Solved "Your computer is in danger" Windows 10

It's not a good idea to have system restore off.

Last scans....

redtarget.gif
Download Security Check from here or here and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


redtarget.gif
Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
Make sure the following options are checked:
  • Internet Services
  • Windows Firewall
  • System Restore
  • Security Center
  • Windows Update
  • Windows Defender
  • Other Services

Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.
Please copy and paste the log to your reply.


redtarget.gif
Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


redtarget.gif
Download Sophos Free Virus Removal Tool and save it to your desktop.
  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View log file... (bottom left hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program
 
Results of screen317's Security Check version 1.006
x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Windows Defender
avast! Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
MVPS Hosts File
Spybot - Search & Destroy
Wise Registry Cleaner 7.69
Java 7 Update 71
Java 8 Update 45
Java version 32-bit out of Date!
Adobe Flash Player 18.0.0.232
Adobe Reader XI
Mozilla Thunderbird 12.0.1 Thunderbird out of Date!
Google Chrome (44.0.2403.130)
Google Chrome (44.0.2403.155)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Malwarebytes Anti-Malware mbamscheduler.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast AvastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
 
Farbar Service Scanner Version: 26-07-2015
Ran by Yoan2 (administrator) on 14-08-2015 at 21:22:50
Running from "C:\Users\Yoan2\Downloads"
Microsoft Windows 10 Home (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Action Center:
============


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Demand. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend: ""%ProgramFiles%\Windows Defender\MsMpEng.exe"".


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MsMpEng.exe => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****
 
Running the sophos tool looks like it'll take a bit. Also regarding the system restore, I'll put it back on once we're done cleaning this thing out. I appreciate your time and assistance with this.
 
2015-08-15 01:28:50.109 Sophos Virus Removal Tool version 2.5.4
2015-08-15 01:28:50.109 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

2015-08-15 01:28:50.109 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2015-08-15 01:28:50.109 Windows version 6.2 SP 0.0 build 9200 SM=0x300 PT=0x1 WOW64
2015-08-15 01:28:50.109 Checking for updates...
2015-08-15 01:28:50.141 Update progress: proxy server not available
2015-08-15 01:28:57.411 Option all = no
2015-08-15 01:28:57.411 Option recurse = yes
2015-08-15 01:28:57.411 Option archive = no
2015-08-15 01:28:57.411 Option service = yes
2015-08-15 01:28:57.411 Option confirm = yes
2015-08-15 01:28:57.411 Option sxl = yes
2015-08-15 01:28:57.411 Option max-data-age = 35
2015-08-15 01:28:57.411 Option EnableSafeClean = yes
2015-08-15 01:28:58.690 Option vdl-logging = yes
2015-08-15 01:28:58.693 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-08-15 01:28:58.693 Machine ID: d24f0898bccf498f92a9e83a4cc4a725
2015-08-15 01:28:58.694 Component SVRTcli.exe version 2.5.4
2015-08-15 01:28:58.694 Component control.dll version 2.5.4
2015-08-15 01:28:58.694 Component SVRTservice.exe version 2.5.4
2015-08-15 01:28:58.695 Component engine\osdp.dll version 1.44.1.2210
2015-08-15 01:28:58.695 Component engine\veex.dll version 3.61.0.2210
2015-08-15 01:28:58.695 Component engine\savi.dll version 8.1.8.2210
2015-08-15 01:28:58.696 Component rkdisk.dll version 1.5.30.0
2015-08-15 01:28:58.696 Version info: Product version 2.5.4
2015-08-15 01:28:58.696 Version info: Detection engine 3.61.0
2015-08-15 01:28:58.696 Version info: Detection data 5.17
2015-08-15 01:28:58.696 Version info: Build date 7/21/2015
2015-08-15 01:28:58.696 Version info: Data files added 245
2015-08-15 01:28:58.696 Version info: Last successful update (not yet updated)
2015-08-15 01:29:15.662 Downloading updates...
2015-08-15 01:29:15.665 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
2015-08-15 01:29:15.665 Update progress: [I49502] Found supplement SAVIW32 LATEST
2015-08-15 01:29:15.665 Update progress: [I49502] Found supplement IDE518 LATEST
2015-08-15 01:29:15.665 Update progress: [I49502] Found supplement IDE519 LATEST
2015-08-15 01:29:15.665 Update progress: [I49502] Found supplement IDE520 LATEST
2015-08-15 01:29:15.665 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
2015-08-15 01:29:15.665 Update progress: [I19463] Syncing product SAVIW32 58
2015-08-15 01:29:17.438 Update progress: [I19463] Syncing product IDE518 171
2015-08-15 01:29:17.655 Update progress: [I19463] Syncing product IDE519 175
2015-08-15 01:29:29.849 Installing updates...
2015-08-15 01:29:30.491 Error level 1
2015-08-15 01:29:30.506 Update progress: [I19463] Syncing product IDE520 1
2015-08-15 01:29:33.877 Update successful
2015-08-15 01:29:40.350 Option all = no
2015-08-15 01:29:40.350 Option recurse = yes
2015-08-15 01:29:40.350 Option archive = no
2015-08-15 01:29:40.350 Option service = yes
2015-08-15 01:29:40.350 Option confirm = yes
2015-08-15 01:29:40.350 Option sxl = yes
2015-08-15 01:29:40.350 Option max-data-age = 35
2015-08-15 01:29:40.350 Option EnableSafeClean = yes
2015-08-15 01:29:40.709 Option vdl-logging = yes
2015-08-15 01:29:40.709 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-08-15 01:29:40.709 Machine ID: d24f0898bccf498f92a9e83a4cc4a725
2015-08-15 01:29:40.709 Component SVRTcli.exe version 2.5.4
2015-08-15 01:29:40.709 Component control.dll version 2.5.4
2015-08-15 01:29:40.709 Component SVRTservice.exe version 2.5.4
2015-08-15 01:29:40.709 Component engine\osdp.dll version 1.44.1.2210
2015-08-15 01:29:40.709 Component engine\veex.dll version 3.61.0.2210
2015-08-15 01:29:40.709 Component engine\savi.dll version 8.1.8.2210
2015-08-15 01:29:40.709 Component rkdisk.dll version 1.5.30.0
2015-08-15 01:29:40.709 Version info: Product version 2.5.4
2015-08-15 01:29:40.709 Version info: Detection engine 3.61.0
2015-08-15 01:29:40.709 Version info: Detection data 5.17G
2015-08-15 01:29:40.709 Version info: Build date 7/21/2015
2015-08-15 01:29:40.709 Version info: Data files added 344
2015-08-15 01:29:40.709 Version info: Last successful update 8/14/2015 9:29:33 PM

2015-08-15 02:05:45.695 Could not open C:\swapfile.sys
2015-08-15 02:11:59.842 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
2015-08-15 02:11:59.842 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
2015-08-15 02:12:01.076 Could not open C:\Windows\System32\config\BBI
2015-08-15 02:12:01.092 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2015-08-15 02:12:01.092 Could not open C:\Windows\System32\config\RegBack\SAM
2015-08-15 02:12:01.092 Could not open C:\Windows\System32\config\RegBack\SECURITY
2015-08-15 02:12:01.092 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2015-08-15 02:12:01.092 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file E:\Downloads\Assassins.Creed.II.Crack.Only-SKIDROW\SKIDROW\ubiorbitapi_r2.dll
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file E:\Games\Old P\Program Files\Alcohol Soft\Alcohol 120\Alcohol.exe
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file E:\Games\Old P\Program Files\Alcohol Soft\Alcohol 120\AxCmd.exe
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/$FIftiMain (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/$FIftiMain (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#IDXHDR (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#TOPICS (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#URLTBL (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#URLSTR (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#STRINGS (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/$FIftiMain (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/$FIftiMain (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#IDXHDR (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#TOPICS (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#URLTBL (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#URLSTR (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#STRINGS (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Editing_a_Video.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Viewing_Details_About_a_Pic.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Importing_a_Picture_or_Video.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Opening_Your_Gallery.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Printing_an_Picture_or_Vide.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Renaming_an_Image_or_Video.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Selecting_Items_in_Your_Gal.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Sorting_the_Contents_of_You.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Editing_a_Picture.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Setting_a_Picture_as_Your_W.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Viewing_a_Video.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Attaching_an_Image_to_an_E-.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/BSSCDHTM.js (format not supported)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/fh_dhtml.js (format not supported)
2015-08-15 02:25:53.979 Could not check E:\Games\Old P\Program Files\Lavasoft\Ad-aware 6\manual.chm\/snap.jpg (format not supported)
2015-08-15 02:25:53.979 Could not check E:\Games\Old P\Program Files\Lavasoft\Ad-aware 6\manual.chm\/filesp-2.jpg (corrupt)
2015-08-15 02:26:56.171 >>> Virus 'Mal/Generic-L' found in file E:\Games\Old P\WIND2\EliteBar\EliteBar version 46.dll\FILE:0000
2015-08-15 02:26:56.171 Disinfection not offered
2015-08-15 02:27:07.531 Could not check E:\Games\Old P\WIND2\Help\windows.chm\/$WWKeywordLinks/BTree (corrupt)
2015-08-15 02:28:05.862 Could not check E:\Games\Old P\WINDOWS\Help\lang.chm\/lang_show_unicode.htm (corrupt)
2015-08-15 02:28:05.862 Could not check E:\Games\Old P\WINDOWS\Help\lang.chm (virus scan failed)
2015-08-15 02:28:08.081 Could not check E:\Games\Old P\WINDOWS\Help\nthelp.chm\/compile_date.htm (corrupt)
2015-08-15 02:28:08.081 Could not check E:\Games\Old P\WINDOWS\Help\nthelp.chm (virus scan failed)
2015-08-15 02:28:08.644 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/$FIftiMain (corrupt)
2015-08-15 02:28:08.644 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#IDXHDR (corrupt)
2015-08-15 02:28:08.644 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#TOPICS (corrupt)
2015-08-15 02:28:08.644 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#URLTBL (corrupt)
2015-08-15 02:28:08.659 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#URLSTR (corrupt)
2015-08-15 02:28:08.659 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#STRINGS (corrupt)
2015-08-15 02:28:12.050 Could not check E:\Games\Old P\WINDOWS\Help\wab.chm\/wab_add_contacts_overview.htm (corrupt)
2015-08-15 02:28:12.050 Could not check E:\Games\Old P\WINDOWS\Help\wab.chm (virus scan failed)
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file E:\Newest C\Games\Club Control\ClubControl.exe
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file E:\Newest C\Games\Club Control\ClubControl.exe
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file E:\Newest C\Games\Club Control\ClubControl.exe
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:43:18.632 Could not open E:\pagefile.sys
2015-08-15 02:46:40.107 The following items will be cleaned up:
2015-08-15 02:46:40.107 Mal/VMProtBad-A
2015-08-15 02:46:40.107 Mal/EncPk-AAK
2015-08-15 02:46:40.107 Mal/Generic-S
2015-08-15 02:46:40.107 Mal/Generic-L
 
Also Sophos only cleaned 3 of 4 items. It said it found new threats in the clean up process and needed to have a scan redone. should I do this?
 
2015-08-15 01:28:50.109 Sophos Virus Removal Tool version 2.5.4
2015-08-15 01:28:50.109 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

2015-08-15 01:28:50.109 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2015-08-15 01:28:50.109 Windows version 6.2 SP 0.0 build 9200 SM=0x300 PT=0x1 WOW64
2015-08-15 01:28:50.109 Checking for updates...
2015-08-15 01:28:50.141 Update progress: proxy server not available
2015-08-15 01:28:57.411 Option all = no
2015-08-15 01:28:57.411 Option recurse = yes
2015-08-15 01:28:57.411 Option archive = no
2015-08-15 01:28:57.411 Option service = yes
2015-08-15 01:28:57.411 Option confirm = yes
2015-08-15 01:28:57.411 Option sxl = yes
2015-08-15 01:28:57.411 Option max-data-age = 35
2015-08-15 01:28:57.411 Option EnableSafeClean = yes
2015-08-15 01:28:58.690 Option vdl-logging = yes
2015-08-15 01:28:58.693 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-08-15 01:28:58.693 Machine ID: d24f0898bccf498f92a9e83a4cc4a725
2015-08-15 01:28:58.694 Component SVRTcli.exe version 2.5.4
2015-08-15 01:28:58.694 Component control.dll version 2.5.4
2015-08-15 01:28:58.694 Component SVRTservice.exe version 2.5.4
2015-08-15 01:28:58.695 Component engine\osdp.dll version 1.44.1.2210
2015-08-15 01:28:58.695 Component engine\veex.dll version 3.61.0.2210
2015-08-15 01:28:58.695 Component engine\savi.dll version 8.1.8.2210
2015-08-15 01:28:58.696 Component rkdisk.dll version 1.5.30.0
2015-08-15 01:28:58.696 Version info: Product version 2.5.4
2015-08-15 01:28:58.696 Version info: Detection engine 3.61.0
2015-08-15 01:28:58.696 Version info: Detection data 5.17
2015-08-15 01:28:58.696 Version info: Build date 7/21/2015
2015-08-15 01:28:58.696 Version info: Data files added 245
2015-08-15 01:28:58.696 Version info: Last successful update (not yet updated)
2015-08-15 01:29:15.662 Downloading updates...
2015-08-15 01:29:15.665 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
2015-08-15 01:29:15.665 Update progress: [I49502] Found supplement SAVIW32 LATEST
2015-08-15 01:29:15.665 Update progress: [I49502] Found supplement IDE518 LATEST
2015-08-15 01:29:15.665 Update progress: [I49502] Found supplement IDE519 LATEST
2015-08-15 01:29:15.665 Update progress: [I49502] Found supplement IDE520 LATEST
2015-08-15 01:29:15.665 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
2015-08-15 01:29:15.665 Update progress: [I19463] Syncing product SAVIW32 58
2015-08-15 01:29:17.438 Update progress: [I19463] Syncing product IDE518 171
2015-08-15 01:29:17.655 Update progress: [I19463] Syncing product IDE519 175
2015-08-15 01:29:29.849 Installing updates...
2015-08-15 01:29:30.491 Error level 1
2015-08-15 01:29:30.506 Update progress: [I19463] Syncing product IDE520 1
2015-08-15 01:29:33.877 Update successful
2015-08-15 01:29:40.350 Option all = no
2015-08-15 01:29:40.350 Option recurse = yes
2015-08-15 01:29:40.350 Option archive = no
2015-08-15 01:29:40.350 Option service = yes
2015-08-15 01:29:40.350 Option confirm = yes
2015-08-15 01:29:40.350 Option sxl = yes
2015-08-15 01:29:40.350 Option max-data-age = 35
2015-08-15 01:29:40.350 Option EnableSafeClean = yes
2015-08-15 01:29:40.709 Option vdl-logging = yes
2015-08-15 01:29:40.709 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-08-15 01:29:40.709 Machine ID: d24f0898bccf498f92a9e83a4cc4a725
2015-08-15 01:29:40.709 Component SVRTcli.exe version 2.5.4
2015-08-15 01:29:40.709 Component control.dll version 2.5.4
2015-08-15 01:29:40.709 Component SVRTservice.exe version 2.5.4
2015-08-15 01:29:40.709 Component engine\osdp.dll version 1.44.1.2210
2015-08-15 01:29:40.709 Component engine\veex.dll version 3.61.0.2210
2015-08-15 01:29:40.709 Component engine\savi.dll version 8.1.8.2210
2015-08-15 01:29:40.709 Component rkdisk.dll version 1.5.30.0
2015-08-15 01:29:40.709 Version info: Product version 2.5.4
2015-08-15 01:29:40.709 Version info: Detection engine 3.61.0
2015-08-15 01:29:40.709 Version info: Detection data 5.17G
2015-08-15 01:29:40.709 Version info: Build date 7/21/2015
2015-08-15 01:29:40.709 Version info: Data files added 344
2015-08-15 01:29:40.709 Version info: Last successful update 8/14/2015 9:29:33 PM

2015-08-15 02:05:45.695 Could not open C:\swapfile.sys
2015-08-15 02:11:59.842 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
2015-08-15 02:11:59.842 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
2015-08-15 02:12:01.076 Could not open C:\Windows\System32\config\BBI
2015-08-15 02:12:01.092 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2015-08-15 02:12:01.092 Could not open C:\Windows\System32\config\RegBack\SAM
2015-08-15 02:12:01.092 Could not open C:\Windows\System32\config\RegBack\SECURITY
2015-08-15 02:12:01.092 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2015-08-15 02:12:01.092 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file E:\Downloads\Assassins.Creed.II.Crack.Only-SKIDROW\SKIDROW\ubiorbitapi_r2.dll
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:22:39.327 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file E:\Games\Old P\Program Files\Alcohol Soft\Alcohol 120\Alcohol.exe
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:24:41.991 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file E:\Games\Old P\Program Files\Alcohol Soft\Alcohol 120\AxCmd.exe
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:24:48.585 >>> Virus 'Mal/EncPk-AAK' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/$FIftiMain (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/$FIftiMain (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#IDXHDR (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#TOPICS (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#URLTBL (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#URLSTR (corrupt)
2015-08-15 02:25:13.805 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#STRINGS (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/$FIftiMain (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/$FIftiMain (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#IDXHDR (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#TOPICS (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#URLTBL (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#URLSTR (corrupt)
2015-08-15 02:25:14.415 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#STRINGS (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Editing_a_Video.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Viewing_Details_About_a_Pic.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Importing_a_Picture_or_Video.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Opening_Your_Gallery.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Printing_an_Picture_or_Vide.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Renaming_an_Image_or_Video.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Selecting_Items_in_Your_Gal.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Sorting_the_Contents_of_You.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Editing_a_Picture.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Setting_a_Picture_as_Your_W.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Viewing_a_Video.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Attaching_an_Image_to_an_E-.htm (corrupt)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/BSSCDHTM.js (format not supported)
2015-08-15 02:25:51.073 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/fh_dhtml.js (format not supported)
2015-08-15 02:25:53.979 Could not check E:\Games\Old P\Program Files\Lavasoft\Ad-aware 6\manual.chm\/snap.jpg (format not supported)
2015-08-15 02:25:53.979 Could not check E:\Games\Old P\Program Files\Lavasoft\Ad-aware 6\manual.chm\/filesp-2.jpg (corrupt)
2015-08-15 02:26:56.171 >>> Virus 'Mal/Generic-L' found in file E:\Games\Old P\WIND2\EliteBar\EliteBar version 46.dll\FILE:0000
2015-08-15 02:26:56.171 Disinfection not offered
2015-08-15 02:27:07.531 Could not check E:\Games\Old P\WIND2\Help\windows.chm\/$WWKeywordLinks/BTree (corrupt)
2015-08-15 02:28:05.862 Could not check E:\Games\Old P\WINDOWS\Help\lang.chm\/lang_show_unicode.htm (corrupt)
2015-08-15 02:28:05.862 Could not check E:\Games\Old P\WINDOWS\Help\lang.chm (virus scan failed)
2015-08-15 02:28:08.081 Could not check E:\Games\Old P\WINDOWS\Help\nthelp.chm\/compile_date.htm (corrupt)
2015-08-15 02:28:08.081 Could not check E:\Games\Old P\WINDOWS\Help\nthelp.chm (virus scan failed)
2015-08-15 02:28:08.644 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/$FIftiMain (corrupt)
2015-08-15 02:28:08.644 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#IDXHDR (corrupt)
2015-08-15 02:28:08.644 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#TOPICS (corrupt)
2015-08-15 02:28:08.644 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#URLTBL (corrupt)
2015-08-15 02:28:08.659 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#URLSTR (corrupt)
2015-08-15 02:28:08.659 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#STRINGS (corrupt)
2015-08-15 02:28:12.050 Could not check E:\Games\Old P\WINDOWS\Help\wab.chm\/wab_add_contacts_overview.htm (corrupt)
2015-08-15 02:28:12.050 Could not check E:\Games\Old P\WINDOWS\Help\wab.chm (virus scan failed)
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file E:\Newest C\Games\Club Control\ClubControl.exe
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file E:\Newest C\Games\Club Control\ClubControl.exe
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file E:\Newest C\Games\Club Control\ClubControl.exe
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:31:52.025 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2015-08-15 02:43:18.632 Could not open E:\pagefile.sys
2015-08-15 02:46:40.107 The following items will be cleaned up:
2015-08-15 02:46:40.107 Mal/VMProtBad-A
2015-08-15 02:46:40.107 Mal/EncPk-AAK
2015-08-15 02:46:40.107 Mal/Generic-S
2015-08-15 02:46:40.107 Mal/Generic-L
2015-08-15 02:57:08.379 Threat 'Mal/VMProtBad-A' has been cleaned up.
2015-08-15 02:57:08.379 File "E:\Downloads\Assassins.Creed.II.Crack.Only-SKIDROW\SKIDROW\ubiorbitapi_r2.dll" belongs to malware 'Mal/VMProtBad-A'.
2015-08-15 02:57:08.379 File "E:\Downloads\Assassins.Creed.II.Crack.Only-SKIDROW\SKIDROW\ubiorbitapi_r2.dll" has been cleaned up.
2015-08-15 02:57:08.379 Registry value "HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609" belongs to malware 'Mal/VMProtBad-A'.
2015-08-15 02:57:08.379 Registry value "HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609" has been cleaned up.
2015-08-15 02:57:08.379 Registry value "HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500" belongs to malware 'Mal/VMProtBad-A'.
2015-08-15 02:57:08.379 Registry value "HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500" has been cleaned up.
2015-08-15 02:57:08.380 Registry value "HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500" belongs to malware 'Mal/VMProtBad-A'.
2015-08-15 02:57:08.380 Registry value "HKU\S-1-5-21-2215824855-1170150186-1298706218-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500" has been cleaned up.
2015-08-15 02:57:08.380 Removal successful
2015-08-15 02:57:21.776 Threat 'Mal/EncPk-AAK' has been cleaned up.
2015-08-15 02:57:21.776 File "E:\Games\Old P\Program Files\Alcohol Soft\Alcohol 120\Alcohol.exe" belongs to malware 'Mal/EncPk-AAK'.
2015-08-15 02:57:21.776 File "E:\Games\Old P\Program Files\Alcohol Soft\Alcohol 120\Alcohol.exe" has been cleaned up.
2015-08-15 02:57:21.776 File "E:\Games\Old P\Program Files\Alcohol Soft\Alcohol 120\AxCmd.exe" belongs to malware 'Mal/EncPk-AAK'.
2015-08-15 02:57:21.776 File "E:\Games\Old P\Program Files\Alcohol Soft\Alcohol 120\AxCmd.exe" has been cleaned up.
2015-08-15 02:57:21.776 Removal successful
2015-08-15 02:57:28.713 Threat 'Mal/Generic-S' has been cleaned up.
2015-08-15 02:57:28.713 File "E:\Newest C\Games\Club Control\ClubControl.exe" belongs to malware 'Mal/Generic-S'.
2015-08-15 02:57:28.713 File "E:\Newest C\Games\Club Control\ClubControl.exe" has been cleaned up.
2015-08-15 02:57:28.714 Removal successful
2015-08-15 02:57:28.955 >>> Virus 'Mal/Generic-L' found in file E:\Games\Old P\WIND2\EliteBar\EliteBar version 46.dll\FILE:0000
2015-08-15 02:57:28.955 Disinfection not offered
2015-08-15 02:57:28.955 Disinfection failed [0xa0040208]
2015-08-15 02:57:28.956 Error: cleanup failed.
2015-08-15 02:57:29.132 Contents of SafeClean bin directory:
2015-08-15 02:57:29.132 {
2015-08-15 02:57:29.132 RecordID : "0000000000000001",
2015-08-15 02:57:29.132 ItemType : "1",
2015-08-15 02:57:29.132 Location : "E:\Downloads\Assassins.Creed.II.Crack.Only-SKIDROW\SKIDROW\",
2015-08-15 02:57:29.132 FileName : "ubiorbitapi_r2.dll",
2015-08-15 02:57:29.132 ThreatName : "Mal/VMProtBad-A",
2015-08-15 02:57:29.133 Checksum : "92008fda897387f1e79bc32f8c19b5b7db3f5c46d695d45738e3758af76347a4",
2015-08-15 02:57:29.133 TimeStamp : "Fri Aug 14 22:57:00 2015"
2015-08-15 02:57:29.133 }
2015-08-15 02:57:29.133 {
2015-08-15 02:57:29.133 RecordID : "0000000000000002",
2015-08-15 02:57:29.133 ItemType : "1",
2015-08-15 02:57:29.133 Location : "E:\Games\Old P\Program Files\Alcohol Soft\Alcohol 120\",
2015-08-15 02:57:29.133 FileName : "Alcohol.exe",
2015-08-15 02:57:29.133 ThreatName : "Mal/EncPk-AAK",
2015-08-15 02:57:29.133 Checksum : "8d32fe239e4526a43d8b0c9d0dec8d881ae27aed9b83169a4c8cad996a49d2dd",
2015-08-15 02:57:29.133 TimeStamp : "Fri Aug 14 22:57:08 2015"
2015-08-15 02:57:29.133 }
2015-08-15 02:57:29.133 {
2015-08-15 02:57:29.133 RecordID : "0000000000000003",
2015-08-15 02:57:29.133 ItemType : "1",
2015-08-15 02:57:29.133 Location : "E:\Games\Old P\Program Files\Alcohol Soft\Alcohol 120\",
2015-08-15 02:57:29.133 FileName : "AxCmd.exe",
2015-08-15 02:57:29.133 ThreatName : "Mal/EncPk-AAK",
2015-08-15 02:57:29.133 Checksum : "0e18af3c07285634b92647131992c603ed96f7022290bfd1f2c73af2a4c3b646",
2015-08-15 02:57:29.133 TimeStamp : "Fri Aug 14 22:57:08 2015"
2015-08-15 02:57:29.133 }
2015-08-15 02:57:29.133 {
2015-08-15 02:57:29.133 RecordID : "0000000000000004",
2015-08-15 02:57:29.133 ItemType : "1",
2015-08-15 02:57:29.133 Location : "E:\Newest C\Games\Club Control\",
2015-08-15 02:57:29.133 FileName : "ClubControl.exe",
2015-08-15 02:57:29.133 ThreatName : "Mal/Generic-S",
2015-08-15 02:57:29.133 Checksum : "25239e48d57275c06ae86dd01b00a72e18d0e16c831a28eaa5b7b8b9fe1f174b",
2015-08-15 02:57:29.133 TimeStamp : "Fri Aug 14 22:57:21 2015"
2015-08-15 02:57:29.133 }
2015-08-15 02:57:30.216 Error level 0

2015-08-15 02:57:55.975

------------------------------------------------------------

2015-08-15 03:05:30.473 Sophos Virus Removal Tool version 2.5.4
2015-08-15 03:05:30.473 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

2015-08-15 03:05:30.473 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2015-08-15 03:05:30.473 Windows version 6.2 SP 0.0 build 9200 SM=0x300 PT=0x1 WOW64
2015-08-15 03:05:30.473 Checking for updates...
2015-08-15 03:05:30.486 Update progress: proxy server not available
2015-08-15 03:05:34.444 Downloading updates...
2015-08-15 03:05:34.449 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
2015-08-15 03:05:34.449 Update progress: [I49502] Found supplement SAVIW32 LATEST
2015-08-15 03:05:34.449 Update progress: [I49502] Found supplement IDE518 LATEST
2015-08-15 03:05:34.449 Update progress: [I49502] Found supplement IDE519 LATEST
2015-08-15 03:05:34.449 Update progress: [I49502] Found supplement IDE520 LATEST
2015-08-15 03:05:34.449 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
2015-08-15 03:05:34.449 Update progress: [I19463] Syncing product SAVIW32 58
2015-08-15 03:05:34.449 Update progress: [I19463] Syncing product IDE518 171
2015-08-15 03:05:34.859 Update progress: [I19463] Syncing product IDE519 176
2015-08-15 03:05:34.979 Installing updates...
2015-08-15 03:05:39.484 Option all = no
2015-08-15 03:05:40.486 Option recurse = yes
2015-08-15 03:05:40.486 Option archive = no
2015-08-15 03:05:40.486 Option service = yes
2015-08-15 03:05:40.486 Option confirm = yes
2015-08-15 03:05:40.486 Option sxl = yes
2015-08-15 03:05:40.486 Option max-data-age = 35
2015-08-15 03:05:40.486 Option EnableSafeClean = yes
2015-08-15 03:05:40.487 Option vdl-logging = yes
2015-08-15 03:05:40.487 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-08-15 03:05:40.487 Machine ID: d24f0898bccf498f92a9e83a4cc4a725
2015-08-15 03:05:40.487 Component SVRTcli.exe version 2.5.4
2015-08-15 03:05:40.487 Component control.dll version 2.5.4
2015-08-15 03:05:40.487 Component SVRTservice.exe version 2.5.4
2015-08-15 03:05:40.487 Component engine\osdp.dll version 1.44.1.2210
2015-08-15 03:05:40.487 Component engine\veex.dll version 3.61.0.2210
2015-08-15 03:05:40.487 Component engine\savi.dll version 8.1.8.2210
2015-08-15 03:05:40.487 Component rkdisk.dll version 1.5.30.0
2015-08-15 03:05:40.487 Version info: Product version 2.5.4
2015-08-15 03:05:40.487 Version info: Detection engine 3.61.0
2015-08-15 03:05:40.487 Version info: Detection data 5.17G
2015-08-15 03:05:40.487 Version info: Build date 7/21/2015
2015-08-15 03:05:40.488 Version info: Data files added 344
2015-08-15 03:05:40.488 Version info: Last successful update 8/14/2015 9:29:33 PM
2015-08-15 03:05:40.488 Error level 1
2015-08-15 03:05:40.680 Update progress: [I19463] Syncing product IDE520 1
2015-08-15 03:05:40.732 Update successful
2015-08-15 03:05:49.125 Option all = no
2015-08-15 03:05:49.125 Option recurse = yes
2015-08-15 03:05:49.125 Option archive = no
2015-08-15 03:05:49.125 Option service = yes
2015-08-15 03:05:49.125 Option confirm = yes
2015-08-15 03:05:49.125 Option sxl = yes
2015-08-15 03:05:49.126 Option max-data-age = 35
2015-08-15 03:05:49.126 Option EnableSafeClean = yes
2015-08-15 03:05:49.493 Option vdl-logging = yes
2015-08-15 03:05:49.496 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-08-15 03:05:49.496 Machine ID: d24f0898bccf498f92a9e83a4cc4a725
2015-08-15 03:05:49.497 Component SVRTcli.exe version 2.5.4
2015-08-15 03:05:49.497 Component control.dll version 2.5.4
2015-08-15 03:05:49.497 Component SVRTservice.exe version 2.5.4
2015-08-15 03:05:49.497 Component engine\osdp.dll version 1.44.1.2210
2015-08-15 03:05:49.497 Component engine\veex.dll version 3.61.0.2210
2015-08-15 03:05:49.497 Component engine\savi.dll version 8.1.8.2210
2015-08-15 03:05:49.498 Component rkdisk.dll version 1.5.30.0
2015-08-15 03:05:49.498 Version info: Product version 2.5.4
2015-08-15 03:05:49.498 Version info: Detection engine 3.61.0
2015-08-15 03:05:49.498 Version info: Detection data 5.17G
2015-08-15 03:05:49.498 Version info: Build date 7/21/2015
2015-08-15 03:05:49.498 Version info: Data files added 345
2015-08-15 03:05:49.499 Version info: Last successful update 8/14/2015 11:05:40 PM

2015-08-15 03:43:28.200 Could not open C:\swapfile.sys
2015-08-15 03:49:51.398 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
2015-08-15 03:49:51.414 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
2015-08-15 03:49:52.773 Could not open C:\Windows\System32\config\BBI
2015-08-15 03:49:52.789 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2015-08-15 03:49:52.789 Could not open C:\Windows\System32\config\RegBack\SAM
2015-08-15 03:49:52.789 Could not open C:\Windows\System32\config\RegBack\SECURITY
2015-08-15 03:49:52.789 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2015-08-15 03:49:52.789 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2015-08-15 04:03:01.227 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/$FIftiMain (corrupt)
2015-08-15 04:03:01.227 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/$FIftiMain (corrupt)
2015-08-15 04:03:01.243 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#IDXHDR (corrupt)
2015-08-15 04:03:01.243 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#TOPICS (corrupt)
2015-08-15 04:03:01.243 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#URLTBL (corrupt)
2015-08-15 04:03:01.243 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#URLSTR (corrupt)
2015-08-15 04:03:01.243 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCDSS10.CHM\/#STRINGS (corrupt)
2015-08-15 04:03:01.840 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/$FIftiMain (corrupt)
2015-08-15 04:03:01.840 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/$FIftiMain (corrupt)
2015-08-15 04:03:01.840 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#IDXHDR (corrupt)
2015-08-15 04:03:01.840 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#TOPICS (corrupt)
2015-08-15 04:03:01.840 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#URLTBL (corrupt)
2015-08-15 04:03:01.840 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#URLSTR (corrupt)
2015-08-15 04:03:01.840 Could not check E:\Games\Old P\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\OWCRPL10.CHM\/#STRINGS (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Editing_a_Video.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Viewing_Details_About_a_Pic.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Importing_a_Picture_or_Video.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Opening_Your_Gallery.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Printing_an_Picture_or_Vide.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Renaming_an_Image_or_Video.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Selecting_Items_in_Your_Gal.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Sorting_the_Contents_of_You.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Editing_a_Picture.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Setting_a_Picture_as_Your_W.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Viewing_a_Video.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/Attaching_an_Image_to_an_E-.htm (corrupt)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/BSSCDHTM.js (format not supported)
2015-08-15 04:03:39.561 Could not check E:\Games\Old P\Program Files\Labtec\WebCam\Help\gallery.chm\/fh_dhtml.js (format not supported)
2015-08-15 04:03:42.327 Could not check E:\Games\Old P\Program Files\Lavasoft\Ad-aware 6\manual.chm\/snap.jpg (format not supported)
2015-08-15 04:03:42.327 Could not check E:\Games\Old P\Program Files\Lavasoft\Ad-aware 6\manual.chm\/filesp-2.jpg (corrupt)
2015-08-15 04:04:46.493 >>> Virus 'Mal/Generic-L' found in file E:\Games\Old P\WIND2\EliteBar\EliteBar version 46.dll\FILE:0000
2015-08-15 04:04:46.493 Disinfection not offered
2015-08-15 04:04:58.640 Could not check E:\Games\Old P\WIND2\Help\windows.chm\/$WWKeywordLinks/BTree (corrupt)
2015-08-15 04:05:58.035 Could not check E:\Games\Old P\WINDOWS\Help\lang.chm\/lang_show_unicode.htm (corrupt)
2015-08-15 04:05:58.035 Could not check E:\Games\Old P\WINDOWS\Help\lang.chm (virus scan failed)
2015-08-15 04:06:00.269 Could not check E:\Games\Old P\WINDOWS\Help\nthelp.chm\/compile_date.htm (corrupt)
2015-08-15 04:06:00.269 Could not check E:\Games\Old P\WINDOWS\Help\nthelp.chm (virus scan failed)
2015-08-15 04:06:01.133 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/$FIftiMain (corrupt)
2015-08-15 04:06:01.134 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#IDXHDR (corrupt)
2015-08-15 04:06:01.134 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#TOPICS (corrupt)
2015-08-15 04:06:01.135 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#URLTBL (corrupt)
2015-08-15 04:06:01.135 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#URLSTR (corrupt)
2015-08-15 04:06:01.135 Could not check E:\Games\Old P\WINDOWS\Help\password.chm\/#STRINGS (corrupt)
2015-08-15 04:06:04.498 Could not check E:\Games\Old P\WINDOWS\Help\wab.chm\/wab_add_contacts_overview.htm (corrupt)
2015-08-15 04:06:04.498 Could not check E:\Games\Old P\WINDOWS\Help\wab.chm (virus scan failed)
2015-08-15 04:20:36.408 Could not open E:\pagefile.sys
2015-08-15 04:24:03.551 The following items will be cleaned up:
2015-08-15 04:24:03.551 Mal/Generic-L
 
Hmm it appears I have some corruption going on... and the last virus won't clean. but not worried about it I've deleted the whole folder it was in.just an old version of windows as this is an older drive from my previous computer.
 
redtarget.gif
Uninstall Wise Registry Cleaner.
Registry cleaners/optimizers are not recommended for several reasons:

  • Registry cleaners are extremely powerful applications that can damage the registry by using aggressive cleaning routines and cause your computer to become unbootable.

    The Windows registry is a central repository (database) for storing configuration data, user settings and machine-dependent settings, and options for the operating system. It contains information and settings for all hardware, software, users, and preferences. Whenever a user makes changes to settings, file associations, system policies, or installed software, the changes are reflected and stored in this repository. The registry is a crucial component because it is where Windows "remembers" all this information, how it works together, how Windows boots the system and what files it uses when it does. The registry is also a vulnerable subsystem, in that relatively small changes done incorrectly can render the system inoperable. For a more detailed explanation, read Understanding The Registry.
  • Not all registry cleaners are created equal. There are a number of them available but they do not all work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad entry". One cleaner may find entries on your system that will not cause problems when removed, another may not find the same entries, and still another may want to remove entries required for a program to work.
  • Not all registry cleaners create a backup of the registry before making changes. If the changes prevent the system from booting up, then there is no backup available to restore it in order to regain functionality. A backup of the registry is essential BEFORE making any changes to the registry.
  • Improperly removing registry entries can hamper malware disinfection and make the removal process more difficult if your computer becomes infected. For example, removing malware related registry entries before the infection is properly identified can contribute to system instability and even make the malware undetectable to removal tools.
  • The usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid, and erroneous entries does not affect system performance but it can result in "unpredictable results".
Unless you have a particular problem that requires a registry edit to correct it, I would suggest you leave the registry alone. Using registry cleaning tools unnecessarily or incorrectly could lead to disastrous effects on your operating system such as preventing it from ever starting again. For routine use, the benefits to your computer are negligible while the potential risks are great.


redtarget.gif
Update your Java version here: https://www.techspot.com/downloads/6463-java-se.html
Alternate download: http://www.java.com/en/download/manual.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

redtarget.gif
Update Thunderbird to the latest version or uninstall it if you don't use it.

==================================================

Your computer is clean

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download
51a5ce45263de-delfix.png
DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore
  • Reset system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.

3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

4. Check if your browser plugins are up to date.
Firefox - https://www.mozilla.org/en-US/plugincheck/
other browsers: https://browsercheck.qualys.com/ (click on "Scan without installing plugin" and then on "Scan now")

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

11. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

12. Please, let me know, how your computer is doing.
 
Bad news. It's back. Came up about 2.5 hours after the last post. I wasn't aware of it as I had gone to bed and worked today. I loaded up chrome and there it was. The time stamp on the htm file it created was last night at 9:48 EST.
 
Reset Chrome...
Click on "Customize and control Google Chrome":
p22003758.gif

Click "Settings" then "Show advanced settings" at the bottom of the screen.
Click "Reset browser settings" button.
Restart Chrome.

If the above didn't help....

Reinstall Chrome...
If you want to save your bookmarks...
How to Backup Bookmarks in Google Chrome
If you want to save your passwords as well see here: http://www.intowindows.com/how-to-backup-saved-passwords-in-google-chrome-browser/
  • Close all Chrome windows and tabs.
  • Go to the Start menu > Control Panel. (Windows 8 users: Learn how to access the Control Panel)
  • Click Programs and Features.
  • Double-click Google Chrome.
  • Click Uninstall from the confirmation dialog. Delete your user profile information, like your browser preferences, bookmarks, and history, by selecting the "Also delete your browsing data" checkbox.
Install fresh copy.
 
Back