On October 4th 2018 I tried to get a youtube video which I was not able to play in my country, I saw several messages suggesting the replacement of "tube" with "Pak" and nothing about anyone having any problems with this fix. So I decided to go ahead, which sent me down the rabbit hole of links. I didn't complete this process but at one point I believe I saved a program and allowed something to access/change my windows (which I would never usually do!) I had a change of heart and uninstalled (using the program's uninstall feature) the proxy program from my hard drive almost immediately without running it, and everything seemed ok. The next morning however, my Google Chrome did not recognise my internet connection and my Anti Virus programs were disabled. I didn't put these things together right away but enabled my anti-virus program. Then I restarted my machine. After booting back up, it was extremely slow, and Google Chrome no longer loads or I get a strange window (cannot link in this message) which I have never seen before, it has google chrome in top left corner and Chrome in bottom left, an avatar in the center with my name underneath, and two buttons on the bottom right stating to browse as guest, and add person. I didn't click on anything. I ran two anti-virus scans-which found nothing, cleared my junk folders and still the same window pops up when trying to access Google Chrome (every now and then I saw a notification pop up which says it's from YouPak.com, but this does not appear in my notification list). Unfortunately I ran a system restore prior to seeing your site, which took about 1hr but was successful. Unfortunately this also didn't fix my pc, I'm still getting the weird Google Chrome window and everything is super slow. I ran a Malwarebytes scan and quarantined a bunch of items, restarted my machine, and everything is the same.

I have read "Before you post" and tried to run the recommended scans. Below are Farbar Recovery Scan Tool (which was to big to attach even without the the buttons suggested to be switched off) and Addition files (attached). Unfortunately the aswMBR will not completely scan and results in a blue screen and my pc restarts.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24.10.2018
Ran by Sandy (administrator) on PEGICORNHOME (06-11-2018 14:14:35)
Running from C:\Program Files
Loaded Profiles: Sandy (Available Profiles: Sandy)
Platform: Windows 10 Home Version 1803 17134.345 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24.10.2018
Ran by Sandy (06-11-2018 13:13:08)
Running from C:\Program Files
Windows 10 Home Version 1803 17134.345 (X64) (2018-06-10 21:12:20)
Boot Mode: Normal

2018-11-07, 17:59
I have found maybe 3/4 different antivirus apps on your computer.
I think, mostly remnants of 2/3 but I need to know if I'm right.

Avast <==main antivirus

Avira Free Antivirus <==remnants?
Avg Free Antivirus <==remnants?
C:\Program Files (x86)\TotalAV <==remnants?
we'll need to remove those.


Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::

HKLM-x32\...\Run: [] => [X]
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx <not found>
Task: {152F76AC-A967-454F-A4FD-25A963105ED8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {39BEC352-AD65-4265-97A6-DA79AD1F5EC5} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {3DC103F8-107E-411B-93F2-F9C57A473029} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {53AB3FD0-EFBE-43A3-B4DA-CE82A1179A75} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {5B67092F-A897-475C-9840-893DA2EF1FEE} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {5BFCB5C7-626C-4360-B3A2-9D1F5370833C} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {7BB25B29-9FB8-485F-84D1-4BEAEEE9C48D} - System32\Tasks\{D95C9BA5-36DA-42C3-BB94-3086F2247E6D} => C:\WINDOWS\system32\pcalua.exe -a C:\Users\Sandy\AppData\Local\Temp\Temp1_USBFormat.zip\usb_format.exe <==== ATTENTION
Task: {8325F6A8-6E0A-4A96-A9DB-0CFF4EBDE1A1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {859A94B1-F50D-4285-A5C6-CFFDAA0DB224} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {960BB529-728B-4BBA-BE2F-47CB10DF2C05} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {98204AC4-6C4E-44EA-B9F9-21C66928CDAA} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {C038AC15-8417-46DF-9536-C295EB251C21} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {C11B64BC-4EF8-40FA-9A29-72950B117D20} - \WPD\SqmUpload_S-1-5-21-1498807687-2397506290-3852286947-1001 -> No File <==== ATTENTION
Task: {D5EF6CFC-D658-4F53-A05C-B5DF8388EA2B} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {D946A03A-53CF-445D-BAA3-0CC63451B719} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
ShortcutWithArgument: C:\Users\Sandy\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\1431596800.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -contentTile -formatVersion 0x00000003 -pinnedTimeLow 0x79cc2de3 -pinnedTimeHigh 0x01cf2b95 -securityFlags 0x00000000 -tileType 0x00000000 -url 0x00000046 hxxp://tvlistings.zap2it.com/my-faves?aid=zap2it&loginRedirectReq=true
ShortcutWithArgument: C:\Users\Sandy\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\21332297470.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -contentTile -formatVersion 0x00000003 -pinnedTimeLow 0xa5485429 -pinnedTimeHigh 0x01cf2b95 -securityFlags 0x00000000 -tileType 0x00000000 -url 0x00000051 hxxp://www.fortedmontonpark.ca/plan-your-trip/attractions/fort-edmonton-park-map/

Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.


http://i.imgur.com/zcMPezJ.pngAdwCleaner - Fix Mode

Download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/dl/125/) and move it to your Desktop
Right-click on AdwCleaner.exe and select http://i.imgur.com/Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
Accept the EULA (I accept), then click on Scan
Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button. This will kill all the active processes
Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply


Download the right version of RogueKiller (http://www.adlice.com/download/roguekiller/#download) for your Windows version (32 or 64-bit)
Once done, move the executable file to your Desktop, right-click on it and select http://i.imgur.com/Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
Wait for the scan to complete
On completion, the results will be displayed
Check every single entry (threat found), and click on the Remove Selected button
On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
This will open the report in Notepad. Copy/paste its content in your next reply

Your next reply(ies) should therefore contain:

Copy/pasted Fixlog.txt
Copy/pasted AdwCleaner clean log
Copy/pasted RogueKiller clean log

2018-11-08, 00:30
Hi Juliet,
Thanks for the quick response. I think the format of Roguekiller may have changed because some of the directions of what and where to click didn't match with the actual downloaded program but I have added the resulting report. Please see resulting logs below:

Fix result of Farbar Recovery Scan Tool (x64) Version: 07.11.2018
Ran by Sandy (07-11-2018 12:20:21) Run:1
Running from C:\Program Files
Loaded Profiles: Sandy (Available Profiles: Sandy)
Boot Mode: Normal

fixlist content:
HKLM-x32\...\Run: [] => [X]
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx <not found>
Task: {152F76AC-A967-454F-A4FD-25A963105ED8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {39BEC352-AD65-4265-97A6-DA79AD1F5EC5} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {3DC103F8-107E-411B-93F2-F9C57A473029} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {53AB3FD0-EFBE-43A3-B4DA-CE82A1179A75} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {5B67092F-A897-475C-9840-893DA2EF1FEE} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {5BFCB5C7-626C-4360-B3A2-9D1F5370833C} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {7BB25B29-9FB8-485F-84D1-4BEAEEE9C48D} - System32\Tasks\{D95C9BA5-36DA-42C3-BB94-3086F2247E6D} => C:\WINDOWS\system32\pcalua.exe -a C:\Users\Sandy\AppData\Local\Temp\Temp1_USBFormat.zip\usb_format.exe <==== ATTENTION
Task: {8325F6A8-6E0A-4A96-A9DB-0CFF4EBDE1A1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {859A94B1-F50D-4285-A5C6-CFFDAA0DB224} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {960BB529-728B-4BBA-BE2F-47CB10DF2C05} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {98204AC4-6C4E-44EA-B9F9-21C66928CDAA} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {C038AC15-8417-46DF-9536-C295EB251C21} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {C11B64BC-4EF8-40FA-9A29-72950B117D20} - \WPD\SqmUpload_S-1-5-21-1498807687-2397506290-3852286947-1001 -> No File <==== ATTENTION
Task: {D5EF6CFC-D658-4F53-A05C-B5DF8388EA2B} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {D946A03A-53CF-445D-BAA3-0CC63451B719} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
ShortcutWithArgument: C:\Users\Sandy\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\1431596800.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -contentTile -formatVersion 0x00000003 -pinnedTimeLow 0x79cc2de3 -pinnedTimeHigh 0x01cf2b95 -securityFlags 0x00000000 -tileType 0x00000000 -url 0x00000046 hxxp://tvlistings.zap2it.com/my-faves?aid=zap2it&loginRedirectReq=true
ShortcutWithArgument: C:\Users\Sandy\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\21332297470.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -contentTile -formatVersion 0x00000003 -pinnedTimeLow 0xa5485429 -pinnedTimeHigh 0x01cf2b95 -securityFlags 0x00000000 -tileType 0x00000000 -url 0x00000051 hxxp://www.fortedmontonpark.ca/plan-your-trip/attractions/fort-edmonton-park-map/


Processes closed successfully.
Restore point was successfully created.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\" => removed successfully
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{152F76AC-A967-454F-A4FD-25A963105ED8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{152F76AC-A967-454F-A4FD-25A963105ED8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{39BEC352-AD65-4265-97A6-DA79AD1F5EC5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{39BEC352-AD65-4265-97A6-DA79AD1F5EC5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3DC103F8-107E-411B-93F2-F9C57A473029}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DC103F8-107E-411B-93F2-F9C57A473029}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{53AB3FD0-EFBE-43A3-B4DA-CE82A1179A75}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53AB3FD0-EFBE-43A3-B4DA-CE82A1179A75}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5B67092F-A897-475C-9840-893DA2EF1FEE}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B67092F-A897-475C-9840-893DA2EF1FEE}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5BFCB5C7-626C-4360-B3A2-9D1F5370833C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5BFCB5C7-626C-4360-B3A2-9D1F5370833C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7BB25B29-9FB8-485F-84D1-4BEAEEE9C48D}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7BB25B29-9FB8-485F-84D1-4BEAEEE9C48D}" => removed successfully
C:\WINDOWS\System32\Tasks\{D95C9BA5-36DA-42C3-BB94-3086F2247E6D} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D95C9BA5-36DA-42C3-BB94-3086F2247E6D}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8325F6A8-6E0A-4A96-A9DB-0CFF4EBDE1A1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8325F6A8-6E0A-4A96-A9DB-0CFF4EBDE1A1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{859A94B1-F50D-4285-A5C6-CFFDAA0DB224}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{859A94B1-F50D-4285-A5C6-CFFDAA0DB224}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{960BB529-728B-4BBA-BE2F-47CB10DF2C05}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{960BB529-728B-4BBA-BE2F-47CB10DF2C05}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{98204AC4-6C4E-44EA-B9F9-21C66928CDAA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{98204AC4-6C4E-44EA-B9F9-21C66928CDAA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C038AC15-8417-46DF-9536-C295EB251C21}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C038AC15-8417-46DF-9536-C295EB251C21}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C11B64BC-4EF8-40FA-9A29-72950B117D20}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C11B64BC-4EF8-40FA-9A29-72950B117D20}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-1498807687-2397506290-3852286947-1001" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D5EF6CFC-D658-4F53-A05C-B5DF8388EA2B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D5EF6CFC-D658-4F53-A05C-B5DF8388EA2B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D946A03A-53CF-445D-BAA3-0CC63451B719}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D946A03A-53CF-445D-BAA3-0CC63451B719}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
C:\Users\Sandy\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\1431596800.lnk => Shortcut argument removed successfully
C:\Users\Sandy\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\21332297470.lnk => Shortcut argument removed successfully

=========== "C:\Windows\Temp\*.*" ==========

C:\Windows\Temp\chrome_installer.log => moved successfully
C:\Windows\Temp\lpksetup-20181104-214846-0.log => moved successfully
C:\Windows\Temp\lpksetup-20181105-145938-0.log => moved successfully
C:\Windows\Temp\lpksetup-20181105-205854-0.log => moved successfully
C:\Windows\Temp\lpksetup-20181105-235645-0.log => moved successfully
C:\Windows\Temp\lpksetup-20181106-044746-0.log => moved successfully
C:\Windows\Temp\lpksetup-20181106-131817-0.log => moved successfully
C:\Windows\Temp\lpksetup-20181106-132734-0.log => moved successfully
C:\Windows\Temp\MSI1f162.LOG => moved successfully
C:\Windows\Temp\MSI8f627.LOG => moved successfully

========= End -> "C:\Windows\Temp\*.*" ========

=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 161295284 B
Java, Flash, Steam htmlcache => 1144 B
Windows/system/drivers => 43859079 B
Edge => 1225986 B
Chrome => 2637923 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 35906 B
LocalService => 0 B
NetworkService => 10460 B
NetworkService => 0 B
Sandy => 50547005 B

RecycleBin => 0 B
EmptyTemp: => 256.4 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 12:22:33 ====

# -------------------------------
# Malwarebytes AdwCleaner
# -------------------------------
# Build: 09-25-2018
# Database: 2018-11-05.1 (Cloud)
# Support: https://www.malwarebytes.com/support
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 11-07-2018
# Duration: 00:00:17
# OS: Windows 10 Home
# Cleaned: 17
# Failed: 1

***** [ Services ] *****

Deleted SecurityService

***** [ Folders ] *****

Deleted C:\ProgramData\RegInOut
Not Deleted C:\Program Files (x86)\TotalAV
Deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\TotalAV
Deleted C:\Users\Sandy\AppData\Roaming\TotalAV
Deleted C:\Users\Sandy\Documents\TotalAV
Deleted C:\Users\Public\Documents\Downloaded Installers
Deleted C:\Users\Sandy\AppData\Local\slimware utilities inc

***** [ Files ] *****

Deleted C:\Users\Sandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TotalAV.lnk
Deleted C:\Users\Sandy\Desktop\TotalAV.lnk
Deleted C:\Windows\System32\drivers\swdumon.sys
Deleted C:\Users\Sandy\Downloads\TOTALAV_SETUP.EXE

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\TotalAV
Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\SecurityService
Deleted HKLM\Software\Wow6432Node\SlimWare Utilities Inc
Deleted HKLM\SOFTWARE\Mozilla\NativeMessagingHosts\com.totalav.passwordvaultassistant
Deleted HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.totalav.passwordvaultassistant

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

Deleted Ask

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


[+] Delete Tracing Keys
[+] Reset Winsock


AdwCleaner[S00].txt - [2561 octets] - [07/11/2018 12:47:36]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

RogueKiller Anti-Malware V13.0.8.0 (x64) [Nov 6 2018] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.17134) 64 bits
Started in : Normal mode
User : Sandy [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Standard Scan, Delete -- Date : 2018/11/07 14:13:28 (Duration : 01:06:38)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Slimware (Potentially Malicious)] SWDUMon -- %SystemRoot%\system32\DRIVERS\SWDUMon.sys -> Stopped
[PUP.Slimware (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SWDUMon -- [%SystemRoot%\system32\DRIVERS\SWDUMon.sys] -> Deleted
[PUP.PCProtect (Potentially Malicious)] TotalAV -- %programfiles(x86)%\TotalAV -> Deleted
[PUP.PCProtect (Potentially Malicious)] TotalAV -- %programfiles(x86)%\TotalAV -> Removed at reboot [2]

2018-11-08, 11:49
Let's check for remnants

Open Malwarebytes Anti-Malware

Then go to the Dashboard and click on SCAN NOW
If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
Upon completion of the scan (or after the reboot), click the Reports tab.
Double-click the Scan Log.
At the bottom click Export and choose Text file.

Save the file to your desktop and include its content in your next reply.

You can access the logs by going in the "Reports" tab, clicking on the latest "Scan" entry (the one with detections), then clicking on the "Export" button in the bottom-left corner and select "Copy to clipboard". After that, all you have to do is paste it here
Then click on POST
Exit Malwarebytes


http://i.imgur.com/G0tu5D9.pngEmsisoft Emergency Kit - Fix Mode
Follow the instructions below to run a scan using the Emsisoft Emergency Kit.

Download the Emsisoft Emergency Kit (https://www.emsisoft.com/en/software/eek/download/) and execute it. From there, click on the Install button to extract the program in the EEK folder;
Once the extraction is complete, the EEK folder will open. Right-click on http://i.imgur.com/G0tu5D9.pngstart emergency kit scanner.exe and select [img=http://i.imgur.com/Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
After the restart, open EEK again (in the C:\EEK folder);
This time, click on Logs;
From there, go under the Quarantine Log tab, and click on the Export button;
Save the log on your desktop, then open it, and copy/paste its content in your next reply;

Please post these 2 logs when finished.

Also, tell me how the computer is now.

2018-11-08, 23:32
Hi Juliet,

Thanks again for the prompt response. I ran both of these scans but both came back clean (see below). My system is significantly faster than it was but unfortunately my Google Chrome is still the same. I took a screenshot of it but cannot load it to show you.

Please advise my next steps.


2018-11-09, 01:47
I'm beginning to think it's not malware but something with either antivirus block, or Google Chrome itself.

What we can attempt is a reset, then if that doesn't work, uninstall/reinstall and see how that goes.

http://i.imgur.com/U5NwUGc.png Backup Chrome Bookmarks (http://www.wikihow.com/Export-Bookmarks-from-Chrome)
Proceed with the reset once done.
Chrome - Reset browser settings (https://support.google.com/chrome/answer/3296214?hl=en)

if you can do a screen capture and save it to desktop, then you should be able to attach that here using the attachment button.

2018-11-09, 03:20
Hi Juliet,
Thank you for your help and suggestions. I had been unable to access Google Chrome without the attached window displaying which I had never seen before (nor had anyone I know who I showed this to) and was afraid to click any of the buttons in case this would enable a virus or any further intrusion into my pc. Your last suggestions asked me to open Chrome, which I believed was the issue, so I took the plunge and clicked the icon in this window. This brought me to my regular Google Chrome page. I feel like I have wasted your time and for that I apologise. If nothing else my pc is so much faster now we've cleared the junk. One thing I will mention is that I can no longer operate my speakers from the taskbar, so if you could help me fix this I would appreciate it.

Thanks Sandy

2018-11-09, 12:35
You haven't wasted my time.

try this
Click on the Start button and then Control Panel.

In the Control Panel double-click on the Sounds and Audio Devices icon.

Under Device Volume put a checkmark next to the checkbox labeled Place volume icon in the taskbar.

Press the Apply button and then the OK button.

You should now have a volume icon in your taskbar.


2018-11-09, 13:54
Hi Juliet,
Thanks again for the suggestion. So I went into the control Panel (see attached) and couldn't see the Sounds and Audio Devices icon, so I double-clicked the Hardware & Sound (see attached screenshot). I still didn't see Device Volume so I clicked Manage Audio Devices under sound (see attached) and still couldn't find any checkboxes for "Place volume icon in the taskbar", so I tried all of the other options including properties, and still no luck I'm afraid.

I also took a look at the link you added about "missing volume icon in your taskbar", my icon isn't missing, it's just not working (nothing happens when I select it from the taskbar) but I tried all the same. I found the settings page to turn systems icons on or off. Volume was on. I toggled off and on again but it's still not working.

Sorry to be such a pain :)

2018-11-09, 20:33
I've tried to research and pull together a few things to help (I hope)

To run chkdsk /r

Type cmd in search
Right click the command prompt response to “run as administrator”
Run chkdsk /r in the command prompt window (note the space between k and /)
The response will be the option to run chkdsk /r after your next reboot click yes.
Now reboot and go do other business. When finished, and it can take some time, Windows should reboot.
Check the sound icon.


I would suggest you to try reinstalling the audio driver in compatibility mode and check the issue.

You need to download audio driver from the computer manufacturer's website.

Further, please follow these steps:

a. Right click the audio driver file and click properties.

b. Click compatibility tab.

c. Click to check "Run this program in compatibility mode for" box and select Windows 8.

d. Click apply and ok.

Now, install the driver.


Please run playing audio troubleshooter and check if it helps. Please follow these steps:

a. Type troubleshooting in the search box on taskbar and click on it in search results.
b. Click "View all" and then click "Playing Audio".
c. Click "Next" and follow on-screen instructions.

Some people state running the above 2 times fixed their issues.

Please keep us updated.

2018-11-10, 08:35
Hi again Juliet,

Looks like the chkdsk fix did the trick! I am now able to access my speakers from the taskbar. yay!!
Thanks for all your help.


2018-11-10, 13:13

Let's remove tools and quarantine folders now.


Please download DelFix (https://www.bleepingcomputer.com/download/delfix/) or from Here (http://www.bleepingcomputer.com/download/delfix/) and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:
Activate UAC
Remove disinfection tools
Click the Run button.
-- This will remove the specialized tools we used to disinfect your system.
Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


Keeping your programs up-to-date

Like keeping Windows updated, keeping your installed programs up-to-date is another important step in having a safe and secure system. Outdated programs can be exploited by hackers and malware to infect a system and take it over. This is especially true today with the rise of Exploit Kits (https://en.wikipedia.org/wiki/Exploit_kit) (and also 0-days (https://en.wikipedia.org/wiki/Zero-day_(computing))) which is one of the biggest attack vectors to distribute malware. Therefore, you should always keep vulnerable programs like Adobe Flash Player, Adobe Shockwave Player, Java, Silverlight, Google Chrome, Mozilla Firefox, VLC Media Player, etc. updated to their most recent version (even better, you don't have to install them if you don't use them). Programs like https://i.imgur.com/eF2jhaz.pngUCheck (https://www.adlice.com/download/ucheck/), SUMo (http://www.kcsoftwares.com/?sumo) and https://i.imgur.com/y5YE7At.pngHeimdal Free (http://www.bleepingcomputer.com/download/heimdal-free/) will scan your system for outdated programs, and help you identify them, as well as update them.

UCheck Documentation (https://www.adlice.com/documentation/ucheck/documentation/)

Here are a few guides, tutorials, articles, etc. that you could read in order to learn more about computer protection and security to improve your current computer protection setup but also improve your good web browsing and computer usage practices :

Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7
How Malware Spreads - How did I get infected (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams (aka Grinler)
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes
Tips & Advice (http://www.staysafeonline.org/stop-think-connect/tips-and-advice) on StaySafeOnline.org

