• Content Count

  • Joined

  • Last visited

Everything posted by AOH

  1. Since yesterday, my PC has been infected with the virus mentioned in the title of the topic, according to Windows Defender. I deleted a couple of programs that were installed along with the virus but after a couple of restarts, command prompts and unknown programs seem to start along with Windows. In addition, there is a bunch of exclusions for certain programs in folders with made up names that Windows Defender is unable to scan. I never excluded those folders myself. What is more, these said folders are located in the Program Files (x86), ProgramData, AppData\Local\Temp, WINDOWS\Temp folders of my PC. I refrain from logging in in various sites and apps I used to, at least without creating a new password, since I'm terrified that my personal data will be compromised through the malicious program. I do not know whether they've already been compromised or the worst is yet to come. I will stand by, waiting for further instructions as to how to proceed on the matter. Thank you in advance. scan_181011-012112.txt Addition.txt FRST.txt
  2. Thank you once again for all your help. You can close the thread if you wish.
  3. Thank you for your being so helpful and patient with me through this whole process. A true professional in malware removal. Thank you yet again for your much appreciated help.
  4. It didn't show up after I reopened Chrome.
  5. Google's search engine was the default, I found the one you mentioned before and removed it from Chrome's suggested search engines. How should I proceed?
  6. Windows Defender does not detect the program. However, I do not know how to reset Chrome's Search preferences.
  7. How can I reset Chrome's Search preferences? Should I whitelist the detection through EEK?
  8. Reseted Chrome to default settings and ran the fix. Here you are: Fixlog.txt
  9. Indeed. The file is still there. scan_181019-032848.txt FRST.txt
  10. Should I run new scans with EEK and FRST? Here's AdwCleaner' log: AdwCleaner[S01].txt
  11. After running a scan with RogueKiller and deleting the findings, both the folder and the PUP are present, according to EEK's scan that I ran after restarting my system. Here are the logs: RogueKiller Report.txt scan_181018-050058.txt FRST.txt
  12. Someone under the name "CREATOR OWNER" has rights to that very folder. I managed to remove those rights as well as the PUP through EEK, but after restarting my systerm, the PUP still exists along with the folder. "CREATOR OWNER" still has rights to the folder.
  13. Should I try to delete the PUP through EEK, restart my PC and run some fresh scans?
  14. The problem seems to persist. Here are the new logs: scan_181018-030652.txt FRST.txt
  15. Thank you for bringing this to my attention. I proceeded to completely remove the pirated software from my computer. Here are the new scans: FRST.txt scan_181017-032814.txt
  16. Actually, before deleting the programs I decided to run a final scan and it looks like a PUP named "Application.AppInstall(A)" and located in C:\ProgramData\simplitec is still there. I remember it showing up in two of the last scans before the logs were finally clean. Could it be coming back after I terminate and start my PC? Here are the logs of the most recent scans: scan_181016-134513.txt Addition.txt FRST.txt
  17. Will do. Thank you once again for your help.
  18. Thank you very much for being so helpful and analytical throughout this whole process. I truly appreciate your help and advice. You're doing a great job in maintaining this forum as one of the best one should visit when seeking malware removal expertise. Keep it up. Thank you very much once again.
  19. Everything seems fine. My only concern is whether I should change my log in passwords or not. Is it possible that they could have been intercepted? What would you suggest?
  20. Here you go: scan_181013-024858.txt FRST.txt
  21. I checked manually for malware through Chrome and nothing was found. Here's FRST's fixlog: Fixlog.txt
  22. Here you go: RogueKiller Report.txt scan_181013-020800.txt FRST.txt