1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Stubborn Virus

Discussion in 'Windows - Virus and spyware problems' started by raff, Mar 4, 2016.

  1. raff

    raff Newbie

    Joined:
    Mar 4, 2016
    Messages:
    13
    Likes Received:
    0
    Trophy Points:
    1
    Hi 2old.

    Please tell me Spybot is still good! What's happened its always been my 'go to' program.(I have uninstalled it btw)

    Here is the Zoek results:

    Zoek.exe v5.0.0.1 Updated 31-December-2015

    Tool run by Aimee on 07/03/2016 at 0:54:22.61.

    Microsoft Windows 8.1 with Bing 6.3.9600 x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Aimee\Desktop\zoek.exe

    Script used: C:\Users\Aimee\Desktop\zoekscript.txt


    ==== Older Logs ======================


    C:\zoek-results2016-03-05-103258.log 53343 bytes


    ==== System Restore Info ======================


    07/03/2016 00:55:01 Zoek.exe System Restore Point Created Successfully.


    ==== Empty Folders Check ======================


    C:\PROGRA~3\295ece5b deleted successfully

    C:\PROGRA~3\da4a9c05-04d5-0 deleted successfully

    C:\PROGRA~3\da4a9c05-2051-1 deleted successfully


    ==== Deleting CLSID Registry Keys ======================



    ==== Deleting CLSID Registry Values ======================



    ==== Deleting Services ======================



    ==== Batch Command(s) Run By Tool======================



    Sucessfully reset the Winsock Catalog.

    You must restart the computer in order to complete the reset.



    ==== Orphaned Tasks deleted from Registry ======================


    {CA4D980C-5B7F-03BC-059C-4ADA24945334} deleted


    ==== Chromium Look ======================



    ==== Set IE to Default ======================


    Old Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

    "Start Page"="https://www.google.co.uk/?gfe_rd=cr&ei=ML7ZVvi2NKrS8Aef0YGIBA&gws_rd=ssl"


    New Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

    "Start Page"="https://www.google.co.uk/?gfe_rd=cr&ei=ML7ZVvi2NKrS8Aef0YGIBA&gws_rd=ssl"


    ==== All HKLM and HKCU SearchScopes ======================


    HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

    HKLM\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146} - No_Url_Value

    HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

    HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=HPNTDFJS

    HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

    HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}

    HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=WCUG


    ==== Empty IE Cache ======================


    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Aimee\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Aimee\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully

    C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Aimee\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\Users\Aimee\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully

    C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully


    ==== Empty FireFox Cache ======================


    No FireFox Profiles found


    ==== Empty Chrome Cache ======================


    C:\Users\Aimee\AppData\Local\Chromium\User Data\Default\Cache emptied successfully

    C:\Users\Aimee\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully


    ==== Empty All Flash Cache ======================


    Flash Cache Emptied Successfully


    ==== Empty All Java Cache ======================


    No Java Cache Found


    ==== C:\zoek_backup content ======================


    C:\zoek_backup (files=254 folders=76 164472534 bytes)


    ==== Empty Temp Folders ======================


    C:\Users\Aimee\AppData\Local\Temp will be emptied at reboot

    C:\Users\Default\AppData\Local\Temp emptied successfully

    C:\Users\Default User\AppData\Local\Temp emptied successfully

    C:\Users\DefaultAppPool\AppData\Local\Temp emptied successfully

    C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully

    C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

    C:\Windows\Temp will be emptied at reboot


    ==== After Reboot ======================


    ==== Empty Temp Folders ======================


    C:\Windows\Temp successfully emptied

    C:\Users\Aimee\AppData\Local\Temp successfully emptied


    ==== Empty Recycle Bin ======================


    C:\$RECYCLE.BIN successfully emptied


    ==== EOF on 07/03/2016 at 9:30:52.09 ======================

    I've carried out the other steps also.

    Can I ask, where did you build up your knowledge? Are you employed in the tech industry? I really appreciate your time and effort here, thanks.
     
  2. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Started as a programmer in 1965 on an IBM65 mainframe... Then over 50 years of digging and learning..
    I am 73, be 74 in may and retired. but still work some, when needed, for a hotel chain that I spent nearly 30 yrs in their IT dept.
    You are welcome. Helping you is my choice. I have been doing this since the Internet has been around and I do this because I care, I don't get any other reward for it.

    Great! Now let me see the latest Logs:

    Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
    • Right-click on [​IMG] icon and select [​IMG] Run as Administrator to start the tool.
    • Make sure that Addition option is checked.
    • Press Scan button and wait.
    • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

    Please attach these logfiles to your next reply and let me know if you are having any problems or whatever...

    2oG :)
     
  3. raff

    raff Newbie

    Joined:
    Mar 4, 2016
    Messages:
    13
    Likes Received:
    0
    Trophy Points:
    1
    Hi thanks for the reply. Here are the logs, addition below and FRST log attached:

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
    Ran by Aimee (2016-03-07 21:52:42)
    Running from C:\Users\Aimee\Desktop
    Windows 8.1 Connected (X64) (2015-12-24 04:36:29)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-4076074391-1741049511-317624565-500 - Administrator - Disabled)
    Aimee (S-1-5-21-4076074391-1741049511-317624565-1001 - Administrator - Enabled) => C:\Users\Aimee
    Guest (S-1-5-21-4076074391-1741049511-317624565-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-4076074391-1741049511-317624565-1003 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Ad-Aware Antivirus (HKLM\...\{50E2E8FE-1F8B-4F21-BE9F-F9152D3EA5B1}_AdAwareUpdater) (Version: 11.10.767.8917 - Lavasoft)
    Apple Application Support (32-bit) (HKLM-x32\...\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\...\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
    AVG (HKLM\...\AvgZen) (Version: 1.41.1.56922 - AVG Technologies)
    AVG (Version: 16.41.7442 - AVG Technologies) Hidden
    AVG 2016 (Version: 16.0.4540 - AVG Technologies) Hidden
    AVG Protection (HKLM\...\AVG) (Version: 2016.41.7442 - AVG Technologies)
    AVG Zen (Version: 1.41.29 - AVG Technologies) Hidden
    Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
    Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: - Broadcom Corporation)
    Broadcom Bluetooth Drivers (HKLM\...\{0A1B4690-E176-4533-8058-939480AEE1D0}) (Version: 12.0.0.9840 - Broadcom Corporation)
    Decrap my Computer (HKLM-x32\...\Decrap my Computer) (Version: - Macecraft Software)
    DisableMSDefender (Version: 1.0.0 - Hewlett-Packard Company) Hidden
    FMW 1 (Version: 1.62.2 - AVG Technologies) Hidden
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.75 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
    Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
    HP Documentation (HKLM-x32\...\{9BCC40C6-8A7C-4134-AF7D-9C2332E2DA80}) (Version: 1.1.0.0 - Hewlett-Packard)
    HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7745.4851 - Hewlett-Packard)
    HP Support Assistant (HKLM-x32\...\{E959FD01-BD01-4CC4-9BB8-4EBE8309BF37}) (Version: 8.1.52.1 - HP)
    HP Support Solutions Framework (HKLM-x32\...\{E2CB09C1-3C76-4395-BB47-50C066535CF8}) (Version: 12.0.30.473 - HP)
    HP System Event Utility (HKLM-x32\...\{8B4EE87E-6D40-4C91-B5E8-0DC77DC412F1}) (Version: 1.4.1 - Hewlett-Packard Company)
    HP Utility Center (HKLM\...\{403E9EFF-C4B4-4308-BA4E-7093B6BA03D5}) (Version: 2.5.5 - Hewlett-Packard Company)
    HP Wireless Button Driver (HKLM-x32\...\{EFA01423-3857-468C-B7B6-F30AA08E50BC}) (Version: 1.1.5.1 - Hewlett-Packard)
    Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C) (Version: 7.10.0.2210 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3925 - Intel Corporation)
    Intel(R) Sideband Fabric Device Driver (HKLM-x32\...\C5A8BC6E-723A-4C0F-96E1-C426D1A4BCA9) (Version: 1.70.305.16316 - Intel Corporation)
    Intel(R) Trusted Execution Engine (HKLM\...\{176E2755-0A17-42C6-88E2-192AB2131278}) (Version: 1.0.0.1064 - Intel Corporation)
    iTunes (HKLM\...\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)
    Kaspersky Security Scan (HKLM-x32\...\InstallWIX_{D1282694-0693-41A8-ABC1-6D1FFC1F65C5}) (Version: 16.0.0.1344 - Kaspersky Lab)
    Kaspersky Security Scan (x32 Version: 16.0.0.1344 - Kaspersky Lab) Hidden
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 15.0.4797.1003 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4797.1003 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Licensing Component (Version: 15.0.4797.1003 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4797.1003 - Microsoft Corporation) Hidden
    Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.30176 - Realtek Semiconductor Corp.)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7339 - Realtek Semiconductor Corp.)
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 18.1.29.0 - Synaptics Incorporated)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.19.904 - Zemana Ltd.)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {0F05BF6B-CF30-4008-A242-F34B3094C11E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-02-18] (Hewlett-Packard)
    Task: {1AA6FD88-FA8F-4A66-9BAD-37190BE76E5D} - \{7D7D7847-0F05-047F-7811-79057A79110C} -> No File <==== ATTENTION
    Task: {2FC6617D-287D-4D49-9FDD-139B84A27953} - \{087D7F47-0578-0C04-7F11-097E0B7A110C} -> No File <==== ATTENTION
    Task: {41F4D2C0-CB0F-44DC-BA02-1C7981537078} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-02-17] (Hewlett-Packard)
    Task: {492288FF-D2F2-496B-9DD8-251A416C8E78} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-12-27] (Microsoft Corporation)
    Task: {5D2BAFC8-E9DA-447B-8184-BE68479365E5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
    Task: {61A3A877-8A8F-4BF5-B6C0-3452319CAA45} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-21] (Google Inc.)
    Task: {6316164F-C3C0-48A4-BC51-3DC5BE644C1D} - \{CA4D980C-5B7F-03BC-059C-4ADA24945334} -> No File <==== ATTENTION
    Task: {67714BFE-D7EB-48E0-B102-3E1F4F5EAB90} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2016-02-20] (Microsoft Corporation)
    Task: {77DC108E-F02C-498E-A9C3-C0C353DA3EBB} - System32\Tasks\HPCeeScheduleForAimee => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
    Task: {7F5A477F-A8D6-4C59-BF77-4F09AE108B93} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)
    Task: {81FE16EC-E5C9-4649-B72D-DDEE72ADC620} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2016-02-23] (Microsoft Corporation)
    Task: {8746B524-267B-4974-8949-6FD52A6FD465} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-01-12] (Microsoft Corporation)
    Task: {92EF088F-CC19-4355-8309-D46B1049223A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
    Task: {B1B42DC6-E061-47B2-842A-220A6B8FFA39} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-01-12] (Microsoft Corporation)
    Task: {BCEE2E7B-2530-406F-9267-79F72AF40C69} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-12-27] (Microsoft Corporation)
    Task: {C789089B-515C-4039-90ED-21993E7F27D7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-21] (Google Inc.)
    Task: {EDB3EBEA-6D9E-44BF-BA74-DAF54FD9B148} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Active Health Launcher => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-01-20] (Hewlett-Packard)
    Task: {FD81132D-B191-48E9-89A8-9519C2A90113} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-02-17] (Hewlett-Packard)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\HPCeeScheduleForAimee.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-12-17 18:38 - 2015-12-17 18:38 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2015-12-17 18:38 - 2015-12-17 18:38 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2015-12-25 10:34 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
    2015-12-25 10:35 - 2015-12-27 13:52 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
    2016-03-04 09:55 - 2016-03-04 09:55 - 00118640 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
    2016-03-04 10:24 - 2016-03-02 04:49 - 02140824 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.75\libglesv2.dll
    2016-03-04 10:24 - 2016-03-02 04:49 - 00097944 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.75\libegl.dll
    2016-03-04 10:24 - 2016-03-02 04:49 - 29267608 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.75\PepperFlash\pepflashplayer.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\08991931.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\27229187.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\39782278.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\60697541.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2ce.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\08991931.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\27229187.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\39782278.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\60697541.sys => ""="Driver"

    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
    IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
    IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
    IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
    IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
    IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

    There are 7871 more sites.

    IE trusted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\localhost -> localhost
    IE trusted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\webcompanion.com -> hxxp://webcompanion.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\008i.com -> 008i.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\008k.com -> www.008k.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\010402.com -> 010402.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\123simsen.com -> www.123simsen.com

    There are 7871 more sites.


    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2013-08-22 13:25 - 2016-03-07 11:29 - 00000021 _RASH C:\Windows\system32\Drivers\etc\hosts

    127.0.0.1 localhost

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-4076074391-1741049511-317624565-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Theme2\img9.jpg
    DNS Servers: 192.168.1.254
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    HKLM\...\StartupApproved\Run: => "iTunesHelper"
    HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_A03C23FA974063E9DD13FDBC39A730DC"
    HKU\S-1-5-21-4076074391-1741049511-317624565-1001\...\StartupApproved\Run: => "Web Companion"

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [{8E6F2939-9128-440D-9686-63AF725781AD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{DEB607F7-4F2C-403A-8240-F4BA8B16B920}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{8A6C5C27-3C51-4888-8AA1-99FAB3A1B472}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{45FDB096-8190-4F1D-AD5A-12559D21E0A3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{0FA69D9B-06CF-461B-BDBD-D47B425BE84C}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
    FirewallRules: [{FA1A1094-7790-4A4A-A28E-AEE1AC89328A}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
    FirewallRules: [{A2FFF473-F979-476C-8D27-D308558033CA}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
    FirewallRules: [{3455B446-1F93-4194-9692-01157B4D765A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{2B0E2181-2CAF-432A-8CCC-7A593F3B891E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{501CB945-563C-4534-8035-517D89CDDA01}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{EB54B82F-8695-4C38-A383-06DC2F79B1DC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{F24D7976-6295-407E-943A-662CFF20392D}] => (Allow) C:\Program Files\iTunes\iTunes.exe
    FirewallRules: [{AB1BAA89-E9F0-4440-832B-605EA6A211DA}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
    FirewallRules: [{D42BA360-6F71-4B76-8916-CFD5BD70A2FC}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
    FirewallRules: [{025C283A-E66B-4142-8C30-DDB3BF481466}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
    FirewallRules: [{2D22121C-3EBE-4BAB-9817-49E44F8F26EA}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
    FirewallRules: [{98F5DE42-BB45-4550-8AC4-4E0E86F9877D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{3A37AAF4-02B4-4892-9B2C-5BC1F74176CF}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{869E6A0A-A161-4B21-B532-06B23529F61F}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{17ECB865-CEDA-481D-B0B6-C118C0683FF7}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{54D10AD0-C8A5-4761-B8F7-37A605EA7BC1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
    FirewallRules: [{B129528F-B047-4BB7-8463-96865A0B9337}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
    FirewallRules: [{799A733A-D84B-417C-A85A-46C28C39D496}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    FirewallRules: [{84CD1487-3F8C-4489-9507-B4E4707E626F}] => (Allow) C:\Users\Aimee\AppData\Local\Chromium\Application\chrome.exe

    ==================== Restore Points =========================

    07-03-2016 12:19:40 Decrap my Computer [W8-x64] - Decrap my Computer

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (03/07/2016 09:53:41 PM) (Source: DptfEvent) (EventID: 2) (User: )
    Description: DptfPolicyLpmServiceHelper
    WinMain: CreateSharedMemory() failed.
    Session ID = 3

    Error: (03/07/2016 09:53:41 PM) (Source: DptfEvent) (EventID: 3) (User: )
    Description: DptfPolicyLpmServiceHelper
    CreateSharedMemory: WaitForSingleObject() with g_pkeLpmSharedMemoryCreated failed
    Last error = [0x00000102]
    Session ID = 3

    Error: (03/07/2016 12:37:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 30688

    Error: (03/07/2016 12:37:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 30688

    Error: (03/07/2016 12:37:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (03/07/2016 12:37:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 15063

    Error: (03/07/2016 12:37:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 15063

    Error: (03/07/2016 12:37:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (03/07/2016 11:48:45 AM) (Source: DptfEvent) (EventID: 2) (User: )
    Description: DptfPolicyLpmServiceHelper
    WinMain: CreateSharedMemory() failed.
    Session ID = 1

    Error: (03/07/2016 11:48:45 AM) (Source: DptfEvent) (EventID: 3) (User: )
    Description: DptfPolicyLpmServiceHelper
    CreateSharedMemory: WaitForSingleObject() with g_pkeLpmSharedMemoryCreated failed
    Last error = [0x00000102]
    Session ID = 1


    System errors:
    =============
    Error: (03/07/2016 12:37:50 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgsvc service.

    Error: (03/07/2016 12:32:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Kaspersky Security Scan Service service failed to start due to the following error:
    %%2

    Error: (03/07/2016 12:32:23 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has stopped unexpectedly.

    Module Path: C:\Windows\System32\bcmihvsrv64.dll

    Error: (03/07/2016 12:32:23 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has stopped unexpectedly.

    Module Path: C:\Windows\System32\bcmihvsrv64.dll

    Error: (03/07/2016 12:32:10 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has stopped unexpectedly.

    Module Path: C:\Windows\System32\bcmihvsrv64.dll

    Error: (03/07/2016 12:26:23 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Apple Mobile Device Service service terminated unexpectedly. It has done this 4 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

    Error: (03/07/2016 12:26:23 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Intel(R) Capability Licensing Service Interface service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.

    Error: (03/07/2016 12:25:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Microsoft Office ClickToRun Service service terminated unexpectedly. It has done this 4 time(s).

    Error: (03/07/2016 12:25:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Apple Mobile Device Service service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

    Error: (03/07/2016 12:25:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Intel(R) Capability Licensing Service Interface service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.


    CodeIntegrity:
    ===================================
    Date: 2016-03-07 21:52:59.985
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-03-07 21:52:58.642
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-03-07 21:52:03.704
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avgfmwbasex.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-03-07 21:52:02.314
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avgfmwbasex.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-03-07 21:51:38.643
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avgfmwbasex.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-03-07 21:51:36.956
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avgfmwbasex.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-03-07 21:51:35.206
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avgfmwbasex.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-03-07 21:51:32.892
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avgfmwbasex.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-03-07 21:51:24.489
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avgfmwbasex.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-03-07 21:51:24.348
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.


    ==================== Memory info ===========================

    Processor: Intel(R) Celeron(R) CPU N2840 @ 2.16GHz
    Percentage of memory in use: 74%
    Total physical RAM: 1939.04 MB
    Available physical RAM: 503.21 MB
    Total Virtual: 3603.04 MB
    Available Virtual: 1650.45 MB

    ==================== Drives ================================

    Drive c: (Windows) (Fixed) (Total:21.52 GB) (Free:5.51 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 29.1 GB) (Disk ID: 538F454A)

    Partition: GPT.

    ==================== End of Addition.txt ============================
     

    Attached Files:

  4. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    raff, please please attach all logs they really get in the way pasted on here...... :eek:

    How is everything acting now??? Were you able to reset your router?? Were you able to run the little .bat file???
    What problems do you have, if any??

    2oG
     
  5. raff

    raff Newbie

    Joined:
    Mar 4, 2016
    Messages:
    13
    Likes Received:
    0
    Trophy Points:
    1
    I didn't reset the router, not sure how to do that yet.

    I managed to do all the other stuff and it seems to be running OK. I've disabled IE and now using Chrome.

    I had to past the addition file as it wouldn't let me post it - kept saying not allowed hence me copying and pasting!
     
  6. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    google "how to reset a linksys (or your) router"

    see what you can do with that. most have a reset button on the bottom and must be re-configured.. you will have to do that, I can't from here... lol but, I'll try to help..

    2oG
     
  7. Danny34671

    Danny34671 Newbie

    Joined:
    May 20, 2016
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    1
    Could be adware. Some adware can escape from the recognition of certain security tools. You'd better check more carefully. For example, Wajam, which is a stubborn thing that should be removed manually. I got this pest once and cannot remove it via automatic tool, but remove it manually via this
     
    Last edited: May 20, 2016
  8. raff

    raff Newbie

    Joined:
    Mar 4, 2016
    Messages:
    13
    Likes Received:
    0
    Trophy Points:
    1
    Thanks Dannyt34671 not sure what it was but it was resolved with the above steps.

    Many thanks to all who helped and my apologies at not thanking you all sooner.
     
  9. mahlemuts

    mahlemuts Member

    Joined:
    May 13, 2016
    Messages:
    41
    Likes Received:
    2
    Trophy Points:
    8
    I had a Stream 11 (Pro, Grey version - no difference) I would recommend you create a Win 10 usb key and wipe over the top of the current installation, just make sure you backup what you need and get ALL the drivers beforehand and a copy of your key (or use an activator!) search online for how to do this - If you get it all working on W10, uninstall everything you dont need/want, disable hibernation and system restore and you should get it to around 11gb installed (just under half the emmc 32gb capacity) and for AV use Immunet as its cloud based and doesnt install updates every day like most AVs - Chrome with ublock origin will stop your pop ups too - try not to use IE or Edge

    You could do this with Win 8.1 if you prefer, dont need to go to W10
     
    Last edited: May 20, 2016
  10. pcrepair

    pcrepair Regular member

    Joined:
    Aug 17, 2005
    Messages:
    582
    Likes Received:
    0
    Trophy Points:
    26
    Run adwcleaner
    Then run avastbrowser cleaner
    That ought to fix it

    Kyran
     
  11. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    If you took the time to read the thread, you would see that the problem has been fixed...:rolleyes:
     
    mahlemuts likes this.
  12. mahlemuts

    mahlemuts Member

    Joined:
    May 13, 2016
    Messages:
    41
    Likes Received:
    2
    Trophy Points:
    8
    plus adwcleaner has fake versions floating around cyberspace - stick to official channels or better apps
     
  13. pcrepair

    pcrepair Regular member

    Joined:
    Aug 17, 2005
    Messages:
    582
    Likes Received:
    0
    Trophy Points:
    26
    Sorry lol was reading it on my phone and thought i,d be helpful i use those two programs all the time i keep them on my flash drive
     

Share This Page