Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Help removing "Ads by Jabuticata" [Solved]

Malware?

  • This topic is locked This topic is locked

#16
Johnde2000

Johnde2000

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts

I may be speaking/typing too soon, but, I rebooted after running the last three scans and posted here. I came back to this site and clicked on "MY CONTENT" I got another tab open that was a web page for GEEKS TECH. Then I closed it and clicked MY CONTENT again, another web page opened. I closed that and now nothing, It seems to be gone. We'll see ! ....NOPE when I clicked to post this message this web page opened in another tab, http://www.reimagepl...ntext=518923594


Edited by Johnde2000, 30 July 2015 - 09:59 AM.

  • 0

Advertisements


#17
Johnde2000

Johnde2000

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts

After all that it's still doing it, Can we set up a time and use teamveiwer or something else, I want you to see what's happening


  • 0

#18
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts

After all that it's still doing it, Can we set up a time and use teamveiwer or something else, I want you to see what's happening


Hi :)

I'm not allowed to use teamviewer and such in malware support. Let's run Zoek and see what it comes up with. I'm not seeing anything in the FRST logs, and the JRT and AdwCleaner logs didn't find much. However, let's see what Zoek finds. :thumbsup:

Also, you do not use Chrome on this machine, correct?



Please download zoek.exe to your Desktop:
  • On Windows Vista, 7, and 8, right-click Zoek.exe and select: Run as Administrator
  • Give it a few seconds to appear
  • Click the Options button and place a checkmark only on the following options:
  • AutoClean
  • Now...
  • Close any open programs.
  • Click the Run script button, and wait.
  • It takes a few minutes to run.
  • When the tool finishes, the zoek-results.log is opened in Notepad.
  • The log is also found on the systemdrive, normally C:\
  • If a reboot is needed, the log is opened after the reboot.
Please post the zoek-results.log in your reply.
  • 0

#19
Johnde2000

Johnde2000

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by John on Thu 07/30/2015 at 20:03:04.20.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\John\Desktop\zoek.exe [Scan all users]  [Checkboxes used]

==== System Restore Info ======================

7/30/2015 8:04:03 PM Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\PROGRA~2\gravitysensation.com deleted successfully
C:\PROGRA~2\InstallConverter bundle uninstaller deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\Piranha Games deleted successfully
C:\PROGRA~2\TechVedic deleted successfully
C:\PROGRA~2\Yahoo! deleted successfully
C:\PROGRA~2\COMMON~1\Blizzard Entertainment deleted successfully
C:\Program Files\office.tmp deleted successfully
C:\Program Files\Common Files\AV deleted successfully
C:\PROGRA~3\Avg_Update_0615pi deleted successfully
C:\PROGRA~3\Battle.net deleted successfully
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully
C:\PROGRA~3\SystemRequirementsLab deleted successfully
C:\PROGRA~3\WinZip deleted successfully
C:\Users\John\AppData\Roaming\Battle.net deleted successfully
C:\Users\John\AppData\Roaming\Open Download Manager deleted successfully
C:\Users\John\AppData\Local\Battle.net deleted successfully
C:\Users\John\AppData\Local\LogMeIn Rescue Applet deleted successfully
C:\Users\John\AppData\Local\NVIDIA deleted successfully
C:\Users\John\AppData\Local\Steam deleted successfully
C:\Users\John\AppData\Local\Unity deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BE608C-CC87-4A89-828F-7C282D0189A} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{13DC7C8-1C54-4BE4-8E32-C121CDACDFD2} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1445B07D-D59E-4B03-8C98-E9E3766E2652} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D326504-3339-4AF8-A4BE-FEEDFD249592} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2DAA6596-9AE-4C62-BD23-E2CFD075575F} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{364F5943-D205-4FF7-8B98-576BFD8B4BC} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4115D8A1-2488-497D-B1DE-46CFD4C85C3} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43CA7DD9-C006-47F6-A864-2CAA34FDD396} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{658DB89C-6ADF-48A5-AA7D-A6D296F2AEC} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{756514D6-F357-44F5-BADF-E2CFBC128AEC} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7AEFE841-DCA1-4A95-80CB-BE935D020302} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7AEFE841-DCA1-4A95-80CB-BE935D020302} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{81E629D7-49C2-43D3-957-2A5018FD85E3} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9FB196EC-5739-4846-B9BF-3DBB76A455E} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A1E128B7-66C2-4EC0-BD7E-93319CE6B73} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A638D650-B3B0-4915-9115-6B4864ABC52} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C5E6EF5-277D-41A3-9B28-7AAE821E585} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C85A7F16-B9E5-421F-B3F8-B6CE23B8AEB6} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CD80E9B7-CCD-4F2E-A9B8-7DE68CEF2A9} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D19B69A4-3CD9-457E-B5D2-1B262A9B3FB9} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D3E42964-7344-4D2A-AD9-7D5621394EC8} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D4D97DEC-8C9E-40C0-AAB1-98AC5BB959A} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F7883CF1-850F-4FDF-BD94-8834588C5DC} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA392FDC-EC03-4736-BB54-99B4806C4C50} deleted successfully
HKEY_USERS\S-1-5-21-4074055908-3935984809-2394099874-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB561D68-4B36-4745-8F55-65FAB8387C33} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AEFE841-DCA1-4A95-80CB-BE935D020302} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~2\gravitysensation.com not found
C:\PROGRA~2\InstallConverter bundle uninstaller not found
C:\PROGRA~2\Piranha Games not found
C:\PROGRA~2\TechVedic not found
C:\PROGRA~2\Yahoo! not found
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) not found
C:\PROGRA~2\Raptr deleted
C:\PROGRA~2\CTB deleted
C:\Users\John\AppData\Roaming\Yahoo! deleted
C:\PROGRA~3\Package Cache deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A} deleted
C:\Windows\wininit.ini deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\7od82dfo.default
user_pref("browser.search.defaultenginename.US", "Google");

==== Firefox Extensions ======================

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\7od82dfo.default
18CF51689186AEB9D1D149AEB0E92D03    - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL -    Microsoft Office 2013
FD82108FD60B63010325D9AF6F00AF99    - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll -    Shockwave Flash
EF3CA2A515FEC970E22D2C424A42401E    - C:\Users\John\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll -    Unity Player


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com/"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com/"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.co...={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/...ox&FORM=IE8SRC"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\John\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\John\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\John\AppData\Local\Mozilla\Firefox\Profiles\7od82dfo.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=30 folders=36 28265438 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\John\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\John\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on Thu 07/30/2015 at 20:29:26.34 ======================
 


  • 0

#20
Johnde2000

Johnde2000

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts

In case you already didn't know it, I may have identified the problem, it's called "Reimage Plus.com" or Search reimage.com  It seems to be a virus from what I'm reading, any ideas?


Edited by Johnde2000, 30 July 2015 - 07:14 PM.

  • 0

#21
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Hello :)

The Zoek log looks good. I'd like to put an anti-virus program on the machine as well as install AdBlock Edge in FF that should help block the popups. But before we do that, how is the machine running?
  • 0

#22
Johnde2000

Johnde2000

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts

In case you already didn't know it, I may have identified the problem, it's called "Reimage Plus.com" or Search reimage.com  It seems to be a virus from what I'm reading, any ideas?

Sometimes its fine then all of a sudden I get these , for lack of a better word, redirects., It doesnt happen except here on this web page. I can play games, surf the web, check emails, its fine no redirects or pop ups, UNTIL I come to this site, anything I click redirects me, but its just on a second or third click then it stops again until I close this site and come back


Edited by Johnde2000, 30 July 2015 - 07:20 PM.

  • 0

#23
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts

In case you already didn't know it, I may have identified the problem, it's called "Reimage Plus.com" or Search reimage.com  It seems to be a virus from what I'm reading, any ideas?

Sometimes its fine then all of a sudden I get these , for lack of a better word, redirects., It doesnt happen except here on this web page. I can play games, surf the web, check emails, its fine no redirects or pop ups, UNTIL I come to this site, anything I click redirects me, but its just on a second or third click then it stops again until I close this site and come back


Ok, that helps a lot actually. There are ads on the website, however, once you log in you shouldn't see those anymore. I get them when I come to the site and do not log, but merely surf. Your logs are definitely clean, but we need to address your security issues with not having an anti-virus and install a Firefox extension called AdBlock Edge to help block the ads.


Step 1: Avast Installation

Please click here to go to Avast's website. Please select the Free Download version of Avast and install it on your machine.
Once it's installed, it will request to do a scan, please let it do so.


Step 2: Install AdBlock Edge

Please click here to go to AdBlock Edge's page. This extension will help block popups and opening of new tabs as well.


Please let me know when these steps are complete. I still need to remove my tools, and perform some maintenance on the machine. :thumbsup:
  • 0

#24
Johnde2000

Johnde2000

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts

Ok both have been downloaded. Avast scanned and no threats were found. I already had AdBlock Plus on the computer but it was deleted during one of our scans. Should I reinstall that as well?


  • 0

#25
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts

Ok both have been downloaded. Avast scanned and no threats were found. I already had AdBlock Plus on the computer but it was deleted during one of our scans. Should I reinstall that as well?


Actually, I'd leave AdBlock Plus off the machine. They've gone to the dark side, basically. They take money from big name companies and allow their ads to come through. Here's an article about it.

https://nakedsecurit...t-adblock-plus/



Step 1: Tool Removal with Delfix and Creation of a clean restore point
  • Download Delfix from here
  • Ensure Remove disinfection tools is ticked
    Also tick:
    • Create registry backup
    • Purge system restore
    • Reset System Settings
    delfix.jpg
  • Click Run
The program will run for a few moments and then notepad will open with a log. Please paste the log in your next reply.
  • You can uninstall ESET Online Scanner at this time.
  • I recommend keeping Malwarebytes Anti-Malware installed. Make sure to update it and run it at least once a week. If it finds things such as PUP's (Potentially Unwanted Programs) you can delete those with no worries. However, if it finds something like a trojan, come see us.
Step 2: Tips, Information, and Optional Installation of Unchecky
  • Watch what you open in your emails. If you get an email from an unknown source with any attached files, do not open it.
  • Install and keep only one anti-virus on your machine. Update it and scan your machine with it at least once a week.
  • Be careful of the websites you visit.
  • When installing new programs, don't be "click happy" and click through the screens. Many programs come with adware in them and are set to install them by default. Several programs require that you uncheck or select no to prevent the installation. Take your time and read each screen as you go. :)
To help protect yourself while on the web, I recommend you read How did I get infected in the first place?


Installation of Unchecky

This is a very good little program that will automatically uncheck any boxes during a software installation. This helps prevent the software from installing any malware that is by default checked while the program is being installed.
  • Click here to be taken to Unchecky.com
  • Click the very large Download button.
  • Click Save
  • Once downloaded, double click the program (Vista, Win 7, and 8, right click and Run as Administrator)
  • Once open, click the Install button.
unchecky1_zps667e512d.jpg


Then click Finish

unchecky2_zpsca4e7d0d.jpg


Unchecky is now installed and will help you keep unwanted check boxes unchecked. :thumbsup:


Things I need to see in your next post

Delfix Log

  • 0

Advertisements


#26
Johnde2000

Johnde2000

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts

# DelFix v10.8 - Logfile created 31/07/2015 at 00:13:33
# Updated 29/07/2014 by Xplode
# Username : John - JOHN-PC-1
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\Users\John\Desktop\mbar
Deleted : C:\zoek-results.log
Deleted : C:\Users\John\Desktop\Addition.txt
Deleted : C:\Users\John\Desktop\esetsmartinstaller_enu.exe
Deleted : C:\Users\John\Desktop\Fixlog.txt
Deleted : C:\Users\John\Desktop\FRST.txt
Deleted : C:\Users\John\Desktop\FRST64.exe
Deleted : C:\Users\John\Desktop\JRT.exe
Deleted : C:\Users\John\Desktop\JRT.txt
Deleted : C:\Users\John\Desktop\SecurityCheck.exe
Deleted : C:\Users\John\Desktop\zoek.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #222 [Revo Uninstaller's restore point - Java 8 Update 45 | 07/27/2015 12:58:03]
Deleted : RP #223 [Removed Java 8 Update 45 | 07/27/2015 12:58:15]
Deleted : RP #224 [Revo Uninstaller's restore point - Mozilla Firefox 39.0 (x86 en-US) | 07/27/2015 12:59:56]
Deleted : RP #225 [Installed AVG 2015 | 07/27/2015 16:05:07]
Deleted : RP #226 [Installed AVG 2015 | 07/27/2015 16:05:46]
Deleted : RP #227 [Removed AVG 2015 | 07/29/2015 14:52:42]
Deleted : RP #228 [Removed AVG 2015 | 07/29/2015 14:53:57]
Deleted : RP #229 [Removed Google Earth | 07/29/2015 14:56:16]
Deleted : RP #230 [Revo Uninstaller's restore point - Steam | 07/29/2015 14:56:54]
Deleted : RP #231 [Revo Uninstaller's restore point - Sumotori Dreams | 07/29/2015 14:59:54]
Deleted : RP #232 [Revo Uninstaller's restore point - MechWarrior Online | 07/29/2015 15:00:44]
Deleted : RP #233 [MechWarrior Online | 07/29/2015 15:00:56]
Deleted : RP #234 [Revo Uninstaller's restore point - Malwarebytes Anti-Malware version 2.1.8.1057 | 07/29/2015 15:01:59]
Deleted : RP #235 [Revo Uninstaller's restore point - Yahoo! Messenger | 07/29/2015 15:02:50]
Deleted : RP #236 [Revo Uninstaller's restore point - Winamp | 07/29/2015 18:55:30]
Deleted : RP #238 [Restore Point Created by FRST | 07/30/2015 01:15:36]
Deleted : RP #240 [Restore Point Created by FRST | 07/30/2015 01:21:56]
Deleted : RP #242 [Restore Point Created by FRST | 07/30/2015 01:23:32]
Deleted : RP #244 [Restore Point Created by FRST | 07/30/2015 01:37:58]
Deleted : RP #246 [Restore Point Created by FRST | 07/30/2015 01:44:15]
Deleted : RP #247 [JRT Pre-Junkware Removal | 07/30/2015 02:04:09]
Deleted : RP #248 [Windows Update | 07/30/2015 07:08:32]
Deleted : RP #249 [Installed SoundMAX | 07/30/2015 10:26:31]
Deleted : RP #250 [Installed Host OpenAL (ADI) | 07/30/2015 10:27:04]
Deleted : RP #251 [zoek.exe restore point | 07/31/2015 00:03:44]
Deleted : RP #252 [avast! antivirus system restore point | 07/31/2015 01:37:11]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
 


  • 0

#27
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Hello :)

The Delfix log looks good, however I did forget one item. We need to turn your User Account Control on. This will help prevent malware from installing itself on your machine without asking.

Enable UAC in Windows 7
  • Open User Account Control Settings by clicking the Start button and then clicking Control Panel
  • In the Search Box, type in uac and then click Change User Account Control settings.
  • To turn on UAC, move the slider to choose when you want to be notified, and then click OK.
  • If you're prompted for an administrator password or confirmation, type the password or provide confirmation.

  • 0

#28
Johnde2000

Johnde2000

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts

OK done


  • 0

#29
Johnde2000

Johnde2000

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts

Now Py I truly don't want to seem ungrateful because I am. You've been great and very knowledgeable, But, After all you've done, nothing has changed. I'm still having the exact same problem I was having when I started this thread. Since last night, when you wanted me to download DelFix, I've been recording everything that is still wrong. I've taken a screen shot of several things you should see. (see below) First is the History since I tried to download Delfix and the others are pop ups. Not only the same pop ups but many more different ones now. My computer is acting very slow and sluggish. Pages won't scroll easy. full page pop ups under my browser. So what's next ?

 

2jJPRJt.jpg

 

QGCcs1C.jpg

 

uIViTlr.jpg


  • 0

#30
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts

Now Py I truly don't want to seem ungrateful because I am. You've been great and very knowledgeable, But, After all you've done, nothing has changed. I'm still having the exact same problem I was having when I started this thread. Since last night, when you wanted me to download DelFix, I've been recording everything that is still wrong. I've taken a screen shot of several things you should see. (see below) First is the History since I tried to download Delfix and the others are pop ups. Not only the same pop ups but many more different ones now. My computer is acting very slow and sluggish. Pages won't scroll easy. full page pop ups under my browser. So what's next ?


No worries, you're quite welcome. :) I've got some of my colleagues taking a look at this thread as well now, so we've got extra eyes helping to clean the machine. We want your machine clean and you happy when we're done. :thumbsup: You've been good to work with, and helpful with the details. I'd like you to download a fresh copy of FRST, as there are new changes to it since we started. Please follow the instructions below and post both logs when complete. :)


Scan with Farbar's Recovery Scan Tool (FRST)


Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Place a check in the box marked Addition.txt

    farbarmainpanel_zps77bf9e25.jpg
  • Press the Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
Things I need to see in your next post:

Please post each of these logs as a separate reply in this thread.

FRST Log

Addition.txt Log

  • 0






Similar Topics


Also tagged with one or more of these keywords: Malware?

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP