Computer Was Hijacked, System Partition Mess, 72 Could Use Some Help Please.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mladynicole, Apr 16, 2025.

Tags:
  1. mladynicole

    mladynicole Private E-2

    I am a 72-year-old disabled senior with early onset dementia. 4 days ago yahoo took over google as my search engine without me knowing what happened. A day later my Total AV stopped working and Windows Defender took over. My computer is a 3-year-old Dell Desktop XPS8940. It was a year old when a friend gave it to me. Windows needed to be updated. I have been trying to update it for 2 days now. I keep getting this error message "couldn't update system reserved partition" I looked it up; however, I cannot figure out how to fix this. Then another site said it meant my computer was dying?
    I am going to have 3 surgeries in the next 3 months, and I really need my computer to work. So I can get to my my chart, write emails, check my mail, etc., oh, and go on Facebook. All my family has passed except for a brother that lives in OKC and he is very sick. I live alone in an apartment. When I went to the first forum it said to try Malwarebytes- It would not install. Window defender is not finding anything, and I can't get my total AV to install.
    It won't take me back to a system restore point before this all happened. Using Win 11.
    I am not sure what to do and what would be the next step. I can't afford at this time to buy another computer so I am really praying this can be fixed. Thank you for taking the time to read this, I am grateful.
     
  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome to the Major Geeks Malware Forum.

    Please do this

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Download FRST64 and save the file on your Desktop
    • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • When completed, FRST.txt and Addition.txt reports will be saved on the Desktop
    • Please attach the reports to your reply
    ===================================================

    Things I would like to see in your next reply.
    • Attached reports
     
  3. mladynicole

    mladynicole Private E-2

    When I tried in MS Edge it said we don't know this is it safe. Then I hit save and it made me go to a page that said =
    Make sure you trust FRST64 (1).exe before you open it
    Microsoft Defender SmartScreen couldn't verify if this file is safe because it isn't commonly downloaded. Make sure you trust the file you're downloading or its source before you open it.


    Name: FRST64 (1).exe
    Publisher: Unknown So them I clicked keep anyway. Then I tried Chrome it said
    Windows protected your PC
    Microsoft Defender SmartScreen prevented an unrecognized app from starting. Running this app might put your PC at risk.
    More info I can't get Defender to shut off so I can try to download it.
     
  4. mladynicole

    mladynicole Private E-2

    Thank you. I tried to download it. Chrome and FF said-
    Microsoft Defender SmartScreen prevented an unrecognized app from starting. Running this app might put your PC at risk.
    More info I can't turn Defender off I have tried for two days. I am attaching screen shots for each browser. If I can't get Defender to shut down I can't install anything. I tried to screen shot what I did. I am at a loss. Thank you for your help I am grateful
     

    Attached Files:

  5. mladynicole

    mladynicole Private E-2

    I finally found a way to get it to run... I hope I did this properly. Thank you for your help :D
     

    Attached Files:

  6. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for working through all of that to get the reports.

    There is no evidence of malicious software on your system which is good news. There are a number of security related programs on your computer and that is causing us some problems. We are going to remove them, including TotalAV. We can reinstall the program if you'd like once we are finished.

    If at any time you feel overwhelmed or unsure about what to do simply stop and let me know. This stuff can be very confusing and intimidating. My primary goal is to get us through this without too much trauma!

    Let's start with this.

    ===================================================

    Uninstalling Programs Using Revo Uninstaller

    --------------------

    I recommend uninstalling the below listed program(s) from your computer. I see you already have Revo Uninstaller on your computer.
    • Right click on Revo Uninstaller and select Run as administrator
    • From the list of programs highlight the listed program(s), or anything similar, then select Uninstall
    Code:
    CCleaner
    TotalAV
    Tweaking.com - Windows Repair
    
    • If the program's uninstaller appears work through the steps to remove the program(s)
    • Be sure the Advanced option is selected then click Scan
    • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
    • Once done click Finish
    • Reboot your computer
    ===================================================

    Managing Edge Search Engines

    --------------------
    • Launch Edge
    • Type or copy and paste edge://settings/searchEngines in the address bar and hit Enter
    • Review the list of Search Engines and remove any malicious or unwanted entries you see by clicking on the 3 dots to the right and selecting Remove
    • Select Google as your desired default Search Engine by clicking on the 3 dots to the right and selecting Make default
    • Close Edge, relaunch it and check the search engine
    ===================================================

    Farbar Recovery Scan Tool - Run Fix Using Attached File

    --------------------
    • Download the attached file and save it in the same location as FRST64.exe, which in your case is the Downloads folder <<< Important
    • Right click on FRST and select Run as administrator
    • Click Fix and once completed your computer will reboot
    • A Fixlog.txt file will be saved in the Downloads folder
    • Attach the Fixlog.txt report to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Programs uninstalled?
    • Edge search engine changed to Google?
    • Attached Fixlog report
     

    Attached Files:

  7. mladynicole

    mladynicole Private E-2

    Thank you very much. Just returned from the hospital so I am going to rest for a while and then start on the tasks you gave me to do. I am so so grateful. Thank you, if I get confused or overwhelmed, I will ask for help. Grateful
     
  8. Oh My!

    Oh My! Malware Expert Staff Member

    I hope you are doing OK. We will continue on when you are able.
     
  9. mladynicole

    mladynicole Private E-2

    I'm Ok, they just have to do tests before I have surgery and before they start me on the dementia medicine.
    Thank you! I just finished I hope I did it right. Windows still won't update. It gets to 8% and then I get the partition message. Every item I had to uninstall gave me trouble. I just kept trying until I figured out a way to fix one problem at a time. Thank you for your help I am grateful. I hope we can get this working. I am leaving for now Defender it won't uninstall, and I don't want to mess with it until we fix this and until Windows updates it's been almost a week now. Again, thank you very much.
     

    Attached Files:

  10. mladynicole

    mladynicole Private E-2

    Forgot to add this one was able to make it work today.
     

    Attached Files:

  11. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for staying with it. Take all the time you need to take care of yourself.

    In referring back to my instructions in Post #6, were you able to change the Edge Search to Google? And were you able to run the Farbar Recovery Scan Tool - Run Fix Using Attached File step? If so, are you able to locate and attach the Fixlog.txt report?

    I sent you a personal message. You should have received a notification that you received a personal message.
     
  12. mladynicole

    mladynicole Private E-2

    Yes, I could change it to Google or Duck Duck Goose. I can't download Total AV ( not sure if I can keep it even if I could because I paid for it for a year. Can't uninstall Defender and still cannot update.
    I will go to your message and respond. My computer is acting wiggy so I will try to do this after I do a few things on the computer. Thank you very much for your support and understanding how challenging this is for me. Thank you
     
  13. mladynicole

    mladynicole Private E-2

    PS FRST64 still cannot download - Window defender is still blocking it, same as Total AV, and Window update this is a mess
     
  14. Oh My!

    Oh My! Malware Expert Staff Member

    Yes, I know. FRST64 is safe despite the warning.

    Some other things need to be resolved before we can fix Windows Defender and Windows Update. By the way, you can't uninstall Windows Defender. The computer will not allow you to do that.
     
  15. mladynicole

    mladynicole Private E-2

    Thank you! I can't seem to get around the warning on Total AV and FRST64. Hoping there is a way.
     
  16. Oh My!

    Oh My! Malware Expert Staff Member

    Tim has not yet seen the Personal Message.

    You should already have FRST64.exe in the C:\Users\cfids\Downloads folder. We don't need to download it again.

    Go back to the Farbar Recovery Scan Tool - Run Fix Using Attached File instructions in Post #6. Right click on Fixlist.txt near the bottom of the post. Select Save Link As... and a new window will open. Look near the top and if it says Downloads simply click Save. If it doesn't say Downloads but something else look on the left side of the open window. Left click on Downloads. Click Save

    Let me know how that goes.
     
  17. mladynicole

    mladynicole Private E-2

    Ok, I tried. I could not get it to run as Admin. Let me know if it's OK.
    I will check back later tonight. Needing to take meds and rest for a while.
    I used to love doing this, now, it's challenging. Thank you!
     

    Attached Files:

  18. mladynicole

    mladynicole Private E-2

    I think this was run by admin.
     

    Attached Files:

  19. Oh My!

    Oh My! Malware Expert Staff Member

    I sent you a Personal Message.
     
  20. Oh My!

    Oh My! Malware Expert Staff Member

    I think you almost got there with the last attempt. Try clicking Fix instead of Scan and see if you get a Fixlog.txt.
     
  21. mladynicole

    mladynicole Private E-2

    OK, I will try again.. :) So, close, but that only counts in horse shoes... ( Sorry I could not resist) I tried it said... NO FixList.txt. Sigh.
     
  22. Oh My!

    Oh My! Malware Expert Staff Member

    How are we doing Nicole?
     
    TimW likes this.
  23. mladynicole

    mladynicole Private E-2

    Terrible, I think I have the flu and the computer is all wiggy since I tried to connect it to the printer. I have the flu :( I am now on Cox, 300 instead of the 100 I was on with Visible. I am hoping this computer is not dying. It was working fine... Its very slow when I get to an website it takes longer now for the pictures to show up. I am not sure if I am making sense. I was talking to my surgeon and the problem started again. I don't know where the problem is, the computer, the phone, etc. Or both. When I attached the printer... suddenly in the top right of the computer was a ghost symbol of a sound icon. The file is what it looked like only it was much bigger and flashing and not solid. I will write more tomorrow. I don't feel well. Thank you very much for helping me. PS this is from the speed test -
    DOWNLOAD Mbps
    346.87
    UPLOAD Mbps
    34.20
    Ping ms 14 25 27
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry to hear that. My maintenance routine includes right clicking start, click run and type in %temp%..then remove as much as it will let you.
     
    mladynicole likes this.
  25. mladynicole

    mladynicole Private E-2

    TY, I will try that ...
     
  26. Reese2500

    Reese2500 Private E-2

    completely unrelated but I love your PFP, looks just like my best freinds pitbull we call papsmear
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds