i am not sure but i becoming suspicious. can you help me?
am i infected?
Started by
canberkto
, Mar 16 2018 05:49 AM
#1
Posted 16 March 2018 - 05:49 AM
#2
Posted 16 March 2018 - 07:10 AM
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions!
Drive c: () (Fixed) (Total:930.96 GB) (Free:19.41 GB) NTFS
Your running out of hard drive space, this can cause variuos issues and errors and could eventually crash the drive. Free up space. You should have about a 186GB of free space on that drive.
Next
Download AdwCleaner from here. Save the file to the desktop.
NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.
Close all open windows and browsers.
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions!
Drive c: () (Fixed) (Total:930.96 GB) (Free:19.41 GB) NTFS
Your running out of hard drive space, this can cause variuos issues and errors and could eventually crash the drive. Free up space. You should have about a 186GB of free space on that drive.
Next
Download AdwCleaner from here. Save the file to the desktop.
NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.
Close all open windows and browsers.
- XP users: Double click the AdwCleaner icon to start the program.
- Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
- Click the Scan button and wait for the scan to finish.
- After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Pending. Please uncheck elements you don't want to remove.
- Click the Clean button.
- Everything checked will be moved to Quarantine.
- When the program has finished cleaning a report appears.Once done it will ask to reboot, allow this
- On reboot a log will be produced please copy / paste that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C0].txt
#3
Posted 16 March 2018 - 09:02 AM
thanks for the reply. here the results:
Attached Files
#4
Posted 16 March 2018 - 05:21 PM
Hello,
That log looks good. Lets run a Malwarebytes scan. You can skip the download part of my instruction if Malwarebytes is already installed.
That log looks good. Lets run a Malwarebytes scan. You can skip the download part of my instruction if Malwarebytes is already installed.
#5
Posted 17 March 2018 - 01:04 AM
thanks for another reply. i think im just a paranoid because malwarebytes detect nothing
Attached Files
#6
Posted 17 March 2018 - 01:50 PM
Hello,
A few items to fix. Left over junk not necessarily malware.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
A few items to fix. Left over junk not necessarily malware.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
start CloseProcesses: CreateRestorePoint: HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION S4 cpuz143; \??\C:\WINDOWS\temp\cpuz143\cpuz143_x64.sys [X] ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File ContextMenuHandlers4: [EncryptionMenu] -> {A470F8CF-A1E8-4f65-8335-227475AA5C46} => -> No File ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File Task: {82ADC0EF-CF3A-42DB-88A7-4724F431B4BF} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {FE53D2BC-2686-4704-A18C-EB11AC2F43AC} - \Optimize Desktop Icon Cache -> No File <==== ATTENTION AlternateDataStreams: C:\Users\can\AppData\Local\Temp:$DATA [16] CMD: bitsadmin /reset /allusers Emptytemp:
- Click Format and ensure Wordwrap is unchecked.
- Save as Fixlist.txt to your Desktop (Must be in this location)
- Run FRST/FRST64 and press the Fix button just once and wait.
- If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
- The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
#7
Posted 18 March 2018 - 01:35 AM
thank you very much. I really appreciate your support.
Attached Files
#8
Posted 18 March 2018 - 09:35 AM
Hello,
Looks good! Free up that space on the c drive. Windows should have 15% free space at least, I like to have 20% myself.
Looks good! Free up that space on the c drive. Windows should have 15% free space at least, I like to have 20% myself.
#9
Posted 18 March 2018 - 11:48 AM
again thanks a lot. i will keep in mind your advice
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users