Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works

my computer is replacing my updated drivers with legacy and theres mo

antivirus/malware debug locking me out virtualized changing my recovery redirecting my windows instal

  • This topic is locked This topic is locked



    New Member

  • Member
  • Pip
  • 1 posts

hi im sorry to be   a pain in the but by asking you for help  but i am desperate  really truly desperate i have pretty decent knowlege in using a pc but for over 3 weeks now i have been trying to get rid of this issue its cost me money i dont really have only thanx to my mother who i currently care for so idont get to have priveliges like most iknow do my pc and games are all have and my mother but who ever is doing it or what i dont know anymore so i will refer to it as IT.so IT started when i noticed alot more activity going on than usual i was not certain then and thought nothing of itbut then when i was checking in my taskmanager  the processors i noticed 1 or 2 that i did not recall ever seeing as iwas looking at these processorsi noticed something really strange like  1 of them was  1 second  a sytem process then was a localnetwork process it kept changing rapidly so i opened its location and started to notice lots of other thingsi cannot explain what or how i knew i just seen how it looks in the system32 folder so many times that i knew there was way more there than there should be so  cutting a very long story shorter i looked around found more then more then i found something stranger like folders named send and upload dotted here and there and in some was programmes i had installed but iknow should not be there and next day i updated my gpu drivers with the latest  which for example version would be something like this-8.028674 but then after rebooting my aero was not working so i went to programms and features was about to uninstall  it and it came to my attention the version was 1.0.000000 or somthing so ii uninstalled it tried again the same thning happend so i removed it once again

and did not install it this time  but when i right clicked the desktop later on i notriced it catalist control centre was still there even though it shouldnt be so i checkr4ed back at programmes and features and  wellit was not there so i opened task manager and found it to openits location and it was there  alright but not where it should of been not even close so i started to delete it all but so far in started getting prompts for admin  in order to deletethen evenafter tyhat it say accesws denied so i started manually taking back  my rights and then it got to a point where i went to click ok to accept the delete but nothing happened at all as if it was just pl;aced there infront of me for to dono purpuse at all exept its purpose to do nothingand it was same with all the rest  then suddenly started freezing  and was hard to move my mouse pointer i got taskmanager open  by clicking the ctrl+alt+del and when it opened and was back at the desktop in taskmanager was lots of porocessors called consent so then after 20mins i ended up rebooting but it just showed a blackscreen ieven waited an 10mins and rebooted then itried safemode and still same so i reinstalled and deleted the contents during the reinstall and after login i noticed aero was alreadyenabled which has never happened ever so ilooked around and found that a lot of my stuff from previous installwas still  there and back as if i had not even reinstalled at all i could go on  and tellyou about all the other 40 or so reinstalls and how they got worse and worse and now there even more processors running that i not seen i found logs with command scripts and all kinds read some strange stuff when iopened themin notepad like the commands and what they are for  and debugging enabled all the time even after reinstall  and its linked to security accounts manager and i noticed a textr file in the debug folder in the wim folder called nrtsetup which is a  set of commands to a domain in order to  setup the debugging and asking toverify my computer checking that its workgroup then confirming it is and that its good for setup 2 or somthing please please say you can helpme  i tried everything i can i not sleep for days on days thenionly get a coupleof hours i even tried new windows disk from my local retail and same and alsoprnd new components basicly only the shell was not new and the same again then itried buying windows 8.1 and still its same they are here only i thinkits slightly harder for them or IT thank you in advance even if you are unableto help your timeis appreciated

  • 0




    Trusted Helper

  • Malware Removal
  • 3,590 posts

Hi. My name is Brian, and I will be helping you with Malware Removal.


I am currently in training and my posts will need to be reviewed by an expert, so expect a slight delay between posts.

- General Instructions -

  • Please read all instructions and fixes thoroughly. Read the ENTIRE post BEFORE performing any steps so you understand all that needs to be done.
  • I would advise printing any instructions for easy reference as some of the fixes may require you to boot in Safe mode. Access to these instructions may not be available in Safe Mode.
  • Any fixes provided by myself are for this log file only and should not be used on any other systems.
  • Do not run any other removal software or perform updates other than the ones I provide, as it will complicate the cleaning process.
  • You have 4 days to reply to each post or the topic will be closed. You will be able to request that the topic be re-opened by sending me a PM (Personal Message) or PM a moderator.
  • Please feel free to ask any questions, especially if you are having problems with my instructions.

- Save ALL Tools to your Desktop-


All tools that I have you download should be placed on the desktop unless otherwise stated. If you are familiar with how to save files to the desktop then you can skip this step.


Since you are continuing with this step then I assume you are unfamiliar with saving files to your desktop. As a result it's easiest if you configure your browser(s) to download any tools to the desktop by default. Please use the appropriate instructions below depending on the browser you are using.

Chrome.JPGGoogle Chrome - Click the "Customize and control Google Chrome" button in the upper right-corner of the browser.Settings.JPG Choose Settings. at the bottom of the screen click the
"Show advanced settings..." link. Scroll down to find the Downloads section and click the Change... button. Select your desktop and click OK.

Firefox.JPGMozilla Firefox - Click the "Open Menu" button in the upper right-corner of the browser. Settings.JPG Choose Options. In the downloads section, click the Browse button, click on the Desktop folder
and the click the "Select Folder" button. Click OK to get out of the Options menu.

IE.jpgInternet Explorer - Click the Tools menu in the upper right-corner of the browser. Tools.JPG Select View downloads. Select the Options link in the lower left of the window. Click Browse and
select the Desktop and then choose the Select Folder button. Click OK to get out of the download options screen and then click Close to get out of the View Downloads screen.

NOTE: IE8 Does not support changing download locations in this manner. You will need to download the tool(s) to the default folder, usually Downloads, then copy them to the desktop.


- Finally Before We Start-


Removing malware is a complicated multiple step process, Please stay with me until I have declared your system clean. I strongly recommend you backup your personal files and folders. Although rare, attempting to remove malware can render your machine unbootable or cause data loss. Having backups of your data is your responsibility. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.


OK, Let's get started. Please follow the instructions below.


Fresh Set of Logs Needed
Let's begin. Please follow the steps below.
1. Please download Farbar Recovery Scan Tool and save it to your Desktop.
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them.
    Only one of them will run on your system, that will be the right version.
2. Right click on the file and select Run as administrator (If you don't have this option simply double-click the file to open). When the tool opens click Yes to disclaimer.
3. Press Scan button.
4. It will produce a log called FRST.txt in the same directory the tool is run from (which should be the desktop)
5. Please copy and paste log back here.
6. The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe). Please also paste that along with the FRST.txt into your reply.
     Note: Please do not attach any logs unless specifically requested. It's easier if you simply copy and paste them into your reply. It's OK if you have to use more than one post to do so.


  • 0



    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP