Re-install Chrome
Unless you did this yourself, malware has changed your Chrome version into the Development Build. Among other things this allows malware to install any extension it wants. We need to resolve this.
- If you have bookmarks, let’s save them by exporting them - Export Bookmarks
- Then I need you to go Google Sync and sign into your account
- Scroll down until you see the “Stop and Clear” button and click on the button. At the prompt click on “Ok”
- Now we need to uninstall chrome.
Note: When asked about user data or settings you must remove this also so please check the box.
- Restart the computer and reinstall chrome, You can download The latest version from here - Google Chrome
- Import your bookmarks back into Chrome
- Sign back in to your Chrome browser so that your bookmarks sync with your online account.
THEN
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2689726006-3933415143-659271278-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
2015-04-04 02:35 - 2015-04-04 03:13 - 00000000 ____D () C:\Program Files (x86)\9eb08200-8451-400f-a40b-8b18a34bc5a6
2015-04-04 02:33 - 2015-04-04 03:05 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-04-04 02:25 - 2015-04-04 03:13 - 00000000 ____D () C:\Program Files (x86)\57fc5bd0-add7-485c-908c-b8dd6e5a3b37
2015-04-04 02:24 - 2015-04-04 03:13 - 00000000 ____D () C:\ProgramData\3a8c9699124a4506a71d46fb652dc7b1
2015-04-04 02:24 - 2015-04-04 02:24 - 00000000 ____D () C:\ProgramData\36ebbb131f884f3aa5b926d4db990ab9
2015-01-25 09:12 - 2015-04-04 14:05 - 0000365 _____ () C:\Users\B\AppData\Roaming\AUSAMRFZ
2015-03-26 12:14 - 2015-03-26 12:14 - 0004185 _____ () C:\Users\B\AppData\Roaming\CWR
2015-03-26 12:14 - 2015-04-04 14:05 - 0000385 _____ () C:\Users\B\AppData\Roaming\FTKEM
2015-03-26 12:14 - 2015-04-04 14:05 - 0000385 _____ () C:\Users\B\AppData\Roaming\KBHVDLCG
2015-03-26 12:14 - 2015-03-26 12:14 - 0004185 _____ () C:\Users\B\AppData\Roaming\VJJ
Task: {0456C0FB-F043-47EA-90F4-B4A8423D5240} - System32\Tasks\TKKMJ => C:\ProgramData\3a8c9699124a4506a71d46fb652dc7b1\3a8c9699124a4506a71d46fb652dc7b1.exe
2015-04-15 13:17 - 2015-04-26 21:03 - 00000080 _____ () C:\Users\B\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that