Jump to content

PUP.Optional.OpenCandy


irehc

Recommended Posts

Hi there

 

For the second time Malwarebytes has found pup.optional.opencandy files on my system.  I remove them, restart and scan again and hey presto - they are back.  What are these files?  How do I successfully remove them?

Your help would be really appreciated.

 

Cheri

Link to post
Share on other sites

Hello Cheri and :welcome:! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
Please follow the instructions here and then post the log files in your next reply.

http://forums.malwarebytes.org/index.php?showtopic=9573

Link to post
Share on other sites

DDS (Ver_2012-11-20.01) - NTFS_AMD64 

Internet Explorer: 10.0.9200.16660  BrowserJavaVersion: 10.25.2

Run by Cheri G-J at 21:46:40 on 2013-09-08

Microsoft Windows 8 Pro  6.2.9200.0.1252.44.2057.18.8154.5571 [GMT 12:00]

.

AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\WINDOWS\system32\svchost.exe -k DcomLaunch

C:\WINDOWS\system32\nvvsvc.exe

C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\WINDOWS\system32\svchost.exe -k RPCSS

C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\WINDOWS\system32\dwm.exe

C:\WINDOWS\system32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k LocalService

C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Program Files\Classic Shell\ClassicShellService.exe

C:\WINDOWS\system32\svchost.exe -k NetworkService

C:\WINDOWS\System32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE

C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

C:\WINDOWS\system32\nvvsvc.exe

C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe

C:\Program Files\Cucusoft\NetGuard\BandwidthGuardSrvc64.sys

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\WINDOWS\system32\dashost.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe

C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

C:\WINDOWS\SysWOW64\PnkBstrA.exe

C:\Program Files\Classic Shell\ClassicStartMenu.exe

C:\WINDOWS\system32\taskhostex.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe

C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe

c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe

c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe

C:\Program Files\Windows Defender\MsMpEng.exe

C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe

C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

C:\Windows\System32\WUDFHost.exe

C:\WINDOWS\system32\SearchIndexer.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\WINDOWS\explorer.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files (x86)\Steam\Steam.exe

C:\Program Files (x86)\Common Files\Steam\SteamService.exe

C:\Users\Cheri G-J\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Cheri G-J\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Cheri G-J\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Cheri G-J\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Cheri G-J\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Cheri G-J\AppData\Local\Google\Chrome\Application\chrome.exe

C:\WINDOWS\system32\taskhost.exe

C:\WINDOWS\System32\svchost.exe -k WerSvcGroup

C:\WINDOWS\system32\SearchProtocolHost.exe

C:\WINDOWS\system32\SearchFilterHost.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.


uProxyOverride = <local>

mWinlogon: Userinit = userinit.exe,

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: ArcPluginIEBHO Class: {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - C:\Program Files (x86)\Perfect World Entertainment\Arc\plugins\ArcPluginIE.dll

BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.5.0.2\AVG Secure Search_toolbar.dll

BHO: SpeedBit Link Verification Helper: {D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} - C:\Program Files (x86)\DAP\LinkVerifier.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.5.0.2\AVG Secure Search_toolbar.dll

uRun: [Google Update] "C:\Users\Cheri G-J\AppData\Local\Google\Update\GoogleUpdate.exe" /c

uRun: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent

uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

uRun: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

uRun: [Pokki] "C:\Users\Cheri G-J\AppData\Local\Pokki\v0.260.8.396\pokki.exe"

uRun: [DownloadAccelerator] "C:\Program Files (x86)\DAP\DAP.EXE" /STARTUP

uRun: [Akamai NetSession Interface] "C:\Users\Cheri G-J\AppData\Local\Akamai\netsession_win.exe"

uRun: [X-Lite] "C:\Program Files (x86)\CounterPath\X-Lite\X-Lite.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [instaLAN] "C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup

mRun: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide

mRun: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"

StartupFolder: C:\Users\CHERIG~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

IE: &Download with &DAP - C:\Program Files (x86)\DAP\dapextie.htm

IE: &Verify with DAP - C:\Program Files (x86)\DAP\dapverify.htm

IE: Download &all with DAP - C:\Program Files (x86)\DAP\dapextie2.htm

TCP: NameServer = 192.168.2.1

TCP: Interfaces\{1048A38A-45F1-4741-A50A-68B6FC571F40} : DHCPNameServer = 192.168.2.1

TCP: Interfaces\{EF3ADB43-ACD9-4FA9-8EF2-A8E2E44E76D5} : DHCPNameServer = 10.1.1.1

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll

Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie.dll

Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie.dll

AppInit_DLLs= C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll

SSODL: WebCheck - <orphaned>

mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\WINDOWS\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings

x64-BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll

x64-BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

x64-Run: [CucusoftNetGuard] <no file>

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>

x64-Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie64.dll

x64-Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie64.dll

x64-SSODL: WebCheck - <orphaned>

.

============= SERVICES / DRIVERS ===============

.

R1 HWiNFO32;HWiNFO32/64 Kernel Driver;C:\WINDOWS\System32\Drivers\HWiNFO64A.SYS [2013-8-17 31136]

R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-23 14928]

R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-13 12368]

R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-12 140672]

R2 CS_BandwidthGuard64;CS_BandwidthGuard64;C:\Program Files\Cucusoft\NetGuard\BandwidthGuardSrvc64.sys [2013-4-29 292000]

R2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe [2009-10-7 191000]

R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-29 418376]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-29 701512]

R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-8-1 14997280]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-6-21 413472]

R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2012-12-6 3463080]

R2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [2013-8-15 1643184]

R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;C:\WINDOWS\System32\Drivers\L1C63x64.sys [2012-6-22 110744]

R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\WINDOWS\System32\Drivers\LVPr2M64.sys [2009-10-7 30232]

R3 MBAMProtector;MBAMProtector;C:\WINDOWS\System32\Drivers\mbam.sys [2012-12-29 25928]

R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\WINDOWS\System32\Drivers\nvvad64v.sys [2013-9-8 39200]

R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\Drivers\WUDFRd.sys [2012-7-26 198656]

S3 ArcService;Arc Service;C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [2013-4-18 88424]

S3 athur;Qualcomm Atheros AR9271 Wireless Network Adapter Service;C:\WINDOWS\System32\Drivers\athuw8x.sys [2012-12-6 3744256]

S3 LVRS64;Logitech RightSound Filter Driver;C:\WINDOWS\System32\Drivers\lvrs64.sys [2012-10-26 351520]

S3 LVUVC64;@oem26.inf,%PID_0825_DD%(UVC);Logitech HD Webcam C270(UVC);C:\WINDOWS\System32\Drivers\lvuvc64.sys [2012-10-26 4758176]

S3 vmbusr;Virtual Machine Bus Provider;C:\WINDOWS\System32\Drivers\vmbusr.sys [2012-7-26 117248]

S3 zghsdiag;ZTE General Handset Diagnostic Port;C:\WINDOWS\System32\Drivers\zghsdiag.sys [2011-1-13 122624]

S3 zghsmdm;ZTE General Handset USB Modem Proprietary;C:\WINDOWS\System32\Drivers\zghsmdm.sys [2011-1-13 122624]

S3 zghsnmea;ZTE General Handset NMEA Port;C:\WINDOWS\System32\Drivers\zghsnmea.sys [2011-1-13 122624]

.

=============== File Associations ===============

.

FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [userChoice]

.

=============== Created Last 30 ================

.

2013-09-08 02:50:38 -------- d-----w- C:\WINDOWS\LastGood.Tmp

2013-09-08 02:50:33 39200 ----a-w- C:\WINDOWS\System32\drivers\nvvad64v.sys

2013-09-08 02:50:33 28448 ----a-w- C:\WINDOWS\SysWow64\nvaudcap32v.dll

2013-09-08 02:03:51 9515512 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5E08EDCC-2A8A-4DC4-8214-FF57E3EBE3DB}\mpengine.dll

2013-09-07 15:00:11 9515512 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll

2013-09-04 12:59:35 270512 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10215.bin

2013-08-17 22:52:48 -------- d-----w- C:\Program Files (x86)\AVG Secure Search

2013-08-17 10:59:42 -------- d-----w- C:\Users\Cheri G-J\AppData\Local\PAYDAY 2

2013-08-17 10:56:19 31136 ----a-w- C:\WINDOWS\System32\drivers\HWiNFO64A.SYS

2013-08-17 10:56:11 -------- d-----w- C:\Program Files\HWiNFO64

2013-08-17 06:08:49 -------- d-----w- C:\ProgramData\HitmanPro

2013-08-17 02:53:20 -------- d-----w- C:\Users\Cheri G-J\AppData\Local\avgchrome

2013-08-17 02:53:09 -------- d-----w- C:\WINDOWS\SysWow64\searchplugins

2013-08-17 02:53:09 -------- d-----w- C:\WINDOWS\SysWow64\Extensions

2013-08-17 02:53:00 -------- d-----w- C:\ProgramData\BrowserDefender

2013-08-17 02:52:27 -------- d-----w- C:\Program Files\CPUID

2013-08-17 02:51:27 -------- d-----w- C:\ProgramData\Babylon

2013-08-17 02:44:09 -------- d-----w- C:\Program Files (x86)\SlimDrivers

2013-08-15 04:56:59 -------- d-----w- C:\WINDOWS\System32\MRT

2013-08-14 21:27:23 98304 ----a-w- C:\WINDOWS\System32\apprepsync.dll

2013-08-14 21:27:23 87040 ----a-w- C:\WINDOWS\SysWow64\apprepapi.dll

2013-08-14 21:27:23 74240 ----a-w- C:\WINDOWS\SysWow64\apprepsync.dll

2013-08-14 21:27:23 68096 ----a-w- C:\WINDOWS\System32\cryptsvc.dll

2013-08-14 21:27:23 124416 ----a-w- C:\WINDOWS\System32\apprepapi.dll

2013-08-13 08:03:40 278800 ------w- C:\WINDOWS\System32\MpSigStub.exe

.

==================== Find3M  ====================

.

2013-09-08 08:23:34 281688 ----a-w- C:\WINDOWS\SysWow64\PnkBstrB.xtr

2013-09-08 08:23:34 281688 ----a-w- C:\WINDOWS\SysWow64\PnkBstrB.exe

2013-08-20 13:32:58 29984 ----a-w- C:\WINDOWS\System32\nvaudcap64v.dll

2013-08-14 22:16:22 45856 ----a-w- C:\WINDOWS\System32\drivers\avgtpx64.sys

2013-08-14 05:04:58 290776 ----a-w- C:\WINDOWS\SysWow64\PnkBstrB.ex0

2013-07-29 08:26:28 76888 ----a-w- C:\WINDOWS\SysWow64\PnkBstrA.exe

2013-07-26 05:12:08 3958784 ----a-w- C:\WINDOWS\System32\jscript9.dll

2013-07-26 05:12:04 136704 ----a-w- C:\WINDOWS\System32\iesysprep.dll

2013-07-26 05:12:03 67072 ----a-w- C:\WINDOWS\System32\iesetup.dll

2013-07-26 03:35:08 2706432 ----a-w- C:\WINDOWS\System32\mshtml.tlb

2013-07-26 03:13:15 44032 ----a-w- C:\WINDOWS\SysWow64\UXInit.dll

2013-07-26 03:12:04 2877440 ----a-w- C:\WINDOWS\SysWow64\jscript9.dll

2013-07-26 03:12:00 61440 ----a-w- C:\WINDOWS\SysWow64\iesetup.dll

2013-07-26 03:12:00 109056 ----a-w- C:\WINDOWS\SysWow64\iesysprep.dll

2013-07-26 02:49:14 2706432 ----a-w- C:\WINDOWS\SysWow64\mshtml.tlb

2013-07-09 06:07:17 2233168 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys

2013-07-02 00:44:14 36288 ----a-w- C:\WINDOWS\System32\drivers\WdBoot.sys

2013-07-01 22:08:49 247216 ----a-w- C:\WINDOWS\System32\drivers\WdFilter.sys

2013-06-27 22:04:51 78200 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl

2013-06-27 22:04:51 693112 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe

2013-06-24 21:30:46 96168 ----a-w- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll

2013-06-24 21:30:44 867240 ----a-w- C:\WINDOWS\SysWow64\npDeployJava1.dll

2013-06-24 21:30:44 789416 ----a-w- C:\WINDOWS\SysWow64\deployJava1.dll

2013-06-21 10:23:16 6496544 ----a-w- C:\WINDOWS\System32\nvcpl.dll

2013-06-21 10:23:16 3514656 ----a-w- C:\WINDOWS\System32\nvsvc64.dll

2013-06-21 10:23:11 884512 ----a-w- C:\WINDOWS\System32\nvvsvc.exe

2013-06-21 10:23:10 63776 ----a-w- C:\WINDOWS\System32\nvshext.dll

2013-06-21 10:23:10 2555680 ----a-w- C:\WINDOWS\System32\nvsvcr.dll

2013-06-21 10:23:10 237856 ----a-w- C:\WINDOWS\System32\nvmctray.dll

2013-06-20 17:16:02 566048 ----a-w- C:\WINDOWS\SysWow64\nvStreaming.exe

2013-06-20 04:17:49 3253909 ----a-w- C:\WINDOWS\System32\nvcoproc.bin

2013-06-16 22:41:31 997632 ----a-w- C:\WINDOWS\System32\drivers\ndis.sys

2013-06-11 23:43:37 1767936 ----a-w- C:\WINDOWS\SysWow64\wininet.dll

2013-06-11 23:26:20 2241024 ----a-w- C:\WINDOWS\System32\wininet.dll

.

============= FINISH: 21:47:20.96 ===============

 

 

 

 

 


.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft Windows 8 Pro

Boot Device: \Device\HarddiskVolume1

Install Date: 06/12/2012 20:41:37

System Uptime: 08/09/2013 21:19:16 (0 hours ago)

.

Motherboard: Gigabyte Technology Co., Ltd. |  | Z77M-D3H-MVP

Processor: Intel® Core i5-3570K CPU @ 3.40GHz | Intel® Core i5-3570K CPU @ 3.40GHz | 3801/100mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 699 GiB total, 500.052 GiB free.

D: is CDROM (UDF)

F: is Removable

G: is Removable

H: is Removable

I: is Removable

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP72: 17/08/2013 22:58:37 - Installed DirectX

RP73: 26/08/2013 03:01:50 - Scheduled Checkpoint

RP74: 02/09/2013 03:03:29 - Scheduled Checkpoint

.

==== Installed Programs ======================

.

Adobe AIR

Adobe Flash Player 11 Plugin

Adobe Reader XI (11.0.03)

Adobe Shockwave Player 11.6

Akamai NetSession Interface

APB Reloaded

Arc

ArcSoft MediaImpression

ArmA 2 Free Uninstall

ARMA 2 Operation Arrowhead Uninstall

BattlEye for OA Uninstall

Belkin Setup and Router Monitor

Blacklight: Retribution

Borderlands 2

Borderlands 2: Premiere Club

Call of Duty® 4 - Modern Warfare

Call of Duty® 4 - Modern Warfare 1.2 Patch

Call of Duty® 4 - Modern Warfare 1.3 Patch

Call of Duty® 4 - Modern Warfare 1.4 Patch

Call of Duty® 4 - Modern Warfare 1.5 Multiplayer Patch

Call of Duty® 4 - Modern Warfare 1.5 Patch

Call of Duty® 4 - Modern Warfare 1.6 Patch

Call of Duty® 4 - Modern Warfare 1.7 Patch

Call of Duty: Black Ops II

Call of Duty: Black Ops II - Multiplayer

Call of Duty: Black Ops II - Zombies

CCleaner

Classic Shell

CPUID CPU-Z 1.65.1

Cry of Fear

DayZ Commander

Don't Starve

Download Accelerator Plus (DAP)

Far Cry 3

GamersFirst LIVE!

GeForce Experience NvStream Client Components

Google Chrome

Google Earth

Half-Life 2

HWiNFO64 Version 4.22

ImgBurn

Java 7 Update 25

Java 7 Update 9 (64-bit)

Java Auto Updater

K-Lite Codec Pack 9.5.5 (64-bit)

K-Lite Codec Pack 9.5.5 (Full)

Leisure Suit Larry in the Land of the Lounge Lizards: Reloaded

Logitech Vid HD

Logitech Webcam Software

Malwarebytes Anti-Malware version 1.75.0.1300

Mensa Academy

Microsoft .NET Framework 1.1

Microsoft Mouse and Keyboard Center

Microsoft Silverlight

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219

Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106

Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106

Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106

MikesBikes-Advanced

NVIDIA 3D Vision Controller Driver 320.49

NVIDIA 3D Vision Driver 320.49

NVIDIA Control Panel 320.49

NVIDIA GeForce Experience 1.6.1

NVIDIA Graphics Driver 320.49

NVIDIA HD Audio Driver 1.3.24.2

NVIDIA Install Application

NVIDIA PhysX

NVIDIA Stereoscopic 3D Driver

NVIDIA Update 8.3.14

NVIDIA Update Components

NVIDIA Virtual Audio 1.2.5

Omerta - City of Gangsters

OpenOffice.org 3.4.1

PAYDAY 2

PDFCreator

Pokki

PunkBuster Services

QuickTime

SHIELD Streaming

Skype™ 6.0

SlimComputer

SlimDrivers

Steam

SUPERAntiSpyware

swMSM

Team Fortress 2

TeamSpeak 3 Client

TeamViewer 8

TP-LINK Wireless Client Utility

Unity Web Player

Uplay

Visual Studio 2010 x64 Redistributables

VLC media player 2.0.5

WinRAR 4.20 (64-bit)

X-Lite 4

Xfire

.

==== End Of File ===========================

 

Link to post
Share on other sites

Step 1

Please uninstall this application: Pokki

Step 2

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Step 3

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Clean.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[s1].txt as well.
Step 4
  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.

In your next reply, post the following log files:

  • Junkware Removal Tool log
  • AdwCleaner log
  • Malwarebytes' Anti-Malware log
Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.