1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Code:
Task: {2DEB20F4-5E77-4619-AE2B-F6427EB3F758} - System32\Tasks\PC Optimizer Pro64 startups => C:\Program Files\PC Optimizer Pro\StartApps.exe <==== ATTENTION
Task: {5E5C6768-C88C-4D23-8C76-DA3612493B6D} - System32\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A} => C:\Users\Dave\AppData\Local\Temp\Ese.exe <==== ATTENTION
Task: {724A14A7-E1C8-45F9-8762-39759B902CE2} - System32\Tasks\4565 => Wscript.exe C:\Users\Dave\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION
Task: {D5238CFC-031E-462F-8067-9B3C43195C01} - System32\Tasks\0 => Iexplore.exe <==== ATTENTION
Task: {ECAF3408-12F4-4DBF-9184-32C8642C38D4} - System32\Tasks\{22116563-108C-42c0-A7CE-60161B75E508} => C:\Users\Dave\AppData\Local\Temp\Esd.exe <==== ATTENTION
Task: C:\Windows\Tasks\PC Optimizer Pro64 startups.job => C:\Program Files\PC Optimizer Pro\StartApps.exe <==== ATTENTION
HKU\S-1-5-21-128655061-1982285771-4068978593-1000\Software\Classes\.exe: => <===== ATTENTION!
C:\Users\Dave\AppData\LocalLow\Apple Computer\Jvknlkdcyyc
HKLM-x32\...\Run: [VideoDownloadConverter EPM Support] => "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zmedint.exe" T8EPMSUP.DLL,S
HKLM-x32\...\Run: [VideoDownloadConverter Search Scope Monitor] => "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h
HKLM-x32\...\Run: [VideoDownloadConverter_4z Browser Plugin Loader] => C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe
HKLM-x32\...\Run: [VideoDownloadConverter_4z Browser Plugin Loader 64] => C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon64.exe [71752 2014-02-24] (VER_COMPANY_NAME)
C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zmedint.exe
C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe
C:\Program Files (x86)\VideoDownloadConverter_4z
HKLM-x32\...\Run: [TelevisionFanatic Browser Plugin Loader 64] => C:\PROGRA~2\TELEVI~2\bar\1.bin\64brmon64.exe
C:\PROGRA~2\TELEVI~2\bar\1.bin\64brmon64.exe
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\PC Tools <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Trend Micro <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\McAfee <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Malwarebytes <====== ATTENTION
HKU\S-1-5-21-128655061-1982285771-4068978593-1000\...\Run: [Vpozfpi] => regsvr32.exe /s "C:\Users\Dave\AppData\Local\{0301732F-6F4B-487F-9BE3-74C5970794D4}\Vpozfpi.dll" <===== ATTENTION
C:\Users\Dave\AppData\Local\{0301732F-6F4B-487F-9BE3-74C5970794D4}
SearchScopes: HKLM - {4A7B0228-166C-4E49-B331-69C852A9D0B3} URL = http://search.live.com/results.aspx?q={searchTerms}&Form=DLCDF7&pc=MDDC&src={referrer:source?}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=394&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=3043345243514158&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {6447BEB2-2EC2-438A-823C-833A98A91DA9} URL =
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=394&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=3043345243514158&q={searchTerms}
SearchScopes: HKLM-x32 - {a5b9c0f5-5616-47cd-a95f-e43b488faccf} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^XP^man000^YYA^&ptb=0EFD797F-CC18-4E83-8045-AD9C7501F033&psa=&ind=2014040900&st=sb&n=780bd344&searchfor={searchTerms}
SearchScopes: HKLM-x32 - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm017^YYA^us&si=pconvIE&ptb=8BE77CB9-6E25-475C-930E-5598303FAA53&ind=2014022502&n=780b8b66&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
BHO: TidyNetwork -> {15B1F55D-C5B2-3E44-FDE0-EC7BD34A3A36} -> C:\Program Files (x86)\TidyNetwork\petn64.dll No File
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
Toolbar: HKCU - No Name - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
Toolbar: HKCU - No Name - {B2BF7B3F-BF0B-4C48-AEC6-F92C51BE63E1} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
CHR Extension: (MapsGalaxy) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcpehlgijbdajfafffojllcaecaecngb [2014-09-17]
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcpehlgijbdajfafffojllcaecaecngb
CHR HKCU\...\Chrome\Extension: [fdkednngfjmpnljkolbapdednncafhen] - C:\Users\Dave\AppData\Local\CRE\fdkednngfjmpnljkolbapdednncafhen.crx [2013-09-08]
CHR HKCU\...\Chrome\Extension: [jnidgldcbakaidffpjinopjbmobecifb] - C:\Users\Dave\AppData\Local\CRE\jnidgldcbakaidffpjinopjbmobecifb.crx [2013-09-08]
CHR HKCU\...\Chrome\Extension: [njljkdinboobkmkihgcohanchjnjpgjk] - C:\Users\Dave\AppData\Local\CRE\njljkdinboobkmkihgcohanchjnjpgjk.crx [2013-09-08]
C:\Users\Dave\AppData\Local\CRE\fdkednngfjmpnljkolbapdednncafhen.crx
C:\Users\Dave\AppData\Local\CRE\jnidgldcbakaidffpjinopjbmobecifb.crx
C:\Users\Dave\AppData\Local\CRE\njljkdinboobkmkihgcohanchjnjpgjk.crx
CHR HKLM-x32\...\Chrome\Extension: [bicnnkjibmphdeigoodpjlcklcnaobdj] - C:\Program Files (x86)\TornTV.com\torntv10.crx [2013-09-08]
C:\Program Files (x86)\TornTV.com\torntv10.crx
CHR HKLM-x32\...\Chrome\Extension: [fdkednngfjmpnljkolbapdednncafhen] - C:\Users\Dave\AppData\Local\CRE\fdkednngfjmpnljkolbapdednncafhen.crx [2013-09-08]
CHR HKLM-x32\...\Chrome\Extension: [jbpkiefagocgkmemidfngdkamloieekf] - C:\Program Files (x86)\TornTV.com\torn11.crx [2013-09-08]
CHR HKLM-x32\...\Chrome\Extension: [jnidgldcbakaidffpjinopjbmobecifb] - C:\Users\Dave\AppData\Local\CRE\jnidgldcbakaidffpjinopjbmobecifb.crx [2013-09-08]
C:\Users\Dave\AppData\Local\CRE\fdkednngfjmpnljkolbapdednncafhen.crx
C:\Program Files (x86)\TornTV.com\torn11.crx
C:\Users\Dave\AppData\Local\CRE\jnidgldcbakaidffpjinopjbmobecifb.crx
CHR HKLM-x32\...\Chrome\Extension: [njljkdinboobkmkihgcohanchjnjpgjk] - C:\Users\Dave\AppData\Local\CRE\njljkdinboobkmkihgcohanchjnjpgjk.crx [2013-05-14]
C:\Users\Dave\AppData\Local\CRE\njljkdinboobkmkihgcohanchjnjpgjk.crx
C:\Program Files (x86)\Conduit
C:\Users\Dave\SkypeSetup.exe
EmptyTemp:
2. Save notepad as
fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
3. Run
FRST/FRST64 and press the
Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (
Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.