Broni
Posts: 56,041 +517
Run OTL
NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.
====================================
Last scans...
1. Download Security Check from HERE, and save it to your Desktop.
2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
3. Please download AdwCleaner by Xplode onto your desktop.
Next...
4. Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
5. Please run a free online scan with the ESET Online Scanner
- Under the Custom Scans/Fixes box at the bottom, paste in the following
Code::OTL IE - HKU\S-1-5-21-2504441003-1554018461-1511963873-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local> O4 - HKLM..\Run: [] File not found O4 - HKU\S-1-5-21-2504441003-1554018461-1511963873-1000..\Run: [AdobeBridge] File not found O4 - HKU\S-1-5-21-2504441003-1554018461-1511963873-1000..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent File not found O4 - HKU\S-1-5-21-2504441003-1554018461-1511963873-1000..\Run: [PlayNC Launcher] File not found O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-21-2504441003-1554018461-1511963873-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-2504441003-1554018461-1511963873-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-2504441003-1554018461-1511963873-1000\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-2504441003-1554018461-1511963873-1000\..Trusted Domains: sony.com ([]* in Trusted sites) [2012/10/06 19:39:44 | 000,000,000 | ---D | C] -- C:\FRST [2012/10/04 18:31:16 | 000,030,720 | ---- | C] () -- C:\Users\Taylor\kytqetorjans.exe [2012/07/16 06:17:24 | 000,004,140 | ---- | C] () -- C:\ProgramData\mtbjfghn.xbe [2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 00:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] @Alternate Data Stream - 251 bytes -> C:\ProgramData\Temp:33384BC0 @Alternate Data Stream - 239 bytes -> C:\ProgramData\Temp:CA8D6B60 @Alternate Data Stream - 239 bytes -> C:\ProgramData\Temp:88AE8AB0 @Alternate Data Stream - 237 bytes -> C:\ProgramData\Temp:A2B3764A @Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:C0A2E219 @Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:D2A5A561 @Alternate Data Stream - 228 bytes -> C:\ProgramData\Temp:56C66609 @Alternate Data Stream - 226 bytes -> C:\ProgramData\Temp:3790BACD @Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:22741C1F @Alternate Data Stream - 224 bytes -> C:\ProgramData\Temp:AE2EA3C2 @Alternate Data Stream - 224 bytes -> C:\ProgramData\Temp:4A966CC2 @Alternate Data Stream - 223 bytes -> C:\ProgramData\Temp:96646EC1 @Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:B1E64E47 @Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:3BF63E4A @Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:2F93516B @Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:439E3411 @Alternate Data Stream - 220 bytes -> C:\ProgramData\Temp:EB5BDBB0 @Alternate Data Stream - 220 bytes -> C:\ProgramData\Temp:073139EC @Alternate Data Stream - 219 bytes -> C:\ProgramData\Temp:02B823FE @Alternate Data Stream - 217 bytes -> C:\ProgramData\Temp:5F1019FF @Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:B722BCE5 @Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:417B6FAC @Alternate Data Stream - 215 bytes -> C:\ProgramData\Temp:D8DB81DC @Alternate Data Stream - 215 bytes -> C:\ProgramData\Temp:0DFE2AE1 @Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:BDF08FAF @Alternate Data Stream - 211 bytes -> C:\ProgramData\Temp:63F8EC77 @Alternate Data Stream - 210 bytes -> C:\ProgramData\Temp:E5DE9C8F @Alternate Data Stream - 210 bytes -> C:\ProgramData\Temp:393F7B1E @Alternate Data Stream - 210 bytes -> C:\ProgramData\Temp:0D52F295 @Alternate Data Stream - 210 bytes -> C:\ProgramData\Temp:0860D6D6 @Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:DF0BC727 @Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:FC60E0F8 @Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:6FD26134 @Alternate Data Stream - 205 bytes -> C:\ProgramData\Temp:6BD304B9 @Alternate Data Stream - 203 bytes -> C:\ProgramData\Temp:52E1DB1D @Alternate Data Stream - 192 bytes -> C:\ProgramData\Temp:A688EF17 @Alternate Data Stream - 192 bytes -> C:\ProgramData\Temp:27C3CD07 :Commands [purity] [emptytemp] [emptyjava] [emptyflash] [Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot the PC when it is done
- You will get a log that shows the results of the fix. Please post it.
NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.
====================================
Last scans...
1. Download Security Check from HERE, and save it to your Desktop.
- Double-click SecurityCheck.exe
- Follow the onscreen instructions inside of the black box.
- A Notepad document should open automatically called checkup.txt; please post the contents of that document.
NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.
2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
- Make sure the following options are checked:
- Internet Services
- Windows Firewall
- System Restore
- Security Center
- Windows Update
- Windows Defender
- Press "Scan".
- It will create a log (FSS.txt) in the same directory the tool is run.
- Please copy and paste the log to your reply.
3. Please download AdwCleaner by Xplode onto your desktop.
- Close all open programs and internet browsers.
- Double click on adwcleaner.exe to run the tool.
- Click on Delete.
- Confirm each time with Ok.
- Your computer will be rebooted automatically. A text file will open after the restart.
- Please post the contents of that logfile with your next reply.
- You can find the logfile at C:\AdwCleaner[S1].txt as well.
Next...
- Double click on adwcleaner.exe to run the tool.
- Click on Uninstall.
- Confirm with yes.
4. Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
- Double click on TFC.exe to run the program.
- Click on Start button to begin cleaning process.
- TFC will close all running programs, and it may ask you to restart computer.
5. Please run a free online scan with the ESET Online Scanner
- Disable your antivirus program
- Tick the box next to YES, I accept the Terms of Use
- Click Start
- Accept any security warnings from your browser.
- Check Scan archives
- Click Start
- ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
- When the scan completes, click on List of found threats
- Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
- NOTE. If Eset won't find any threats, it won't produce any log.