Hello,

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the ‘all clear’ even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper


First, you need to uninstall Google Chrome browser. It has been compromised by malware as it is changed in developer version. All security features in Chrome are now disabled by default. This need to be fixed first. Make shure to chech the box ‘Also delete your browsing data’ as we need to remove preferences as well.

So, uninstall Google Chrome web browser and then continue and preform fixing with FRST tool.


This FixList shall target the malware. When FRST finnish with fixing, it will ask and preform the system reboot.

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Start
CreateRestorePoint:
CMD: bitsadmin /reset /allusers
Folder: C:\ProgramData\10594458285607738608
Folder: C:\ProgramData\{d9eaf9ef-3a4b-6820-d9ea-af9ef3a4e7bc}
Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f
Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f

CloseProcesses:
HKLM-x32\...\Run: [] => [X]
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]

Hosts:
C:\ProgramData\DP45977C.lfl
C:\Program Files (x86)\Google

RemoveProxy:
Task: {EC0468E3-36C5-4682-A03E-51367FE9961A} - System32\Tasks\DataKeeper => c:\programdata\{d9eaf9ef-3a4b-6820-d9ea-af9ef3a4e7bc}\5558725635412276772c.exe [2014-06-21] () <==== ATTENTION
Task: C:\WINDOWS\Tasks\DataKeeper.job => c:\programdata\{d9eaf9ef-3a4b-6820-d9ea-af9ef3a4e7bc}\5558725635412276772c.exe <==== ATTENTION
AlternateDataStreams: C:\Users\Prateek5\Documents\GEO530 Assignment 2 Prateek Saxena.pdf:com.dropbox.attributes

EmptyTemp:
End

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.


Now, download fresh Google Chrome installer and install it. Sing in into Gmail account and all your personal data and bookmarks will be synced.