- Fix with FRST
Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
- Open Notepad.exe. Do not use any other text editor software;
- Copy and Paste the contents inside the code-box to your Notepad --
Code:
Code:
Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] <======= ATTENTION (Policy restriction on ProxySettings)
S3 clwvd6; system32\DRIVERS\clwvd6.sys [X]
2015-05-24 09:08 - 2015-05-24 09:08 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\jmbxndng
2015-05-24 09:00 - 2015-05-24 09:00 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\lsrvalcj
2015-05-24 05:24 - 2015-05-24 05:24 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\xqmvqkqt
2015-05-24 05:21 - 2015-05-24 05:21 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\onaoptad
2015-05-24 05:19 - 2015-05-24 05:19 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\tlhcuxpe
2015-05-24 05:19 - 2015-05-24 05:19 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\pxndjdu
2015-05-24 05:19 - 2015-05-24 05:19 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\cmjnswam
2015-05-24 05:18 - 2015-05-24 05:18 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\kfwokscb
2015-05-24 05:13 - 2015-05-24 05:13 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\woxqqgoq
2015-05-24 05:10 - 2015-05-24 05:10 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\hupkvhqk
2015-05-24 05:08 - 2015-05-24 05:08 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\mllrfnev
2015-05-24 05:07 - 2015-05-24 05:07 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\buufafcb
2015-05-24 05:06 - 2015-05-24 05:06 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\tkxeodiw
2015-05-24 05:06 - 2015-05-24 05:06 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\nyyaarbl
2015-05-24 05:06 - 2015-05-24 05:06 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\ncybskmg
2015-05-24 04:39 - 2015-05-24 04:39 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\rqvyoajy
2015-05-24 04:39 - 2015-05-24 04:39 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\nbbzegfa
2015-05-24 04:38 - 2015-05-24 04:38 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\nubemtsz
2015-05-24 04:37 - 2015-05-24 04:37 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\ytimpjym
2015-05-24 04:37 - 2015-05-24 04:37 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\cwnsubka
2015-05-24 04:35 - 2015-05-24 04:35 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\bsjdqwsi
2015-05-24 04:34 - 2015-05-24 04:34 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\pneeorob
2015-05-24 04:32 - 2015-05-24 04:32 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\lgjimqno
2015-05-24 04:29 - 2015-05-24 04:29 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\fftndlpa
2015-05-24 04:14 - 2015-05-24 04:14 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\gxuqkiuv
2015-05-24 04:13 - 2015-05-24 04:13 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\gmrqqrzs
2015-05-24 04:13 - 2015-05-24 04:13 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\cbawibdw
2015-05-24 04:12 - 2015-05-24 04:12 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\bblhtlzd
2015-05-24 04:08 - 2015-05-24 04:08 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\laozsdbl
2015-05-24 04:05 - 2015-05-24 04:05 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\uiadahpk
2015-05-24 04:01 - 2015-05-24 04:01 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\dyqgmofp
2015-05-24 04:00 - 2015-05-24 04:00 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\exocbwji
2015-05-24 03:56 - 2015-05-24 03:56 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\tvmpcwmc
2015-05-24 03:55 - 2015-05-24 03:55 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\pagcpeao
2015-05-24 03:55 - 2015-05-24 03:55 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\okghxrmo
2015-05-24 03:54 - 2015-05-24 03:54 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\rymzsodb
2015-05-24 03:53 - 2015-05-24 03:53 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\gxgbidto
2015-05-24 03:40 - 2015-05-24 03:40 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\xsjfbgdv
2015-05-24 03:40 - 2015-05-24 03:40 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\oefwawtr
2015-05-24 03:37 - 2015-05-24 03:37 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\pdjttled
2015-05-24 03:28 - 2015-05-24 03:28 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\vqrxhxlg
2015-05-24 03:27 - 2015-05-24 03:27 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\omvzmbmj
2015-05-23 21:21 - 2015-05-23 21:22 - 00000000 ____D () C:\Program Files (x86)\473801ed-a546-443a-93d0-6590433a6262
2015-05-23 21:19 - 2015-05-24 08:52 - 00000000 ____D () C:\Users\Ethan\AppData\Local\29032
2015-05-23 20:53 - 2015-05-23 20:53 - 00613255 _____ () C:\Users\Ethan\AppData\Local\nsf39FF.tmp
2015-05-23 20:25 - 2015-05-23 20:25 - 00000000 ____D () C:\ProgramData\c6fe7a800002f1e
2015-05-23 20:19 - 2015-05-23 21:19 - 00000000 ___HD () C:\ProgramData\jod
2015-05-23 17:43 - 2015-05-23 17:43 - 00613255 _____ () C:\Users\Ethan\AppData\Local\nsa2A8B.tmp
2015-05-23 17:41 - 2015-05-23 17:41 - 00000000 ____D () C:\Users\Ethan\Documents\Optimizer Pro
2015-05-23 17:38 - 2015-05-23 17:38 - 00631296 _____ () C:\Windows\jod.dat
2015-05-23 17:23 - 2015-05-23 17:23 - 00000000 ____D () C:\Users\Ethan\AppData\Roaming\One System Care
2015-05-23 17:00 - 2015-05-24 02:59 - 00000112 _____ () C:\ProgramData\45A7xM2.dat
2015-05-23 16:51 - 2015-05-23 16:51 - 00000000 ____D () C:\ProgramData\Naxrefsemigew
2015-05-23 16:50 - 2015-05-23 16:50 - 00000000 ____D () C:\ProgramData\f3a5ddd00007f6d
2015-05-23 16:39 - 2015-05-23 22:20 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-23 16:34 - 2015-05-24 03:16 - 00000000 ____D () C:\ProgramData\abc
2015-05-23 16:33 - 2015-05-23 16:36 - 00000000 ____D () C:\Program Files (x86)\MaxComputerCleaner_v17.514
2015-05-23 16:22 - 2015-05-23 16:22 - 00000000 ____D () C:\Users\Ethan\AppData\Local\Zeoinsight
2015-05-23 16:22 - 2015-05-23 16:22 - 00000000 ____D () C:\Users\Ethan\AppData\Local\ZBAnalyticsCore
2015-05-10 12:23 - 2015-05-10 12:23 - 00000950 _____ () C:\Users\Ethan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2015-05-10 12:23 - 2015-05-10 12:23 - 00000942 _____ () C:\Users\Ethan\Desktop\osu!.lnk
2015-05-15 05:56 - 2015-05-15 05:57 - 00000000 ____D () C:\ProgramData\Gyazo
2015-05-14 20:56 - 2015-05-23 23:51 - 00000000 ____D () C:\Program Files (x86)\SystemContinue
2015-05-10 12:22 - 2015-05-10 12:22 - 03262024 _____ (ppy) C:\Users\Ethan\Downloads\osu!install.exe
2015-05-01 18:26 - 2015-05-14 21:16 - 00000000 ____D () C:\ProgramData\10008724138348112492
2015-05-01 18:25 - 2015-05-01 18:25 - 00300032 _____ () C:\Users\Ethan\Downloads\The Hunger Games 2012 [1080p].exe
2015-04-25 12:08 - 2015-04-25 12:08 - 00000000 ____D () C:\Users\Ethan\AppData\Local\openvr
2015-05-23 17:43 - 2015-05-23 17:43 - 0613255 _____ () C:\Users\Ethan\AppData\Local\nsa2A8B.tmp
2015-05-23 20:53 - 2015-05-23 20:53 - 0613255 _____ () C:\Users\Ethan\AppData\Local\nsf39FF.tmp
2015-05-23 17:00 - 2015-05-24 02:59 - 0000112 _____ () C:\ProgramData\45A7xM2.dat
C:\ProgramData\45A7xM2.dat
Edu App (HKLM\...\Edu App) (Version: 2015.05.24.012424 - Edu App) <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-3805462314-2989857978-3840800272-1001_Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InprocServer32 -> C:\Users\Ethan\AppData\Roaming\sursenel\ticyver.dll No File <==== ATTENTION
CMD: ipconfig /flushdns
End
- Click on File > Save as...
- Inside the File Name box type fixlist.txt
- From the Save as type drop down list, choose All Files
- Save the file to your Desktop;
- Re-run FRST.exe and click Fix;
- Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.
- Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.
- After the completion, a log will be produced;
- Attach the log in your next reply.
- Click on File > Save as...
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support!
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>
</div></left>
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>
</div></left>