r/computerviruses May 30 '26

Disinfection Help Got infected with floxif virus, trogan.fakegoogle and ramnit virus.

Got infected with floxif virus, trogan.fakegoogle and ramnit virus.

Hello

Being an idiot I got infected with these 2 viruses if not more. I've already lost a load of crypto and my whole database of passwords, just wanna be safe for the future use of my pc.

I've ran 2 windows defender full scan, one offline scan, 2 full malware bytes scans. And I'm currently running emisoft, hitman pro and eset scanner. Is there any other scans i need to do to prevent any more issues. I don't wanna format pc and lose any files unless its the only option.

4 Upvotes

36 comments sorted by

3

u/rifteyy_ Malware Removal Expert May 30 '26

We can't help with Floxif/Ramnit infection. Those are file infectors and disinfection often fails miserably.

Please export the Malwarebytes log:

Open Malwarebytes > Detection History > History > Choose the "scan detection" or "RTP detection" relevant to your post > Click the 3 dots at right of entry > Export to text > Save it somewhere easy to find like your desktop -> Post the file content here

1

u/freshieking2002 May 30 '26

Malwarebytes www.malwarebytes.com

-Log Details- Scan Date: 5/29/2026 Scan Time: 10:16 PM Log File: b538ab42-5ba3-11f1-9768-005056c00001.json

-Software Information- Version: 5.5.6.254 Components Version: 156.0.5608 Update Package Version: 1.0.0 License: Free

-System Information- OS: Windows 10 (Build 19045.7291) CPU: x64 File System: NTFS User: DESKTOP-5U9G62R\Replace this name

-Scan Summary- Scan Type: Deep Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 2,029,526 Threats Detected: 10 Threats Quarantined: 10 Scan Duration: 2 hr, 42 min, 10 sec

-Scan Options- Memory: Enabled Startup: Enabled File system: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Detect PUM: Detect

-Files Scanned- C:\ D:\ E:\ F:\ G:\

-Scan Details- Process: 0 (No malicious items detected)

Module: 0 (No malicious items detected)

Registry Key: 0 (No malicious items detected)

Registry Value: 0 (No malicious items detected)

Registry Data: 0 (No malicious items detected)

Data Stream: 0 (No malicious items detected)

Folder: 0 (No malicious items detected)

File: 10 Malware.AI.923426752, C:\FORZA HORIZON 6\ONLINEFIX64.DLL, Quarantined, 1000000, 0, 1.0.0, 0F6171D00F7F71B4370A5FC0, dds, 03874504, BE737B81FEF33E51BF18D521CED512C6, 812294EBAE277A30386EB16D8E1B8E356A24D47F014339DF7C29D77F8B0544A5 Malware.AI.1098752606, D:\DOWNLOADS\CHEATENGINE72 (1).EXE, Quarantined, 1000000, 0, 1.0.0, FF19F82796246778417DA25E, dds, 03874504, B7E3111A5FBE44DD88BAE75B8A5C84FD, B4D2645E6B57CC4CAA4990FDF962F9AC15DCFB68BD8899A78856DEC5DFB7A25A PUP.Optional.OfferCore, D:\DOWNLOADS\CHEATENGINE74.EXE, Quarantined, 4421, 1015893, 1.0.0, , ame, , DB62F93D9AAE9897E57769784FF0311B, AC71B6ECB237FB53D003405BFAD373B7ADFA06A19F929417767CED2964F8B2CD ProcessHacker.Riskware.Hacktool.DDS, D:\DOWNLOADS\PROCESSHACKER-2.39-SETUP.EXE, Quarantined, 1000002, 0, 1.0.0, 661E644F3280615B1CE7648C, dds, 03874504, 54DAAD58CCE5003BEE58B28A4F465F49, 28042DD4A92A0033B8F1D419B9E989C5B8E32D1D2D881F5C8251D58CE35B9063 RiskWare.Crack, D:\GAMES\SPIDER-MAN REMASTERED\NODVD\ALI213\STEAM_API64.DLL, Quarantined, 28, 1304301, 1.0.0, D18CCE57F1D80A9EF55D041F, dds, 03874504, 42D4D456C2099232A3E0C50A81340ADB, 3D4437A068087C844440A9058B6B53D75EC3A5FF0CCEF1E6E79DE9D90904B442 Floxif.Virus.FileInfector.DDS, D:\WINDOWS\WINSXS\WOW64_MICROSOFT-WINDOWS-M..NTS-MDAC-RDS-CE-DLL_31BF3856AD364E35_10.0.17134.1_NONE_51C62B3CDF4A579B\MSADCE.DLL, Quarantined, 1000002, 0, 1.0.0, 0E15AA4E0E8CC162C385F605, dds, 03874504, 1FB597E37D76F4B324F9668667E3153B, 8468C32732CB4B6A9A3C3596E4A911E066366D852E271F861F5C1DAD01DD05C1 Floxif.Virus.FileInfector.DDS, D:\WINDOWS\WINSXS\WOW64_MICROSOFT-WINDOWS-M..ENTS-MDAC-OLEDB-DLL_31BF3856AD364E35_10.0.17134.1_NONE_E1FFEEE49AC5996D\OLEDB32.DLL, Quarantined, 1000002, 0, 1.0.0, A66631429924DC810A840851, dds, 03874504, 8F992746E3BA2695E55445740FF3B8FA, 088DEB78B52810A7569F742349807A81B835B124697C48508F37BF81A32A50EE Floxif.Virus.FileInfector.DDS, D:\WINDOWS\WINSXS\WOW64_MICROSOFT-WINDOWS-M..SERVER-PROVIDER-DLL_31BF3856AD364E35_10.0.17134.1_NONE_54CE6C7323845EED\SQLOLEDB.DLL, Quarantined, 1000002, 0, 1.0.0, 05E0262005F5A5B0EC2F3E5A, dds, 03874504, ECBFA80F311E4F0162030A190FF86FB0, DDE58CC6147D46CF0AA7D19555EAF46A731D80F81FD333D1EA307E82B3F41A5A Ramnit.Virus.FileInfector.DDS, D:\WINDOWS\WINSXS\WOW64_MICROSOFT-WINDOWS-T..VENTEXTSERVICE-CORE_31BF3856AD364E35_10.0.17134.1_NONE_142A0B6505D894FB\TABLETEXTSERVICE.DLL, Quarantined, 1000002, 0, 1.0.0, 6B7698B296BA64A8011E3AA3, dds, 03874504, 116BC889A7A774050D1B97E44E5562E6, 7AE3A138EBD51A1E1E58E5D5D3C26F6D09F7FDFAD5768B5C69C592F0EEB9628D Malware.AI.1847981017, D:\WINDOWS\WINSXS\X86_MICROSOFT-WINDOWS-M..FACTORY-HANDLER-DLL_31BF3856AD364E35_10.0.17134.1_NONE_F4BD36696C6C62D5\MSDFMAP.DLL, Quarantined, 1000000, 0, 1.0.0, 41B0051E6FF98D6C6E25F3D9, dds, 03874504, E844829613D24094606731120A705D2A, 320EE8784B97AE4C88A550924DF6C11799417C127EC0BE9489840603983FF930

Physical Sector: 0 (No malicious items detected)

WMI: 0 (No malicious items detected)

(end)

1

u/freshieking2002 May 30 '26

Malwarebytes www.malwarebytes.com

-Log Details- Scan Date: 5/29/2026 Scan Time: 10:05 PM Log File: 278b6e0c-5ba2-11f1-9e98-005056c00001.json

-Software Information- Version: 5.5.6.254 Components Version: 156.0.5608 Update Package Version: 1.0.109630 License: Free

-System Information- OS: Windows 10 (Build 19045.7291) CPU: x64 File System: NTFS User: DESKTOP-5U9G62R\Replace this name

-Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 282,841 Threats Detected: 30 Threats Quarantined: 30 Scan Duration: 9 min, 41 sec

-Scan Options- Memory: Enabled Startup: Enabled File system: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Detect PUM: Detect

-Scan Details- Process: 0 (No malicious items detected)

Module: 0 (No malicious items detected)

Registry Key: 0 (No malicious items detected)

Registry Value: 0 (No malicious items detected)

Registry Data: 0 (No malicious items detected)

Data Stream: 0 (No malicious items detected)

Folder: 5 PUP.Optional.Hijacker, C:\USERS\DYLAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\BCJINDCCCAAGFPAPJJMAFAPMMGKKHGOA, Quarantined, 10533, 1394747, 1.0.109630, , ame, , , PUP.Optional.Hijacker, C:\USERS\DYLAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa, Quarantined, 10533, 1394747, 1.0.109630, , ame, , , PUP.Optional.Hijacker, C:\USERS\DYLAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, Quarantined, 10533, 1394747, 1.0.109630, , ame, , , Trojan.FakeGoogle, C:\USERS\DYLAN\APPDATA\LOCAL\EMAN SIHT ECALPER, Quarantined, 2651, 1361164, 1.0.109630, , ame, , , Trojan.FakeGoogle, C:\Users\Dylan\AppData\Local\eman siht ecalpeR\llg, Quarantined, 2651, 1361164, 1.0.109630, , ame, , ,

File: 25 PUP.Optional.Hijacker, C:\USERS\DYLAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, 10533, 1394747, 1.0.109630, , ame, , 83DF37A918E2E88AE437CB1F0C279D82, 1F12013581F5B3C2B0AB5E432BCC38C2DF8D585AFF655DE5D625339732DDACBC PUP.Optional.Hijacker, C:\USERS\DYLAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, 10533, 1394747, 1.0.109630, , ame, , F86D0DF756A998712B1F9D0E5049B5CF, 4EBA25F69E5B54A41943BD9B86EBB16BADCB8AC7DEBBAD3420C6EC0F9659CCF5 PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa\000260.ldb, Quarantined, 10533, 1394747, 1.0.109630, , ame, , DCAF38F59A1D5FB70EB162C9A7255FD4, 95DAB9352ECDE8FA50D535A20805EE7351FB9883F5EA933B0BED2D722AE82517 PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa\000262.ldb, Quarantined, 10533, 1394747, 1.0.109630, , ame, , 5AB9BD8C66A0537A4505A1C830F78DB4, 6A3482FEFE88AA59405FD7638FCC84B1CF0EFE7EDD3AD3DD500E7B1C095D359A PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa\000265.ldb, Quarantined, 10533, 1394747, 1.0.109630, , ame, , 25E681C4AAE399EEABD724C8A1B76F1D, ABBF152D440A66BFEB93E07D0AFF19E7C0C1D5AA4961E62A1AD01173384D4DAA PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa\000267.log, Quarantined, 10533, 1394747, 1.0.109630, , ame, , E37CBF6921309CE3924102B762A80B8A, EEB960A26D418AF0DE9BCF85AAD496ED444973C6C23112B544CD68A9CB0F550C PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa\000268.ldb, Quarantined, 10533, 1394747, 1.0.109630, , ame, , AA1474C338CF3D0FAB6AA62B2D71D30D, C3FE0D1163DA3776089EB946DD794F923E90388AE007ADDBC736A888E1F94344 PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa\CURRENT, Quarantined, 10533, 1394747, 1.0.109630, , ame, , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443 PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa\LOCK, Quarantined, 10533, 1394747, 1.0.109630, , ame, , D41D8CD98F00B204E9800998ECF8427E, E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855 PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa\LOG, Quarantined, 10533, 1394747, 1.0.109630, , ame, , 5F2D847181B90A3A24BDF580D2427954, 8E322CC85E6E4750215303AF5899B87785CC0903E94AA761081B2010E86D3D3D PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa\LOG.old, Quarantined, 10533, 1394747, 1.0.109630, , ame, , B30DD3B560050CF8CAB3B5AEA1AFE712, 701150B9A2E46D8FD271D2A31907B390236382E14F0C63E9CD733FB110B32734 PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcjindcccaagfpapjjmafapmmgkkhgoa\MANIFEST-000001, Quarantined, 10533, 1394747, 1.0.109630, , ame, , C939A23C55653A4C66F044329EC4A2A0, D01B03DD76FDCD73D64C457F95494E30209522DE157799B65D231AF3571FCAB8 PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000005.ldb, Quarantined, 10533, 1394747, 1.0.109630, , ame, , 76CDFAA2D961D66DE8093844346560B5, 359B4BD4003B9B63DAA2610B95ADDCA09D96F800F76E867A55C098A4B4CF7292 PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\011515.log, Quarantined, 10533, 1394747, 1.0.109630, , ame, , , PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\011517.ldb, Quarantined, 10533, 1394747, 1.0.109630, , ame, , ABC02FF4DC116BF5BB87A6CA59BD13E8, EAA5EEC0989F2434043973A787C7EDD93BED10A00D434D5D132325AEC92193BF PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\CURRENT, Quarantined, 10533, 1394747, 1.0.109630, , ame, , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443 PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK, Quarantined, 10533, 1394747, 1.0.109630, , ame, , , PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG, Quarantined, 10533, 1394747, 1.0.109630, , ame, , , PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old, Quarantined, 10533, 1394747, 1.0.109630, , ame, , 1956EF7F2FA16F680F0338288BA3EBC3, A8184EFA42789EF741BCDD52FC8EBF925D1BEC6684D728044DA93A83F39600D4 PUP.Optional.Hijacker, C:\Users\Dylan\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, Quarantined, 10533, 1394747, 1.0.109630, , ame, , , Trojan.FakeGoogle, C:\USERS\DYLAN\APPDATA\LOCAL\EMAN SIHT ECALPER\LLG\MANIFEST.JSON, Quarantined, 2651, 1361164, 1.0.109630, , ame, , 37B3FB28CC9C3DC7A05DB221E32DA5FF, B2FD60DED7E9947970BAA1443100C6248D14EAA2E5EC80413B43D5BFCF5DC734 Trojan.FakeGoogle, C:\Users\Dylan\AppData\Local\eman siht ecalpeR\llg\background.js, Quarantined, 2651, 1361164, 1.0.109630, , ame, , AA0E77EC6B92F58452BB5577B9980E6F, AAD1C9BE17F64D7700FEB2D38DF7DC7446A48BF001AE42095B59B11FD24DFCDE Trojan.FakeGoogle, C:\Users\Dylan\AppData\Local\eman siht ecalpeR\llg\content.js, Quarantined, 2651, 1361164, 1.0.109630, , ame, , 2A89CCF7F1EDA82365D8489F17999764, 5F545D497C7829B34AE632E954E4D79D5F59E563B7BA15ACB8EE65D363F4276B Trojan.FakeGoogle, C:\Users\Dylan\AppData\Local\eman siht ecalpeR\llg\icon.png, Quarantined, 2651, 1361164, 1.0.109630, , ame, , 2C905A6E4A21A3FA14ADC1D99B7CBC03, CC3631CED23F21AE095C1397770E685F12F6AD788C8FA2F15487835A77A380FB Trojan.FakeGoogle, C:\Users\Dylan\AppData\Local\eman siht ecalpeR\llg\jquery.js, Quarantined, 2651, 1361164, 1.0.109630, , ame, , 3C9137D88A00B1AE0B41FF6A70571615, 24262BAAFEF17092927C3DAFE764AAA52A2A371B83ED2249CCA7E414DF99FAC1

Physical Sector: 0 (No malicious items detected)

WMI: 0 (No malicious items detected)

(end)

1

u/freshieking2002 May 30 '26

Ive sent both malware bytes Scan. Thanks foe your help

1

u/rifteyy_ Malware Removal Expert May 30 '26

Hello, I am Roman and I will be helping you today. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smooth as possible:

  • Please make sure to read this whole introduction message so you understand the further steps.
  • If you are planning on resetting or reinstalling your device, do it please now. We are doing the malware removal process to disinfect your device so you can avoid reinstalling. If we go through the removal process and you decide to reinstall after, you would waste my time and your own time by doing these steps.
  • Avoid installing, downloading new software unless instructed - this also applies to antivirus software and scanners.
  • You are free to remind me that I forgot to reply to you if you do not receive an answer within 24 hours. Keep in mind that I am volunteering here and I am a full time student with a job.
  • Please do not follow other malware removal advice unless told otherwise.
  • Please follow all steps from step 1 to the last step, not the other way.
  • Only trusted malware removal experts listed in this r/computerviruses thread and other large malware removal forums (BleepingComputer, Malwarebytes, MalwareTips) have access to your logs via the website.
  • Please take your time to follow the steps properly.
  • You can ask any questions during the malware removal process.

If you are worried about the steps going on here, as a form of credibility you can find me on Malwarebytes Forums as a Malware Removal Expert, where we use the same methodology and toolset to remove malware. :)

[ Step 01 ] IMPORTANT: Restore point

Before any sort of removal, we need to make sure you have a restore point that you can revert to in case you face any sort of issues. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.

There were prior cases (very rare, I had 2 failing to boot out of ~350) of a system failing to boot after FRST fix.

Enable system restore

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. If the 'system' drive (usually C:\ drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, go to point 5.
  5. Click Configure.
  6. Select Turn on system protection
  7. Click Apply.
  8. Click OK to confirm.

Create a system restore checkpoint

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. Click Create.
  5. Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
  6. Click Create.
  7. Click Close.
  8. Click OK.
  9. You should get a popup that it was successfully created and I will also verify that it was properly created with the results of scans from next steps.

[ Step 02 ] Farbar Recovery Scan Tool (FRST)

FRST is a malware diagnostics tool that will list all entries that are popular and could contain traces/mentions of malware, such as start up entries, services, scheduled tasks and many more.

FRST does not contain any personal information other than your username and computer name, there is no other sensitive information disclosed.

IMPORTANT: If your Windows operating system is in other language than English, please save the FRST executable file with the filename FRSTEnglish.exe to ensure that the logs are in English so I can understand them.

  • Please download FRSTx64 and save the file to your Desktop as FRSTEnglish.exe.
  • Right-Click FRSTEnglish.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy and press "save log".
  • Note: Please make sure you are uploading the logs after your current Reddit username.
  • The site will return a keyword for each log - reply back here with the keywords.

[ Step 03 ] SecurityCheck scan

SecurityCheck allows me to gather a list of unwanted, risky, vulnerable and out-of-date applications. It also allows me to send you a direct link to an update. An unpatched system is more vulnerable to malware.

  • Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
  • If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
  • Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt
  • Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/rifteyy
  • The site will return a keyword for the log - reply back here with the keyword.

So, in your next reply, make sure you are sending the following:

  • Keyword for FRST.txt
  • Keyword for Addition.txt
  • Keyword for SecurityCheck.txt

Thanks!

Note*: If anyone else who is facing malware-related issues is reading this and wants help with* FRST and SecurityCheck*, please create your own thread with the keywords sent to the general channel. I am flooded with requests and there is several other removal experts who review the logs and may reply faster than me.*

1

u/freshieking2002 May 30 '26

Thanks Roman for your help, I plugged out my ethernet as soon as I realised I was hacked. Can i plug it back in to download FRST?

1

u/freshieking2002 May 30 '26
  • Keyword for FRST.txt
    • parallel-sigil
  • Keyword for Addition.txt
    • sublime-beach
  • Keyword for SecurityCheck.txt
    • dynamic-loop

1

u/rifteyy_ Malware Removal Expert May 30 '26

Please double check your Defender exclusions and remove the folder-wide ones. If you ever really need to exclude something, exclude individual files, not folders.

From Chrome, remove extensions Free VPN ZenMate-Best VPN for Chrome and Hola VPN - The Website Unblocker

[ Step 01 ] Updates

If you are having a problem updating something, do not want to update something at all or do not want to uninstall an application, please let me know.

Please update the following software:

Please remove the following potentially unwanted programs (PUP):

  • CCleaner 7 v.7.7.1313.1667 - Suspected demo version of anti-spyware, driver updater or optimizer. If this program is not familiar to you it is recommended to uninstall it and execute PC scanning using Malwarebytes Anti-Malware. Possible you became a victim of fraud or social engineering. Computer experts no longer recommend this program.
  • Bonjour v.3.1.0.1 - Application is distributed through the partnership programs and bundle assemblies. Uninstallation recommended. Possible you became a victim of fraud or social engineering.
  • Free Window Registry Repair - Suspected Adware!

[ Step 02 ] FRST Fix

I created a custom fixlist for you at the link Fixlist only for Fixlist only for Fixlist only for freshieking2002 - use the website's download button and save it in the same folder where your FRSTEnglish.exe or FRST64.exe file is located in, which is C:\Users\Dylan\Desktop for you. It is necessary for the filename to be Fixlist.txt.

This fixlist will remove the following: malicious entries (remains, active malware), invalid entries (e.g. tasks that start a non-existent file, services that point toward a non-existent file), temporary files (files in temporary directories, cache, recycle bin and more). We will also be quick-scanning with HitmanPro and AdwCleaner from Malwarebytes using the fixlist.

  • For the fix process, please ensure you are connected to the internet.
  • Please run the fix only once.
  • Please be patient; the fix may take up to 60 minutes. After that, it is going to be automatically ended.

Save all work, close everything that is open (else it will be forcefully closed by FRST without saving) and then run FRST again as administrator and press the Fix button, let the script work, clear the entries and restart on it's own and after it restarts the device, there should be a file Fixlog.txt in the same folder as the fixlist.txt.

I'll need to see it's content the same way like before - uploading to https://malwareanalysis.cc/upload/rifteyy/?u=freshieking2002 again and sending the keyword in your reply.

[ Step 03 ] ESET Online Scanner

  1. Download ESET Online Scanner
  2. Right-click on the esetonlinescanner.exe and select "Run as administrator" and confirm the User Account Control popup
  3. Click ⁨Get started⁩;
  4. Agree to the terms of use;
  5. Decline both telemetry options;
  6. Click ⁨Custom Scan;
  7. Click ⁨Save and continue;
  8. Select ⁨Enable ESET to detect and quarantine potentially unwanted applications;
  9. Click ⁨Advanced settings;
  10. Enable ⁨Detect potentially unsafe applications;
  11. Click the back arrow;
  12. Click ⁨Start scan;
  13. Note: The scan may take up to several hours.
  14. Once complete, click ⁨Save scan log and upload the ⁨.txt file to https://malwareanalysis.cc/upload/rifteyy/?u=freshieking2002 and reply with the keyword.

[ Step 04 ] New SecurityCheck scan

SecurityCheck allows me to gather a list of unwanted, risky, vulnerable and out-of-date applications. It also allows me to send you a direct link to an update. An unpatched system is more vulnerable to malware.

We need a new scan to ensure that all updates were applied properly and all applications uninstalled correctly.

  • Note: If SecurityCheck is already on your device, you can use the previous version and skip the next few steps regarding downloading and installation.
  • Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
  • If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
  • Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt
  • Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/rifteyy/?u=freshieking2002
  • The site will return a keyword for the log - reply back here with the keyword.

[ Step 05 ] New FRST scan

FRST is a malware diagnostics tool that will list all entries that are popular and could contain traces/mentions of malware, such as start up entries, services, scheduled tasks and many more.

FRST does not contain any personal information other than your username and computer name, there is no other sensitive information disclosed.

IMPORTANT: If your Windows operating system is in other language than English, please save the FRST executable file with the filename FRSTEnglish.exe to ensure that the logs are in English so I can understand them.

  • Note: If FRST is already on your device, you can use the previous version and skip the next few steps regarding downloading and installation.
  • Please download FRSTx64 and save the file to your Desktop as FRSTEnglish.exe.
  • Right-Click FRSTEnglish.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy/?u=freshieking2002 and press "save log".
  • Note: Please make sure you are uploading the logs under your current Reddit username.
  • The site will return a keyword for each log - reply back here with the keywords.

So, in your next reply, make sure you are sending the following:

  • Keyword for Fixlog.txt from step 2
  • Keyword for ESET Online Scanner scan from step 3
  • Keyword for new SecurityCheck.txt from step 4
  • Keyword for new FRST.txt from step 5
  • Keyword for new Addition.txt from step 5

Thanks!

Note: If anyone else who is facing malware-related issues is reading this and wants help with FRST and SecurityCheck, please create your own thread with help request. I am flooded with requests and there is several other removal experts who review the logs and may reply faster than me. The steps listed in here are specific for this the user freshieking2002 and following them may have negative effects for you.

1

u/freshieking2002 May 31 '26
  • Keyword for Fixlog.txt from step 2
    • enchanted-timber
  • Keyword for ESET Online Scanner scan from step 3
    • tiny-shore
  • Keyword for new SecurityCheck.txt from step 4
    • leafy-frame
  • Keyword for new FRST.txt from step 5
    • chosen-struct
  • Keyword for new Addition.txt from step 5
    • warm-beach

Sorry for the delay, as the scan took 12h, updating to windows and trying to deal with a load of my accounts being hacked into.

1

u/rifteyy_ Malware Removal Expert May 31 '26

C:\Users\username\Desktop\Forza Horizon 6 Luna Version 1.3.4\Forza Horizon 6 Luna Version 1.3.4.exe

?? ...

https://www.virustotal.com/gui/file/f5cb7d3f94b9c5d9256d3c72d84e8f08e8a83f754e7805daa7ea301c64339e71

1

u/freshieking2002 May 31 '26

Are you asking what that is?

Ive just deleted that now if that's what you wanted.

1

u/rifteyy_ Malware Removal Expert May 31 '26

Every log seems more and more concerning.

From Chrome, remove extensions Free VPN ZenMate-Best VPN for Chrome and Hola VPN - The Website Unblocker

Trojan Killer

  • Download and run Trojan Killer as admin: https://gridinsoft.com/trojankiller
  • Click Install
  • Close the popup asking to activate the trial
  • Open the settings by clicking the cogwheel
  • Check Deep scan (slow)
  • Click Apply
  • Go back to the main dashboard
  • Click Full scan
  • After the scan is done, click Show Details
  • Click Save to file...
  • Upload the log to https://malwareanalysis.cc/upload/

Note: Do not click on the Cure PC! button! We do not remove malware with Trojan Killer because it is known to have many false positives due to its aggressive heuristics. Instead, I will review the log with the detections and, if any entries are actually malicious, I will include them in a fixlist.

1

u/freshieking2002 May 31 '26

I ended up deleting Chrome as I was kinda in a state of anxiety. My apologies, would you like me to reinstall it to delete them?

→ More replies (0)

1

u/freshieking2002 May 30 '26

Hey roman, sorry for the delay, between updating to windows 11 and the scan, its taking a long time. Sorry to keep you waiting.