Solved Distromatic

Ole Baert

New Member
Thread author
Aug 1, 2016
5
Hello

'Distromatic' keeps comming back after removal with spybot. It could well be that it's been there before, I had a threath in avast some time ago, alas, can't remember the name.

I'll include the two files asked, let me know what you want me to do.

Friendly greetings

Ole Baert
 

Attachments

  • FRST.txt
    104.4 KB · Views: 4
  • Addition.txt
    66.4 KB · Views: 3

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,



51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a612a8b27e2-Zoek.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    Code:
    createsrpoint;
    autoclean;
    emptyclsid;
    emptyalltemp;
    ipconfig /flushdns >>"%temp%\log.txt";b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Upload it in your next reply.
 
  • Like
Reactions: Ole Baert

Ole Baert

New Member
Thread author
Aug 1, 2016
5
I still doesn't seem to be right. I'll show you what I see. I'll attacht the log from spybot, just in case you could use it.


upload_2016-8-2_16-36-9.png
 

Attachments

  • Scan Results.160802-1634 Spybot.txt
    10.4 KB · Views: 2

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
adwcleaner_new.png
Fix with AdwCleaner

Please download AdwCleaner by Xplode and save the file to your Desktop.
  • Right-click on
    adwcleaner_new.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Accept the Terms of use.
  • Wait until the database is updated.
  • Click Scan.
  • When finished, please click Cleaning.
  • Your PC should reboot now.
  • After reboot, logfile will be opened. Copy its content into your next reply.

Note: Reports will be saved in your system partition, usually at C:\Adwcleaner



FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.

    2873ryc.png

  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 

Ole Baert

New Member
Thread author
Aug 1, 2016
5
Done

# AdwCleaner v5.201 - Logbestand aangemaakt 03/08/2016 op 11:03:17
# Laatste update 30/06/2016 door ToolsLib
# Database : 2016-08-02.3 [Server]
# Besturingssysteem : Windows 10 Pro (X64)
# Gebruikersnaam : Ole - OLE-HP
# Gestart vanuit : C:\Users\Ole\Desktop\AdwCleaner.exe
# Optie : Verwijderen
# Ondersteuning : ToolsLib

***** [ Services ] *****

[-] Service verwijderd : Amazon 1Button App Service

***** [ Mappen ] *****

[-] Map verwijderd : C:\Program Files (x86)\Amazon Browser Settings
[-] Map verwijderd : C:\Program Files (x86)\Amazon\Amazon1ButtonApp
[-] Map verwijderd : C:\Users\Ole\AppData\Local\Amazon Browser Settings

***** [ Bestanden ] *****


***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Snelkoppelingen ] *****


***** [ Geplande taken ] *****

[-] Taak verwijderd : LaunchSignup
[-] Taak verwijderd : DistromaticSearchProtect-logon
[-] Taak verwijderd : DistromaticUpdater-periodic
[-] Taak verwijderd : DistromaticSearchProtect-hourly
[-] Taak verwijderd : DistromaticUpdater-logon

***** [ Register ] *****

[-] Sleutel verwijderd : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\gamingwonderland.com
[-] Sleutel verwijderd : HKCU\Software\Google\Chrome\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
[-] Sleutel verwijderd : HKCU\Software\Classes\TornTvDownloader.File
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\Amazon1ButtonBrowserHelper.Amazon1ButtonBHO
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\Amazon1ButtonRuntime.Amazon1ButtonRuntime
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\Amazon1ButtonRuntime.AmazonRuntimeServer
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\AmazonAppIE.AppGateway
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\AmazonAppIE.GadgetGateway
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\TornTvDownloader.File
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}
[-] Sleutel verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
[-] Sleutel verwijderd : HKCU\Software\distromatic
[-] Sleutel verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Amazon Assistant
[-] Sleutel verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B6DCCCD3-520D-4485-B642-FCC136CE12C3}
[-] Sleutel verwijderd : HKU\.DEFAULT\Software\TornTv Downloader
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\Installer\Features\3DCCCD6BD02558446B24CF1C63EC213C
[-] Sleutel verwijderd : HKLM\SOFTWARE\Classes\Installer\Products\3DCCCD6BD02558446B24CF1C63EC213C
[-] Sleutel verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
[-] Sleutel verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[-] Sleutel verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com

***** [ Internetbrowsers ] *****

[-] [C:\Users\Ole\AppData\Roaming\Mozilla\Firefox\Profiles\nshlac17.default\prefs.js] verwijderd : user_pref("network.hxxp.request.max-start-delay", 0);
[-] [C:\Users\Ole\AppData\Roaming\Mozilla\Firefox\Profiles\nshlac17.default\user.js] verwijderd : user_pref("network.hxxp.request.max-start-delay", 0);
[-] [C:\Users\Ole\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] verwijderd : eu.ask.com
[-] [C:\Users\Ole\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] verwijderd : audacity.nl.softonic.com
[-] [C:\Users\Ole\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] verwijderd : cyberlink-power2go.nl.softonic.com
[-] [C:\Users\Ole\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] verwijderd : hdd-regenerator.en.softonic.com
[-] [C:\Users\Ole\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] verwijderd : easy-disk-drive-repair.en.softonic.com
[-] [C:\Users\Ole\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] verwijderd : pbjikboenpfhbbejgkoklgkhjpfogcam

*************************

:: "Tracing" sleutels verwijderd
:: Winsock instellingen gereset

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [4561 bytes] - [03/08/2016 11:03:17]
C:\AdwCleaner\AdwCleaner[S1].txt - [4732 bytes] - [03/08/2016 10:58:58]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4707 bytes] ##########
 

Attachments

  • FRST.txt
    104 bytes · Views: 3
  • Addition.txt
    65.2 KB · Views: 3

Ole Baert

New Member
Thread author
Aug 1, 2016
5
Seems clean to me, I was waiting for your approval.
If that's it. Thx and gratz on a job well done!
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top