2014-12-15, 13:52
I have this problem I could not get rid of myself and ask for assistance.

Whenever I restart the chrome browser and look at the 'Extensions' page (through 'Settings'), I see that the BestSaveForYou extension re-appears. Every time I remove it, and as long as I do not restart chrome it does not reappear. But as soon as I close chrome and then open it again, the BestSaveForYou extension is there again.

Before I discovered this blessed assistance service I tried to solve the problem myself. I did some online searches, found some tools and tried them:
Spybot S&D
Malwarebytes Anti-Malware
ESET online scanner

but the problem remains.

Then I discovered this service, so here are the results of FRST and aswMBR. Please help.

One more point: I also use Microsoft IE from time to time - but there the problem does not show up. I do not use Firefox.

Thanks in advance,


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-12-2014
Ran by Opher (administrator) on OPHER-L-8 on 14-12-2014 13:26:22
Running from C:\Users\Opher\Downloads
Loaded Profile: Opher (Available profiles: Opher)
Platform: Windows 8.1 Pro (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-12-2014
Ran by Opher at 2014-12-14 13:28:06
Running from C:\Users\Opher\Downloads
Boot Mode: Normal

aswMBR version Copyright(c) 2014 AVAST Software
Run date: 2014-12-14 13:49:21
13:49:21.421 OS Version: Windows x64 6.2.9200
13:49:21.421 Number of processors: 4 586 0x3A09
13:49:21.424 ComputerName: OPHER-L-8 UserName: Opher
13:49:22.207 Initialize success
13:49:22.277 VM: initialized successfully
13:49:22.280 VM: Intel CPU supported
13:49:26.909 VM: disk I/O iaStorA.sys
13:52:37.562 AVAST engine defs: 14121400
13:53:00.805 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000036
13:53:00.814 Disk 0 Vendor: LITEONIT_LMT-256M6M_mSATA_256GB DM8110F Size: 244198MB BusType: 11
13:53:00.836 Disk 0 MBR read successfully
13:53:00.843 Disk 0 MBR scan
13:53:00.862 Disk 0 unknown MBR code
13:53:00.871 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
13:53:01.014 Disk 0 scanning C:\WINDOWS\system32\drivers
13:53:22.393 Service scanning
13:54:13.864 Modules scanning
13:54:13.886 Disk 0 trace - called modules:
13:54:13.915 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll iaStorA.sys
13:54:13.931 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe000757ad060]
13:54:13.943 3 CLASSPNP.SYS[fffff8019337127b] -> nt!IofCallDriver -> \Device\00000036[0xffffe00073fb8060]
13:54:14.817 AVAST engine scan C:\WINDOWS
13:54:17.864 AVAST engine scan C:\WINDOWS\system32
14:01:17.962 AVAST engine scan C:\WINDOWS\system32\drivers
14:01:57.035 AVAST engine scan C:\Users\Opher
14:28:05.799 AVAST engine scan C:\ProgramData
14:34:18.866 Disk 0 statistics 4487760/0/0 @ 1498.83 MB/s
14:34:18.881 Scan finished successfully
14:56:01.144 Disk 0 MBR has been saved successfully to "C:\Users\Opher\Downloads\MBR.dat"
14:56:01.159 The log file has been saved successfully to "C:\Users\Opher\Downloads\aswMBR.txt"

2014-12-15, 19:16
Hi and welcome

Running from C:\Users\Opher\Downloads
We can't use FRST running from this directory.

Please go to your downloads folder and locate Farbar Recovery Scan Tool, right click on select CUT
Go to an open space on your desktop, right click and select PASTE.

You should now see Farbar Recovery Scan Tool on your desktop.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2817043930-95399970-204707143-1001 -> DefaultScope {88625FBA-601E-4698-9956-78137F6C6405} URL =
SearchScopes: HKU\S-1-5-21-2817043930-95399970-204707143-1001 -> {88625FBA-601E-4698-9956-78137F6C6405} URL =
CHR StartupUrls: Default -> "https://mail.google.com/mail/?shva=1#", "hxxp://search.gboxapp.com/"
CustomCLSID: HKU\S-1-5-21-2817043930-95399970-204707143-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Opher\AppData\Local\Google\Update\\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2817043930-95399970-204707143-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Opher\AppData\Local\Google\Update\\psuser_64.dll No File

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

We need to reset your browsers.

Instructions on how to backup your Favourites/Bookmarks and other data can be found below.

http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png Backup Internet Explorer Favourites (http://www.wikihow.com/Back-Up-Favorites-in-Internet-Explorer)
http://2-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg Backup Firefox Bookmarks (https://support.mozilla.org/en-US/kb/export-firefox-bookmarks-to-backup-or-transfer)
http://i.imgur.com/U5NwUGc.png Backup Chrome Bookmarks (http://www.wikihow.com/Export-Bookmarks-from-Chrome)

Proceed with the reset once done.

http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png Internet Explorer: How to reset Internet Explorer settings (http://support.microsoft.com/kb/923737)
http://2-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg Firefox: Reset Firefox (https://support.mozilla.org/en-US/kb/reset-firefox-easily-fix-most-problems)
http://i.imgur.com/U5NwUGc.png Chrome: Chrome - Reset browser settings (https://support.google.com/chrome/answer/3296214?hl=en)


Did you save the results of your ESET scan?

Please post

2014-12-16, 12:46
Thank you very much for the assistance. I performed everything as requested.

- Moved FRST64 to my desktop.
- Created fixlist.txt on the desktop with the provided content and clicked Fix. The content of the resulting Fixlog.txt is enclosed below.
- Reset both Chrome and IE
- To your question - I did not save the results of ESET, but I did find a log.txt file in the directory "C:\Program Files (x86)\ESET\ESET Online Scanner" which I also enclose below.



Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-12-2014
Ran by Opher at 2014-12-16 11:15:18 Run:1
Running from C:\Users\Opher\Desktop
Loaded Profile: Opher (Available profiles: Opher)
Boot Mode: Normal

Content of fixlist:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2817043930-95399970-204707143-1001 -> DefaultScope {88625FBA-601E-4698-9956-78137F6C6405} URL =
SearchScopes: HKU\S-1-5-21-2817043930-95399970-204707143-1001 -> {88625FBA-601E-4698-9956-78137F6C6405} URL =
CHR StartupUrls: Default -> "https://mail.google.com/mail/?shva=1#", "hxxp://search.gboxapp.com/"
CustomCLSID: HKU\S-1-5-21-2817043930-95399970-204707143-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Opher\AppData\Local\Google\Update\\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2817043930-95399970-204707143-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Opher\AppData\Local\Google\Update\\psuser_64.dll No File

Processes closed successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-21-2817043930-95399970-204707143-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-2817043930-95399970-204707143-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{88625FBA-601E-4698-9956-78137F6C6405}" => Key deleted successfully.
"HKCR\CLSID\{88625FBA-601E-4698-9956-78137F6C6405}" => Key not found.
Chrome StartupUrls deleted successfully.
C:\Users\Opher\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Opher\AppData\Local\Temp\sqlite3.dll => Moved successfully.
"HKU\S-1-5-21-2817043930-95399970-204707143-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}" => Key deleted successfully.
"HKU\S-1-5-21-2817043930-95399970-204707143-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}" => Key deleted successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.3 GB temporary data.

The system needed a reboot.

==== End of Fixlog ====

log.txt (from ESET)

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# product=EOS
# version=8
# IEXPLORE.EXE=11.00.9600.16384 (winblue_rtm.130821-1623)
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=a8304e02fb7c1f498f1e8d9e79059653
# engine=21539
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-12-13 05:57:06
# local_time=2014-12-13 06:57:06 (+0100, Romance Standard Time)
# country="United States"
# lang=1033
# osver=6.3.9600 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 8169 8797745 0 0
# scanned=273739
# found=5
# cleaned=4
# scan_time=5478
sh=8DE70672AAB8D3EAAF81BB16E08BCB4871E4B65B ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan" ac=I fn="C:\Users\All Users\caeggdfedigfgecjehcifckjiecpkhhb\LDgS7w7K9.js"
sh=58F99AE9EA22F56F28B6C5FA798BDA3109F297F6 ft=1 fh=c71c0011bbaa4749 vn="a variant of Win32/AdWare.MultiPlug.N application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\DowwnlOaaD keeper\T.dll.vir"
sh=8DE70672AAB8D3EAAF81BB16E08BCB4871E4B65B ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB trojan (cleaned by deleting - quarantined)" ac=C fn="C:\ProgramData\caeggdfedigfgecjehcifckjiecpkhhb\LDgS7w7K9.js"
sh=6244E31D0DED30FCC4CCA87E97B46131D85E6769 ft=1 fh=753be446caef270a vn="a variant of Win32/InstallCore.BQ potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Opher\Downloads\DownloadAcceleratorSetup.exe"
sh=69ADE5DEF3FCAF55DEF6E905B37162F6A4629F3C ft=1 fh=aaefd566e4c73c47 vn="a variant of Win32/InstallCore.BQ potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Opher\Downloads\FLVPlayerSetup.exe"

2014-12-16, 13:52
Tell me what the computer is doing now?

2014-12-16, 14:48
The problem remains. When I close Chrome after deleting the extension BestSaveForYou and then reopen Chrome, the extension BestSaveForYou re-appears.

2014-12-16, 16:33
Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


We need to temporarily uninstall Google Chrome. You have Firefox onboard to use till Google Chrome can be re-installed.

Instructions on how to backup your Favourites/Bookmarks

http://i.imgur.com/U5NwUGc.png Backup Chrome Bookmarks (http://www.wikihow.com/Export-Bookmarks-from-Chrome)


Please download and install Revo Uninstaller Free (http://www.revouninstaller.com/)

Double click Revo Uninstaller to run it.
From the list of programs double click on The Program to remove Google Chrome
When prompted if you want to uninstall click Yes.
Be sure the Moderate option is selected then click Next.
The program will run, If prompted again click Yes
when the built-in uninstaller is finished click on Next.
Once the program has searched for leftovers click Next.
Check/tick the bolded items only on the list then click Delete
when prompted click on Yes and then on next.
put a check on any folders that are found and select delete
when prompted select yes then on next
Once done click Finish.

Google Chrome can be installed from the below link.


1.Please download HitmanPro

For 32-bit Operating System - http://i.imgur.com/dEMD6.gif (http://dl.surfright.nl/HitmanPro.exe).
For 64-bit Operating System - http://i.imgur.com/dEMD6.gif (http://dl.surfright.nl/HitmanPro_x64.exe)

2.Launch the program by double clicking on the http://i.imgur.com/5vo5F.jpg icon.

Note: If the program won't run please then open the program while holding down the left CTRL key until the program is loaded.

3.Click on the next button. You must agree with the terms of EULA. (if asked)

4.Check the box beside "No, I only want to perform a one-time scan to check this computer".

5.Click on the next button.

6.The program will start to scan the computer. The scan will typically take no more than 5-10 minutes.

7.When the scan is done click on drop-down menu of the found entries (if any) and choose - Apply to all => Ignore <= IMPORTANT!!!

8.Click on the next button.

9.Click on the "Save Log" button.

10.Save that file to your desktop and post the content of that file in your next reply.

Note: if there isn't a dropdown menu when the scan is done then please don't delete anything and close HitmanPro

http://forums.majorgeeks.com/chaslang/images/Hitman/6-scanfin-choose.jpg (http://forums.majorgeeks.com/chaslang/images/Hitman/6-scanfin-choose.jpg)

Navigate to C:\Documents and Settings\All Users\Application Data\HitmanPro\Logs (for Windows XP) or to C:\ProgramData\HitmanPro\Logs (for Windows Vista/7) open the report and copy and paste it to your next reply.

Please post
HitmanPro log

2014-12-16, 18:32
Thanks again for the continued support. The two requested logs are enclosed below. Can I re-install Chrome? If not, please let me know when I can. For the time being I use IE.



Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-12-2014
Ran by Opher at 2014-12-16 16:50:34 Run:2
Running from C:\Users\Opher\Desktop
Loaded Profile: Opher (Available profiles: Opher)
Boot Mode: Normal

Content of fixlist:

Processes closed successfully.
C:\ProgramData\caeggdfedigfgecjehcifckjiecpkhhb => Moved successfully.
EmptyTemp: => Removed 87.2 MB temporary data.

The system needed a reboot.

==== End of Fixlog ====

HitmanPro log file


Computer name . . . . : OPHER-L-8
Windows . . . . . . . :
User name . . . . . . : OPHER-L-8\Opher
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free

Scan date . . . . . . : 2014-12-16 17:21:31
Scan mode . . . . . . : Normal
Scan duration . . . . : 2m 44s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No

Threats . . . . . . . : 0
Traces . . . . . . . : 5

Objects scanned . . . : 2,037,583
Files scanned . . . . : 66,122
Remnants scanned . . : 613,163 files / 1,358,298 keys

Suspicious files ____________________________________________________________

Size . . . . . . . : 2,119,168 bytes
Age . . . . . . . : 2.2 days (2014-12-14 13:22:12)
Entropy . . . . . : 7.5
SHA-256 . . . . . : 8E11298707098151A068B0B6288CFBD68CF161AB0FBFF025F7D449336EDB32A9
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-0.5s C:\Users\Opher\AppData\Local\Microsoft\Windows\Notifications\70fd9a9fb31611e2be6eb4b6762af138\BBbiVgI_h150_w310_m7[2].jpg
0.0s C:\Users\Opher\Desktop\FRST64.exe

Cookies _____________________________________________________________________


2014-12-16, 19:22
How's the computer now?

Allow or Block Cookies Per Site in Internet Options (http://www.eightforums.com/tutorials/36633-internet-explorer-cookies-allow-block-windows-8-a.html)

Yes, I think it safe to download Google Chrome again.

2014-12-16, 20:55
Problem seems to be over! Thanks again for the effective assistance!


2014-12-16, 22:44
http://i.imgur.com/AFZxnZc.jpg DelFix

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix) and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools
Create registry backup
Purge system restore
Reset system settings

Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7, MVP
How Malware Spreads - How did I get infected? (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7, MVP
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams, MVP
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes, MVP
How to backup and restore your data using Cobian Backup (http://www.bleepingcomputer.com/tutorials/backup-and-restore-data-with-cobian-backup/) by YourHighness
Slow Computer/browser? It May Not Be Malware (http://www.bleepingcomputer.com/forums/t/87058/slow-computerbrowser-check-here-first;-it-may-not-be-malware/) by quietman7, MVP

The following programmes come highly recommended in the security community.

http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpgAdBlock (https://adblockplus.org/en/firefox) is a browser add-on that blocks annoying banners, pop-ups and video ads.
http://i.imgur.com/E8I37RF.pngCryptoPrevent (https://www.foolishit.com/) places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
http://i.imgur.com/EG85Vjt.png Malwarebytes Anti-Exploit (https://www.malwarebytes.org/antiexploit/) (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpgMalwarebytes Anti-Malware Premium (https://www.malwarebytes.org/) (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xjv4nhMJ.png.pagespeed.ic.A5YbWn1eDO.png NoScript (http://noscript.net/) is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
http://i.imgur.com/3O8r9Uq.png (http://www.sandboxie.com/) Sandboxie (http://www.sandboxie.com/) isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/DgW1XL2.png.pagespeed.ce.v1OlJl_ZAS.png Secuina PSI (http://secunia.com/vulnerability_scanning/personal/) will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xj1OLIec.png.pagespeed.ic.k6hhwopU0q.jpg SpywareBlaster (https://www.brightfort.com/spywareblaster.html) is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xJEP5iWI.png.pagespeed.ic.4tmM1lM7DQ.pngWeb of Trust (https://www.mywot.com/) (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

2014-12-17, 13:12
Thank you, Juliet.

I ran DelFix as requested, the log file is posted below. I have 2 additional questions for you:
1. Can you tell what was the specific problem in my computer?
2. Do you suggest that I regularly use all of the 9 highly recommended programs you mentioned at the bottom of your latest post?

Thanks again,


# DelFix v10.8 - Logfile created 17/12/2014 at 12:00:58
# Updated 29/07/2014 by Xplode
# Username : Opher - OPHER-L-8
# Operating System : Windows 8.1 Pro (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\Opher\Desktop\Addition.txt
Deleted : C:\Users\Opher\Desktop\Fixlog.txt
Deleted : C:\Users\Opher\Desktop\FRST.txt
Deleted : C:\Users\Opher\Desktop\FRST64.exe
Deleted : C:\Users\Opher\Downloads\AdwCleaner.exe
Deleted : C:\Users\Opher\Downloads\aswMBR.exe
Deleted : C:\Users\Opher\Downloads\MBR.dat
Deleted : C:\Users\Opher\Downloads\SecurityCheck.exe
Deleted : HKLM\SOFTWARE\AdwCleaner

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #62 [paint.net 4.0.4 | 12/01/2014 09:14:13]
Deleted : RP #63 [Removed Google Talk Plugin | 12/10/2014 08:31:57]
Deleted : RP #64 [Windows Update | 12/14/2014 11:39:23]
Deleted : RP #66 [Revo Uninstaller Pro's restore point - Google Chrome | 12/16/2014 16:11:21]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########

2014-12-17, 16:23
I have 2 additional questions for you:
1. Can you tell what was the specific problem in my computer?
2. Do you suggest that I regularly use all of the 9 highly recommended programs you mentioned at the bottom of your latest post?

You had a combination of infections, malware/adware related that cause interference of daily use.
It affected system files and browsers. To give it a specific name, sorry I can't

Those items listed in prevention tips are for you to decide which will work well on your system. In some cases people cannot use them all but can use some.
CryptoPrevent causes issues with some onboard security applications already installed so that you might have to experiment with.

2014-12-20, 16:29
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.