This article can help you if you have an unknown Malwarebytes MS removal tool installed on your computer.
Step 01 and step 02 are not working (virus cannot be detected), so I followed the third steps and here are the details of the computer file logs generated.
Farbar Recovery Scan Tool (FRST) (x86) Version: 01/02/2018
Performed by Deepak (administrator) on DEEPAK-PC 17:39:20)
Running (01.11.2018 from C: Users Deepak Downloads
Loaded profiles: Deepak (Available profiles: Deepak)
Platform: Microsoft Windows 7 Ultimate Service Pack 5 (X86) Language: US English
Internet Explorer version 19 (default browser: Chrome)
Startup mode: normal
Farbar Recovery Scan Tool Tutorial: http://www.geekstogo.An com / forum / topic / 335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool /
(If the entry is safe in the patch list, the operation will be closed. The file will not be moved.)
(TeamViewer GmbH) C: Program Files TeamViewer TeamViewer_Service.exe
(Malwarebytes) C: Program Files Malwarebytes Anti-Malware MBAMService.exe
(Skillbrains) C: Program Files Skillbrains lightshot Lightshot.exe
(Oracle Corporation) C: Program Files Common Files Java Java Update jusched.exe
(Google Inc.) C: Program Files Google Update GoogleCrashHandler.exe
(f.lux Software LLC) C: Users Deepak AppData Local FluxSoftware Flux flux.exe
(Malwarebytes) C: Program Files Malwarebytes Anti-Malware mbamtray.exe
(Google Inc.) C: Program Files Google Chrome Application chrome.exe
(Google Inc.) C: Program Files Google Chrome Application chrome.exe
(Google Inc.) C: Program Files Google Chrome Application chrome.exe
(Microsoft Corporation) C: Windows Microsoft.NET Framework v4.0.30319 mscorsvw.exe
(Malwarebytes) C: Program Files Malwarebytes Anti-Malware mbam.exe
(Google Inc.) C: Program Files Google Chrome Application chrome.exe
(If a specific entry is in the hotfix list, all registry entries are restored or deleted by default. The file cannot be moved.)
HKLM … Run: [Lightshot] => C: Program Files Skillbrains lightshot Lightshot.exe [225944 04/11/2017] ()
HKLM … Run: [SunJavaUpdateSched] => Files Common c: program Files Java Java Update jusched.exe [587288 09/05/2017] (Oracle Corporation)
HKU S-1-5-21-3322282323-1521124264-3092823622-1000 … Run: [f.lux] => C: Users Deepak AppData Local FluxSoftware Flux flux.exe [ 1678840 10.11.2017] (f.lux Software LLC)
(If there is an addition to the hotfix list because it is a registry entry, it will be converted to deletedor restored to default.)
Internet Explorer:
HKU S-1-5-21-3322282323-1521124264-3092823622-1000 Software Microsoft Internet Explorer Main, start page redirect cache = hxxp: //www.msn.Java ™ com / en-in / ? ocid = iehp
bho: SSV Helper -> 761497BB-D6F0-462C-B6EB-D4DAF1D92D43 -> C: Program Files Java jre1.8.0_151 bin ssv.dll [2018-01-10] (Oracle Corporation)
FF (Oracle DefaultProfile: o1rqh4ku.default
FF ProfilePath: C: Users Deepak AppData Roaming Mozilla Firefox Profiles o1rqh4ku.default [2018-01-11]
FF Plugin: @ / DTPlugin, version = 11.151.2 -> C: Program Files Java jre1.8.0_151 bin dtplugin npDeployJava1.dll (Oracle [2018-01-10] Corporation)
FF Plugin: @ / JavaPlugin, version = 11.151.2 -> C: Program Files Java jre1.8.0_151 bin plugin2 npjp2.dll [10.01.2018] (Oracle Corporation)
FF @tools plugin: / Google Update; version = 3 -> C: Program Files Google Update npGoogleUpdate3.dll [2018-01-01] (Google Inc.)
FF Plugin: @ / Google Update; version = 9 -> C: Programs Google Update npGoogleUpdate3.dll [2018-01-01] (Google Inc.)
FF Plugin: Adobe Reader C: Program Files -> Files Adobe Acrobat Reader DC Reader AIR nppdf32.dll [2017-11-05] (Adobe Systems Inc.)
CHR Profile: C: Users Deepak AppData Local Google Chrome User Data Default [2018-01-11]
Expanded Ne CHR: (Slides) – C: Users Deepak AppData Local Google Chrome User Data Default Extensions aapocclcgogkmnckokdopfmhonfmgoek [2018-01-01]
Extension CHR: – (docs) C: Users Deepak AppData Local Google Chrome User Data Default Extensions aohghmighlieiainnegkcijnfilokake [2018-01-01]
CHR extension: (Google Drive) – C: Users Deepak AppData Local Google Chrome User Data Default Extensions apdfllckaahabafndbhieahigkjlhalf [2018-01-01]
Extension CHR: (YouTube) – C: Users Deepak AppData Local Google Chrome User Data Default Extensions blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-01]
Extension CHR: (Flikover) – C: Users Deepak AppData Local Google Chrome User Data Default Extensions bpchjdomogcnjcpiommjlhgmngalhppb [01/10/2018]
Extension CHR: (Tables) – C: Users Deepak AppData Local Google Chrome User Data Default Extensions felcaaldnbdncclmgdcncolpebgiejap [2018-01-01]
Extension CHR: (FlikoverTwo) – C: Users Deepak AppData Local Google Chrome User Data Default Extensions fkdgnchibkdnlcffkafniolmfiahehjh [2018-01-01]
CHR Extension: (Google Docs Offline) – C: Users Deepak AppData Local Google Chrome User Data Default Extensions ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-02]
Extension CHR: (Chrome Web Store Payments) – C: Users Deepak AppData Local Google Chrome User Data Default Extensions nmmhkkegccagdldgiimedpiccmgmieda [2018-01-01]
CHR extension: (Gmail) – C: Users Deepak AppData Local Google Chrome User Data Default Extensions pjkljhegncpnkpknbcohdijeoejaedia [2018-01-01]
Extension CHR: (Chrome Media Router) – C: Users Deepak AppData Local Google Chrome User Data Default Extensions pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-01]
(If your path is on the hotfix list, it will most likely be removed from the registry. The folder will not be moved unless it is placed separately.)
MBAM R2 service; C: Program Files Malwarebytes Anti-Malware mbamservice. [4563920 exe] (Malwarebytes)
R2 TeamViewer; C: Program Files TeamViewer TeamViewer_Service.exe 12/15/2017] [10945776 (TeamViewer GmbH)
R2 WinDefend; C: Program Files Windows Defender mpsvc.dll [680960 2016-05-16] (Microsoft Corporation)
(If the entry is in the hotfix list, it is removed from the computer. The file does not move, as shown separately.)
R1 ES protection driver; C: Windows system32 drivers mbae.sys [59896 2017-11-29] ()
chameleon R2 MBAM; C: Windows System32 Drivers MbamChameleon.sys [168376 12/30/2017] (Malwarebytes)
R3 C: Windows System32 DRIVERS farflt mbamfarflt; .sys 01/11/2018] [91576 (Malwarebytes)
MBAM R3 protection; C: Windows System32 DRIVERS mbam.sys 2018-01-11] [40376 (Malwarebytes)
R3 MBAMSwissArmy; C: Windows System32 Drivers mbamswissarmy.sys [221112 2018-01-11] (Malwarebytes)
R3 MBAMWebProtection; C: Windows System32 DRIVERS mwac.sys [65824 (Malwarebytes)
R3 2018-01-11] MP sensor; C: Windows System32 DRIVERS ASACPI. [5810 sys 2004-08-13] ()
C3-VGPU; System32 drivers rdvgkmd.sys [X]
S1 ZAM; ?? C: Windows System32 drivers zam32.sys [X]
S1 ZAM_Guard; ?? C: Windows System32 drivers zamguard32.sys [X]
(If an entry is clearly in the hotfix list, it is sometimes removed from the registry. Do not move the file unless it is listed separately.)
(If there is another entry in the patch list, that particular file / folder will be moved.)
01-11-2018 17:39 01-01-2018 – 17:41 – 000007934 _____ C: Users Deepak Downloads FRST.txt
01-11-2018 17:39 01-01-2018> 17:39 – 00000000 ____D C: FRST
01-11-2018 17:38 01-01-2018 – 17:38 – 001753600 _____ (Farbar) C: Users Deepak Downloads FRST.exe
17:35 10.01.2018 – 17:35 10.01.2018 / 000000000 ____D C: Users Deepak AppData Roaming BeamUsUp
01/10/2018 17:34 – 01/10/2018 17:34 – 00000000 ____D C: Users Deepak AppData LocalLow Sun
01/10/2018 17:33 – 01/10/2018 17:33 – – 00000000 ____D C: Users Deepak AppData Roaming Sun
2018-01-10 17:33 electronic 2018-01-10 17:33 – 00000000 ____D C: ProgramData Microsoft Windows Start Menu Programs Java
10.01.2018 17:33 – 10.01.2018 17:33 – 0000000
