Can't remove SShopDorOPP 4.7 extension from Chrome

2015-01-19, 14:40

I am a first time poster here.
My computer has been infected by SShopDorOPP , such extension will reappear in Chrome each time after being removed. Internet Explorer apparently has not been infected but is running slowly or freezing.

Before finding your website I had tried to uninstall unknown programs and to use some free malware removal tools.

Before posting, I did a backup of the registry and ran FRST and aswmbr as per your instructions
FRST freezes after opening, while trying to download updates, so I could not generate a log
Aswmbr freezes too, unless I do the Scan without downloading AVAST datafiles. The log is the following (you will see that it had been run already)

I thank you very much in advance for your help and am available to follow your instructions.

2015-01-19, 19:45
We need to uninstall Google Chrome, then reinstall.

Instructions on how to backup your Favourites/Bookmarks and other data can be found below.

http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png Backup Internet Explorer Favourites (http://www.wikihow.com/Back-Up-Favorites-in-Internet-Explorer)
http://2-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg Backup Firefox Bookmarks (https://support.mozilla.org/en-US/kb/export-firefox-bookmarks-to-backup-or-transfer)
http://i.imgur.com/U5NwUGc.png Backup Chrome Bookmarks (http://www.wikihow.com/Export-Bookmarks-from-Chrome)

Download Google Chrome from here https://www.google.com/chrome/browser/desktop/

Next please boot into safe mode and try to run FRST again. If it still freezes please disable your antivirus and try again

the above tutorial is for Windows 7 and Windows 8


Right-Click FRST.exe / FRST64.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Click Yes to the disclaimer.
Ensure the Addition.txt box is checked.
Click the Scan button and let the programme run.
Upon completion, click OK, then OK on the Addition.txt pop up screen.
Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

2015-01-20, 23:11
Thank you very much for your reply.

I followed your instructions. After reinstalling Chrome the Shopdrop extension is not shown any more.

Here are the contents of the two log files:
2015-01-20, 23:58
Please go to add/remove programs list and remove
YouTube Downloader Toolbar v4.6 <-- this application is malware /spyware loaded.

Go to add remove programs list, Look for your Java Icon, right click and open (may have to give permission first)
Look at the top tabs, click on update. At the bottom click on update now. It may ask you to run an installer.

Let it update to the latest version.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.


CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1430131261-1029319254-1685335828-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

http://i.imgur.com/BY4dvz9.png AdwCleaner

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) and save the file to your Desktop.
Right-Click AdwCleaner.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Follow the prompts.
Click Scan.
Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
Follow the prompts and allow your computer to reboot.
After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.

-- File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.


Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

please post

2015-01-21, 00:12
YouTube Downloader Toolbar v4.6 can't be uninstalled even if it shows up in the add and remove programs list, it says it does not find "youtubedownloaderToolbar.msi" at the right location (C:Users/User/AppData/Local/Temp/xxxx where xxx is a string of letters and numbers, but the directory is not there).
I searched C: and could not find a file named so anywhere.

In the list of programs there is "Java 7 Update 71" If I click on it, the only option is to uninstall it, not to open it or to update it.

Should I go on with the following instructions?

2015-01-21, 00:29
Yes, just continue the other items we can repair later.

2015-01-21, 14:31
I followed the instructions, even though - unfortunately - I am afraid I had already run two tools in the past days, so the logs do not contain information...

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 19-01-2015
Ran by User at 2015-01-21 12:16:00 Run:1
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Boot Mode: Normal


Content of fixlist:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1430131261-1029319254-1685335828-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

Processes closed successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKU\S-1-5-21-1430131261-1029319254-1685335828-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
EmptyTemp: => Removed 699.2 MB temporary data.

The system needed a reboot.

==== End of Fixlog 12:18:10 ====
# AdwCleaner v4.108 - Rapporto creato 21/01/2015 in 12:27:48
# Aggiornato 17/01/2015 di Xplode
# Database : 2015-01-18.1 [Live]
# Sistema operativo : Windows 7 Professional Service Pack 1 (32 bits)
# Nome utente : User - USER-PC
# In esecuzione da : C:\Users\User\Desktop\AdwCleaner.exe
# Opzione : Pulisci

***** [ Servizi ] *****

***** [ File / Cartelle ] *****

***** [ Compiti ] *****

***** [ Collegamenti ] *****

***** [ Registro ] *****

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17280

-\\ Google Chrome v39.0.2171.99


AdwCleaner[R0].txt - [752 octets] - [21/01/2015 12:25:37]
AdwCleaner[S0].txt - [671 octets] - [21/01/2015 12:27:48]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [730 octets] ##########
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Professional x86
Ran by User on 21/01/2015 at 13:27:33,63

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ Event Viewer Logs were cleared

Scan was completed on 21/01/2015 at 13:29:08,83
End of JRT log

2015-01-21, 16:06
Your doing fine.

Tell me what your computer is doing now?

2015-01-21, 16:09
I meant to add this and forgot, :)

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 6 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.

rkill.exe (http://download.bleepingcomputer.com/grinler/rkill.exe)
rkill.com (http://download.bleepingcomputer.com/grinler/rkill.com)
rkill.scr (http://download.bleepingcomputer.com/grinler/rkill.scr)
rkill.pif (http://download.bleepingcomputer.com/grinler/rkill.pif)
WiNlOgOn.exe (http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe)
uSeRiNiT.exe (http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe)


Please download RogueKiller and save it to your desktop.

You can check here (http://support.microsoft.com/kb/827218) if you're not sure if your computer is 32-bit or 64-bit

Download RogueKiller (http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe) to your desktop.

Quit all running programs.
For Windows XP, double-click to start.
For Vista,Windows 7/8, Right-click on the program and select Run as Administrator to start and when prompted allow it to run.
Read and accept the EULA (End User Licene Agreement)
Click Scan to scan the system.
When the scan completes Close the program > Don't Fix anything!
Don't run any other options, they're not all bad!!
Post back the report which should be located on your desktop.

Please post these 2 logs when finished.

2015-01-22, 15:12
Hi, Chrome seems to work normally after reinstalling.

I have run rkill.exe and Roguekiller, here are their logs:

Rkill 2.7.0 by Lawrence Abrams (Grinler)
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:

Program started at: 01/22/2015 01:39:28 PM in x86 mode.
Windows Version: Windows 7 Professional Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found: localhost

Program finished at: 01/22/2015 01:40:58 PM
Execution time: 0 hours(s), 1 minute(s), and 30 seconds(s)

RogueKiller V10.2.0.0 [Jan 19 2015] di Adlice Software
posta : http://www.adlice.com/contact/
Commenti : http://forum.adlice.com
Sito Web : http://www.adlice.com/softwares/roguekiller/
Discussione : http://www.adlice.com

Sistema Operativo : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Iniziato in : Modalità Normale
Utente : User [Amministratore]
Modalità : Scansione -- Data : 01/22/2015 13:47:24

¤¤¤ Processi : 1 ¤¤¤
[Proc.Svchost] svchost.exe(6968) -- [x] -> Eliminato [TermThr]

¤¤¤ Registro : 15 ¤¤¤
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\catchme (\??\C:\Users\User\AppData\Local\Temp\catchme.sys) -> Trovato
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\catchme (\??\C:\Users\User\AppData\Local\Temp\catchme.sys) -> Trovato
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\catchme (\??\C:\Users\User\AppData\Local\Temp\catchme.sys) -> Trovato
[PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=;https= -> Trovato
[PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=;https= -> Trovato
[PUM.HomePage] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : -> Trovato
[PUM.HomePage] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> Trovato
[PUM.HomePage] HKEY_USERS\S-1-5-21-1430131261-1029319254-1685335828-1000\Software\Microsoft\Internet Explorer\Main | Start Page : https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=https://mail.google.com/mail/?tab%3Dwm&scc=1&ltmpl=default&ltmplcache=2&emr=1#inbox -> Trovato
[PUM.HomePage] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> Trovato
[PUM.SearchPage] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> Trovato
[PUM.SearchPage] HKEY_USERS\S-1-5-21-1430131261-1029319254-1685335828-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> Trovato
[PUM.SearchPage] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> Trovato
[PUM.StartMenu] HKEY_USERS\S-1-5-21-1430131261-1029319254-1685335828-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trovato
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trovato
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Trovato

¤¤¤ Attività : 0 ¤¤¤

¤¤¤ Archivi : 0 ¤¤¤

¤¤¤ Archivio Hosts : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] localhost

¤¤¤ Antirootkit : 0 (Driver: Caricato) ¤¤¤

¤¤¤ Web Browser : 0 ¤¤¤

¤¤¤ Controllo MBR : ¤¤¤
+++++ PhysicalDrive0: ST31000528AS ATA Device +++++
--- User ---
[MBR] 2f2fe050d6fe7256558dd4f0fc36f3c5
[BSP] 10702be15b3c79edaafdb2f01b192c92 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206896 | Size: 236849 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 485275455 | Size: 716916 MB [Windows XP Bootstrap | Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Verbatim STORE N GO USB Device +++++
--- User ---
[MBR] ab785f90b7edfa4adef1ffcbc87d9a4f
[BSP] 70b7b59bf101cbdbb77c0ab521835606 : Unknown MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 32 | Size: 3848 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Richiesta non supportata. )


2015-01-22, 16:24
This is what concerns me
[PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=;https= -> Trovato -> Found
[PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=;https= -> Trovato->Found

Do you connect through a Proxy?

Tell me how your computer is acting now.

2015-01-22, 20:32
I dont' really know if I am connecting through a proxy...
At home I am using a pc, and a wifi router provided by the internet operator (the main telephone company in my country)

I don't notice anything strange in the computer, but I don't use it extensively, only some surfing

2015-01-22, 23:00
Well so far thats good news.

Let's try a different anti-malware scanner.

Emsisoft Anti-Malware

Download and save the Emsisoft Anti-Malware (http://www.emsisoft.com/en/software/antimalware/download/) setup program to your desktop. The download is fairly large, so please be patient while it downloads.
Once the file has been downloaded, close all open programs.
Double-click on the EmsisoftAntiMalwareSetup.exe icon to start the program. If Windows Smart Screen issues an alert, please allow it to run anyway.
If the setup program displays an alert about safe mode, please click on the Yes button to continue. You should now see a dialog asking what language you would like to use. Please select the language you wish to use and press the OK button.
You will eventually get to a screen asking the mode that you wish to use Emsisoft Anti-Malware.
Click on the Freeware mode link:
You will now be at a screen asking if you wish to join Emsisoft's Anti-Malware network. Read the descriptions and uncheck the options that you wish to use. When you are ready click on the Next button.
Allow it to update the definitions. Please be patient as it may take a few minutes for the updates to finish downloading.
When the updates are completed, click on the Clean computer now button. Emsisoft Anti-Malware will start to load its scanning engine and then display a screen asking what type of scan you would like to perform.
Please select the Deep Scan option and then click on the Scan button. The Deep Scan option will take the longest time to scan your computer, but will also be the most thorough. As you are here to clean infections, it is worth the wait to make sure your computer is properly scanned. Please don't run any other program while it is scanning.
When the scan has finished, the program will display the scan results that shows what infections where found.
Click on the View Report link, and double click the text file to open it. Please copy and paste the contents of this text file into your next reply (this file can be found at C:\Users\Tim\Documents\Anti-Malware\Reports)
Click on the Quarantine Selected Objects button, which will remove the infections and place them in the program's quarantine. You will now be at the last screen of the Emsisoft Anti-Malware setup program, which you can close. If Emsisoft prompts you to reboot your computer to finish the clean up process, please allow it to do so.

In your next reply, please include:

Emsisoft Anti-Malware log (located at C:\Users\Tim\Documents\Anti-Malware\Reports)

2015-01-24, 00:59
I did as you suggested and here is the log. (thank you for your support by the way)

Emsisoft Anti-Malware - Versione 9.0
Ultimo aggiornamento: 23/01/2015 22:03:38
Account utente: User-PC\User

Impostazioni scansione:

Tipo scansione: Completa
Oggetti: Rootkits, Memoria, Tracce, C:\, F:\

Rileva PUPs: On
Archivio scansioni: On
Scansione ADS: On
Filtro estensione dei file: Off
Caching avanzato: On
Accesso diretto al disco: Off

Scansione avviata: 23/01/2015 22:04:26
Value: HKEY_USERS\S-1-5-21-1430131261-1029319254-1685335828-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR rilevati: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-1430131261-1029319254-1685335828-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS rilevati: Setting.DisableRegistryTools (A)
F:\Lacie\Backup\Outlook\Outlookimap.alumni.sdabocconi.it-00000007.pst -> [Subject: Give we shall meet!][From: Gustavo Sterling] -> (body) -> (JAVASCRIPT 1) rilevati: Trojan.Script.34854 (B)
F:\Lacie\Backup\Outlook\Outlookimap.alumni.sdabocconi.it-00000007.pst -> [Subject: Give we shall meet!][From: Gustavo Sterling] -> (body) -> (JAVASCRIPT 2) rilevati: Trojan.Script.34880 (B)
F:\Lacie\Backup\Outlook\Outlookimap.alumni.sdabocconi.it-00000007.pst -> [Subject: Give we shall meet!][From: Gustavo Sterling] -> (body) -> (JAVASCRIPT-COMPILATION) rilevati: Trojan.Script.34854 (B)
F:\Lacie\Backup\Outlook\Outlookimap.alumni.sdabocconi.it-00000007.pst -> [Subject: Give we shall meet!][From: Gustavo Sterling] -> (body) -> (INFECTED_JS) rilevati: JS:Trojan.Script.FR (B)

Scansionati 289401
Rilevato 9

Fine scansione: 23/01/2015 23:53:08
Tempo scansione: 1:48:42

2015-01-24, 01:04
Click on the Quarantine Selected Objects button ?

Hows the computer now?

2015-01-25, 11:32
I did click on the Quarantine selected objects.
The computer is still looking good

2015-01-25, 12:41
Good deal

http://i.imgur.com/AFZxnZc.jpg DelFix

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix)
or from here http://www.bleepingcomputer.com/download/delfix/ and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools
Create registry backup

Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7, MVP
How Malware Spreads - How did I get infected? (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7, MVP
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams, MVP
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes, MVP
How to backup and restore your data using Cobian Backup (http://www.bleepingcomputer.com/tutorials/backup-and-restore-data-with-cobian-backup/) by YourHighness
Slow Computer/browser? It May Not Be Malware (http://www.bleepingcomputer.com/forums/t/87058/slow-computerbrowser-check-here-first;-it-may-not-be-malware/) by quietman7, MVP

The following programmes come highly recommended in the security community.

http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpgAdBlock (https://adblockplus.org/en/firefox) is a browser add-on that blocks annoying banners, pop-ups and video ads.
http://i.imgur.com/E8I37RF.pngCryptoPrevent (https://www.foolishit.com/) places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
http://i.imgur.com/EG85Vjt.png Malwarebytes Anti-Exploit (https://www.malwarebytes.org/antiexploit/) (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpgMalwarebytes Anti-Malware Premium (https://www.malwarebytes.org/) (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xjv4nhMJ.png.pagespeed.ic.A5YbWn1eDO.png NoScript (http://noscript.net/) is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
http://i.imgur.com/3O8r9Uq.png (http://www.sandboxie.com/) Sandboxie (http://www.sandboxie.com/) isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/DgW1XL2.png.pagespeed.ce.v1OlJl_ZAS.png Secuina PSI (http://secunia.com/vulnerability_scanning/personal/) will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xj1OLIec.png.pagespeed.ic.k6hhwopU0q.jpg SpywareBlaster (https://www.brightfort.com/spywareblaster.html) is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xJEP5iWI.png.pagespeed.ic.4tmM1lM7DQ.pngWeb of Trust (https://www.mywot.com/) (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

2015-01-26, 23:24
*I ran Delfix, it also gave me a log (see below)

*On the desktop I still have the tweaking.com_registry_backup_setup, should I keep it?

*There are some programs that I have installed in the past days while trying to remove the infection, should I remove them:
Emsisoft Anti-Malware
Tweaking.com - Registry Backup
ERUNT 1.1.j
Malwarebytes Anti-Malware

Thanks a lot!

# DelFix v10.8 - Logfile created 26/01/2015 at 22:18:27
# Updated 29/07/2014 by Xplode
# Username : User - USER-PC
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\_OTL
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\User\Desktop\Addition.txt
Deleted : C:\Users\User\Desktop\AdwCleaner.exe
Deleted : C:\Users\User\Desktop\aswmbr.exe
Deleted : C:\Users\User\Desktop\aswMBR.txt
Deleted : C:\Users\User\Desktop\Extras.Txt
Deleted : C:\Users\User\Desktop\Fixlog.txt
Deleted : C:\Users\User\Desktop\FRST.exe
Deleted : C:\Users\User\Desktop\FRST.txt
Deleted : C:\Users\User\Desktop\JRT.exe
Deleted : C:\Users\User\Desktop\JRT.txt
Deleted : C:\Users\User\Desktop\MBR.dat
Deleted : C:\Users\User\Desktop\OTL.Txt
Deleted : C:\Users\User\Desktop\OTL.exe
Deleted : C:\Users\User\Desktop\rkill.exe
Deleted : C:\Users\User\Desktop\Rkill.txt
Deleted : C:\Users\User\Desktop\RKreport_SCN_01222015_135609.log
Deleted : C:\Users\User\Desktop\RogueKiller.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

~ Creating registry backup ... OK

########## - EOF - ##########

2015-01-26, 23:41
We can delete Tweaking and create a restore point, or continue to use Tweaking.com as a back up.

To create a restore point

Open System by clicking the Start button , right-clicking Computer, and then clicking Properties.
In the left pane, click System protection. ...
Click the System Protection tab, and then click Create.
In the System Protection dialog box, type a description, and then click Create.

I would keep Malwarebytes Anti-Malware, update it regularly and use it as needed.

Not sure if Emsisoft Anti-Malware has an update feature to use it regularly. You can always download and use it again if needed.

ERUNT 1.1.j <-- you can delete.

2015-01-29, 22:48
Thank you very much

2015-01-29, 22:57
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.