hi, the system seems cleaned. I will monitor for 24hrs for any recurrence.
here are the fixlogs
Fix result of Farbar Recovery Scan Tool (x86) Version:09-08-2015
Ran by PC1 (2015-08-10 03:45:52) Run:2
Running from C:\Users\PC1\Desktop
Loaded Profiles: PC1 (Available Profiles: PC1)
Boot Mode: Normal
==============================================
fixlist content:
CreateRestorePoint:
2012-08-31 05:12 - 2010-11-20 20:17 - 70271360 ___SH () C:\ProgramData\msequupj.exe
2015-04-02 06:13 - 2015-04-02 16:59 - 0000000 _____ () C:\Users\PC1\AppData\Local{52628801-7BDE-4B1A-BEA9-14C99D7F008E}
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Restore point was successfully created.
Could not move “C:\ProgramData\msequupj.exe” => Scheduled to move on reboot.
C:\Users\PC1\AppData\Local{52628801-7BDE-4B1A-BEA9-14C99D7F008E} => moved successfully.
========= RemoveProxy: =========
HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings => value removed successfully.
HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings => value removed successfully.
HKU\S-1-5-21-831649127-2642341190-1748921548-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings => value removed successfully.
HKU\S-1-5-21-831649127-2642341190-1748921548-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings => value removed successfully.
========= End of RemoveProxy: =========
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
Unable to cancel {DEC3C6B5-ACB9-4ECF-8A87-AF32A8C26083}.
{27F63B7F-5388-4BE4-8D5B-C0B6D286BEC1} canceled.
{FF689439-AE35-4775-B6B3-66A0C6282AC5} canceled.
2 out of 3 jobs canceled.
========= End of CMD: =========
EmptyTemp: => 990.7 MB temporary data Removed.
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-08-10 03:49:42)<=
C:\ProgramData\msequupj.exe => is moved successfully
==== End of Fixlog 03:49:43 ====