Good Evening,
I am experiencing browser redirect to Get Private and have to click thru to get where I want to go. Also it is continuing to degrade and I have pop ups coming up every 4th-5th website visited. I recently had help removing malware here and it looks like it is back and getting worse. HDD is running almost constantly, connections time because they are taking so long to load.

Here are the logs:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-08-2015 01
Ran by CIDER (administrator) on CIDER-PC (04-08-2015 19:34:39)
Running from C:\Users\CIDER\Desktop
Loaded Profiles: CIDER (Available Profiles: CIDER)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

Additional scan result of Farbar Recovery Scan Tool (x86) Version:02-08-2015 01
Ran by CIDER (2015-08-04 19:35:26)
Running from C:\Users\CIDER\Desktop
Boot Mode: Normal

Thanks in advance for anything you can help me with!!


Hi Chuck, you have a bit going on, malware set a proxy server and also infected your hosts file, let do this

Open notepad , Go to Start --> All Programs --> Accessories --> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please

ProxyEnable: [S-1-5-21-80477484-922998690-3827157042-1001] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-80477484-922998690-3827157042-1001] =>
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-80477484-922998690-3827157042-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM\...\Chrome\Extension: - No Path Or update_url value
R2 PrivoxyService; C:\Program Files\Alfasistem Memory\privoxy.exe [371200 2015-08-02] (The Privoxy team - www.privoxy.org) [File not signed] <==== ATTENTION
2015-07-09 21:51 - 2015-08-02 14:44 - 00000000 ____D C:\Program Files\Alfasistem Memory
2015-07-29 21:27 - 2009-07-14 12:04 - 00449982 ____R C:\Windows\system32\Drivers\etc\hosts.20150802-094629.backup
2015-07-15 19:51 - 2009-07-14 12:04 - 00449982 ____R C:\Windows\system32\Drivers\etc\hosts.20150729-212753.backup
2015-07-15 19:49 - 2009-07-14 12:04 - 00449982 ____R C:\Windows\system32\Drivers\etc\hosts.20150715-195132.backup
2015-07-08 19:10 - 2009-07-14 12:04 - 00449982 ____R C:\Windows\system32\Drivers\etc\hosts.20150715-194916.backup
Task: {0A50A229-1E69-4A7E-AE2E-A1A7274FC22D} - System32\Tasks\Alfasistem Memory Job => C:\Program Files\Alfasistem Memory\ tmjob.exe
Task: {1D619927-C78A-4A46-A707-4870A844671F} - System32\Tasks\Windows Defrag => C:\Users\CIDER\AppData\Roaming\Updater\winupd.exe <==== ATTENTION
CMD: ipconfig /flushdns

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


-AdwCleaner-by Xplode

Click on this link to download : ADWCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) TO YOUR DESKTOP
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers

Do not click on any links in the top Advertisment.

http://i24.photobucket.com/albums/c30/ken545/AdwCleaner4.201_zpsxrbk2llq.jpg (http://s24.photobucket.com/user/ken545/media/AdwCleaner4.201_zpsxrbk2llq.jpg.html)

Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Scan.
After the scan is complete click on "Clean"
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next reply.
You can find the logfile at C:\AdwCleaner[S1].txt as well.


http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) TO YOUR DESKTOP

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.


Download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) TO YOUR DESKTOP

Windows XP : [B]Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"

http://i24.photobucket.com/albums/c30/ken545/MBAM_zpsr1ew7hep.png (http://s24.photobucket.com/user/ken545/media/MBAM_zpsr1ew7hep.png.html)

On the Dashboard click on Update Now
Go to the Setting Tab
Under Setting go to Detection and Protection
Under PUP and PUM make sure both are set to show Treat Detections as Malware
Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
Then on the Dashboard click on Scan
Make sure to select THREAT SCAN
Then click on Scan
When the scan is finished and the log pops up...select Copy to Clipboard
Please paste the log back into this thread for review
Exit Malwarebytes

2015-08-06, 12:55
So I ran the ADW cleaner with no issue , the JRT is loaded and running but has been stuck on "Checking Shortcuts for about 6 hrs now so I don't want to interrupt it, but it seems like a long time, I have already deleted and reinstalled (the last one was stuck there for about 4 hours). I downloaded and installed Malware bites and it tells me that my free trial has ended. That's where I'm at for now any advice on the JRT?

2015-08-06, 13:49
Good Morning

Did you run the fix with FRST, if not run it, if so post the log

Post the log from AdwCleaner

Forget about JWR for the time being

Uninstall and reinstall Malwarebytes and post the log after the scan

Use this procedure to remove Malwarebytes from your computer

Download and run their removal utility HERE (http://downloads.malwarebytes.org/file/mbam_clean)
It will ask to restart your computer (please allow it to).
Then download Malwarebytes' Anti-Malware Version 2.1.8 from HERE (http://www.malwarebytes.org/mbam-download.php)
On the Dashboard click on Update Now
Go to the Setting Tab
Under Setting go to Detection and Protection
Under PUP and PUM make sure both are set to show Threat Detections as Malware
Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
Then on the Dashboard click on Scan
Make sure to select THREAT SCAN
Then click on Scan
When the scan is finished and the log pops up...select Copy to Clipboard
Please paste the log back into this thread for review
Exit Malwarebytes

2015-08-07, 01:45
Here are the logs requested:

Fix result of Farbar Recovery Scan Tool (x86) Version:02-08-2015 01
Ran by CIDER (2015-08-06 08:22:49) Run:3
Running from C:\Users\CIDER\Desktop
Loaded Profiles: CIDER (Available Profiles: CIDER)
Boot Mode: Normal


fixlist content:
ProxyEnable: [S-1-5-21-80477484-922998690-3827157042-1001] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-80477484-922998690-3827157042-1001] =>
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-80477484-922998690-3827157042-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
2015-08-07, 04:55
Good. Open up FRST, checkmark Additions, run a new scan and post both the FRST and Additions logs please

2015-08-07, 10:19
Here are the frst logs, I do have to say that I don't see the pop ups or redirects anymore, my system is now "Not Responding" a lot with MS based programs. Also now every time I log into this forum I am getting a text only version of it.

2015-08-07, 14:34

Actually your log is not looking to bad. As far as Spybot website, part of it is down and there working on it. Sometimes the malware installed can cause some issues when being removed. Try just rebooting your computer a few times and see if it helps those programs. What programs specifically ?

2015-08-08, 01:06
Good Morning,

Ran a Checkdisk and rebooted and its not doing it any more, it was MS Office (all) and IE that were hanging up. Everything seems to be working good and the HDD is not working constantly anymore.

2015-08-08, 02:41
Wonderful, that's nice to hear :bigthumb:

Double click on AdwCleaner.exe to run the tool again.

Click on the Uninstall button.
Click Yes when asked are you sure you want to uninstall.
Both AdwCleaner.exe, its folder and all logs will be removed.


Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix) and save the file to your Desktop.

http://i24.photobucket.com/albums/c30/ken545/DelFix_zps139e2ea1.jpg (http://s24.photobucket.com/user/ken545/media/DelFix_zps139e2ea1.jpg.html)

Windows XP Double Click DelFix.exe to run the program.
Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR
Checkmark " Remove Disinfection Tools"
Click the Run button

This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually


How did I get infected in the first place ?

WhattheTech (http://forums.whatthetech.com/index.php?showtopic=97186&quot;)
Grinler BleepingComputer (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)

Safe Surfn

2015-08-08, 04:28
Hey thanks for everything!! My system seems to be good now, not seeing any of the old issues!!

Best Regards,


2015-08-08, 12:31
Your very welcome

Take care my friend

Ken :)