I tried to install what I now know to be an illegitimate copy of Microsoft Office, during installation I got a notification that "TAP VPN" was being installed.

I've uninstalled the software but my PC is running slowly and I can't seem to find the location of this "TAP VPN" malware that installed itself.

Any help would be greatly appreciated.

Here is my FRST log:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.01.2019 01
Ran by Mark (administrator) on MARK-PC (15-01-2019 15:57:32)
Running from C:\Users\Mark\Desktop
Loaded Profiles: Mark (Available Profiles: Mark & Work)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

2019-01-16, 00:49
Unfortunately there is evidence of illegal software on your computer. I am going to request you completely uninstall all products for which you do not have a valid Product Key, including all "cracked" software. This is a must.

Is this what your talking about?
S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project)
we can remove this but I believe it to be legit.

Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::

Highlight the entire content of the quote box below and select Copy.

HKU\S-1-5-21-2250887051-2314894825-2524768795-1000\...\ChromeHTML: -> <==== ATTENTION
FirewallRules: [{A7841B01-15DF-47C8-A965-FD86C1A81E00}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe No File
FirewallRules: [{AE428147-750D-4E79-92C0-B0E02DCD04E6}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe No File

Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.

http://i.imgur.com/zcMPezJ.pngAdwCleaner - Fix Mode

Download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/dl/125/) and move it to your Desktop
Right-click on AdwCleaner.exe and select http://i.imgur.com/Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
Accept the EULA (I accept), then click on Scan
Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button. This will kill all the active processes
Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply


Download the right version of RogueKiller (http://www.adlice.com/download/roguekiller/#download) for your Windows version (32 or 64-bit)
Once done, move the executable file to your Desktop, right-click on it and select http://i.imgur.com/Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
Wait for the scan to complete
On completion, the results will be displayed
Check every single entry (threat found), and click on the Remove Selected button
On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
This will open the report in Notepad. Copy/paste its content in your next reply
created by Aura

Please post these 3 logs when finished.

2019-01-16, 22:22
Hello, thank you for your reply.

Just to confirm I have removed every trace of the offending software to the best of my ability.

As I did not intend to install that VPN I would be interested in removing all trace of it, yes.

Here is the Farbar fixlog:

Fix result of Farbar Recovery Scan Tool (x64) Version: 16.01.2019
Ran by Mark (16-01-2019 19:47:38) Run:1
Running from C:\Users\Mark\Desktop
Loaded Profiles: Mark (Available Profiles: Mark & Work)
Boot Mode: Normal

fixlist content:
HKU\S-1-5-21-2250887051-2314894825-2524768795-1000\...\ChromeHTML: -> <==== ATTENTION
FirewallRules: [{A7841B01-15DF-47C8-A965-FD86C1A81E00}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe No File
FirewallRules: [{AE428147-750D-4E79-92C0-B0E02DCD04E6}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe No File


Processes closed successfully.

The ADW Cleaner log:

# -------------------------------
# Malwarebytes AdwCleaner
# -------------------------------
# Build: 12-18-2018
# Database: 2019-01-10.1 (Cloud)
# Support: https://www.malwarebytes.com/support
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 01-16-2019
# Duration: 00:00:00
# OS: Windows 7 Home Premium
# Cleaned: 1
# Failed: 0

***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\csastats

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


[+] Delete Tracing Keys
[+] Reset Winsock


AdwCleaner[S00].txt - [1275 octets] - [16/01/2019 19:50:14]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

And finally the RogueKiller fixlog:

RogueKiller Anti-Malware V13.0.22.0 (x64) [Jan 14 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : Mark [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Standard Scan, Scan -- Date : 2019/01/16 19:55:18 (Duration : 00:09:01)

中中中中中中中中中中中中 Processes 中中中中中中中中中中中中

中中中中中中中中中中中中 Process Modules 中中中中中中中中中中中中

中中中中中中中中中中中中 Services 中中中中中中中中中中中中

中中中中中中中中中中中中 Tasks 中中中中中中中中中中中中

中中中中中中中中中中中中 Registry 中中中中中中中中中中中中
>>>>>> O101 - Clsid
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_CLASSES_ROOT\CLSID\{3E3AD4BD-346A-460A-80E8-90699B75C00B} -- (Microsoft Corporation) C:\Users\Mark\AppData\Local\Microsoft\SkypeForBusinessPlugin\\GatewayActiveX-x64.dll -> Found
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_CLASSES_ROOT\CLSID\{FE2EC208-BECF-4E83-8BF4-E35DBA4EB6A1} -- (Microsoft Corporation) C:\Users\Mark\AppData\Local\Microsoft\SkypeForBusinessPlugin\\GatewayVersion-x64.exe -> Found
>>>>>> O87 - Firewall
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{2D4B689A-84D8-4DD9-A78E-609E2425E0EA}C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe -- (Microsoft Corporation) v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe|Name=pluginhost.exe|Desc=pluginhost.exe|Defer=User| (C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe) -> Found
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{CBAB24FD-78FA-4ABF-A5AF-D89E2BD9BCCC}C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe -- (Microsoft Corporation) v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe|Name=pluginhost.exe|Desc=pluginhost.exe|Defer=User| (C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe) -> Found
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{2D4B689A-84D8-4DD9-A78E-609E2425E0EA}C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe -- (Microsoft Corporation) v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe|Name=pluginhost.exe|Desc=pluginhost.exe|Defer=User| (C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe) -> Found
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{CBAB24FD-78FA-4ABF-A5AF-D89E2BD9BCCC}C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe -- (Microsoft Corporation) v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe|Name=pluginhost.exe|Desc=pluginhost.exe|Defer=User| (C:\users\mark\appdata\local\microsoft\skypeforbusinessplugin\\pluginhost.exe) -> Found

中中中中中中中中中中中中 WMI 中中中中中中中中中中中中

中中中中中中中中中中中中 Hosts File 中中中中中中中中中中中中

中中中中中中中中中中中中 Files 中中中中中中中中中中中中
[PUP.Gen1 (Potentially Malicious)] (folder) PackageAware -- C:\Users\Mark\AppData\Local\PackageAware -> Found
[PUP.HackTool (Potentially Malicious)] (folder) KMSAuto -- C:\ProgramData\KMSAuto -> Found
[PUP.Gen1 (Potentially Malicious)] (folder) PackageAware -- C:\Users\Mark\AppData\Local\PackageAware -> Found

中中中中中中中中中中中中 Web browsers 中中中中中中中中中中中中

2019-01-16, 23:54
Did you allow RogueKiller to remove what it found?


Not sure why but the entire Fixlog from Farbar Recovery Scan Tool did not post.


Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::

Highlight the entire content of the quote box below and select Copy.

S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys

Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.

Let's check for remnants

Please download the Malwarebytes Anti-Malware (https://downloads.malwarebytes.org/file/mbam) setup file to your Desktop.

OR from this location Here (https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/)

Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
After the installation IS complete let it update if it asks.
Under SETTINGS.....APPLICATIONS leave everything at default
Then go to the Dashboard and click on SCAN NOW
If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
Upon completion of the scan (or after the reboot), click the Reports tab.
Double-click the Scan Log.
At the bottom click Export and choose Text file.

Save the file to your desktop and include its content in your next reply.

You can access the logs by going in the "Reports" tab, clicking on the latest "Scan" entry (the one with detections), then clicking on the "Export" button in the bottom-left corner and select "Copy to clipboard". After that, all you have to do is paste it here
Then click on POST
Exit Malwarebytes


Emsisoft Emergency Kit - Fix Mode
Follow the instructions below to run a scan using the Emsisoft Emergency Kit.

Download the Emsisoft Emergency Kit (https://www.emsisoft.com/en/software/eek/download/) and execute it. From there, click on the Install button to extract the program in the EEK folder;
Once the extraction is complete, the EEK folder will open. Right-click on http://i.imgur.com/G0tu5D9.pngstart emergency kit scanner.exe and select http://i.imgur.com/Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
After the restart, open EEK again (in the C:\EEK folder);
This time, click on Logs;
From there, go under the Quarantine Log tab, and click on the Export button;
Save the log on your desktop, then open it, and copy/paste its content in your next reply;

Please post these 3 logs when finished.

Also, tell me how the computer is now.

2019-01-18, 00:32
Hello again, hopefully we have more luck with Farbar this time:

Restore point was successfully created.
HKLM\System\CurrentControlSet\Services\ptun0901 => removed successfully
ptun0901 => service removed successfully
C:\Windows\System32\DRIVERS\ptun0901.sys => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 85748748 B
Java, Flash, Steam htmlcache => 157804769 B
Windows/system/drivers => 347912 B
Edge => 0 B
Chrome => 539618451 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 58558278 B
systemprofile32 => 68964 B
LocalService => 0 B
NetworkService => 293322 B
Mark => 765486909 B
Work => 23373 B

RecycleBin => 1207929 B
EmptyTemp: => 1.5 GB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 22:10:02 ====

I couldn't find any apply action option on Malwarebytes but there was a "quarantine selected" option, not sure if that helps:


-Log Details-
Scan Date: 1/17/19
Scan Time: 10:14 PM
Log File: 3d11d888-1aa5-11e9-b00a-74d435d74a2b.json

-Software Information-
Components Version: 1.0.519
Update Package Version: 1.0.8840
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Mark-PC\Mark

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 341533
Threats Detected: 1
Threats Quarantined: 1
Time Elapsed: 3 min, 31 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 1
Generic.Malware/Suspicious, C:\USERS\MARK\DOWNLOADS\KMSAUTO+NET.ZIP, Quarantined, [0], [392686],1.0.8840

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


I couldn't find a "Quarantine Log" section but under logs there was an "export" option, this is what I got from it:

Emsisoft Emergency Kit 2018.6.0.8742 stable [en-us]
OS: Windows 7 Service Pack 1 (Version 6.1, Build 7601, 64-bit Edition)

Forensics log

Date Component Action Details
17/01/2019 22:29:08 Scanner Scan finished Scanned 77035 objects and found nothing.
17/01/2019 22:27:50 User MARK-PC\Mark Scan started Malware Scan
17/01/2019 22:27:50 User MARK-PC\Mark Setting modified "Detect PUPs" has been changed to "Enabled".
17/01/2019 22:27:02 User Update Downloaded and installed 64 files (34458 kb) (15 sec.) Application restart notification.
17/01/2019 22:26:45 User Update Failed with error "Server returned error" (0 sec.).

Computer is actually running a little smoother now.

2019-01-18, 12:52
All sounds good.
Are the notifications gone?

2019-01-19, 01:03
Yes, haven't seen any.

2019-01-19, 14:41
I think your good to go

Please download DelFix (https://www.bleepingcomputer.com/download/delfix/) or from Here (http://www.bleepingcomputer.com/download/delfix/) and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:
Activate UAC
Remove disinfection tools
Click the Run button.
-- This will remove the specialized tools we used to disinfect your system.
Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7, MVP
How Malware Spreads - How did I get infected? (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7, MVP
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams, MVP
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes, MVP
How to backup and restore your data using Cobian Backup (http://www.bleepingcomputer.com/tutorials/backup-and-restore-data-with-cobian-backup/) by YourHighness
Slow Computer/browser? It May Not Be Malware (http://www.bleepingcomputer.com/forums/t/87058/slow-computerbrowser-check-here-first;-it-may-not-be-malware/) by quietman7, MVP

AdBlock (https://adblockplus.org/en/firefox) is a browser add-on that blocks annoying banners, pop-ups and video ads.
http://i.imgur.com/E8I37RF.pngCryptoPrevent (https://www.foolishit.com/) places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
http://i.imgur.com/EG85Vjt.png Malwarebytes Anti-Exploit (https://www.malwarebytes.org/antiexploit/) (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
http://i.imgur.com/6YRrgUC.png Malwarebytes Anti-Malware Premium (https://www.malwarebytes.org/) (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
http://i.imgur.com/jv4nhMJ.png NoScript (http://noscript.net/) is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
http://i.imgur.com/3O8r9Uq.png (http://www.sandboxie.com/) Sandboxie (http://www.sandboxie.com/) isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
http://i.imgur.com/DgW1XL2.png Secunia PSI (http://secunia.com/vulnerability_scanning/personal/) will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.

http://i.imgur.com/sHjS79L.png Unchecky (http://unchecky.com/) automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.

2019-01-21, 15:13
I've run the tool, thanks for all your help!

2019-01-21, 16:21
Glad we could help. http://i.imgur.com/SakDYGv.gif
Since this issue appears resolved ... this Topic is closed.