Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Do I have a malware problem? [Solved]


  • This topic is locked This topic is locked

#16
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
Hi Deevly,

Just a note for the 1st step--I am asking you to do that in order to enable me to remove the entries you disabled, via the script in the 3rd step.
 

2. I ran the uninstallers for Malwarebytes and Norton Security, and I also ran one from the McAfee site to try and clean up leftovers from a free trial that was preinstalled. Note: There is still a 516 MB McAfee folder on the D drive under "Applications." And there are three Norton folders still on the C drive under "Program Files (x86) ). The folders are Norton Security (136 MB), Norton Security Scan (45 KB), and Norton Installer (496 KB). Do you think it's safe to just delete those folders?


You can safely delete both folders. Did this laptop come pre-installed with an anti-virus, by the way? Copies are usually kept in a folder called "Applications" by the manufacturers. Such may be the case for McAfee.
 

3. I haven't downloaded any new security yet. The laptop came with Windows Defender, which I assume is sufficient for now?


Windows Defender is a supplementary program and will not stand on its own. Kindly refer to my prior post and choose one anti-virus to install. :) I would recommend Avast.
 

Oh, another quirky thing: My Kindle app stopped working last night, after working fine the night before. It starts to open, then crashes. I tried uninstalling and reinstalling with no joy. It seems to be the only app affected. Trying to figure that out now. *shrug*


Did you mean 'this'?
  • Step 1

    Open System Configuration by following the steps below.
    • Press the Windows and R buttons together. The Run prompt should appear.
    • Type in msconfig and press OK.
    • Navigate to the Startup tab > Enable All > Apply > OK.
    • You will be prompted to restart. Do not allow it by choosing Exit without restart.
  • Step 2

    Upon careful inspection, your log indicates that the program(s) listed below is installed on your computer. I would like to request for the removal of the program(s) as it is associated with malware, adware or spyware. Please proceed to uninstalling by going to Control Panel (Windows XP) or Programs and Features (Windows Vista or Windows 7). If Windows says it cannot locate the program(s) and that it prompts for it to be removed from the list instead, do so by allowing it.
    • Lenovo Browser Guard
    Inform me if you encounter problems in the removal process.
  • Step 3

    Copy and paste the following into Notepad and save as fixlist.txt to your desktop:
    EmptyTemp:
    CloseProcesses:
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
    S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X]
    R2 VDWFP; C:\windows\system32\Drivers\VDWFP64.sys [39800 2014-05-12] (Superfish, Inc.)
    2014-12-08 21:18 - 2014-12-08 21:25 - 188058456 _____ () C:\Users\Deidra\Downloads\OJ5740_117.exe
    2014-12-08 21:31 - 2014-12-08 21:31 - 00000057 _____ () C:\ProgramData\Ament.ini
    2014-12-07 19:33 - 2014-12-14 13:05 - 00000000 ____D () C:\Program Files (x86)\Norton Security
    2014-12-07 18:24 - 2014-12-14 13:15 - 00000000 ____D () C:\ProgramData\Norton
    2014-12-07 18:24 - 2014-12-07 20:53 - 00000000 ____D () C:\Program Files (x86)\Norton Security Scan
    2014-12-03 12:53 - 2014-12-03 12:53 - 00000000 ____D () C:\Users\Public\Pokki
    2014-12-03 12:52 - 2014-12-07 21:18 - 00002302 _____ () C:\Users\Deidra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
    2014-12-03 11:48 - 2014-12-09 02:20 - 00000000 ____D () C:\Users\Deidra\AppData\Local\Pokki
    2014-12-03 11:48 - 2014-12-03 11:48 - 00000180 _____ () C:\windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
    2014-12-03 11:48 - 2014-12-03 11:48 - 00000000 ____D () C:\Users\Deidra\AppData\Local\LenovoBrowserGuard
    2014-12-03 11:48 - 2014-03-18 04:55 - 00000369 _____ () C:\Users\Deidra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
    2014-12-03 11:48 - 2014-03-18 04:55 - 00000369 _____ () C:\Users\Deidra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
    2014-12-14 15:23 - 2014-08-20 21:09 - 00000000 ____D () C:\ProgramData\McAfee
    2014-12-12 01:04 - 2014-08-20 21:11 - 00010920 _____ () C:\windows\SysWOW64\VisualDiscovery.ini
    2014-12-12 01:04 - 2014-08-20 21:11 - 00005376 _____ () C:\windows\SysWOW64\VisualDiscoveryOff.ini
    2014-12-12 01:04 - 2014-08-20 21:11 - 00005376 _____ () C:\windows\system32\VisualDiscoveryOff.ini
    2014-12-07 20:53 - 2014-08-20 21:07 - 00000000 ____D () C:\Users\Default\AppData\Local\Pokki
    2014-12-07 20:53 - 2014-08-20 21:07 - 00000000 ____D () C:\Users\Default User\AppData\Local\Pokki
    2014-12-07 20:53 - 2014-08-20 21:07 - 00000000 ____D () C:\ProgramData\Pokki
    2014-12-03 11:48 - 2014-08-20 21:08 - 00000000 ____D () C:\Program Files (x86)\LenovoBrowserGuard
    AlternateDataStreams: C:\Users\Deidra\Downloads\Facebook-20141203-121530.jpg:StreamedFileState
    AlternateDataStreams: C:\ProgramData\TEMP:B3503B59
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver"
    HKLM\...\StartupApproved\Run: => "Yoga PhoneCompanion"
    HKLM\...\StartupApproved\Run32: => "ISUSPM"
    HKLM\...\StartupApproved\Run32: => "Yoga Picks"
    HKU\S-1-5-21-818984236-3831732592-3455439087-1001\...\StartupApproved\Run: => "Pokki"
    HKLM\...\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-08-20] (Lenovo)
    HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2075480 2013-06-24] (Flexera Software LLC.)
    • Run your copy of FRST. It is important to ensure it is located in your desktop.
    • Press the Fix button.
    • It will produce a log (fixlog.txt) once done.
    • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log(s) in your next reply.
  • Logs to Post

    In summary of the above, I will need you to post the following log(s):
    • fixlog.txt (Farbar Recovery Scan Tool)

  • 0

Advertisements


#17
Deevly

Deevly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts

 1. I installed Avast.

2. Yes, that is the Kindle app that's not working.

 

3. The System Configuration box doesn't have any options under the startup tab. It only has a link to open the Task Manager. I wanted to ask before proceeding: Is it okay to perform this step from the Task Manager? There are 12 entries under the Startup Tab in Task Manager; Two are disabled; there is no "enable all" button, but I can enable them individiually. Do I proceed with that? 


  • 0

#18
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts

Yes, please. :)


  • 0

#19
Deevly

Deevly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-12-2014 01
Ran by Deidra at 2014-12-15 14:11:19 Run:1
Running from C:\Users\Deidra\Desktop
Loaded Profile: Deidra (Available profiles: Deidra)
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
EmptyTemp:
CloseProcesses:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X]
R2 VDWFP; C:\windows\system32\Drivers\VDWFP64.sys [39800 2014-05-12] (Superfish, Inc.)
2014-12-08 21:18 - 2014-12-08 21:25 - 188058456 _____ () C:\Users\Deidra\Downloads\OJ5740_117.exe
2014-12-08 21:31 - 2014-12-08 21:31 - 00000057 _____ () C:\ProgramData\Ament.ini
2014-12-07 19:33 - 2014-12-14 13:05 - 00000000 ____D () C:\Program Files (x86)\Norton Security
2014-12-07 18:24 - 2014-12-14 13:15 - 00000000 ____D () C:\ProgramData\Norton
2014-12-07 18:24 - 2014-12-07 20:53 - 00000000 ____D () C:\Program Files (x86)\Norton Security Scan
2014-12-03 12:53 - 2014-12-03 12:53 - 00000000 ____D () C:\Users\Public\Pokki
2014-12-03 12:52 - 2014-12-07 21:18 - 00002302 _____ () C:\Users\Deidra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-12-03 11:48 - 2014-12-09 02:20 - 00000000 ____D () C:\Users\Deidra\AppData\Local\Pokki
2014-12-03 11:48 - 2014-12-03 11:48 - 00000180 _____ () C:\windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2014-12-03 11:48 - 2014-12-03 11:48 - 00000000 ____D () C:\Users\Deidra\AppData\Local\LenovoBrowserGuard
2014-12-03 11:48 - 2014-03-18 04:55 - 00000369 _____ () C:\Users\Deidra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-12-03 11:48 - 2014-03-18 04:55 - 00000369 _____ () C:\Users\Deidra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-12-14 15:23 - 2014-08-20 21:09 - 00000000 ____D () C:\ProgramData\McAfee
2014-12-12 01:04 - 2014-08-20 21:11 - 00010920 _____ () C:\windows\SysWOW64\VisualDiscovery.ini
2014-12-12 01:04 - 2014-08-20 21:11 - 00005376 _____ () C:\windows\SysWOW64\VisualDiscoveryOff.ini
2014-12-12 01:04 - 2014-08-20 21:11 - 00005376 _____ () C:\windows\system32\VisualDiscoveryOff.ini
2014-12-07 20:53 - 2014-08-20 21:07 - 00000000 ____D () C:\Users\Default\AppData\Local\Pokki
2014-12-07 20:53 - 2014-08-20 21:07 - 00000000 ____D () C:\Users\Default User\AppData\Local\Pokki
2014-12-07 20:53 - 2014-08-20 21:07 - 00000000 ____D () C:\ProgramData\Pokki
2014-12-03 11:48 - 2014-08-20 21:08 - 00000000 ____D () C:\Program Files (x86)\LenovoBrowserGuard
AlternateDataStreams: C:\Users\Deidra\Downloads\Facebook-20141203-121530.jpg:StreamedFileState
AlternateDataStreams: C:\ProgramData\TEMP:B3503B59
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver"
HKLM\...\StartupApproved\Run: => "Yoga PhoneCompanion"
HKLM\...\StartupApproved\Run32: => "ISUSPM"
HKLM\...\StartupApproved\Run32: => "Yoga Picks"
HKU\S-1-5-21-818984236-3831732592-3455439087-1001\...\StartupApproved\Run: => "Pokki"
HKLM\...\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-08-20] (Lenovo)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2075480 2013-06-24] (Flexera Software LLC.)
 
*****************
 
Processes closed successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} not found.
McAfee SiteAdvisor Service => Service deleted successfully.
VDWFP => Unable to stop service
VDWFP => Service deleted successfully.
C:\Users\Deidra\Downloads\OJ5740_117.exe => Moved successfully.
C:\ProgramData\Ament.ini => Moved successfully.
C:\Program Files (x86)\Norton Security => Moved successfully.
C:\ProgramData\Norton => Moved successfully.
C:\Program Files (x86)\Norton Security Scan => Moved successfully.
C:\Users\Public\Pokki => Moved successfully.
C:\Users\Deidra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk => Moved successfully.
"C:\Users\Deidra\AppData\Local\Pokki" => File/Directory not found.
C:\windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => Moved successfully.
C:\Users\Deidra\AppData\Local\LenovoBrowserGuard => Moved successfully.
C:\Users\Deidra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk => Moved successfully.
C:\Users\Deidra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk => Moved successfully.
C:\ProgramData\McAfee => Moved successfully.
C:\windows\SysWOW64\VisualDiscovery.ini => Moved successfully.
C:\windows\SysWOW64\VisualDiscoveryOff.ini => Moved successfully.
C:\windows\system32\VisualDiscoveryOff.ini => Moved successfully.
C:\Users\Default\AppData\Local\Pokki => Moved successfully.
"C:\Users\Default User\AppData\Local\Pokki" => File/Directory not found.
C:\ProgramData\Pokki => Moved successfully.
C:\Program Files (x86)\LenovoBrowserGuard => Moved successfully.
C:\Users\Deidra\Downloads\Facebook-20141203-121530.jpg => ":StreamedFileState" ADS removed successfully.
C:\ProgramData\TEMP => ":B3503B59" ADS removed successfully.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc" => Key deleted successfully.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc" => Key deleted successfully.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\VDWFP" => Key deleted successfully.
HKLM\...\StartupApproved\Run: => "Yoga PhoneCompanion" => Error: No automatic fix found for this entry.
HKLM\...\StartupApproved\Run32: => "ISUSPM" => Error: No automatic fix found for this entry.
HKLM\...\StartupApproved\Run32: => "Yoga Picks" => Error: No automatic fix found for this entry.
HKU\S-1-5-21-818984236-3831732592-3455439087-1001\Software\Microsoft\Windows\CurrentVersion\Run\\HKU\S-1-5-21-818984236-3831732592-3455439087-1001\...\StartupApproved\Run: => "Pokki" => Value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Yoga PhoneCompanion => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ISUSPM => value deleted successfully.
EmptyTemp: => Removed 569.7 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog ====

  • 0

#20
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
Looks like that is the last of it. Re-run DelFix again for me, please.
  • 0

#21
Deevly

Deevly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
# DelFix v10.8 - Logfile created 15/12/2014 at 22:45:57
# Updated 29/07/2014 by Xplode
# Username : Deidra - FLIPSY
# Operating System : Windows 8.1  (64 bits)
 
~ Removing disinfection tools ...
 
Deleted : C:\FRST
Deleted : C:\Users\Deidra\Desktop\FRST-OlderVersion
Deleted : C:\Users\Deidra\Desktop\Addition.txt
Deleted : C:\Users\Deidra\Desktop\Fixlog.txt
Deleted : C:\Users\Deidra\Desktop\FRST.txt
Deleted : C:\Users\Deidra\Desktop\FRST64.exe
 
~ Creating registry backup ... OK
 
~ Cleaning system restore ...
 
Deleted : RP #9 [End of disinfection | 12/13/2014 16:09:51]
Deleted : RP #10 [avast! antivirus system restore point | 12/15/2014 18:08:36]
 
New restore point created !
 
########## - EOF - ##########

  • 0

#22
Deevly

Deevly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts

Everything seems to be okay ... Kindle app is working again ... no weird popups or slowdowns anywhere. I did discover a lost driver for an app, and my Documents and Pictures icons disappeared from my Start Screen, but those were easily replaced. Hopefully, we're all good. Thanks for your help!


  • 0

#23
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
I will now proceed to giving to tips on how to maintain your system as it is. Anytime you encounter an infection again, please do not hesitate to go back here at Geeks to Go. :)

Remove, Disable, or Update Java

As Java is the 'most exploited program at this time', I recommend that you remove it unless you need it. If so, it is prudent to 'disable it in your web browser(s)' while ensuring your copy is always up-to-date. Older versions are prone to exploits and vulnerabilities.
  • Download the latest 'Java' installation and save it to your desktop.
    • You need to uninstall any previous Java installations.
      • For Windows XP: Navigate to Start > Control Panel > Add or Remove Programs.
      • For Windows Vista: Navigate to Start > Control Panel > Programs and Features or Uninstall a Program.
      • For Windows 7: Navigate to Start > Control Panel > Programs and Features or Uninstall a Program.
      • For Windows 8: Navigate to Start > Start Context Menu > Programs and Features or Uninstall a Program.
    • Search the list for previous installations of Java such as all versions below:
      • Java™ 7 Update 71
    • Proceed to uninstalling the old versions and install the one you've just downloaded.
Update Your Anti-Virus Every Day

Updating


Ensuring that you have one anti-virus installed in your system is a good way to prevent being infected. You must always make sure to update your anti-virus every day; anti-virus companies see to to it that the latest definition updates are distributed to be up to par with the propagation of malware. Your anti-virus is useless if you do not update it.


Scanning


Set a scanning routine. Ensure that you do a full scan with your anti-virus monthly. This is part of maintaining a clean system--a scanning routine proves to be effective. You can never be sure when your computer has caught an infection.


If you have any unresolved issues with regard to this thread or you need more :help: please ask me. I would assist you further, should it be required. Otherwise, enjoy your clean system.

:cheers:

Thank you.
  • 0

#24
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts

Since this issue appears to be resolved, this topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a new topic.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP