Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.
If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===
Remove this program via the Control Panel > Programs > Programs and Features.
KMSpico v9.2.3 (HKLM\...\KMSpico_is1) (Version: 9.2.3 - )
===
ATTENTION: System Restore is disabledTurn your System Restore ON - Windows Help
http://windows.microsoft.com/en-ca/windows/turn-system-restore-on-off#1TC=windows-7+++
Windows Firewall is disabled.Turn ON your Firewall Windows 10.
https://support.microsoft.com/en-us/instantanswers/c9955ad9-1239-4cb2-988c-982f851617ed/turn-windows-firewall-on-or-off+++
Press the windows key
+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to a new file.
Start
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-2106719365-3044273216-2909515200-1000\...\Run: [AdobeBridge] => [X]
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => No File
GroupPolicy: Restriction <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
FF user.js: detected! => C:\Users\Tenshi\AppData\Roaming\Mozilla\Firefox\Profiles\wiskpths.default\user.js [2016-11-27]
FF NewTab: Mozilla\Firefox\Profiles\wiskpths.default -> chrome://fvd.speeddial/content/fvd_about_blank.html
FF Extension: (Speed Dial [FVD] - New Tab Page, Sync...) - C:\Users\Tenshi\AppData\Roaming\Mozilla\Firefox\Profiles\wiskpths.default\Extensions\pavel.sherbakov@gmail.com [2016-10-15]
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [No File]
FF Plugin-x32: @360.cn/npaxlogin -> C:\Program Files (x86)\360\360Safe\Utils\npaxlogin.dll [No File]
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [No File]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Tenshi\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-27]
CHR Extension: (Chrome Media Router) - C:\Users\Tenshi\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-27]
S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [977088 2014-03-02] () [File not signed]
S4 LenovoPcManagerService; "C:\Program Files (x86)\Lenovo\PCManager\LenovoPcManagerService.exe" [X]
S4 Prercertain; C:\Program Files (x86)\Cherro\kotutherrercapyconfiguration.dll [X]
S1 360AntiHacker; System32\Drivers\360AntiHacker64.sys [X]
S1 360Box64; system32\DRIVERS\360Box64.sys [X]
S3 360Camera; System32\Drivers\360Camera64.sys [X]
S1 360Hvm; System32\Drivers\360Hvm64.sys [X]
S1 360netmon; system32\DRIVERS\360netmon.sys [X]
S3 cpuz140; \??\C:\Users\Tenshi\AppData\Local\Temp\cpuz140\cpuz140_x64.sys [X]
S3 GGSAFERDriver; \??\D:\Games\LienMinhHuyenThoai\GameData\Room\safedrv.sys [X]
S3 gkernel; \??\C:\Users\Tenshi\AppData\Local\Temp\gkernel.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
U0 Partizan; system32\drivers\Partizan.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
Task: {A144FD47-1297-48DA-B0AB-D90BBB9B6E08} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
WMI_ActiveScriptEventConsumer_ASEC: <===== ATTENTION
ShortcutWithArgument: C:\Users\Tenshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://yeabd66.cc/
ShortcutWithArgument: C:\Users\Tenshi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk -> D:\Software\lawlietfox-50.0-1-win32-vc14-betterpgo-sse2\firefox.exe (Mozilla Corporation) -> hxxp://yeabd66.cc/
ShortcutWithArgument: C:\Users\Tenshi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://yeabd66.cc/
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Tenshi\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://yeabd66.cc/
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Tenshi\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://yeabd66.cc/
2016-09-19 22:30 - 2016-09-19 22:30 - 00211968 _____ () C:\Windows\W7FBC\dll.dll
AlternateDataStreams: C:\Windows\EmptyStandbyList.exe:BDU [0]
AlternateDataStreams: C:\Windows\system32\drivers:ucdrv-x64.sys [80850]
AlternateDataStreams: C:\Windows\system32\drivers:x64 [1442146]
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51 [126]
FirewallRules: [{0125E831-AEE8-4DA2-837E-8DE830FA5C34}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{46F8B3EF-0930-4907-BD41-4781DB0BFE8A}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{DF59E931-D8A4-4007-A16C-3ED5327A65E0}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{ECCCC320-B01A-4E7E-92DA-ECB5D5E97549}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
C:\Program Files\KMSpico
C:\Users\Tenshi\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
C:\Users\Tenshi\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
End
Save the file as
fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.
Run
FRST and click
Fix only once and wait.
Restart the computer normally to reset the registry.
The tool will create a log (Fixlog.txt) please post it to your reply.
===
Reset Internet Explorer:
Menu > Tools > Internet Options > Advanced Tab.
Click the Reset button on the bottom of the pane.
Click the Apply button.
Close IE.
Clean the Internet Explorer Cache.
https://kb.wisc.edu/page.php?id=15141===
Please let me know what problem persists with this computer.