Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

CBL blacklisted my IP and says I am infected with corebot


  • Please log in to reply

#16
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 7,500 posts
Excellent. 1 down, 2 to go.

Let's focus on the Windows 7 that you upgraded to Windows 10. Till we know for sure that no malicious personal files were transferred over to it, it might be best to use a USB drive to transfer files for scan logs.

Please do as follows:

On the clean computer, Download McShield2 to your desktop and install with default settings.
In the control center, select scanner and check unhide items on flash drives
mcshield%20unhide.JPG
Anytime you plug in a USB drive, McShield will scan the device.

For the moment, plug your USB drive in and allow McShield to scan it. A log will be found in the following location:

C:\Program Files (x86)\MCShield (folder) > MCShieldCC > logs > all scans

Please post the log.
  • 0

Advertisements


#17
my_name

my_name

    Sophomore

  • Topic Starter
  • GeekU Sophomore
  • PipPipPip
  • 259 posts

I didn't see the MCShieldCC folder existing within the MCShield folder, but I copied the last log from within the program (not sure why it says Windows 8.1)

 

 

MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.5.28 / DB: 2016.2.21.1 / Windows 8.1 <<<


5/5/2016 10:40:08 PM > Drive E: - scan started (LEXAR ~30524 MB, FAT32 flash drive )...



=> The drive is clean.

 

 

 

edit: I just figured out what you meant, sorry.  Here's the complete logs:

 

>>> MCShield AllScans.txt <<<

-----------------------------




MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.5.28 / DB: 2016.2.21.1 / Windows 8.1 <<<


5/5/2016 10:39:18 PM > Drive C: - scan started (no label ~930 GB, NTFS HDD )...



=> The drive is clean.


5/5/2016 10:39:18 PM > Drive E: - scan started (LEXAR ~30524 MB, FAT32 flash drive )...



=> The drive is clean.





MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.5.28 / DB: 2016.2.21.1 / Windows 8.1 <<<


5/5/2016 10:40:08 PM > Drive E: - scan started (LEXAR ~30524 MB, FAT32 flash drive )...



=> The drive is clean.


 


Edited by my_name, 05 May 2016 - 10:36 PM.

  • 0

#18
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 7,500 posts
Good morning my_name,

I didn't see the MCShieldCC folder existing within the MCShield folder,

MCShield is the folder, MCShieldCC is the program user interface Control Center which is actually the application that if you click on will open up the program.

(not sure why it says Windows 8.1)

It says Windows 8.1 because when MS developes their Operating System, they use files from former Operating Systems instead of creating new ones.

Download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flash drive into the infected/problem PC.
  • Open the flash drive.
  • Right click on the FRST.exe and choose Run as administrator
  • When the tool opens click Yes to disclaimer.
  • Under Optional Scan make sure there is a checkmark in the box for Addition.txt to ensure it creates that 2nd log.
  • Press Scan button.
  • The logs will be found on the flashdrive once the scan has completed.
  • Transfer the flashdrive back to the clean computer.
  • Please attach both logs in your next reply.
Unfortunately, I have to work today. Please provide the logs and as soon as I get home I'll have a look.

Thank you,
Donna :)
  • 0

#19
my_name

my_name

    Sophomore

  • Topic Starter
  • GeekU Sophomore
  • PipPipPip
  • 259 posts

Here are the requested logs.

Attached Files


  • 0

#20
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 7,500 posts
Hi my_name,

I see no reason why you couldn't directly connect this computer to your provider.

Did you install the following program intentionally?

Wise Care 365 version 1.84

Wise Care 365 includes a Registry cleaner, and we advise not to use this or any registry cleaner as there have been reports of them clearing out needed registry entries and messing up PCs. In addition, what they do clean up is so small that little or no advantages are noticed.

Modifying registry keys incorrectly can cause Windows instability, or make Windows unbootable. No registry cleaner is completely safe and the potential is ever present to cause more problems than they claim to fix.

Registry cleaners cannot distinguish between good and bad. If you run a registry cleaner, it will delete all those keys which are obsolete and sitting idle; but in reality, those keys may well be needed by some programs or windows at a later time. Personally, I would uninstall Wise Cleaner 365. I'll leave the final decision up to you though.

I see nothing serious in the logs, except a few stragglers that need to be removed, so let's do that and clean up a bit.

Please run the scan in the order posted. :)
  • Open notepad (Start orb > type notepad into Start Search > chose notepad from list)
  • Please copy the entire contents of the code box below.
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
  • Save it to the same directory as frst.exe (or frst64.exe) as fixlist.txt.

    CreateRestorePoint:
    
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
    GroupPolicyScripts-x32: Restriction <======= ATTENTION
    SearchScopes: HKU\S-1-5-21-2855859152-3276993282-1863274073-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-21-2855859152-3276993282-1863274073-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
    Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
    U3 idsvc; no ImagePath
    U3 wpcsvc; no ImagePath
    Task: {050CEDF7-AE0F-4800-AB45-AD691949937A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {0933CC71-C407-46EA-860D-E6F0C5EB4F5F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {27A4C752-4C0B-40E4-81C0-4C85BC4DDC39} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {420F5C84-86B9-4C5E-8B84-E590D028D420} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
    Task: {47D9F22F-FF67-49C5-95AB-8F01F6D9D502} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {4973A9CA-C6CD-45CB-B781-694BC446FDC1} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {58285AD2-2515-4019-96C7-C9070EC1FA67} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
    Task: {6A919727-26BF-4B05-9C1C-6D9755C3A434} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {7FD4F2AE-8BC0-441D-BFA7-004FF207F948} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {8ACF1929-B746-45B1-858F-C65B73F50765} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
    Task: {8BE1BC86-D3C8-4574-82EF-D3894AF4BBAF} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {95257404-9DCE-4EA7-AF77-421B33BA5C1A} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {E5B7A59D-40CD-40A0-AB23-1FC7B7B4C194} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    
    Hosts:
    EmptyTemp:
    
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
  • Run frst64.exe and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you will find where you saved FRST. Please post it to your reply.
  • Next:

    Please download Junkware Removal Tool to your desktop.
    • Disable your AV protection software now to avoid potential conflicts.
    • Run the tool by double-clicking on XP. Or right click and select Run as Administrator Vista/Win7 and above.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    Next:

    Please download AdwCleaner by Xplode onto your Desktop.
    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click the Scan button and wait for the process to complete.
    • Click the logfile button and the log will open in Notepad.
    • Click on the Clean button follow the prompts.
    • A log file will automatically open after the scan has finished and the PC has rebooted.
    • Please post the content of that log file with your next answer.
    • The report will be saved in the C:\AdwCleaner folder.
    Next:
    • Right click on the FRST.exe and choose Run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
    • Under Optional Scan place a checkmark in the box for Addition.txt to ensure it creates that 2nd log.
    • Press Scan button.
    • Please attach both logs in your next reply.
    Please post the following logs:

    Fixlog.txt
    JRT.txt
    AdwCleaner
    New FRST.txt
    New Addition.txt


    Thank you,
    Donna :)

  • 0

#21
my_name

my_name

    Sophomore

  • Topic Starter
  • GeekU Sophomore
  • PipPipPip
  • 259 posts

I've still been using the usb device to transfer.  Should I be using this computer directly now on the internet? I noticed the adware cleaner didn't want to continue at first due to system restore not being enabled, so I enabled before continuing with that scan.  I don't know why system restore was turned off.   Thank you for your advice on deleting the registry cleaner.  I will delete it.  In the meantime, here are the logs you requested:

 

Fix result of Farbar Recovery Scan Tool (x64) Version:06-05-2016 02
Ran by owner (2016-05-06 18:24:41) Run:1
Running from F:\
Loaded Profiles: owner (Available Profiles: owner)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
GroupPolicyScripts-x32: Restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-2855859152-3276993282-1863274073-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2855859152-3276993282-1863274073-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
Task: {050CEDF7-AE0F-4800-AB45-AD691949937A} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {0933CC71-C407-46EA-860D-E6F0C5EB4F5F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {27A4C752-4C0B-40E4-81C0-4C85BC4DDC39} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {420F5C84-86B9-4C5E-8B84-E590D028D420} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {47D9F22F-FF67-49C5-95AB-8F01F6D9D502} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {4973A9CA-C6CD-45CB-B781-694BC446FDC1} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {58285AD2-2515-4019-96C7-C9070EC1FA67} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {6A919727-26BF-4B05-9C1C-6D9755C3A434} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {7FD4F2AE-8BC0-441D-BFA7-004FF207F948} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {8ACF1929-B746-45B1-858F-C65B73F50765} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {8BE1BC86-D3C8-4574-82EF-D3894AF4BBAF} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {95257404-9DCE-4EA7-AF77-421B33BA5C1A} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {E5B7A59D-40CD-40A0-AB23-1FC7B7B4C194} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION

Hosts:
EmptyTemp:
*****************

Error: (0) Failed to create a restore point.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
C:\WINDOWS\SysWOW64\GroupPolicy\Machine => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKU\S-1-5-21-2855859152-3276993282-1863274073-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-2855859152-3276993282-1863274073-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value removed successfully
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value removed successfully
HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => key not found.
idsvc => service removed successfully
wpcsvc => service removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{050CEDF7-AE0F-4800-AB45-AD691949937A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{050CEDF7-AE0F-4800-AB45-AD691949937A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0933CC71-C407-46EA-860D-E6F0C5EB4F5F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0933CC71-C407-46EA-860D-E6F0C5EB4F5F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27A4C752-4C0B-40E4-81C0-4C85BC4DDC39}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27A4C752-4C0B-40E4-81C0-4C85BC4DDC39}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{420F5C84-86B9-4C5E-8B84-E590D028D420}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{420F5C84-86B9-4C5E-8B84-E590D028D420}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47D9F22F-FF67-49C5-95AB-8F01F6D9D502}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47D9F22F-FF67-49C5-95AB-8F01F6D9D502}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4973A9CA-C6CD-45CB-B781-694BC446FDC1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4973A9CA-C6CD-45CB-B781-694BC446FDC1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{58285AD2-2515-4019-96C7-C9070EC1FA67}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58285AD2-2515-4019-96C7-C9070EC1FA67}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A919727-26BF-4B05-9C1C-6D9755C3A434}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A919727-26BF-4B05-9C1C-6D9755C3A434}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7FD4F2AE-8BC0-441D-BFA7-004FF207F948}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7FD4F2AE-8BC0-441D-BFA7-004FF207F948}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8ACF1929-B746-45B1-858F-C65B73F50765}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8ACF1929-B746-45B1-858F-C65B73F50765}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8BE1BC86-D3C8-4574-82EF-D3894AF4BBAF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8BE1BC86-D3C8-4574-82EF-D3894AF4BBAF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{95257404-9DCE-4EA7-AF77-421B33BA5C1A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95257404-9DCE-4EA7-AF77-421B33BA5C1A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E5B7A59D-40CD-40A0-AB23-1FC7B7B4C194}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E5B7A59D-40CD-40A0-AB23-1FC7B7B4C194}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 889.2 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 18:25:46 ====

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.6 (04.25.2016)
Operating System: Windows 10 Home x64
Ran by owner (Administrator) on Fri 05/06/2016 at 18:33:28.81
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 95

Failed to delete: C:\Program Files (x86)\coupons (Folder)
Successfully deleted: C:\ProgramData\Start Menu\Programs\coupons (Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{01BDC527-6020-46BC-9822-45A8063707ED} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{07136A4B-455B-4435-AF87-537EAC65BB51} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{08685167-90CE-4614-AC7F-BBE87A47B1D9} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{0A5E9371-5DC9-4A36-B817-FA836D035F0E} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{0B2258EB-6695-4554-BCEE-04F808F5F536} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{162A17C3-D39F-4C79-810D-067A0E09B695} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{1C76FB98-96B5-4696-B6C7-6DF3C7FD60EF} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{1FE7AF8F-EA0F-438E-8685-E8C9CBBEE183} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{205767C4-C5B8-4F4C-89A1-CB68661E9E56} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{224F9BCE-4ED8-4241-9408-6D6EE9CF7540} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{24D7828C-1406-4FD0-B04D-7228792096FE} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{287B02DB-C533-4157-882F-C7D34DB18540} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{2CBB0DED-2017-4CE6-8DAE-163EF42D11AB} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{2D3E3C26-31A9-420E-9AFE-0831B28AAD11} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{2DABDCD4-6DB0-4571-AC9C-FD6D3CE98F18} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{2EADAA8D-1402-4885-8F2B-DA626933CD17} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{2FAE38A4-5DAA-4E9C-A439-4A237BC22AD3} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{36430632-4493-4A33-8E9A-E2983D3245D8} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{391367BA-9134-4C84-B2F3-65E0F171D2A5} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{3CBA468F-DC61-46F0-964C-0DC303026B79} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{42EDE379-77BB-4F7A-BA43-2589EA2CC57B} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{44830FB3-EE5B-410D-8147-CD9D56544BFA} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{4C04EF2B-DD71-4BDD-8E41-8A4A1724D60E} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{50697A92-9E2F-4458-9601-C93B001542FC} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{506AB7CB-A207-40A0-897E-71199E0F1CA5} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{50B529CE-7408-4BE3-947E-B35C831F2351} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{53F6DDE2-65BF-45D2-B980-95F325BD7C04} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{54EB3087-AD24-49EB-AE7B-6099CEB9CD55} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{57289E5F-56A0-4D8B-B6D8-516C5979C45E} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{5BE6C787-6A0B-427F-B8A1-8FD7241ADF2D} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{5D64279F-36F7-4F45-B80D-7C38587F1C02} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{5E3BE864-B9CE-4F48-84F3-C15DCBA687E9} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{621E6E58-4C0A-4B29-898B-44EBC0C4B3C8} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{67AD01D9-60E2-4F66-A980-DF1ED4062DD4} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{6E8D7A1A-CEF2-4E9C-95DC-759E88A2703E} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{6F8CA769-79E0-45E7-8679-1CB0CB040C8D} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{76904EC4-A332-4012-9292-B54C6BDF3AB1} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{7A1F8489-3CDF-4C9A-B7EE-63173CF423BC} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{7A7F085B-3DAE-4120-9A29-CF557CC54493} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{7D05F8A7-9C7F-4A20-B061-3F5346FC9B2C} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{7DA93B33-6834-4A1D-97EE-8C6DA8504BDE} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{7E415944-4877-49E9-9ACF-E6ADF4AA6030} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{80D6C53A-F100-457A-BB17-9114CD0BBC86} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{81BB763D-9CB6-4A01-AFAC-2F625DCC4378} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{842C57B0-BAE3-4EF1-84C6-1E5A3CF18A81} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{86FFAAD6-0008-492E-B130-462B320ED421} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{86FFE8CD-7CCC-490D-A88D-F15CF2A6C98D} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{88F780FF-E993-4C87-9850-F9D87F4F17F3} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{8A0094E0-0C15-4743-8A3A-C610A3BF9268} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{8BA8E826-CCD5-4231-8132-1B6242AA7CE1} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{8FAB40A8-8706-4BFB-AA98-E93201BBAF50} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{91B6C930-0302-4D5D-BBDF-52BAC40D15BF} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{92B4EDDB-9520-4CF5-B4EC-5BFAC837EB62} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{984DA3E4-F0EC-4906-985E-8CA0BE349E39} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{990A376B-E623-4FDC-8C19-4E6A5798C901} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{9E0DDE2F-EE0B-4E9C-9A69-FB214DBEE989} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{A04CADB1-153E-4181-9246-650B932DC47B} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{A18E917B-64D4-41DC-9977-EB84581C4B09} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{A20E6813-5E77-462B-A588-96816982229E} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{A256E6A4-1838-44E9-BDE9-B0E85D3BB5AD} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{A5F35A8D-2B53-4C41-B54F-D3D93E6B01EC} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{A66135BD-6C32-4AAA-9E09-9C290F9D7D1F} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{AE323EB2-1D54-44A9-B159-9D1428924864} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{AE668281-9344-4575-B6BA-FA7D87DA907D} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{AEEBB165-79DF-4080-B07B-B435404F77E5} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{B1877418-BB1B-440B-ACC8-D37BEAF4CCB2} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{B1DBB035-997F-4D3B-AFF0-E994984938DF} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{B24BBD4E-FEC9-4EE3-A833-C51935B9BC7F} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{B2F12B2D-8ED5-48D2-9D84-2B96FF95659E} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{BAEDF189-E160-41FD-A3A0-98A2F34F8CA3} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{BE2166D6-BB58-4F2A-8E00-87740E990605} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{C03E1592-4F72-4CA0-B04F-621096FC5D46} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{C0528057-C177-46A0-AB04-48CD76B1A533} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{C50566C1-ABBA-4B4E-9CE5-E51FE086085D} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{C6C566BF-E8F2-40C2-B249-082BAEBAD0C4} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{CF19D483-A175-4CCC-B962-BFF14A852DCC} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{D291D098-37A4-4681-945D-D9A3D67BB759} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{D2CB8143-0A21-48D5-9924-E62954FBC66F} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{DDC81A89-BAEF-4D3E-81DA-3B7EE19BD19A} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{DE5D4830-22F9-4E60-8EDD-2FC1BA5E1898} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{DE64438F-D8BF-4D3B-9171-29BA678D2A5A} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{E910AAA8-1FA4-45F6-B616-3AB7410FA5C3} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{E9A85EC9-C130-49CC-893A-E3E813D849BE} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{EDD404BE-C97D-4F18-BB81-32C6094CD781} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{F01EA04D-9F2E-48B7-9760-A70E84CE5070} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{F1381470-D3A4-48CD-99CD-ADE9F2320275} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{F4F0DC73-6ACC-4F04-92E0-88FA225CEDAC} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{F9B970E5-739F-46C8-8150-6E36ADCDD0F6} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{FCAD9899-2B09-4CE5-BDF7-7E4719381CCA} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Local\{FFE689F7-37C7-4E66-8ED8-93620856ADD2} (Empty Folder)
Successfully deleted: C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\63y6lv87.default\searchplugins\swagbucks.xml (File)
Successfully deleted: C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\63y6lv87.default\searchplugins\youtube-video-search.xml (File)
Successfully deleted: C:\WINDOWS\couponprinter.ocx (File)



Registry: 1

Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\CouponPrinterService (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 05/06/2016 at 18:36:28.54
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

# AdwCleaner v5.115 - Logfile created 06/05/2016 at 18:42:53
# Updated 01/05/2016 by Xplode
# Database : 2016-05-01.2 [Local]
# Operating system : Windows 10 Home  (X64)
# Username : owner - OWNER-PC
# Running from : C:\Users\owner\Desktop\adwcleaner_5.115.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : CouponPrinterService

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\Coupons

***** [ Files ] *****


***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKLM\SOFTWARE\Conduit

***** [ Web browsers ] *****

[-] [C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\63y6lv87.default\prefs.js] Deleted : user_pref("extensions.fvd_single.surfcanyon.ramp.start_time", "1394986820846");
[-] [C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [1736 bytes] - [06/05/2016 18:42:53]
C:\AdwCleaner\AdwCleaner[S1].txt - [1814 bytes] - [06/05/2016 18:40:20]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1882 bytes] ##########
 

 

 

 

 

 

 

 

Attached Files


  • 0

#22
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 7,500 posts
Yes. Please do. I had mentioned it in my post above though I wasn't very clear about that. My apologies. It's been a very long day for me... :wacko:

I'll have a look at the logs now...
  • 0

#23
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 7,500 posts
The logs look fine. How is the computer behaving for you?

Let's do an ESET scan before we remove the tools.

Run ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.
  • Please go here then click on: EOLS1.gif

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: EOLS2.gif
  • When prompted allow the Add-On/Active X to install.
  • Uncheck the box beside Remove Found Threats
  • Make sure that the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: EOLS3.gif
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Wait for the scan to finish. Do not touch either the Mouse or keyboard during the scan. Otherwise it may stall.
When The Scan is Complete:
  • If No Threats Were Found:
    • Put a checkmark in "Uninstall application on close"
    • Close the program
    • Report to me that nothing was found
  • If Threats Were Found:
    • Click on "list of threats found"
    • Click on "export to text file" and save it to the desktop as ESET SCAN.txt
    • Click on Back
    • Put a checkmark in "Uninstall application on close" (Be sure you have saved the file first)
    • Click on Finish
    • Close the program
    • Copy and paste the report here
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
  • 0

#24
my_name

my_name

    Sophomore

  • Topic Starter
  • GeekU Sophomore
  • PipPipPip
  • 259 posts
The computer is slow as it has been. It takes a couple seconds for pages to load or applications to load after clicking them unlike the other computer. Sometimes the fan gets really loud like it's running hot.

I am running the eset scan now.
Since I am on windows 10 now, should I delete the windows 7 files that are taking up space or wait 30 days for it to delete itself after upgrading?
  • 0

#25
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 7,500 posts
You're talking about the C:\Windows.old folder, right? I would leave that till you know for sure you have saved everything from it that you want and only then would I delete the folder.

The computer is slow as it has been. It takes a couple seconds for pages to load or applications to load after clicking them unlike the other computer. Sometimes the fan gets really loud like it's running hot.

Is this a desktop? How old is this computer?
  • 0

Advertisements


#26
my_name

my_name

    Sophomore

  • Topic Starter
  • GeekU Sophomore
  • PipPipPip
  • 259 posts
Thanks, Donna. It's an Asus laptop about 4 years old.
  • 0

#27
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 7,500 posts
Ah. Ok. Now I see Synaptics Pointing Device Driver in the installed programs list. That's your touchpad device software. Usually the driver will be listed in the drivers section though it's not. That's weird!

When we make sure this laptop is clean we can do some basic maintenance and see if that will help. One thing I see is that there appears to be 120GB hard drive installed and there's 29gb of free space. That's not too bad and should get better when you delete the windows.old folder. We'll discuss that more before we look at your 3rd computer.

Need to get offline now. 5am comes really quick...
  • 0

#28
my_name

my_name

    Sophomore

  • Topic Starter
  • GeekU Sophomore
  • PipPipPip
  • 259 posts

The ESET scanner is stuck at 28% with some kind of java.cab or something.  The fan is revving up nonstop, so should I stop the scan?


  • 0

#29
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 7,500 posts
No. Let it run. Some files may take longer to scan than others and at time it may appear that it has stopped yet it hasn't. Usually when I scan my system(s) with ESET, I let it run over night since it can take so long to complete.
  • 0

#30
my_name

my_name

    Sophomore

  • Topic Starter
  • GeekU Sophomore
  • PipPipPip
  • 259 posts
Should I be worried about how hot the computer is getting? The fan is really loud non-stop and really hot.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP