CAUTION : This fix is only valid for this specific machine, using it on another may break your computer Open
notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
FF Extension: XUL Cache - C:\Users\nikhil1994\AppData\Roaming\Mozilla\Firefox\Profiles\wjqelr1l.default\Extensions\{7c0f957d-e22b-492b-9c15-abac029fd06f} [2015-05-03]
2015-07-23 18:27 - 2015-07-23 21:31 - 00000000 ____D C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2015-07-23 18:00 - 2015-07-23 20:57 - 00000024 _____ C:\autoexec.bat
2015-07-19 13:57 - 2015-07-19 13:57 - 00004216 _____ C:\Windows\System32\Tasks\Winupdate
2015-07-19 13:57 - 2015-07-19 13:57 - 00004194 _____ C:\Windows\System32\Tasks\EssentialUpdateMachine
2015-07-19 13:57 - 2015-04-25 14:48 - 00295424 _____ (Groom-A-Zebu (tm) ) C:\Windows\system32\ysxja.exe
2015-07-19 13:57 - 2015-04-25 14:48 - 00295424 _____ (Groom-A-Zebu (tm) ) C:\Windows\cygavb.exe
2015-07-19 13:57 - 2013-12-05 18:06 - 00003542 _____ C:\Windows\mstdcvtr.bat
2015-07-19 13:57 - 2013-06-05 18:08 - 00004122 _____ C:\Windows\plofgye
2015-07-19 13:57 - 2013-06-05 18:07 - 00004194 _____ C:\Windows\soxe
2015-07-19 13:57 - 2013-06-05 18:06 - 00000038 _____ C:\Windows\initcvtr.bat
Task: {8330E629-B511-4FA9-A71E-9F2B04969294} - System32\Tasks\EssentialUpdateMachine => chp.exe <==== ATTENTION
Task: {E300F6AA-5165-43B2-A763-076CE20F1350} - System32\Tasks\Winupdate => chp.exe <==== ATTENTION
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as
fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THENPlease download
AdwCleaner by Xplode onto your desktop.
- Close all open programs and internet browsers.
- Double click on AdwCleaner.exe to run the tool.
- Click on Scan.
- After the scan is complete click on "Clean"
- Confirm each time with Ok.
- Your computer will be rebooted automatically. A text file will open after the restart.
- Please post the content of that logfile with your next answer.
- You can find the logfile at C:\AdwCleaner[S0].txt as well.
________________________________________________________________________________________Having done that we will now search for the main miscreant :
Start FRST and copy/paste the following into the search box
Click search registry and attach the resultant log
browserupdatecheck.in;wpad.dat