|
Malware Removal Discussion about Trojans, viruses, hoaxes, firewalls, spyware, and general Security issues. If you suspect your PC is infected with a virus, trojan or spyware app please include any supporting documentation or logs |
![]() |
|
Topic Tools |
#31
|
|||
|
|||
![]()
I didn't download AVAST and is not using it.
I did download TOTAL AV but didn't install it . I did delete it. |
#32
|
||||
|
||||
Okay.
Step 1: FRST Script: Please download this attached Fixlist.txt (2.9 KB, 0 views) downloads and Save it to the Desktop, and name it: fixlist.txt
and fixlist.txt are in the same location or the fix will not work. Step 2: ESET Online Scanner: Temporarily disable your AntiVirus and AntiSpyware protection - instructions here.
|
#33
|
|||
|
|||
![]()
Fix result of Farbar Recovery Scan Tool (x64) Version: 13-12-2017
Ran by George (14-12-2017 12:45:00) Run:9 Running from C:\Users\George\Desktop Loaded Profiles: George & DefaultAppPool (Available Profiles: George & DefaultAppPool) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: CloseProcesses: AlternateDataStreams: C:\Users\George\Downloads\IMG_3453.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3453.JPG:Updt_Summa ryInformation [151] AlternateDataStreams: C:\Users\George\Downloads\IMG_3455.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3455.JPG:Updt_Summa ryInformation [151] AlternateDataStreams: C:\Users\George\Downloads\IMG_3461.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3461.JPG:Updt_Summa ryInformation [151] AlternateDataStreams: C:\Users\George\Downloads\IMG_3465.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3465.JPG:Updt_Summa ryInformation [151] AlternateDataStreams: C:\Users\George\Downloads\IMG_3468.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3468.JPG:Updt_Summa ryInformation [151] AlternateDataStreams: C:\Users\George\Downloads\IMG_3471.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3471.JPG:Updt_Summa ryInformation [151] AlternateDataStreams: C:\Users\George\Downloads\IMG_3472.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3472.JPG:Updt_Summa ryInformation [151] AlternateDataStreams: C:\Users\George\Downloads\IMG_3485.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3485.JPG:Updt_Summa ryInformation [151] AlternateDataStreams: C:\Users\George\Downloads\IMG_3486.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3486.JPG:Updt_Summa ryInformation [151] AlternateDataStreams: C:\Users\George\Downloads\IMG_3489.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3489.JPG:Updt_Summa ryInformation [151] AlternateDataStreams: C:\Users\George\Downloads\IMG_3491.JPG:SummaryInf ormation [0] AlternateDataStreams: C:\Users\George\Downloads\IMG_3491.JPG:Updt_Summa ryInformation [151] FirewallRules: [{6C2F1F10-A6B8-4C64-B68F-7B2D22FF1BF6}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe FirewallRules: [{6CF286E4-6739-4401-B755-8EE131FFD317}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe HKU\S-1-5-21-96959487-344117887-1461987557-1001\...\StartupApproved\Run: => "WeatherBuddy" S2 GlassWire; C:\Program Files (x86)\GlassWire\GWCtlSrv.exe [8924672 2016-02-05] (SecureMix LLC) c:\programdata\glasswire\service\glasswire.db SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = CHR HKLM\...\Chrome\Extension: [looohgelibjoplmkhecmalapkgadkfcc] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [looohgelibjoplmkhecmalapkgadkfcc] - hxxps://clients2.google.com/service/update2/crx C:\EEK C:\Users\George\Documents\TotalAV C:\Users\George\AppData\Roaming\TotalAV CMD: ipconfig /flushdns Emptytemp: ***************** Restore point was successfully created. Processes closed successfully. C:\Users\George\Downloads\IMG_3453.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3453.JPG => ":Updt_Summa ryInformation" ADS could not remove. C:\Users\George\Downloads\IMG_3455.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3455.JPG => ":Updt_Summa ryInformation" ADS could not remove. C:\Users\George\Downloads\IMG_3461.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3461.JPG => ":Updt_Summa ryInformation" ADS could not remove. C:\Users\George\Downloads\IMG_3465.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3465.JPG => ":Updt_Summa ryInformation" ADS could not remove. C:\Users\George\Downloads\IMG_3468.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3468.JPG => ":Updt_Summa ryInformation" ADS could not remove. C:\Users\George\Downloads\IMG_3471.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3471.JPG => ":Updt_Summa ryInformation" ADS could not remove. C:\Users\George\Downloads\IMG_3472.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3472.JPG => ":Updt_Summa ryInformation" ADS could not remove. C:\Users\George\Downloads\IMG_3485.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3485.JPG => ":Updt_Summa ryInformation" ADS could not remove. C:\Users\George\Downloads\IMG_3486.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3486.JPG => ":Updt_Summa ryInformation" ADS could not remove. C:\Users\George\Downloads\IMG_3489.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3489.JPG => ":Updt_Summa ryInformation" ADS could not remove. C:\Users\George\Downloads\IMG_3491.JPG => ":SummaryInf ormation" ADS could not remove. C:\Users\George\Downloads\IMG_3491.JPG => ":Updt_Summa ryInformation" ADS could not remove. HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\\{6C2F1F 10-A6B8-4C64-B68F-7B2D22FF1BF6} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\\{6CF286 E4-6739-4401-B755-8EE131FFD317} => value removed successfully HKU\S-1-5-21-96959487-344117887-1461987557-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\\WeatherBuddy => value removed successfully HKU\S-1-5-21-96959487-344117887-1461987557-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \\WeatherBuddy => value not found. "HKLM\System\CurrentControlSet\Services\GlassW ire" => removed successfully GlassWire => service removed successfully c:\programdata\glasswire\service\glasswire.db => moved successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Google\Chrome\Extensions\looohgelib joplmkhecmalapkgadkfcc" => removed successfully "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extension s\looohgelibjoplmkhecmalapkgadkfcc" => removed successfully C:\EEK => moved successfully C:\Users\George\Documents\TotalAV => moved successfully C:\Users\George\AppData\Roaming\TotalAV => moved successfully ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 9986048 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 4285234 B Java, Flash, Steam htmlcache => 291 B Windows/system/drivers => 7192078 B Edge => 56832 B Chrome => 0 B Firefox => 19659987 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 0 B LocalService => 0 B NetworkService => 0 B George => 70658020 B DefaultAppPool => 0 B RecycleBin => 5052782 B EmptyTemp: => 111.5 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 12:45:39 ==== |
#34
|
|||
|
|||
![]()
I still can't turn on Window Defender also the computer is still slow getting on the internet.
The ESET Scan finish and didn't find any threats , I copy the log , see below Log Version of detection engine: 16573 (20171214) Date: 12/14/2017 Time: 1:08:52 PM Scanned disks, folders and files: C:\ C:\hiberfil.sys - unable to open [4] C:\pagefile.sys - unable to open [4] C:\Program Files (x86)\Garmin\Express\Awesomium.Core.dll » DOTNETREACTOR - archive damaged C:\Program Files (x86)\Garmin\Express\Awesomium.Windows.Controls.dl l » DOTNETREACTOR - archive damaged C:\ProgramData\Microsoft\Network\Downloader\edb.lo g - unable to open [4] C:\ProgramData\Microsoft\Network\Downloader\qmgr.d b - unable to open [4] C:\ProgramData\Microsoft\Network\Downloader\qmgr.j fm - unable to open [4] C:\ProgramData\Microsoft\Search\Data\Applications\ Windows\edb.jtx - unable to open [4] C:\ProgramData\Microsoft\Search\Data\Applications\ Windows\Windows.edb - unable to open [4] C:\ProgramData\Microsoft\Search\Data\Applications\ Windows\Windows.jfm - unable to open [4] C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\Ge ofenceApplicationID.dat - unable to open [4] C:\swapfile.sys - unable to open [4] C:\System Volume Information\{2611f5dc-df92-11e7-9c61-001e4fc94be3}{3808876b-c176-4e48-b7ae-04046e6cc752} - unable to open [4] C:\System Volume Information\{2fe22a15-dac1-11e7-9c55-001e4fc94be3}{3808876b-c176-4e48-b7ae-04046e6cc752} - unable to open [4] C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} - unable to open [4] C:\System Volume Information\{73407811-d8fe-11e7-9c53-001e4fc94be3}{3808876b-c176-4e48-b7ae-04046e6cc752} - unable to open [4] C:\System Volume Information\{7ecf41a3-dd0a-11e7-9c58-001e4fc94be3}{3808876b-c176-4e48-b7ae-04046e6cc752} - unable to open [4] C:\System Volume Information\{7ecf41cb-dd0a-11e7-9c58-001e4fc94be3}{3808876b-c176-4e48-b7ae-04046e6cc752} - unable to open [4] C:\System Volume Information\{7ecf41e8-dd0a-11e7-9c58-001e4fc94be3}{3808876b-c176-4e48-b7ae-04046e6cc752} - unable to open [4] C:\System Volume Information\{a476c1d7-d878-11e7-9c50-001e4fc94be3}{3808876b-c176-4e48-b7ae-04046e6cc752} - unable to open [4] C:\Users\George\AppData\Local\Microsoft\Windows\No tifications\WPNPRMRY.tmp - unable to open [4] C:\Users\George\AppData\Local\Microsoft\Windows\Us rClass.dat - unable to open [4] C:\Users\George\AppData\Local\Microsoft\Windows\Us rClass.dat.LOG1 - unable to open [4] C:\Users\George\AppData\Local\Microsoft\Windows\Us rClass.dat.LOG2 - unable to open [4] C:\Users\George\AppData\Local\Microsoft\Windows\We bCache\V01.log - unable to open [4] C:\Users\George\AppData\Local\Microsoft\Windows\We bCache\WebCacheV01.dat - unable to open [4] C:\Users\George\AppData\Local\Microsoft\Windows\We bCache\WebCacheV01.jfm - unable to open [4] C:\Users\George\AppData\Local\Microsoft\Windows\We bCacheLock.dat - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.S kypeApp_kzf8qxf38zg5c\Settings\settings.dat - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.S kypeApp_kzf8qxf38zg5c\Settings\settings.dat.LOG1 - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.S kypeApp_kzf8qxf38zg5c\Settings\settings.dat.LOG2 - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.W indows.Cortana_cw5n1h2txyewy\Settings\settings.dat - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.W indows.Cortana_cw5n1h2txyewy\Settings\settings.dat .LOG1 - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.W indows.Cortana_cw5n1h2txyewy\Settings\settings.dat .LOG2 - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.W indows.ShellExperienceHost_cw5n1h2txyewy\Settings\ settings.dat - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.W indows.ShellExperienceHost_cw5n1h2txyewy\Settings\ settings.dat.LOG1 - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.W indows.ShellExperienceHost_cw5n1h2txyewy\Settings\ settings.dat.LOG2 - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.W indowsStore_8wekyb3d8bbwe\Settings\settings.dat - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.W indowsStore_8wekyb3d8bbwe\Settings\settings.dat.LO G1 - unable to open [4] C:\Users\George\AppData\Local\Packages\Microsoft.W indowsStore_8wekyb3d8bbwe\Settings\settings.dat.LO G2 - unable to open [4] C:\Users\George\AppData\Local\TileDataLayer\Databa se\EDB.log - unable to open [4] C:\Users\George\AppData\Local\TileDataLayer\Databa se\vedatamodel.edb - unable to open [4] C:\Users\George\AppData\Local\TileDataLayer\Databa se\vedatamodel.jfm - unable to open [4] C:\Users\George\Downloads\AdbDriverInstaller.exe » CAB » Microsoft Kernel-Mode Driver Framework Install-v1.9-Vista.msu - archive damaged - the file could not be extracted. C:\Users\George\Downloads\flash_setup.exe » ZIP » images/bg-close-program.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/bg-download-bar-empty.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/bg-download-bar-error.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/bg-download-bar-full.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/bg-header-error.gif - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/button-center-highlight.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/button-center.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/button-left-highlight.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/button-left.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/button-right-highlight.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/button-right.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/icon-blank.gif - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/icon-complete-error.gif - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/icon-complete.gif - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/icon-error.png - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » images/logo-adobe.gif - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » interop/downloader.dll - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/cn.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/cs.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/da.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/de.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/en-us.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/es.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/fi.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/fr.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/hr.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/hu.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/it.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/ja.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/ko.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/nl.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/no.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/pl.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/pt.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/ro.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/ru.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/sk.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/sl.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/sv.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/tr.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/tw.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » locale/ua.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » util/gccheck.exe - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » util/gtbcheck.exe - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » app.config.xml - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » compact.min.js - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » environment.json - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » logo.ico - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » mainwindow.config.xml - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » mainwindow.css - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » mainwindow.html - error - password-protected file C:\Users\George\Downloads\flash_setup.exe » ZIP » workflow.json - error - password-protected file C:\Users\George\NTUSER.DAT - unable to open [4] C:\Users\George\ntuser.dat.LOG1 - unable to open [4] C:\Users\George\ntuser.dat.LOG2 - unable to open [4] C:\Windows\appcompat\Programs\Amcache.hve - unable to open [4] C:\Windows\appcompat\Programs\Amcache.hve.LOG1 - unable to open [4] C:\Windows\appcompat\Programs\Amcache.hve.LOG2 - unable to open [4] C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT - unable to open [4] C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT .LOG1 - unable to open [4] C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT .LOG2 - unable to open [4] C:\Windows\ServiceProfiles\NetworkService\NTUSER.D AT - unable to open [4] C:\Windows\ServiceProfiles\NetworkService\NTUSER.D AT.LOG1 - unable to open [4] C:\Windows\ServiceProfiles\NetworkService\NTUSER.D AT.LOG2 - unable to open [4] C:\Windows\System32\catroot2\edb.log - unable to open [4] C:\Windows\System32\catroot2\edbtmp.log - unable to open [4] C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - unable to open [4] C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb.jfm - unable to open [4] C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - unable to open [4] C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb.jfm - unable to open [4] C:\Windows\System32\config\BBI - unable to open [4] C:\Windows\System32\config\BBI.LOG1 - unable to open [4] C:\Windows\System32\config\BBI.LOG2 - unable to open [4] C:\Windows\System32\config\DEFAULT - unable to open [4] C:\Windows\System32\config\DEFAULT.LOG1 - unable to open [4] C:\Windows\System32\config\DEFAULT.LOG2 - unable to open [4] C:\Windows\System32\config\RegBack\DEFAULT - unable to open [4] C:\Windows\System32\config\RegBack\SAM - unable to open [4] C:\Windows\System32\config\RegBack\SECURITY - unable to open [4] C:\Windows\System32\config\RegBack\SOFTWARE - unable to open [4] C:\Windows\System32\config\RegBack\SYSTEM - unable to open [4] C:\Windows\System32\config\SAM - unable to open [4] C:\Windows\System32\config\SAM.LOG1 - unable to open [4] C:\Windows\System32\config\SAM.LOG2 - unable to open [4] C:\Windows\System32\config\SECURITY - unable to open [4] C:\Windows\System32\config\SECURITY.LOG1 - unable to open [4] C:\Windows\System32\config\SECURITY.LOG2 - unable to open [4] C:\Windows\System32\config\SOFTWARE - unable to open [4] C:\Windows\System32\config\SOFTWARE.LOG1 - unable to open [4] C:\Windows\System32\config\SOFTWARE.LOG2 - unable to open [4] C:\Windows\System32\config\SYSTEM - unable to open [4] C:\Windows\System32\config\SYSTEM.LOG1 - unable to open [4] C:\Windows\System32\config\SYSTEM.LOG2 - unable to open [4] C:\Windows\System32\config\systemprofile\AppData\L ocal\Microsoft\Windows\Notifications\WPNPRMRY.tmp - unable to open [4] Number of scanned objects: 226284 Number of threats found: 0 Time of completion: 4:10:44 PM Total scanning time: 10912 sec (03:01:52) Notes: [4] Object cannot be opened. It may be in use by another application or operating system. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX When log on to the internet eset security had 22 messages , I only note one as seen below but they are similar kind : ADDRESS HAS BEEN BLOCK URL ADDRESS http:ak.imgfarm.com/images/anx/ancmore-1.2.7.js IP 23.36.32.17 Last edited by Jerry56; December 14th, 2017 at 10:39 PM. |
#35
|
|||
|
|||
![]()
Should I delete the items that were downloaded to desktop .?
The PC is showing that Windows 10 version 1709 is available but each time I tried to update it I will get the following message "We couldn't connect to the update service. We'll try again later, or you can check now. If it still doesn't work, make sure you're connected to the Internet." Last edited by Jerry56; December 15th, 2017 at 01:56 AM. |
#36
|
||||
|
||||
Quote:
Quote:
Quote:
This information is from Ask.com. It may be caused by the softwares you have installed. I have not seen on your reports before. But we must clean. First of all, let's try to repair. Then try updating your operating system again. Windows Repair (All in One):
Reset File Permissions Reset Service Permissions Register System Files Remove Policies Set By Infections Unhide Non System Files Repair File Associations Restore Important Windows Services Set Windows Services To Default Startup Repair WMI Repair Windows Firewall Repair Internet Explorer Repair MDAC & MS Jet Repair Hosts File Repair Icons Repair Winsock & DNS Cache Repair Proxy Settings Unhide Non System Files Repair Windows Updates Repair CD/DVD Missing/Not Working
|
#37
|
|||
|
|||
![]()
I was able to download windows 10 version 1709 manually should I try to install it now or should I follow your instruction first.?
Also the antivirus I am using is the 30 days trial of ESET Internet security which was automatically installed when I did the online scan. |
#38
|
||||
|
||||
Quote:
For Eset; I just wanted you to run ESET Online Scanner. ESET Internet security can cause problems. |
#39
|
|||
|
|||
![]()
I update the PC and delete ESET Internet Security and is now using Windows Defender.
|
#40
|
||||
|
||||
Quote:
Please do these following for Ask.com issue. Step1: Please download AdwCleaner by Xplode onto your desktop.
Please download Junkware Removal Tool to your desktop.
|
#41
|
|||
|
|||
![]()
# AdwCleaner 7.0.5.0 - Logfile created on Sat Dec 16 22:54:38 2017
# Updated on 2017/29/11 by Malwarebytes # Database: 12-15-2017.1 # Running on Windows 10 Pro (X64) # Mode: scan # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** No malicious registry entries found. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries. ************************* C:/AdwCleaner/AdwCleaner[C10].txt - [2208 B] - [2016/9/10 19:8:46] C:/AdwCleaner/AdwCleaner[C11].txt - [2819 B] - [2016/12/18 22:18:14] C:/AdwCleaner/AdwCleaner[C1].txt - [2145 B] - [2016/5/8 13:5:51] C:/AdwCleaner/AdwCleaner[C2].txt - [2261 B] - [2016/8/2 21:39:32] C:/AdwCleaner/AdwCleaner[C5].txt - [2111 B] - [2015/9/3 21:35:30] C:/AdwCleaner/AdwCleaner[C6].txt - [2944 B] - [2015/9/6 17:2:11] C:/AdwCleaner/AdwCleaner[C7].txt - [18976 B] - [2015/11/7 17:39:27] C:/AdwCleaner/AdwCleaner[C8].txt - [1125 B] - [2015/11/24 17:21:13] C:/AdwCleaner/AdwCleaner[C9].txt - [2809 B] - [2015/12/23 17:58:34] C:/AdwCleaner/AdwCleaner[S10].txt - [2375 B] - [2016/9/10 19:8:24] C:/AdwCleaner/AdwCleaner[S11].txt - [2521 B] - [2016/9/22 17:1:30] C:/AdwCleaner/AdwCleaner[S12].txt - [2611 B] - [2016/10/22 17:6:42] C:/AdwCleaner/AdwCleaner[S13].txt - [2843 B] - [2016/12/15 18:9:5] C:/AdwCleaner/AdwCleaner[S14].txt - [2732 B] - [2016/12/18 22:13:21] C:/AdwCleaner/AdwCleaner[S1].txt - [2108 B] - [2016/5/8 13:3:21] C:/AdwCleaner/AdwCleaner[S2].txt - [1795 B] - [2016/5/11 16:45:53] C:/AdwCleaner/AdwCleaner[S3].txt - [1874 B] - [2016/5/29 17:13:31] C:/AdwCleaner/AdwCleaner[S4].txt - [4457 B] - [2015/8/12 0:27:4] C:/AdwCleaner/AdwCleaner[S5].txt - [3897 B] - [2015/9/3 21:34:1] C:/AdwCleaner/AdwCleaner[S6].txt - [4778 B] - [2015/9/6 17:0:8] C:/AdwCleaner/AdwCleaner[S7].txt - [18008 B] - [2015/11/7 17:37:32] C:/AdwCleaner/AdwCleaner[S8].txt - [1020 B] - [2015/11/24 17:19:46] C:/AdwCleaner/AdwCleaner[S9].txt - [829 B] - [2015/12/23 17:53:32] ########## EOF - C:\AdwCleaner\AdwCleaner[S14].txt ########## |
#42
|
|||
|
|||
![]()
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017) Operating System: Windows 10 Pro x64 Ran by George (Administrator) on Sat 12/16/2017 at 17:58:57.92 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~ File System: 0 user_pref(browser.startup.homepage, hxxp://www.excite.com/); Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~ Scan was completed on Sat 12/16/2017 at 18:01:34.18 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~ |
#43
|
||||
|
||||
İs there your ask.com (http:ak.imgfarm.com ) issue still ?
|
#44
|
|||
|
|||
![]()
I don't see (http:ak.imfarm.com) again . I only used to see it when using ESEt internet security.
The Internet is still slow ,sometimes I get the following message (Hmm. We’re having trouble finding that site. We can’t connect to the server at navigator-lxa.mail.com. If that address is correct, here are three other things you can try: Try again later. Check your network connection. If you are connected but behind a firewall, check that Firefox has permission to access the Web." |
#45
|
||||
|
||||
This problem can be caused by proxy settings and windows firewall.I am not sure if Complete Internet Repair will help solve this problem.Maybe your proxy settings could hurt.
===================== Did you used Bytefence software so far? ================================================== = Follow the instructions below please. Farbar Recovery Scan Tool (FRST) - Registry Search Follow the instructions below to download and execute a Registry search on your system with FRST, and provide the log in your next reply.
Code:
rootCert.pfx;Ionic.Zip.dll;TRUSTED.WEB.PROXY.DLL;f6a641 ac642b4dc69c694d1ff32f30c1_1.exe
|
![]() |
Bookmarks |
«
Previous Topic
|
Next Topic
»
|
|
![]() |
||||
Topic | Topic Starter | Forum | Replies | Last Post |
Suspect Virus | Jerry56 | Malware Removal | 1 | October 1st, 2019 10:28 AM |
Suspect Virus | Jerry56 | Malware Removal | 82 | June 11th, 2012 01:08 AM |
IE slow. Suspect spyware/virus | zombyfellow | Malware Removal | 1 | December 27th, 2008 09:13 PM |
suspect a virus in my comp - please help! | vimal_dec15 | Malware Removal | 3 | August 20th, 2007 11:13 AM |
I Need Help With My Ie. I Suspect Its A Virus | techhelp4me | Malware Removal | 1 | December 21st, 2006 06:42 AM |
All times are GMT +1. The time now is 09:36 PM.