-02-03 19:57 - 00000000 ____D () C:\Program Files\ClickFoorSale
2015-02-03 19:50 - 2015-02-03 19:51 - 08423856 _____ (McAfee, Inc.) C:\Users\mikaela\Downloads\SecurityScan_Release.exe
2015-01-27 12:28 - 2015-02-03 19:49 - 00000020 _____ () C:\Users\mikaela\AppData\Roaming\appdataFr3.bin
2015-01-23 13:46 - 2015-01-23 13:46 - 00055821 _____ () C:\Users\mikaela\Downloads\UserFile
2015-01-23 11:40 - 2015-02-03 21:27 - 00000000 ____D () C:\ProgramData\QQueeenCouponn
2015-01-20 16:12 - 2015-01-20 16:16 - 00000000 ____D () C:\Users\mikaela\Downloads\Gossip Girl Season 4
2015-01-20 16:11 - 2015-01-20 16:11 - 00040854 _____ () C:\Users\mikaela\Downloads\[kickass.so]gossip.girl.complete.season.4.torrent
2015-01-17 19:31 - 2015-01-17 19:31 - 00042330 _____ () C:\Users\mikaela\Downloads\[kickass.so]gossip.girl.s03.hdtv.vostfr.torrent
2015-01-16 10:22 - 2015-01-16 10:22 - 00257600 _____ () C:\Users\mikaela\Downloads\[kickass.so]gossip.girl.season.2.complete.mkv.x264.by.riddlera.torrent
2015-01-14 19:58 - 2015-01-14 19:58 - 00106496 _____ () C:\Users\mikaela\Downloads\Övningstentamen 1, lösningsförslag (1)
2015-01-14 13:23 - 2015-01-14 13:23 - 00106496 _____ () C:\Users\mikaela\Downloads\Övningstentamen 1, lösningsförslag
2015-01-14 13:23 - 2015-01-14 13:23 - 00089218 _____ () C:\Users\mikaela\Downloads\Övningstentamen 1
2015-01-14 13:23 - 2015-01-14 13:23 - 00054894 _____ () C:\Users\mikaela\Downloads\Övningstentamen 2
2015-01-14 13:23 - 2015-01-14 13:23 - 00035522 _____ () C:\Users\mikaela\Downloads\Övningstentamen 2, lösningsförslag
2015-01-13 19:26 - 2015-02-03 21:27 - 00000000 ____D () C:\ProgramData\FFianeDealSoft
2015-01-05 22:43 - 2015-01-05 22:43 - 00000000 ____D () C:\ProgramData\hahllkkcgmjblimbfkknnkkefcbkblna
2015-01-05 14:08 - 2015-02-03 21:27 - 00000000 ____D () C:\ProgramData\Savveron
2015-01-05 14:07 - 2015-02-03 21:27 - 00000000 ____D () C:\ProgramData\dealpeAka
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-04 00:37 - 2014-12-17 13:51 - 00000000 ____D () C:\Users\mikaela\AppData\Roaming\uTorrent
2015-02-04 00:22 - 2014-11-30 00:29 - 00000000 ____D () C:\Users\mikaela\AppData\Roaming\Spotify
2015-02-04 00:21 - 2014-11-04 22:10 - 00001006 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-04 00:00 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-02-03 23:53 - 2014-03-14 23:32 - 01203366 _____ () C:\WINDOWS\WindowsUpdate.log
2015-02-03 23:52 - 2013-12-14 03:03 - 00735378 _____ () C:\WINDOWS\system32\perfh01D.dat
2015-02-03 23:52 - 2013-12-14 03:03 - 00153016 _____ () C:\WINDOWS\system32\perfc01D.dat
2015-02-03 23:52 - 2013-12-13 19:56 - 02244852 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-03 23:48 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-02-03 23:47 - 2014-09-13 09:53 - 00000000 ___DO () C:\Users\mikaela\OneDrive
2015-02-03 23:46 - 2014-11-04 22:10 - 00001002 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-03 23:46 - 2013-08-22 08:23 - 00028730 _____ () C:\WINDOWS\setupact.log
2015-02-03 23:46 - 2013-08-22 08:23 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-02-03 23:45 - 2013-12-13 19:40 - 00078474 _____ () C:\WINDOWS\PFRO.log
2015-02-03 23:45 - 2013-08-22 08:22 - 00479648 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-02-03 23:45 - 2013-08-22 07:13 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-02-03 23:27 - 2014-12-17 14:00 - 00000000 ____D () C:\Users\mikaela\AppData\Local\AskPartnerNetwork
2015-02-03 23:27 - 2014-12-17 14:00 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2015-02-03 23:27 - 2014-12-17 14:00 - 00000000 ____D () C:\Program Files\AskPartnerNetwork
2015-02-03 22:20 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2015-02-03 21:27 - 2014-12-22 19:53 - 00000000 ____D () C:\ProgramData\ClickFoorSale
2015-02-03 21:03 - 2014-12-17 14:01 - 00000000 ____D () C:\Program Files\Optimizer Pro 3.13
2015-02-03 19:59 - 2014-12-22 19:52 - 00000000 ____D () C:\ProgramData\5c7d41d1efcbd370
2015-02-03 19:37 - 2014-11-30 00:31 - 00000000 ____D () C:\Users\mikaela\AppData\Local\Spotify
2015-01-26 23:33 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\LiveKernelReports
2015-01-26 17:00 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\system32\NDF
 
==================== Files in the root of some directories =======
 
2015-01-27 12:28 - 2015-02-03 19:49 - 0000020 _____ () C:\Users\mikaela\AppData\Roaming\appdataFr3.bin
2015-02-03 23:24 - 2015-02-03 23:24 - 0152562 _____ () C:\Users\mikaela\AppData\Local\ars.cache
2015-02-03 23:24 - 2015-02-03 23:24 - 0222339 _____ () C:\Users\mikaela\AppData\Local\census.cache
2015-02-03 22:51 - 2015-02-03 22:51 - 0000036 _____ () C:\Users\mikaela\AppData\Local\housecall.guid.cache
2015-02-03 23:25 - 2015-02-03 23:25 - 0000010 _____ () C:\Users\mikaela\AppData\Local\sponge.last.runtime.cache
2013-12-13 19:48 - 2012-07-30 07:03 - 0000217 _____ () C:\ProgramData\SetStretch.cmd
2013-12-13 19:48 - 2009-07-22 11:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2013-12-13 19:48 - 2012-09-07 12:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS
 
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-01-31 15:23
 
==================== End Of Log ============================

Attached Files



BC AdBot (Login to Remove)

 


m

#2 ken545

ken545

    Malware Response Team


  • Malware Response Team
  • 1,685 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Space Coast of Florida
  • Local time:03:35 PM

Posted 06 February 2015 - 08:46 PM

:welcome:

 

Let me explain how you infected your computer, your using the torrents and kickass to download programs that are most likely illegal

 

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Please Run this program only once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply

  • mvp_host.pngConsumer Security 2007-2008-2009-2010-2011-2012-2013-2014



    donate.gif Please consider a donation to help me keep up my fight against malware.

     

    Just a reminder that threads will be closed if no response in 3 days


    #3 ken545

    ken545

      Malware Response Team


    • Malware Response Team
    • 1,685 posts
    • OFFLINE
    •  
    • Gender:Male
    • Location:The Space Coast of Florida
    • Local time:03:35 PM

    Posted 09 February 2015 - 04:59 PM

    Due to the lack of feedback, this topic is now closed.

    In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

    Please include a link to your topic in the Private Message. Thank you.

    mvp_host.pngConsumer Security 2007-2008-2009-2010-2011-2012-2013-2014



    donate.gif Please consider a donation to help me keep up my fight against malware.

     

    Just a reminder that threads will be closed if no response in 3 days





    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users