ok i will do if i get it and here you go a new logs show the same host file
MiniToolBox by Farbar Version: 14-04-2015
Ran by b (administrator) on 10-05-2015 at 22:53:47
Running from "C:\Users\b\Downloads"
Microsoft Windows 7 Ultimate Service Pack 1 (X86)
Model: Aspire 4738 Manufacturer: Acer
Boot Mode: Normal
***************************************************************************
========================= Hosts content: =================================
0.0.0.0 0.0.0.0 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
0.0.0.0 cdn.appround.biz
0.0.0.0 cdn.bigspeedpro.com
0.0.0.0 cdn.bispd.com
0.0.0.0 cdn.bisrv.com
0.0.0.0 cdn.cdndp.com
0.0.0.0 cdn.download.sweetpacks.com
0.0.0.0 cdn.dpdownload.com
0.0.0.0 cdn.visualbee.net
**** End of log ****
Rkill 2.7.0 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.htmlProgram started at: 05/10/2015 10:50:24 PM in x86 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Users\b\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe (PID: 3136) [UP-HEUR]
1 proccess terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
20 out of 34 HOSTS entries shown.
Please review HOSTS file for further entries.
Program finished at: 05/10/2015 10:52:18 PM
Execution time: 0 hours(s), 1 minute(s), and 54 seconds(s)
RogueKiller V10.6.2.0 [May 4 2015] by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/softwares/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : b [Administrator]
Started from : C:\Users\b\Downloads\RogueKiller.exe
Mode : Scan -- Date : 05/10/2015 23:13:02
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 1 ¤¤¤
[Suspicious.Path] HKEY_USERS\S-1-5-21-514264213-2229734732-364638501-1000\Software\Microsoft\Windows\CurrentVersion\Run | Epic Privacy Browser Installer : "C:\Users\b\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe" /c [-]
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 34 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 media.opencandy.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.opencandy.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 tracking.opencandy.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 api.opencandy.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 installer.betterinstaller.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 installer.filebulldog.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 inno.bisrv.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 nsis.bisrv.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.file2desktop.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.goateastcach.us
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.guttastatdk.us
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.inskinmedia.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.insta.oibundles2.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.insta.playbryte.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.llogetfastcach.us
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.montiera.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.msdwnld.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.mypcbackup.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.ppdownload.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.riceateastcach.us
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.shyapotato.us
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.solimba.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.tuto4pc.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.appround.biz
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.bigspeedpro.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.bispd.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.bisrv.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.cdndp.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.download.sweetpacks.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.dpdownload.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 cdn.visualbee.net
¤¤¤ Antirootkit : 1 (Driver: Loaded) ¤¤¤
[IAT:Inl(Hook.IEAT)] (explorer.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xffffffffcb718159 (call 0x54000009)
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MK3265GSX +++++
--- User ---
[MBR] 7030807e5d6303089fdba77edec97688
[BSP] bf4b40ef244bc7ef2f46fa3dd96446e8 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 119900 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 245762048 | Size: 185243 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_09082014_134759.log - RKreport_DEL_09082014_141307.log - RKreport_SCN_09142014_045915.log - RKreport_DEL_09142014_050125.log
RKreport_SCN_09202014_085423.log - RKreport_SCN_09202014_090119.log - RKreport_SCN_09252014_052050.log - RKreport_DEL_09252014_052202.log
RKreport_SCN_09282014_125600.log - RKreport_DEL_09282014_125744.log - RKreport_SCN_09292014_110602.log - RKreport_DEL_09292014_110652.log
RKreport_SCN_10012014_070817.log - RKreport_DEL_10012014_070932.log - RKreport_SCN_10042014_142209.log - RKreport_DEL_10042014_142257.log
RKreport_SCN_10062014_192927.log - RKreport_DEL_10062014_193014.log - RKreport_SCN_10102014_164710.log - RKreport_SCN_10112014_132953.log
RKreport_DEL_10112014_133430.log - RKreport_SCN_10132014_124344.log - RKreport_DEL_10132014_124401.log - RKreport_SCN_10142014_002827.log
RKreport_SCN_10142014_170018.log - RKreport_SCN_10152014_113619.log - RKreport_SCN_10182014_051907.log - RKreport_DEL_10182014_060018.log
RKreport_SCN_10182014_113052.log - RKreport_DEL_10182014_113117.log - RKreport_SCN_10222014_175555.log - RKreport_DEL_10222014_181836.log
RKreport_SCN_10232014_093252.log - RKreport_SCN_10292014_005639.log - RKreport_DEL_10292014_005746.log - RKreport_SCN_11012014_001900.log
RKreport_DEL_11012014_002142.log - RKreport_SCN_11032014_210837.log - RKreport_DEL_11032014_210940.log - RKreport_SCN_11092014_134242.log
RKreport_DEL_11092014_134329.log - RKreport_SCN_11102014_193648.log - RKreport_DEL_11102014_193751.log - RKreport_SCN_11122014_074203.log
RKreport_SCN_11142014_192803.log - RKreport_DEL_11142014_192947.log - RKreport_SCN_11202014_164638.log - RKreport_DEL_11202014_164753.log
RKreport_SCN_11222014_101746.log - RKreport_DEL_11222014_101813.log - RKreport_SCN_12022014_112818.log - RKreport_DEL_12022014_112945.log
RKreport_SCN_12102014_093334.log - RKreport_DEL_12102014_093422.log - RKreport_SCN_12162014_111913.log - RKreport_DEL_12162014_112008.log
RKreport_SCN_12162014_123912.log - RKreport_DEL_12162014_124241.log - RKreport_DEL_12162014_124305.log - RKreport_SCN_12162014_130710.log
RKreport_DEL_12162014_130746.log - RKreport_DEL_12162014_130814.log - RKreport_SCN_12162014_133745.log - RKreport_DEL_12162014_133848.log
RKreport_SCN_12242014_103924.log - RKreport_DEL_12242014_104004.log - RKreport_SCN_12262014_185524.log - RKreport_DEL_12262014_185618.log
RKreport_SCN_12292014_155510.log - RKreport_DEL_12292014_155551.log - RKreport_SCN_01052015_103632.log - RKreport_DEL_01052015_103731.log
RKreport_SCN_01052015_124359.log - RKreport_DEL_01052015_124428.log - RKreport_SCN_01092015_152536.log - RKreport_DEL_01092015_152631.log
RKreport_SCN_01172015_130653.log - RKreport_DEL_01172015_130854.log - RKreport_SCN_01202015_212136.log - RKreport_DEL_01202015_212224.log
RKreport_SCN_01272015_043636.log - RKreport_SCN_01292015_082750.log - RKreport_DEL_01292015_082847.log - RKreport_SCN_02022015_045048.log
RKreport_SCN_02082015_100507.log - RKreport_DEL_02082015_100549.log - RKreport_SCN_02102015_063122.log - RKreport_DEL_02102015_063202.log
RKreport_SCN_02112015_145138.log - RKreport_SCN_02122015_154735.log - RKreport_DEL_02122015_154920.log - RKreport_SCN_02152015_110343.log
RKreport_SCN_02202015_090030.log - RKreport_DEL_02202015_090117.log - RKreport_SCN_02242015_135722.log - RKreport_DEL_02242015_140046.log
RKreport_SCN_03012015_195745.log - RKreport_SCN_03122015_020406.log - RKreport_DEL_03122015_020506.log - RKreport_SCN_03152015_005025.log
RKreport_DEL_03152015_005105.log - RKreport_SCN_03232015_060732.log - RKreport_DEL_03232015_060807.log - RKreport_SCN_04012015_020539.log
RKreport_DEL_04012015_024505.log - RKreport_SCN_04072015_044626.log - RKreport_DEL_04072015_044744.log - RKreport_SCN_04182015_115134.log
RKreport_SCN_04222015_111446.log - RKreport_DEL_04222015_111902.log - RKreport_SCN_04262015_173727.log - RKreport_DEL_04262015_173817.log
RKreport_SCN_04302015_031829.log - RKreport_DEL_04302015_031903.log - RKreport_DEL_04302015_031926.log - RKreport_SCN_05062015_201516.log
RKreport_DEL_05062015_201946.log - RKreport_SCN_05082015_124920.log - RKreport_DEL_05082015_124942.log