2016-11-27, 08:46
hi guy.. all my video format avi cannot be open anymore. All those video has been changed to format video 8488. How i can remove this malware from my PC. i have re-format my PC but my video still cannot be open and still in format 8488. Here i attach file picture. tq

here is the log your require.tq

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-11-2016
Ran by admin (administrator) on ADMIN-PC (27-11-2016 14:40:14)
Running from H:\driver
Loaded Profiles: admin (Available Profiles: admin)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

2016-11-28, 19:21

I don't know if I can fix this, I see errors related to different things then from what you report.


The below items need to be removed/uninstalled from your computer. They are adware/malware packed

WinThruster (HKLM-x32\...\WinThruster) (Version: 1.16.8 - Solvusoft Corporation) <==== ATTENTION
WinThruster (Version: 1.16.8 - Solvusoft Corporation) Hidden <==== ATTENTION
registry repair software


http://i.imgur.com/BY4dvz9.png AdwCleaner

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/dl/125/) and save the file to your Desktop.
In order to use AdwCleaner, you have to agree the Eula:
Right-click AdwCleaner.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Follow the prompts.
Click http://i.imgur.com/A49sxPr.png Scan.
Upon completion, click http://i.imgur.com/6cyn5v5.png Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
Click http://i.imgur.com/MqHawIb.png Clean.
Follow the prompts and allow your computer to reboot.
After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.

-- File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.


Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/)
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

please post

2016-12-01, 10:23
Hi bro.. Here is the result.. Please advice

# AdwCleaner v6.030 - Logfile created 01/12/2016 at 16:16:28
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-12-01.1 [Server]
# Operating System : Windows 7 Ultimate (X64)
# Username : USER - USER-PC
# Running from : C:\Users\USER\Downloads\AdwCleaner.exe
# Mode: Clean
# Support : hxxps://www.malwarebytes.com/support

***** [ Services ] *****

***** [ Folders ] *****

[#] Folder deleted on reboot: C:\ProgramData\Thunder Network
[#] Folder deleted on reboot: C:\ProgramData\thunder network
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Thunder Network
[#] Folder deleted on reboot: C:\ProgramData\Application Data\thunder network

***** [ Files ] *****

***** [ DLL ] *****

***** [ WMI ] *****

***** [ Shortcuts ] *****

***** [ Scheduled Tasks ] *****

***** [ Registry ] *****

[-] Key deleted: HKU\S-1-5-21-1053248485-957906623-3906508135-1000\Software\Ask.com.tmp
[#] Key deleted on reboot: HKCU\Software\Ask.com.tmp
[#] Key deleted on reboot: [x64] HKCU\Software\Ask.com.tmp
[-] Data restored: HKU\S-1-5-21-1053248485-957906623-3906508135-1000\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Value deleted: HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel [Homepage]

***** [ Web browsers ] *****


:: "Tracing" keys deleted
:: Winsock settings cleared


C:\AdwCleaner\AdwCleaner[C0].txt - [1694 Bytes] - [01/12/2016 16:16:28]
C:\AdwCleaner\AdwCleaner[S0].txt - [2047 Bytes] - [01/12/2016 16:10:14]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1840 Bytes] ##########

2016-12-01, 11:29
Hi ..guy please advice

Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 7 Ultimate x64
Ran by USER (Administrator) on Thu 12/01/2016 at 17:13:59.71

File System: 26

Successfully deleted: C:\ProgramData\thunder network (Folder)
Successfully deleted: C:\Users\Public\thunder network (Folder)
Successfully deleted: C:\Users\USER\AppData\Roaming\dg (Folder)
Successfully deleted: C:\Windows\system32\drivers\dgsafe.sys (File)
Successfully deleted: C:\Windows\SysWOW64\drivers\dgsafe.sys (File)
Successfully deleted: C:\Program Files (x86)\mydrivers (Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1AC8FC9W (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3OM3U2H2 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\965KM5N4 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NH93E5P5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\prefetch\APNSTUB.EXE-A2814457.pf (File)
Successfully deleted: C:\Windows\prefetch\DRIVERGENIUS.EXE-11E51084.pf (File)
Successfully deleted: C:\Windows\prefetch\DRIVERUPDATE.EXE-B13B4484.pf (File)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1AC8FC9W (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3OM3U2H2 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\965KM5N4 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NH93E5P5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\SysWOW64\dg597 (Folder)

Registry: 1

Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\dgpnpsev (Registry Key)

Scan was completed on Thu 12/01/2016 at 17:16:13.09
End of JRT log

2016-12-01, 12:23
Let's update Malwarebytes Anti-Malware

Open Malwarebytes Anti-Malware
On the Dashboard click on Update Now

Go to the Setting Tab

Under Setting go to Detection and Protection

Under PUP and PUM make sure both are set to show Treat Detections as Malware

Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked

Then on the Dashboard click on Scan

Make sure to select THREAT SCAN

Then click on Scan

Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
Upon completion of the scan (or after the reboot), click the History tab.
Click Application Logs, followed by the first Scan Log.
Click Export, followed by Copy to Clipboard. Paste the log in your next reply.


Please download Emsisoft Emergency Kit (http://dl.emsisoft.com/EmsisoftEmergencyKit.exe) and save it to your desktop.
Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop.

Leave all settings as they are and click the Extract button at the bottom.
A folder named EEK will be created in the root of the drive (usually c:\).

After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates.
Please click Yes so that it downloads the latest database updates.
When the update process is complete, a new button will appear in the lower-left corner that says Back. Click on this button to return to the Overview screen.
Click on Scan to be taken to the scan options.
If you are asked if you want the scanner to scan for Potentially Unwanted Programs, then click Yes.
Click on the Malware Scan button to start the scan.
When the scan is completed click the Quarantine selected objects button. Note, this option is only available if malicious objects were detected during the scan.
When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
Please save the log in Notepad on your desktop, and copy it to your next reply.
When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.

2016-12-02, 03:45
Malwarebytes Anti-Malware

Scan Date: 12/2/2016
Scan Time: 9:01 AM
Logfile: Malware results.txt
Administrator: Yes

Malware Database: v2016.12.02.01
Rootkit Database: v2016.11.20.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7
CPU: x64
File System: NTFS
User: USER

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 266078
Time Elapsed: 6 min, 21 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


2016-12-02, 03:46
Emsisoft Emergency Kit - Version 12.0
Last update: 12/2/2016 9:34:37 AM
User account: USER-PC\USER
Computer name: USER-PC
OS version: Windows 7x64

Scan settings:

Scan type: Quick Scan
Objects: Rootkits, Memory, Traces

Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Direct disk access: Off

Scan start: 12/2/2016 9:37:40 AM
C:\Users\USER\AppData\Local\Temp\APN-Stub detected: Application.Win32.WebToolbar (A) []

Scanned 61791
Found 1

Scan end: 12/2/2016 9:37:49 AM
Scan time: 0:00:09

C:\Users\USER\AppData\Local\Temp\APN-Stub Application.Win32.WebToolbar (A)

Deleted 1

2016-12-02, 13:05
Hows the computer now?

2016-12-03, 12:15
The problem still exists. I have movie, file and picture which are cannot play using any media and also picture file which cannot be view. All the file become file type 8488. Before this the file format of my movie file is AVI but after that it become file type 8488 which i suspect it cause by malware. Please advice my how i can restore back of my movie and file to originally format which . Here i attach the sample for your analyse.

2016-12-03, 15:36
Exterminate It! <== needs to be uninstalled

QQ??3.7 (HKU\S-1-5-21-1642817827-2581930201-3280809290-1000\...\QQPlayer) (Version: 3.7 - ????(??)????)
was the above installed lately and you think it may have caused the extensions to change?