Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Spyware or Malware, getting bad, personal information could be comprom


  • This topic is locked This topic is locked

#121
Destiny000

Destiny000

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 130 posts

Here it is. It took longer to get add pics since opera blocks the majority of them somehow. These are the ones that got through. Some of the screenshots were even just to show what malwarebytes was blocking.

Attached Thumbnails

  • adds.png
  • adds1.png
  • adds2.png
  • adds3.png
  • adds4.png
  • adds6.png
  • adds7.png
  • adds8.png

Attached Files


Edited by Destiny000, 13 January 2016 - 08:14 PM.

  • 0

Advertisements


#122
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hmm lets take a different approach to this

Download AVZ tool from here to your desktop
Unzip all files to a folder on your desktop
Open the folder and double click the AVZ icon avz.JPG
When the tool opens select "File" > "Standards scripts"
avz1.jpg

Place a tick in :


5. Update signature database

Then press "Execute selected scripts"
avz2.JPG

Once that has execute then
select "File" > "Standards scripts"
Place a tick in :

3. Advanced System Analysis with malware removal mode enabled


When finished look in the folder AVZ4 on your desktop
Open the LOG folder
Attach virusinfo_syscure to your next post
vz3.JPG
  • 0

#123
Destiny000

Destiny000

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 130 posts

Same problem as before. And upon doing that it severed my Internet connection as well, I was able to reestablish it though.

Attached Thumbnails

  • crash.png

  • 0

#124
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Do you know how to reset your router ?
  • 0

#125
Destiny000

Destiny000

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 130 posts

Yes I have done it, we also did it last time. After we reset everything and my laptop seemed fixed I also got a brand new one. No other devices using the same Internet have any problems except mine.

 

And even now that I did it again still nothing. 

 

Windows update isn't updating again,same issue and repair through fix as before. Other programs are stalling as well and same issue with windows button and search bar as before, have to restart before they will work again. If I do not, other programs start to not function and just stall when i open them and then only way to close them is via task manager.

 

Now I've got a new block showing up as well. 

Attached Thumbnails

  • add block.jpg

Edited by Destiny000, 17 January 2016 - 02:11 AM.

  • 0

#126
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Do you have access to a USB drive ?

Create an emergency repair USB drive:
Download Dr Web Live USB to your desktop
  • Connect a USB flash drive to the computer. Registering the plugging in event takes no more than 10 seconds.
  • Launch drwebliveusb.exe.
  • The program will detect available USB-devices automatically and prompt you to choose the one you?d like to use as an emergency repair drive. You can format the device if you like (a warning will be displayed before you proceed with formatting). In order to read the License agreement, follow a corresponding link found in the program window (the page containing the license agreement text will be loaded in your default browser).
    liveusb_ru.jpg
  • To create a bootable USB flash drive, press the Create Dr.Web LiveUSB button.
  • Files will be copied automatically.
  • Once the copying process is completed, press the Exit button to close the application.
  • Reboot the infected computer with the USB in the drive
  • Ensure that the first boot device is USB - If you are not sure about that then see this page for instructions
  • As loading starts, a dialogue window will prompt you to choose between the standard and safe modes.

    Live%20boot%20screen.png
  • Use arrow keys to select DrWeb-LiveCD (Default)

    drwebselect.JPG
  • Press select objects for scanning

    drwebfolders.JPG
  • When the system is loaded, check the disks or folders you want to scan, and click on Start.
  • The programme will now scan for and cure/delete any malware that it finds. Allow it to do so
    drwebscan.JPG
  • When it has completed

    drwebscancomplete.JPG
  • Select Open Report and copy to the USB
  • Once completed reboot to normal windows, and attach the report here

  • 0

#127
Destiny000

Destiny000

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 130 posts

So when I attempted to do this, it appeared like whatever the heck "this" is didn't like it. This method would not work at all, I even formatted the USB twice and even disabled the main boot in order to make it boot the usb, it would not work no matter what i did. It would just go back to the boot menu. After creating the usb via the program i noticed when i went to (the first and second first time after formatting) restart the computer the usb was being accessed, this was while windows was closing to restart. This also happened off and on after loading the main boot with me being on my desktop which was odd. My loading my desktop after logging in took extremely long as well, so that is now messed up again for whatever reason. This is infuriating, lol. I'm sure your feeling that too.

 

And yes my usb functions well, I use it a fair bit.


  • 0

#128
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK starting to run out of tools to use

Could you confirm that you still get the ads and they appear in all the browsers that you have installed

Could you run one further FRST scan please
  • 0

#129
Destiny000

Destiny000

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 130 posts

Yes I get pop ups in every browser I have installed.

Attached Files

  • Attached File  FRST.txt   78.89KB   199 downloads

  • 0

#130
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Let me know if this has any effect

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
Edge Session Restore: HKU\S-1-5-21-3710058852-312542076-3770498964-1001 -> is enabled.
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2015-07-26]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2072928 2014-10-31] (Wondershare)
HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [2001920 2014-04-04] (AimerSoft)
C:\Program Files (x86)\Skype\Toolbars
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
  • 0

Advertisements


#131
Destiny000

Destiny000

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 130 posts

Ok so upon restart after fix I could not do much of anything, I could click on my desktop and that was about it, I couldn't click on windows bar at all and even the control alt delete function was not functioning so I can to manually turn the computer off and restart it again. This time things functioned  and that is when windows defender popped up with this, I have attached the image to show. 

 

Also my ethernet is about never being detected as connected now. However upon intial malfunctioned restart earlier my ethernet internet was actually showing and I was connected, then upon manual restart it was there again, then after changing router settings if dissapeared leaving only wifi available. Also I have a 5ghz connection with this new router and my laptop does not even see it. Other devices do. If i restart the computer the Ethernet is there again for a bit then gone again after a while. 

 

Also I have as of yet to experience any pop ups or blocking warnings from malwarebytes.

 

Adding in here, even though I can click on things now, computer has slowed down and even if i click the windows button it is very laggy, i cannot even close a program or open a new one through the windows button now.

Attached Thumbnails

  • clean.png
  • clean2.jpg

Attached Files


Edited by Destiny000, 20 January 2016 - 01:14 AM.

  • 0

#132
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Have you been using a programme to give windows 10 a start menu ? Similar to classic shell http://www.classicshell.net/
  • 0

#133
Destiny000

Destiny000

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 130 posts

No I haven't, before this problem happened I didn't have the problems I do now.


  • 0

#134
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

Hmm nothing was removed that should have had that affect

 

Could you restore the system prior to the last fix and let me know if that cures the problem

 

Then run a fresh FRST scan


  • 0

#135
Destiny000

Destiny000

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 130 posts

How do I do that?


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP