Not sure if I am really infected but certain sites are not working as they should and download speeds have been slow. Downloading the scan tools for this site took a long, long time. They are posted below.

Scan result of Farbar Recovery Scan Tool (FRST)
Ran by Alan (administrator) on DELL (03-10-2015 10:27:31)
Running from C:\Users\user\Desktop
Loaded Profiles: Alan (Available Profiles: Alan)
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Hi. :)

Could you please post the Addition.txt log created by the Farbar Recovery Scan Tool for my review please, it should be on the desktop. Also could you send the below to a zip file:


So I can in turn download it and analyse, since aswMBR is currently reporting your machine has a unknown MBR code. This is not a cause for concern at this stage and merely view it as myself erring on the side of caution for your good self etc.

Also there is evidence you may have been using the Tor Browser, if not aware this is actually not as secure as once was and has the potential to provide a conduit for malware to gain a foothold.

2015-10-04, 01:50
Thanks for taking a look at my problem. Here is what you requested.


2015-10-05, 01:06
Hi. :)

Thanks for taking a look at my problem.
You're welcome!

Here is what you requested.
Thanks, all good and no further action is required with regard to that since your machine is actually currently using a GUID Partition Table(GPT) and hence aswMBR flagged a unknown MBR(Master Boot Record) code.

Now with regard to the current issuies your machine is experiancing, there is actually no real evidence of anything malware related being the root cause so far. However I will not rule this out just yet, anyway lets proceed as follows shall we...

Java Advice:

There has been a recent severe explotation of this software. Even though this exploit has been reportedly fixed there is still a vulnerability with the software. Which basically means the software is in a constant state of what is known as a zero day type breach and will always be considered a security risk by the Anti-Malware security community.

The below is currently all that it is installed Java related:-

Java 8 Update 51
Java 8 Update 60

So it would be prudent to uninstall both verisons. If however though you opt to keep Java, merely leave Java 8 Update 60 installed as this is apparently the latest version. Then follow the advice below:-

How to Disable Java in your Web Browser (http://www.geekstogo.com/2600/how-to-disable-java-in-your-web-browser/)

Security Software Conflict Advise:

It appears at present you have both MCShield and Panda USB Vaccine installed and active in system memeory. Since both provide basically the same type of protection my friendly advise is choose to uninstall one of them. Also the presently installed McAfee Security Scan Plus apart from being also active in system memory is a waste of installation space in my humble opinion.

Uninstalling two of the above may improve matters performance wise.

Scan with Zoek:

Please download Zoek (http://download.bleepingcomputer.com/smeenk/zoek.exe) and save to to the desktop.

You will need to temp' disable your current installed Anti-Virus/Security software, how to do so can be read here (http://www.bleepingcomputer.com/forums/topic114351.html).

Right-click on zoek.exe and select Run as Administrator .
Once the GUI(graphical user interface) has loaded >> click on the More Options tab >> select Auto Clean only.
Ensure the option Scan All Users is selected >> now click on the Run Script tab.
Zoek will momentary close and a new GUI will appear and the scan will commence.
Please be patient as the scan may take some time depending on the specifications of your computer.
Once the scan is completed a log file named zoek-results.log will open via notepad, post the contents in your next reply.
If the sytem requires a reboot after the aforementioned scan, click on OK at the prompt(the log will appear after the reboot).
The zoek-results.log can also be found on your system drive.

Note: Do not forget to re-enable your Security software after running the above scan and below scans!

Scan with Panda Cloud Cleaner:

Please download Panda Cloud Cleaner (http://pandacloudcleaner.pandasecurity.com/facebook/) and save to your desktop.

Alternate downloads are here (http://acs.pandasoftware.com/pandacloudcleaner/installers/activescan/PandaCloudCleaner.exe) and here (http://www.majorgeeks.com/files/details/panda_cloud_cleaner.html).

Right-click on PandaCloudCleaner.exe and select Run as Administrator >> Next > >> >> Next >
Ensure Launch Panda Cloud Cleaner is selected >> Finish >> once the GUI(graphical user interface) appears >> click on Accept and Scan
Please be patient as the scan may take some time to complete depending on your system's specifications.
Once the scan has completed, if Scan finished with detections is denoted in the GUI do not take any action and or have Panda Cloud Cleaner clean absolutely anything!
Now within the GUI click on the > tab >> then on View Report >> a notepad file should now open called PCloudCleaner.txt
Save this to your desktop and post the contents in your next reply.
Then click on Back >> Exit

Note: When I give the all clear feel free to uninstall Panda Cloud Cleaner if you so wish.


When completed the above, please post back the following in the order asked for:

How is your computer performing now, any further symptoms and or problems encountered?
Zoek Log.
Panda Cloud Cleaner Log.

2015-10-05, 04:37
The computer has been running well. The sites that were not running are back to normal, mostly. Videos still load slower than before but at least they are loading.

The Panda cleaner ran but there was no option to save a log. I pressed the > button for all three and still no log option. This was the only thing I saw on the page that I thought might be relevant:


It did find stuff though. Here is a screenshot of the results page.


Here is the other log.

Hi. :)

The computer has been running well.
Good and as it stands with regards to the online scan all is fine and appears to be what is known as false postive detections. Now taking into account some of the elements Zoek removed/reset I think it prudent to err on the side of caution and run one more scan.

Afterwards post the requested log for my review and let myself know if any further issuies remaining please.

Scan with JRT:

Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/) to your desktop.

Alternate download is here (http://thisisudax.org/downloads/JRT.exe).

Note: Temp' disable/shut down your protection software now to avoid potential conflicts, how to do so can be read here (http://www.bleepingcomputer.com/forums/topic114351.html).

Right-click on on JRT.exe and select Run as Administrator to launch the application >> follow the on-screen prompt.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next reply.

Note: Reboot your machine and ensure all disabled security software is now enabled etc.

2015-10-05, 16:56
The requested log is below.

Aside from this, I noticed something else has changed. Recently I noticed my machine running hot, oftentimes while sitting there, not running any programs. Since implementing your fixes though, I have found that it is running cooler. I don't know exactly when this happened, but I think it was when I was uninstalling the programs you suggested. Is it possible those programs were making my machine run hot all this time?

Hi. :)

Is it possible those programs were making my machine run hot all this time?
Aye that is a entirely feasible scenario, congratulations your computer appears to be malware free!

Clean-Up with DelFix:

Please download DelFix (https://toolslib.net/downloads/viewdownload/2-delfix) to your desktop.

Right-click on delfix.exe and select Run as Administrator to launch the application.
Referring to the image below, select the three options denoted:


Then click on Run.
Once it has finished processing, a notepad file named DelFix.txt will open. Post the contents in your next reply for my review.
The log can also be located at the root of the system drive, C:\DelFix.txt.
After you have posted the aforementioned DelFix.txt, delete it and empty the Recycle Bin.

Note: The above application/overall process will flush old System Restore points and create a new clean one. It should also clean up and remove the vast majority of scanners used and logs created etc.

Any left over merely delete yourself and empty the Recycle Bin.

Now some advice for on-line safety:

The below are worth reading/bookmarking for future reference:

Computer Security - a short guide to staying safer online (http://www.malwareremoval.com/forum/viewtopic.php?f=4&t=54766)

So how did I get infected in the first place? (https://forums.spybot.info/showthread.php?279-So-how-did-I-get-infected-in-the-first-place)


Any questions? Feel free to ask, if not stay safe!

2015-10-06, 01:18
No questions. Thanks for all your help.

Acknowledged and you're most welcome! :)

