Ack! My Computer Must Have A Bad Bug!

Discussion in 'Malware Help - Public (Anyone Can Post & Respond)' started by whitequeen96, Aug 5, 2023.

  1. whitequeen96

    whitequeen96 Private First Class

    1. Computer will not respond when I click on some things. When I do a search on Google and there are questions listed and I click the arrow to make them open up - nothing. Also when I click on pictures next to the article I want to get to. Now it seems to be worsening and not always going to the article.

    2. Won't open most youtube videos; just shows the circle going round and round. Other times it opens up but it's an ad instead of what I wanted to see and it just takes me to a new ad afterwards. (I think the ad problem is only on Opera.) I might open a Short and see the 1st one, but if I arrow down to the next one, it won't play.

    I'm not sure if this started happening after updating Firefox but Opera now has problems too. I opened Task Manager and started ending tasks, mostly Service Host stuff, because Memory would show pretty high and Disk would show as high as 100.
    I've checked Windows Defender, run 360 Total Performance, restarted, turned computer off and started again 20 minutes later. I even went to System Restore but it said something new, sounding as if I would end up deleting my Windows 10 and have to have my password and a key to get back on! I didn't do that - looked too scary.
    PLEASE HELP! I feel like throwing it through a window but I can't afford to! :-(
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome to the MajorGeeks Malware Forum.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Download Farbar Recover Scan Tool for 64 bit systems and save it to your Desktop. <<< Important
    • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
    • 2 Notepad documents should now be open on your desktop.
    • Please copy and paste the contents of each report in separate reply windows
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:

    • FRST.txt
    • Addition.txt
     
  3. whitequeen96

    whitequeen96 Private First Class

    I don't know if I should be able to download Farbar from your link, but I can't. I went to bleepingcomputer.com and downloaded it from there. I see lots of warnings and I want to make sure it's still OK, even tho' I'm not downloading and installing it from majorgeeks.com. Shall I proceed?
     
  4. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for stopping and checking.

    It is common to receive the warning but it is a valid file.
     
  5. whitequeen96

    whitequeen96 Private First Class

    I saw your note but was worried when the download was from another site.
    2 quick questions: 1. Does Belarc have anything to do with this? I don't know where it came from. 2. I was finally able to get CCleaner to work and it showed 1000's of somethings that it then cleared out. I can't get it to run again now because it wants to close everything.
    I wasn't able to save Farbar to my desktop.
    Eeek! I can't copy and past results because I get an error message saying "Please enter a message with no more than 40000 characters". I'm putting some of it below.

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-08-2023
    Ran by Louise (administrator) on LOUISE-PC (Hewlett-Packard DC6000) (05-08-2023 18:30:22)
    Running from C:\Users\Louise\Downloads\FRST64(1).exe
    Loaded Profiles: Louise
    Platform: Microsoft Windows 10 Pro Version 22H2 19045.3208 (X64) Language: English (United States)
    Default browser: FF
    Boot Mode: Normal

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe ->) (Beijing Qihu Technology Co., Ltd. -> Qihoo 360 Technology Co. Ltd.) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
    (C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe ->) (Beijing Qihu Technology Co., Ltd. -> Qihoo 360 Technology Co. Ltd.) C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe
    (C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
    (C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
    (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe <13>
    (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    (services.exe ->) (Beijing Qihu Technology Co., Ltd. -> Qihoo 360 Technology Co. Ltd.) C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
    (services.exe ->) (Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
    (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe <2>
    (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MsMpEng.exe
    (services.exe ->) (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

    ==================== Registry (Whitelisted) ===================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM-x32\...\Run: [QHSafeTray] => C:\Program Files (x86)\360\Total Security\safemon\360Tray.exe [413000 2023-03-15] (Beijing Qihu Technology Co., Ltd. -> Qihoo 360 Technology Co. Ltd.)
    HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
    HKLM Group Policy restriction on software: *.xlsx*.bat <==== ATTENTION
    HKLM Group Policy restriction on software: %allusersprofile%\*.pif <==== ATTENTION
    HKLM Group Policy restriction on software: *.gif*.js <==== ATTENTION
    HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <==== ATTENTION
    HKLM Group Policy restriction on software: %programdata%\*.cmd <==== ATTENTION
    HKLM Group Policy restriction on software: *.avi*.exe <==== ATTENTION
    HKLM Group Policy restriction on software: *.rar*.cmd <==== ATTENTION
    HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <==== ATTENTION
    HKLM Group Policy restriction on software: *.rtf*.jse <==== ATTENTION
    HKLM Group Policy restriction on software: *.pdf*.bat <==== ATTENTION
    HKLM Group Policy restriction on software: *.jpg*.cmd <==== ATTENTION
    HKLM Group Policy restriction on software: *.doc*.pif <==== ATTENTION
    HKLM Group Policy restriction on software: *.mp4*.pif <==== ATTENTION
    HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
    HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <==== ATTENTION
    HKLM Group Policy restriction on software: *.xls*.jse <==== ATTENTION
    HKLM Group Policy restriction on software: *.wav*.com <==== ATTENTION
    HKLM Group Policy restriction on software: *.jpg*.jse <==== ATTENTION
    HKLM Group Policy restriction on software: %userprofile%\*.scr <==== ATTENTION
    HKLM Group Policy restriction on software: %allusersprofile%\*.js <==== ATTENTION
    HKLM Group Policy restriction on software: *.mp4*.exe <==== ATTENTION
    HKLM Group Policy restriction on software: *.wmv*.scr <==== ATTENTION
    HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <==== ATTENTION
    HKLM Group Policy restriction on software: *.png*.bat <==== ATTENTION
    HKLM Group Policy restriction on software: *.wma*.com <==== ATTENTION
    HKLM Group Policy restriction on software: %userprofile%\*.js <==== ATTENTION
     
  6. whitequeen96

    whitequeen96 Private First Class

    Part of the Addition from Notepad:

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-08-2023
    Ran by Louise (05-08-2023 18:34:10)
    Running from C:\Users\Louise\Downloads
    Microsoft Windows 10 Pro Version 22H2 19045.3208 (X64) (2021-05-04 08:09:13)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================


    (If an entry is included in the fixlist, it will be removed.)

    Administrator (S-1-5-21-125910357-3284985775-168995214-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-125910357-3284985775-168995214-503 - Limited - Disabled)
    Guest (S-1-5-21-125910357-3284985775-168995214-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-125910357-3284985775-168995214-1002 - Limited - Enabled)
    Louise (S-1-5-21-125910357-3284985775-168995214-1000 - Administrator - Enabled) => C:\Users\Louise
    WDAGUtilityAccount (S-1-5-21-125910357-3284985775-168995214-504 - Limited - Disabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: 360 Total Security (Enabled - Up to date) {FFDC234A-CE9B-08F9-406B-F876951CE066}
    AS: 360 Total Security (Enabled - Up to date) {91AD8F88-E316-BC3A-E0A3-9F4C5B36A8D0}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    360 Total Security (HKLM-x32\...\360TotalSecurity) (Version: 11.0.0.1028 - 360 Security Center)
    Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20040 - Adobe Systems Incorporated)
    Adobe AIR (HKLM-x32\...\{10E33ABF-D7FB-4F47-900A-7973854AB45A}) (Version: 32.0.0.125 - Adobe) Hidden
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 32.0.0.125 - Adobe)
    Belarc Advisor 12.0 (HKLM-x32\...\Belarc Advisor) (Version: 12.0.0.0 - Belarc, Inc.)
    Canon Digital Camera Solution Disk 40-46 Software Starter Guide (HKLM-x32\...\SoftwareStarterGuide-DCSD40_46) (Version: 1.1.0.1 - Canon Inc.)
    Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
    Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.1.20.13 - Canon Inc.)
    CANON iMAGE GATEWAY Task for ZoomBrowser EX (HKLM-x32\...\CANON iMAGE GATEWAY Task) (Version: 1.7.0.4 - Canon Inc.)
    Canon Internet Library for ZoomBrowser EX (HKLM-x32\...\Canon Internet Library for ZoomBrowser EX) (Version: 1.6.3.9 - Canon Inc.)
    Canon MG3600 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3600_series) (Version: - Canon Inc.)
    Canon MG3600 series On-screen Manual (HKLM-x32\...\Canon MG3600 series On-screen Manual) (Version: 7.8.0 - Canon Inc.)
    Canon MG3600 series User Registration (HKLM-x32\...\Canon MG3600 series User Registration) (Version: - ‭Canon Inc.)
    Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\...\MovieEditTask) (Version: 3.0.0.20 - Canon Inc.)
    Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.6.4 - Canon Inc.)
    Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.6.0 - Canon Inc.)
    Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
    Canon Personal Printing Guide (HKLM-x32\...\Personal Printing Guide) (Version: 1.0.0.1 - Canon Inc.)
    Canon PowerShot SD1200 IS_IXUS 95 IS Camera User Guide (HKLM-x32\...\CameraUserGuide-PSSD1200IS_IXUS95IS) (Version: 1.0.0.1 - Canon Inc.)
    Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.8.5 - Canon Inc.)
    Canon Utilities CameraWindow (HKLM-x32\...\CameraWindowLauncher) (Version: 7.2.0.2 - Canon Inc.)
    Canon Utilities CameraWindow DC (HKLM-x32\...\CameraWindowDC) (Version: 7.4.0.9 - Canon Inc.)
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (HKLM-x32\...\CameraWindowDVC6) (Version: 6.5.0.3 - Canon Inc.)
    Canon Utilities MyCamera (HKLM-x32\...\MyCamera) (Version: 7.2.0.4 - Canon Inc.)
    Canon Utilities MyCamera DC (HKLM-x32\...\MyCameraDC) (Version: 7.2.0.5 - Canon Inc.)
    Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.22.46 - Canon Inc.)
    Canon Utilities RemoteCapture Task for ZoomBrowser EX (HKLM-x32\...\RemoteCaptureTask) (Version: 1.8.0.1 - Canon Inc.)
    Canon Utilities ZoomBrowser EX (HKLM-x32\...\ZoomBrowser EX) (Version: 6.3.0.7 - Canon Inc.)
    Canon ZoomBrowser EX Memory Card Utility (HKLM-x32\...\ZoomBrowser EX Memory Card Utility) (Version: 1.2.0.9 - Canon Inc.)
    CCleaner (HKLM\...\CCleaner) (Version: 6.14 - Piriform)
    CCleaner Update Helper (HKLM-x32\...\{E4EAC0E2-A80B-479F-BA45-DCDA595C9A93}) (Version: 1.8.1583.3 - Piriform Software) Hidden
    CryptoPrevent (HKLM-x32\...\{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1) (Version: - Foolish IT LLC)
    Defraggler (HKLM\...\Defraggler) (Version: 2.22 - Piriform)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 98.0.4758.102 - Google LLC)
    Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2869 - Intel Corporation)
    IObit Uninstaller 10 (HKLM-x32\...\IObitUninstall) (Version: 10.0.2.20 - IObit)
    iTop Screen Recorder (HKLM-x32\...\iTop Screen Recorder_is1) (Version: 3.1.0.1102 - iTop Inc.)
    iTop VPN (HKLM-x32\...\iTop VPN_is1) (Version: 3.3.0.2805 - iTop Inc.)
    Java 8 Update 371 (HKLM-x32\...\{71124AE4-039E-4CA4-87B4-2F32180371F0}) (Version: 8.0.3710.11 - Oracle Corporation)
    JL Country Cottage (HKLM\...\JL Country Cottage) (Version: - Microcourt Ltd.)
    Logitech Camera Settings (HKLM-x32\...\LogiUCDPP) (Version: 2.12.8.0 - Logitech Europe S.A.)
    Microsoft .NET Framework 4.6.1 (HKLM\...\{BD6F5371-DAC1-30F0-9DDE-CAC6791E28C3}) (Version: 4.6.01055 - Microsoft Corporation) Hidden
    Microsoft DVD App Installation for Microsoft.WindowsDVDPlayer_2019.6.13291.0_neutral_~_8wekyb3d8bbwe (x64) (HKLM\...\{25E80DAA-FD87-DCE5-202C-CC02F6673002}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
    Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 115.0.1901.188 - Microsoft Corporation)
    Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 115.0.1901.188 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-125910357-3284985775-168995214-1000\...\OneDriveSetup.exe) (Version: 19.103.0527.0003 - Microsoft Corporation)
    Microsoft Update Health Tools (HKLM\...\{BB052C53-34CB-42DE-AF41-66FDFCEEC868}) (Version: 3.72.0.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
    Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215 (HKLM-x32\...\{69BCE4AC-9572-3271-A2FB-9423BDA36A43}) (Version: 14.0.24215 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215 (HKLM-x32\...\{BBF2AC74-720C-3CB3-8291-5E34039232FA}) (Version: 14.0.24215 - Microsoft Corporation) Hidden
    Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 116.0.1 (x64 en-US)) (Version: 116.0.1 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 112.0.2 - Mozilla)
    Opera Stable 100.0.4815.76 (HKU\S-1-5-21-125910357-3284985775-168995214-1000\...\Opera 100.0.4815.76) (Version: 100.0.4815.76 - Opera Software)
    Privatefirewall 7.0 (HKLM-x32\...\{E8EA933E-03A2-4E62-9F52-812C72BE2A6B}) (Version: 7.0.30.3 - PWI, Inc.)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9239.1 - Realtek Semiconductor Corp.)
    Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
    Revo Uninstaller 2.0.4 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.4 - VS Revo Group, Ltd.)
    Skype version 8.92 (HKLM-x32\...\Skype_is1) (Version: 8.92 - Skype Technologies S.A.)
    Smart Defrag 5 (HKLM-x32\...\Smart Defrag_is1) (Version: 5.8.0 - IObit)
    Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
    SpywareBlaster 6.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 6.0.0 - BrightFort LLC)
    Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.3 - IObit)
    Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{FBA3961B-D1DF-493C-BC1F-E67D3B832895}) (Version: 2.56.0.0 - Microsoft Corporation)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    WiFi Password Revealer (HKLM-x32\...\WiFi Password Revealer_is1) (Version: 1.0.0.13 - Magical Jelly Bean)
    Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
    Zoom (HKU\S-1-5-21-125910357-3284985775-168995214-1000\...\ZoomUMX) (Version: 5.7.7 (1105) - Zoom Video Communications, Inc.)
     
  7. whitequeen96

    whitequeen96 Private First Class

    Stop! I don't you to spend any more of your time and energy on this. I think it's fixed. I'll need to check more on how well it functioning, but maybe the massive clean-up by CCleaner fixed everything. I usually run it every 2-4 days, but I must have picked up a virus or something in that time. I really appreciate you taking the time to help me. I'll report back to you after I see how it does.
    P.S. I wish I could edit the above 2 messages so that you don't waste your time reading them, but it's too late to do that.
     
  8. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the update. This is not a waste of time at all. We are happy to help and ultimately what we all want is a properly functioning computer.

    If the symptoms return or you simply want us to take a look at the computer feel free to post the reports. Rather than copy and paste the information attach the FRST.txt and Addition.txt reports in your reply.
     
  9. whitequeen96

    whitequeen96 Private First Class

    It seems to be OK now, thank God! CCleaner removed over 10,000 trackers. Since I usually run it every 2 or 3 days, my son or I obviously got into something bad. He's special needs so he just stays on youtube, and I don't go anywhere sketchy (tired old lady:rolleyes:) but it found us. Again, thank you so much for your help!

    I must say, your kindness is a good reflection on your signature and what it means.
     
  10. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you, I appreciate your kindness as well. It means a lot to me.

    Might I recommend going ahead with taking a look at the reports anyway? It is completely up to you but normally there is a lot more going on with a computer, even beyond a resolved obvious symptom. If you prefer to leave things as is I understand. If you want to follow up please attach the reports to your reply. It is no bother at all on my side, this is exactly why we are here.
     
  11. JonahWales

    JonahWales Staff Sergeant

    is it out of hardrive space?
     
  12. whitequeen96

    whitequeen96 Private First Class

    That would be wonderful! I'll get new reports in the next few days and attach them here. We have to be out of our home by 11/1, so I'm busy trying to find a place. But it would be a disaster if my computer went out during sending financial info, filling out forms, etc. So thank you!
    I've always wondered, does the light from a halo keep you up at night?
     
  13. whitequeen96

    whitequeen96 Private First Class

    No, only about 15%; no games, music or films. But thanks for asking.
     
  14. whitequeen96

    whitequeen96 Private First Class

     
  15. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    Assuming you would like to continue, take your time and we will get started when you are ready.
     
  16. whitequeen96

    whitequeen96 Private First Class

    I thought I did attach the 2 reports a couple of days ago, but I must have done it incorrectly. I'm not sure how to upload them from notepad. I tried downloading them (and show them in my downloads, then clicked "Upload a File" in my reply to you, but they didn't attach. Am I missing something? I'll run it again right before attaching it.

    Also, if I try to run CCleaner while Firefox is on, until recently it told me to close Firefox. But NOW it tells me to close Firefox and something new, called PROGRAMS. I suspect this is part of the problem; another program running in the background and clogging my computer with 1,000's of trackers each day. (I'm now running CCleaner 3 or 4 times a day and have 4000-5000 trackers each time. I'm terrified to open any of my banking pages. And I can't access them thru my very old Tracfone and wouldn't want to anyway.

    As you can see, I'm a complete neophyte!
     
  17. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    No problem at all, we will get through this. It is a bit complicated.

    In the Post Reply window, after clicking Upload a File go to your Downloads folder, left click on FRST.txt, then select Open. You should see it as an attached file at the bottom of the Reply window. If that works, do the same for the Addition.txt file. When you click Reply they should be attached to your post.

    If this does not work let me know and we will try something else.

    Either way, it would be best to copy and paste FRST64.exe from your Downloads folder to your Desktop. If we do that the reports will be placed on your Desktop where they will be easier to find.
     
  18. whitequeen96

    whitequeen96 Private First Class

    Wasn't able to save icon to desktop but set up shortcuts to latest reports on my desktop; also located in my downloads. I hope I'm able to attach them!
    I think I did it. I'm so grateful because I have to download my information from all my banks by 8/14 and I'm scared to open them! I must go out to take my son for a blood test and pick up his new meds at the pharmacy, so I'll be away from my desk for a few hours.
     

    Attached Files:

  19. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the reports, nice job!

    There is a bit to work through. So far I don't see anything troublesome. I should be able to complete my review tomorrow morning and have something posted for you. Just wanted to update you.
     
  20. Oh My!

    Oh My! Malware Expert Staff Member

    The number of cookies seems excessive but that doesn't automatically equate to malware. Also, CCleaner may simply be asking to close a legitimate program which happens to be running in the background.

    I don't see any malware but the computer seems a bit congested with lots of programs. I don't know if you want to go through the process of streamlining things or leave things as they are and just remove some junk.

    Let me know.
     
  21. whitequeen96

    whitequeen96 Private First Class

    Thank you. I accidentally ran FRST not as administrator one time and it showed I needed to update a lot of security stuff. I tried to do so but was unsuccessful. I'll try to do that again to get the info again. In the meantime, do you have a way of streamlining my programs?
     
  22. whitequeen96

    whitequeen96 Private First Class

    Eeek! I tried to run it again but not as the administrator to see the info mentioned above. I couldn't get into the program; I must have deleted it. I then tried to download it from MajorGeeks.com (the second location listed) and the whole thing hung up on "WaveBrowser.exe" as part of installing it. I finally had to stop everything before it was completed, saying I didn't want Wave to be my browser, but something came up saying it would still run in the background. I have to take my son to the doctor (special needs, medically fragile) again, but I'll come back and see what I can do, then contact you agin. But is there a tool to streamline all my programs. I'm sure I don't use many!
     
  23. Oh My!

    Oh My! Malware Expert Staff Member

    Delete any FRST64 you have, either on the Desktop or the Downloads folder so it isn't on your system at all. Then download a new copy from here. Run a new scan and attach the reports. I need to see the current state of your computer after the last events.

    Take all the time you need to take care of your son. He is always the priority.
     
  24. whitequeen96

    whitequeen96 Private First Class

    My brain is like tangled spaghetti! I finally figured out how to run FRST64 as Administrator AND how to upload the files to here, thank God!
     

    Attached Files:

  25. whitequeen96

    whitequeen96 Private First Class

    I also wanted to copy and paste a section of my Downloads for this week and last, because my problem started then. Can't figure it out, so here's the info, because it might be helpful. This is from before I started over with Frst64

    But now I can't even include that info with this Reply ....(sob) I'll store the info somewhere it you think it might be helpful.
     
  26. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    Hang onto the information for now.

    There are a number of programs I would like to uninstall to help clean things up. Please attempt to do these things. If you have any questions or problems make sure you stop and ask.

    ===================================================

    Uninstalling Programs Using Revo Uninstaller

    --------------------

    I recommend uninstalling the below listed program(s) from your computer.

    • Right click on Revo Uninstaller and select Run as administrator
    • From the list of programs highlight the listed program(s), or anything similar, then select Uninstall
    Code:
    Surfing Protection
    Smart Defrag 5
    Privatefirewall 7.0 
    IObit Uninstaller 10
    
    • If the program's uninstaller appears work through the steps to remove the program(s)
    • Be sure the Advanced option is selected then click Scan
    • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
    • Once done click Finish
    • Reboot your computer
    ===================================================

    Farbar Recovery Scan Tool - Run Fix Using Attached File

    --------------------
    • Please download the attached file and save it in the Downloads folder
    • Right click on FRST and select Run as administrator
    • Click Fix and once completed your computer will reboot
    • The tool will create a Fixlog.txt in your Downloads folder
    • Attach the report to your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
    • Programs uninstall?
    • Fixlog
     

    Attached Files:

  27. whitequeen96

    whitequeen96 Private First Class

    A. Uninstalled Smart Defrag 5 BUT I didn't see the Advanced Option before I clicked Scan. I followed through with the rest of the steps.
    1. Did I screw it up because I failed to click Advanced Option? Can I fix it?
    B. Made same mistake as above when I uninstalled Private Firewall.
    C. Uninstalled Surfing Protection and saw Advanced Option (head slap) and did exactly as I was told.
    Note: Never got a chance to click Finish, as everything disappeard after deleting leftovers for the 3 Uninstalls above.
    D. My Iobit Uninstaller shows 13 instead of 10. Should I uninstall that version?
    1. Iobit Uninstaller has a popup: "New installation detected. Recommend enabling Iobit Install Monitor to help you log and view all changes." I did not click on it because I assume I'll be getting rid of Iobit Uninstaller, even tho' it's 13 (not 10)

    Next step: I have downoads of A. FRST64(1).exe B. FRST.txt C. Addition.txt in my Downloads from 8/10 yesterday. I also have a Notepad page open for each one of the txts because I couldn't figure out how to save to my desktop.
    Once I finish with Iobit (D above) and reboot, where do I download "the attached file" (Farbar Recovery Scan Tool - Run Fix Using Attached File)? When I get that, I'll follow your further steps.
    Thank you again.
     
  28. Oh My!

    Oh My! Malware Expert Staff Member

    You did just fine.

    Go ahead and uninstall any Iobit you see.

    At the bottom of my last post you will see a link called Fixlist.txt. That is what you need to save to the Downloads folder. When you run FRST64 from the Downloads folder and select Run as administrator simply click Fix and it will run. You will get a Fixlog.txt when it is done and you can attach that file to your reply.
     
  29. whitequeen96

    whitequeen96 Private First Class

    Uninstalled Iobit, but am unclear if I should reboot (restart???) while 2 txts are open in notepad. I do see them in Downloads, so there won't be a problem?
     
  30. whitequeen96

    whitequeen96 Private First Class

    OK, figured it out up through the reboot. But:
    A. The only way I can see to get to FRST64 and select "Run as Admin." is if I type it into my search. If I try to run FRST64 from Downloads, I don't get that option. However, the Farbar Recovery Scan Tools boxes that come up from either selection are identical to one another. So does it matter how I get to FRST64?
    B. Within the boxes are 4 buttons: Scan, Search Files, Search Registry, Fix. Should I click Scan first? Or go right to Fix?
    C. So I don't have to click on Fixlist.txt? It just collects the info and shows it as Fixlog.txt?
    D. When you say to attach it to my reply, do you mean "Upload a File" from bottom of this page, next to Post Reply?
    Note: It's been over 24 hours since I ran FRST64, and I just removed 12,638 trackers.
    Excuse all the questions, but this is like working in Greek; I don't understand the terms, especially if 2 terms mean the same thing. I'm afraid to make a move without checking for fear of making a mistake.
     
  31. Oh My!

    Oh My! Malware Expert Staff Member

    Let's tackle this in bits and pieces because it is complicated stuff.

    If you right click on FRST64.exe do you see an option that says Run as administrator?
     
  32. whitequeen96

    whitequeen96 Private First Class

    Yes, even in Downloads!
     
  33. Oh My!

    Oh My! Malware Expert Staff Member

    Excellent.

    I am providing the Fixlist.txt file you need to download and it is at the bottom of this post. Click on it and save it in the Downloads folder. Let me know if that works.
     

    Attached Files:

  34. whitequeen96

    whitequeen96 Private First Class

    I couldn't figure out how to save it to Downloads, but it automatically went there.
     
  35. Oh My!

    Oh My! Malware Expert Staff Member

    Perfect.

    Your browser is set up to automatically save files to the Downloads folder. Let's get you an easier access to that folder.

    Create Downloads Desktop Shortcut

    • Right click on your Desktop, put the cursor over New, then select Shortcut
    • Click Browse...
    • Click on Downloads, then OK
    • Click Next
    • Click Finish
    • You should see a Downloads shortcut on your Desktop and if you double click on that your Downloads folder will open
    -----

    Running a FRST64 Fix

    • Open the Downloads folder
    • Right click on FRST64 and select Run as administrator
    • In the open FRST64 window simply click Fix
    • A Fixlog.txt document will appear and a copy will also be saved in the Downloads folder
    • Go to the topic web page
    • Click on Upload a File
    • In the window that will appear, on the left side look for and click on Downloads
    • Locate and click on Fixlog.txt
    • Click Open and the Fixlog.txt should appear in the Reply window
    • Click Post Reply and everything should work
     
  36. whitequeen96

    whitequeen96 Private First Class

    Did the first 2 steps, but I don't see Downloads on Browse. I tried typing it in, but "The file Downloads cannot be found." Could it be in something else?
     
  37. Oh My!

    Oh My! Malware Expert Staff Member

    Did you click on the Browse button?

    If yes, when the window opens do you see Desktop at the top of the list?
     
  38. whitequeen96

    whitequeen96 Private First Class

    Yes, I see Desktop, but not Downloads.
    Lots of files (?) under it, but not Downloads. It looks as if lists all the things I already have on my Desktop.
     
  39. Oh My!

    Oh My! Malware Expert Staff Member

    Do you see a folder icon on the Taskbar at the bottom of your screen?
     
  40. whitequeen96

    whitequeen96 Private First Class

    Yes, I have it showing Downloads. It also has a separate window showing "Create Shortcut."
     
  41. Oh My!

    Oh My! Malware Expert Staff Member

    If you already have a folder showing Downloads you can just click on that to get to it.
     
  42. whitequeen96

    whitequeen96 Private First Class

    OK, did this and I see the Fixlog.txt in my Downoads. Now there's a popup from Farbar saying that's done, but the computer needs a restart. "Click OK to restart."
    Do I go to the topic Webpage after this? And do I search in Google to find it, or should it be available from anything I've done or is in Downloads?
     
  43. whitequeen96

    whitequeen96 Private First Class

    Should I restart? I'm hesitant because you didn't say to in your steps above.
     
  44. Oh My!

    Oh My! Malware Expert Staff Member

    Yes, restart.

    You will need to come back to the topic like you have done in the past. I am not sure if you Googled it or had some other way.
     
  45. whitequeen96

    whitequeen96 Private First Class

    OK, restarted.
    I never searched for any of these programs before, I downloaded them from links you provided. If I Google fixlog.txt, I don't see what you seem to be asking for.
    If I go to Downloads and right click on Fixlog.txt, I get a menu with: Open, Edit, Share, Send to, Copy, among other choices. So what should I do now?
     
  46. Oh My!

    Oh My! Malware Expert Staff Member

    Let's try this.

    Click Open
    Right click inside the document and select Select all
    Right click inside the document again and select Copy
    Come back to the Reply window on the topic, right click inside where you would normally type and select Paste
    If you see the report information in the Reply window just hit Post Reply
     
  47. whitequeen96

    whitequeen96 Private First Class

    This opened a Notepad page. I right clicked, "Select All" then right clicked "Copy." But when I Hit Post Reply, a message came up saying can't enter a message with more than 40,000 characters. This is probably over 40 pages long. It also says at the bottom "The system needed a reboot" but I did that when I was supposed to.

    "The system needed a reboot.

    ==== End of Fixlog 16:40:40 ===="
     
  48. Oh My!

    Oh My! Malware Expert Staff Member

    If you click Upload a File are you able to find the Downloads folder and the Fixlog.txt file? You would do the same thing you did in Post #24.
     
  49. whitequeen96

    whitequeen96 Private First Class

    YES!!! I hope it works!
     

    Attached Files:

  50. Oh My!

    Oh My! Malware Expert Staff Member

    Yippeeeee! Nice work.

    That looks good.

    How is the computer running now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds