PC infected with "provider" adware/malware - Please help

2015-03-20, 17:15
Hello, about a week or two ago I noticed that my browser (Chrome) was launching new tabs at unusual times (like when I click on a drop down box), and that I was seeing hyperlink ads more often. All of these Ads seem to be by "Provider". I have downloaded and run the Registry back up, FRST, and aswMBR programs as described in the top post on this page. Thank you in advance for any help you are able to render. -Rob Kelly

FRST log:
2015-03-20, 22:50
Running from C:\Users\Robert\Downloads

It's best we move Farbar's to desktop.

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.

Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


R2 PrivoxyService; C:\Program Files (x86)\Jelbrus Secure Web\privoxy.exe [371200 2015-03-09] (The Privoxy team - www.privoxy.org)
ProxyServer: [S-1-5-21-3142822200-3783541570-118272861-1000] =>
Task: {3A904008-F4A4-4F83-AA57-70E44BA72610} - System32\Tasks\Malware Cleaner => C:\Users\Robert\AppData\Roaming\214.tmp.exe <==== ATTENTION
Task: {634AF79B-63AB-4E24-B7CF-9B795BC367BD} - System32\Tasks\FreeFileViewerUpdateChecker => C:\Program Files (x86)\FreeFileViewer\FFVCheckForUpdates.exe [2011-03-11] (Bitberry Software) <==== ATTENTION
Task: {82F0912E-49D7-485B-9C04-A80149B5765A} - System32\Tasks\Jelbrus Secure Web Task => C:\Program Files (x86)\Jelbrus Secure Web\jswtask.exe [2015-03-09] (Jelbrus) <==== ATTENTION
00:07:05.072 File: C:\Users\Robert\AppData\Local\Temp\GPUpd54FE27251.exe
00:07:05.157 File: C:\Users\Robert\AppData\Local\Temp\GPUpd54FE47060.exe
00:07:06.826 File: C:\Users\Robert\AppData\Local\Temp\is1852162411\Setup-D502DD2B71B5.exe
R2 Live Malware Protection; C:\Windows\mlwps.exe [239104 2015-03-05] (AV Security Software) [File not signed] <==== ATTENTION
R2 PrivoxyService; C:\Program Files (x86)\Jelbrus Secure Web\privoxy.exe [371200 2015-03-09] (The Privoxy team - www.privoxy.org) [File not signed] <==== ATTENTION
2015-03-09 19:05 - 2015-03-18 21:50 - 00003282 _____ () C:\Windows\System32\Tasks\Jelbrus Secure Web Task
2015-03-09 19:05 - 2015-03-09 19:05 - 00000000 ____D () C:\Program Files (x86)\Jelbrus Secure Web
2015-03-05 22:19 - 2015-03-05 22:19 - 00239104 _____ (AV Security Software) C:\Windows\mlwps.exe
2015-03-05 22:19 - 2015-03-05 22:19 - 00003262 _____ () C:\Windows\System32\Tasks\Malware Cleaner
2015-03-05 22:19 - 2015-03-05 22:19 - 00000000 _____ () C:\Users\Robert\AppData\Roaming\214.tmp

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) and save the file to your Desktop.
Right-Click AdwCleaner.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Follow the prompts.
Click Scan.
Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
Follow the prompts and allow your computer to reboot.
After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.

-- File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.


please post

2015-03-21, 03:59
Hi Juliet,

Thanks for your reply and instructions. I moved and re-ran FRST without trouble and will post the log below. I had a minor problem with AdwCleaner. I downloaded AdwCleaner, moved it to my desktop, clicked scan, checked the log, left all the boxes checked, and clicked "clean." AdwCleaner got part way through its operation and then stopped - my PC told me it needed to be closed and that it would look for a solution. I wish I wrote down the exact text but I didn't. Anyway, after clicking "ok" I simply restarted AdwCleaner and did another scan. About half of the items that appeared in the first scan were gone. I clicked "clean" again and the program completed properly and generated the AdwCleaner[S0].txt report - which of course does not display all of the items from the first scan, but instead only the items that were still present for the second scan.


FRST log:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Robert at 2015-03-20 17:52:13 Run:1
Running from C:\Users\Robert\Desktop
Loaded Profiles: Robert & UpdatusUser (Available profiles: Robert & UpdatusUser)
Boot Mode: Normal

Content of fixlist:
R2 PrivoxyService; C:\Program Files (x86)\Jelbrus Secure Web\privoxy.exe [371200 2015-03-09] (The Privoxy team - www.privoxy.org)
ProxyServer: [S-1-5-21-3142822200-3783541570-118272861-1000] =>
Task: {3A904008-F4A4-4F83-AA57-70E44BA72610} - System32\Tasks\MALWARE CLEANER => C:\Users\Robert\AppData\Roaming\214.tmp.exe <==== ATTENTION
Task: {634AF79B-63AB-4E24-B7CF-9B795BC367BD} - System32\Tasks\FreeFileViewerUpdateChecker => C:\Program Files (x86)\FreeFileViewer\FFVCheckForUpdates.exe [2011-03-11] (Bitberry SOFTWARE) <==== ATTENTION
Task: {82F0912E-49D7-485B-9C04-A80149B5765A} - System32\Tasks\Jelbrus Secure Web Task => C:\Program Files (x86)\Jelbrus Secure Web\jswtask.exe [2015-03-09] (Jelbrus) <==== ATTENTION
00:07:05.072 File: C:\Users\Robert\AppData\Local\Temp\GPUpd54FE27251.exe
00:07:05.157 File: C:\Users\Robert\AppData\Local\Temp\GPUpd54FE47060.exe
00:07:06.826 File: C:\Users\Robert\AppData\Local\Temp\is1852162411\Setup-D502DD2B71B5.exe
R2 Live MALWARE PROTECTION; C:\Windows\mlwps.exe [239104 2015-03-05] (AV SECURITY SOFTWARE) [File not signed] <==== ATTENTION
R2 PrivoxyService; C:\Program Files (x86)\Jelbrus Secure Web\privoxy.exe [371200 2015-03-09] (The Privoxy team - www.privoxy.org) [File not signed] <==== ATTENTION
2015-03-09 19:05 - 2015-03-18 21:50 - 00003282 _____ () C:\Windows\System32\Tasks\Jelbrus Secure Web Task
2015-03-09 19:05 - 2015-03-09 19:05 - 00000000 ____D () C:\Program Files (x86)\Jelbrus Secure Web
2015-03-05 22:19 - 2015-03-05 22:19 - 00239104 _____ (AV SECURITY SOFTWARE) C:\Windows\mlwps.exe
2015-03-05 22:19 - 2015-03-05 22:19 - 00003262 _____ () C:\Windows\System32\Tasks\MALWARE CLEANER
2015-03-05 22:19 - 2015-03-05 22:19 - 00000000 _____ () C:\Users\Robert\AppData\Roaming\214.tmp

Restore point was successfully created.
Processes closed successfully.
PrivoxyService => Service deleted successfully.
HKU\S-1-5-21-3142822200-3783541570-118272861-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3A904008-F4A4-4F83-AA57-70E44BA72610}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3A904008-F4A4-4F83-AA57-70E44BA72610}" => Key deleted successfully.
C:\Windows\System32\Tasks\MALWARE CLEANER => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MALWARE CLEANER" => Key deleted successfully.
C:\Users\Robert\AppData\Local\Temp\GPUpd54FA7DB10.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\GPUpd54FE27240.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\GPUpd54FE27251.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\GPUpd54FE27282.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\GPUpd54FE47060.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\jre-8u40-windows-au.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\MSETUP4.EXE => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\tasks.dll => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\utt48B5.tmp.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\vlc-2.1.3-win32.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\_is310E.exe => Moved successfully.
C:\Users\Robert\AppData\Local\Temp\_isBAA7.exe => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{634AF79B-63AB-4E24-B7CF-9B795BC367BD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{634AF79B-63AB-4E24-B7CF-9B795BC367BD}" => Key deleted successfully.
C:\Windows\System32\Tasks\FreeFileViewerUpdateChecker => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FreeFileViewerUpdateChecker" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82F0912E-49D7-485B-9C04-A80149B5765A} => Key not found.
C:\Windows\System32\Tasks\Jelbrus Secure Web Task => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Jelbrus Secure Web Task" => Key deleted successfully.
"C:\Users\Robert\AppData\Local\Temp\GPUpd54FA7DB10.exe" => File/Directory not found.
00:07:05.072 File: C:\Users\Robert\AppData\Local\Temp\GPUpd54FE27251.exe => Error: No automatic fix found for this entry.
00:07:05.157 File: C:\Users\Robert\AppData\Local\Temp\GPUpd54FE47060.exe => Error: No automatic fix found for this entry.
00:07:06.826 File: C:\Users\Robert\AppData\Local\Temp\is1852162411\Setup-D502DD2B71B5.exe => Error: No automatic fix found for this entry.
Live MALWARE PROTECTION => Service deleted successfully.
PrivoxyService => Service not found.
"C:\Windows\System32\Tasks\Jelbrus Secure Web Task" => File/Directory not found.
C:\Program Files (x86)\Jelbrus Secure Web => Moved successfully.
C:\Windows\mlwps.exe => Moved successfully.
"C:\Windows\System32\Tasks\MALWARE CLEANER" => File/Directory not found.
C:\Users\Robert\AppData\Roaming\214.tmp => Moved successfully.
"C:\Windows\mlwps.exe" => File/Directory not found.
EmptyTemp: => Removed 2.5 GB temporary data.

The system needed a reboot.

==== End of Fixlog 17:54:37 ====

AdwCleaner log (2nd pass):
# AdwCleaner v4.112 - Logfile created 20/03/2015 at 21:37:45
# Updated 09/03/2015 by Xplode
# Database : 2015-03-15.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : Robert - ROBERT-PC
# Running from : C:\Users\Robert\Desktop\AdwCleaner.exe
# Option : Cleaning

***** [ Services ] *****

***** [ Files / Folders ] *****

***** [ Scheduled tasks ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKCU\Software\Bitberry
Key Deleted : HKLM\SOFTWARE\Freeze.com
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trusted Software Assistant_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - localhost;*.local

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17496

-\\ Google Chrome v41.0.2272.89


AdwCleaner[R0].txt - [2076 bytes] - [20/03/2015 17:59:13]
AdwCleaner[R1].txt - [1307 bytes] - [20/03/2015 21:34:04]
AdwCleaner[S0].txt - [1149 bytes] - [20/03/2015 21:29:16]
AdwCleaner[S1].txt - [1202 bytes] - [20/03/2015 21:37:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1261 bytes] ##########

2015-03-21, 12:51
Please download Malwarebytes Anti-Malware (http://downloads.malwarebytes.org/file/mbam) and save it to your desktop.

Double-click on the setup file (mbam-setup.exe), then click on Run to install.
Malwarebytes will automatically open to it's Dashboard. If you have never run this version, you should see a red note at the top indicating "A scan has never been run on your system"
Click on Update Now to download the current database definitions, then click the Scan Now >> button.
If you have run this version before, you should see a green note at the top indicating "Your system is fully protected".
You will be prompted to update Malwarebytes...click on the Update Now button.
The THREAT SCAN will automatically begin.
When the scan has completed, the results will be displayed. Click on Quarantine All, then click on Apply Actions.
To complete any actions taken you will be prompted to restart your computer...click on Yes. Failure to reboot normally will prevent Malwarebytes from removing all the malware.
After rebooting the computer, copy and paste the mbam.log in your next reply.

To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 1)

Open Malwarebytes Anti-Malware.
Click the History Tab at the top and select Application Logs.
Select (check) the box next to Scan Log. Choose the most current scan.
Click the View button.
Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.

To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 2)

Open Malwarebytes Anti-Malware.
Click the Scan Tab at the top.
Click the View detailed log link on the right.
Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.

Logs are named by the date of scan in the following format: mbam-log-yyyy-mm-dd and automatically saved to the following locations:
-- XP: C:\Documents and Settings\<Username>\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
-- Vista, Windows 7/8: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd


What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.

Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

Please run a free online scan with the ESET Online Scanner

US Link: http://www.eset.com/us/online-scanner/
EU Link: http://www.eset.eu/online-scanner/

Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.

Turn off the real time scanner of any existing antivirus program while performing the online scan.
Click the blue Run ESET Online Scanner button
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
Click on Advanced Settings
Make sure that the option Remove found threats is unticked.
Ensure these options are ticked

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

Under "Current Scan Targets" > click "change" and ensure all your drives are selected
Click Start
Wait for the scan to finish
When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
Save that text file on your desktop. Attach the log as a reply to your next reply..
Close the ESET online scan, and let me know how things are now.


please post
Malwarebytes Anti-Malware log
Eset log

Also tell me how the computer is doing now.

2015-03-22, 00:47
Here is th eMalwarebytes log. NO threats found so no quarantine.

PC is running well - ad pages no longer appear when clicking buttons, webpages no longer have hyperlink ads.

I will do the next step later tonight.

Malwarebytes Anti-Malware

Scan Date: 3/21/2015
Scan Time: 6:31:15 PM
Administrator: Yes

Malware Database: v2015.03.21.06
Rootkit Database: v2015.02.25.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Robert

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 387271
Time Elapsed: 5 min, 29 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


2015-03-22, 05:51
Tried to access ESET, first with Chrome, then with Iinternet Explorer 11. The link took me to this page:


Clicking the "Run ESET online scanner" link took me to a nearly blank page - the words "Online Scanner" appeared at the top, but nothing else happened. Do I need to up date Chrome or IE or Java or something?


2015-03-22, 12:28
I have a feeling your antivirus is interfering

Please open the AVG Control Center, by right clicking on the AVG icon on task bar.

Click on Open AVG User Interface.
On the Menu Bar, click on Tools
Click Advanced Settings
In the new screen which opens, scroll down to Temporarily disable AVG protection. Click on it to highlight it.
In the right hand pane, tick the box for Temporarily disable AVG protection
Click Apply
In the next screen which opens, select 15 minutes from the drop down menu, then click the Disable real time protection button.
Click OK

Tick Enable on the main GUI interface to Re-enable. You may also need to click Fix (enable becomes Fix if all components do not start)

See if you follow this to disable it long enough now to run the scan. Don't do any browsing while the antivirus is disabled.

2015-03-22, 12:35
Let's try downloading the installer and running it this way.

Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

Please download ESET Online Scan (http://download.eset.com/special/eos/esetsmartinstaller_enu.exe) and save the file to your Desktop.
Temporarily disable your anti-virus software. For instructions, please refer to the following link (http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/).
Double-click esetsmartinstaller_enu.exe to run the programme.
Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
Agree to the Terms of Use once more and click Start. Allow components to download.
Place a checkmark next to Enable detection of potentially unwanted applications.
Click Advanced settings. Place a checkmark next to:

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

Ensure Remove found threats is unchecked.
Click Start.
Wait for the scan to finish. Please be patient as this can take some time.
Upon completion, click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png. If no threats were found, skip the next two bullet points.
Click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png and save the file to your Desktop, naming it something such as "MyEsetScan".
Push the Back button.
Place a checkmark next to http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png and click http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png.
Re-enable your anti-virus software.
Copy the contents of the log and paste in your next reply.

2015-03-22, 22:18
Hi Juliet,

I had already disabled AVG (and I had set the duration as "until restart"), so that wasn't the issue.

The second link to ESET worked just fine. I moved the installer file from Downloads to my desktop and ran it as administrator, which brings me to the "step 1 of 4... Computer Scan Settings" page, where I checked and unchecked boxes as requested. When I click "start" the scanner displays "step 2 of 4... Initializing... downloading virus signature database." Unfortunately the progress bar does not progress, and eventually the process time's out, displaying "Can not get update. Is proxy configured?"

On the previous screen, the one labelled "step 1 of 4... Computer Scan Settings," there is a box named "use custom proxy settings" with a link to "configure." This box is unchecked, which I assume means that the proxy settings should be determined automatically. In any event, if you have any suggestions regarding the configuration of "cusotm proxy settings" I am happy to try them, but unfortunately I don't know how to do that myself.

Also, after running into this problem I uninstalled AVG and tried again, with the same results.

Thanks, Rob

2015-03-22, 23:10
Well, I'll chalk this up to "the ghost in the machine"...

Having nothing else to try, I tried running ESET a fourht and fifth time and it worked...the program connected and completed. Here it the Scan file:

C:\FRST\Quarantine\C\Program Files (x86)\Jelbrus Secure Web\jswchromium.exe Win32/Techsnab.D potentially unwanted application
C:\FRST\Quarantine\C\Program Files (x86)\Jelbrus Secure Web\jswchromium64.exe Win64/Techsnab.A potentially unwanted application
C:\FRST\Quarantine\C\Program Files (x86)\Jelbrus Secure Web\jsweb.dll Win32/Techsnab.D potentially unwanted application
C:\FRST\Quarantine\C\Program Files (x86)\Jelbrus Secure Web\jsweb64.dll Win64/Techsnab.A potentially unwanted application
C:\FRST\Quarantine\C\Program Files (x86)\Jelbrus Secure Web\jswff.exe a variant of Win32/Techsnab.C potentially unwanted application

2015-03-22, 23:13
Also, I wanted to ask you for an antivirus suggestion. Do you have a preffered program, or should I reinstall AVG?

Thanks, Rob

Thanks, Rob

2015-03-23, 01:58
Also, I wanted to ask you for an antivirus suggestion. Do you have a preffered program, or should I reinstall AVG?

Thanks, Rob

The Eset scan shows me good results. Items found are in FRST quarantine and thats good news!

I personally use MSE because of ease of use and low resource involvement.

As for which free versus paid for Antivirus I have to leave this up to you but, I've always stayed with a free version, that use less resources and consumes less time in updating. This is my personal opinion and also with free versions of Antivirus, firewall is not included.


Ready to remove tools and quarantine folders?

2015-03-23, 04:55
Hi Juliet,

I think the source of my problem accessing ESET was Malwarebytes. I have disabled it now.

I am ready to remove tools and quarantine folder.


2015-03-23, 11:20
Be sure to re-enable your security programs now.

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix)
or from here http://www.bleepingcomputer.com/download/delfix/ and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools
Create registry backup

Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


Want to help others? Join the ClassRoom (http://forums.whatthetech.com/What_the_Tech_Classroom_t80368.html) and learn how.

2015-03-24, 03:01
Hi Juliet,

I downloaed DelFix, moved it to my desktop, and ran it. The log is below.

Thank you for the links.


# DelFix v10.8 - Logfile created 23/03/2015 at 19:00:47
# Updated 29/07/2014 by Xplode
# Username : Robert - ROBERT-PC
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\Robert\Desktop\AdwCleaner.exe
Deleted : C:\Users\Robert\Desktop\esetsmartinstaller_enu.exe
Deleted : C:\Users\Robert\Desktop\Fixlog.txt
Deleted : C:\Users\Robert\Desktop\FRST64.exe
Deleted : C:\Users\Robert\Downloads\Addition.txt
Deleted : C:\Users\Robert\Downloads\aswMBR log.txt
Deleted : C:\Users\Robert\Downloads\aswMBR.exe
Deleted : C:\Users\Robert\Downloads\FRST.txt
Deleted : C:\Users\Robert\Downloads\MBR.dat
Deleted : C:\Users\Robert\Downloads\mkvtomp4_setup [1].exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

~ Creating registry backup ... OK

########## - EOF - ##########

2015-03-24, 11:16
We're glad to help, safe surfing :)

2015-03-27, 16:22
Since this issue appears resolved ... this Topic is closed.