Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Popup and extra webpages opening, slow speed


  • Please log in to reply
11 replies to this topic

#1 Robs2014

Robs2014

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 06 May 2014 - 04:04 PM

   I have a Windows 8 laptop and just started to have issue in the last few days with lots of popup. I also get popups on the desktop when I boot up and some slide in from the right, it is really annoying and impossible to get anything done. Please help



BC AdBot (Login to Remove)

 


#2 Alex&Vanko

Alex&Vanko

  • Banned
  • 1,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:26 PM

Posted 06 May 2014 - 04:13 PM

Hallo Robs2014 and :welcome:

Would you do the following:

Download Screen317 Security Check HERE and save it to your Desktop.
* Double-click SecurityCheck.exe
* Follow the onscreen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Please post the contents of that document.
Note:: If any security program requests permission to access the Internet, allow it to do so

Please download MiniToolBox HERE to your desktop to run it.
Checkmark the following boxes:
* List content of Hosts
* Flush DNS
* Report IE Proxy Settings
* Reset IE Proxy Settings
* Report FF Proxy Settings
* Reset FF Proxy Settings
* List last 10 Event Viewer log
* List Installed Programs
* List Devices (do NOT change any settings here)
* List Users, Partitions and Memory size
Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
Click Go and Copy / Paste the result. (result.txt)

 

Thank you!



#3 Robs2014

Robs2014
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 06 May 2014 - 08:42 PM

Here are the results:

 

Results of screen317's Security Check version 0.99.82 
   x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled! 
Windows Defender  
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 MVPS Hosts File 
 Spybot - Search & Destroy
 Google Chrome 34.0.1847.116 
 Google Chrome 34.0.1847.131 
````````Process Check: objlist.exe by Laurent```````` 
 Spybot Teatimer.exe is disabled!
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````
 

 

 

MiniToolBox by Farbar  Version: 23-01-2014
Ran by Fran's (administrator) on 06-05-2014 at 20:57:26
Running from "C:\Users\Fran's\Downloads"
Microsoft Windows 8.1  (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is enabled.
ProxyServer: http=127.0.0.1:49951;https=127.0.0.1:49951

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com



#4 Alex&Vanko

Alex&Vanko

  • Banned
  • 1,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:26 PM

Posted 06 May 2014 - 09:03 PM

Hallo Robs2014!

This is just the beginning of the log from Minitoolbox.

Thank you!



#5 Robs2014

Robs2014
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 06 May 2014 - 09:12 PM

Sorry here is the full log -

 

MiniToolBox by Farbar  Version: 23-01-2014
Ran by Fran's (administrator) on 06-05-2014 at 20:57:26
Running from "C:\Users\Fran's\Downloads"
Microsoft Windows 8.1  (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is enabled.
ProxyServer: http=127.0.0.1:49951;https=127.0.0.1:49951

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com

There are 15472 more lines starting with "127.0.0.1"

========================= Event log errors: ===============================

Application errors:
==================
Error: (05/06/2014 04:46:57 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)
Description: Event filter with query "select * from __InstanceModificationEvent where targetinstance isa '__ArbitratorConfiguration'" could not be reactivated in namespace "//./root" because of error 0x80041033. Events cannot be delivered through this filter until the problem is corrected.

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __TimerEvent" whose target class "__TimerEvent" in //./root/subscription namespace does not exist. The query will be ignored.

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __TimerEvent" whose target class "__TimerEvent" in //./root namespace does not exist. The query will be ignored.

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __TimerEvent" whose target class "__TimerEvent" in //./root/CIMV2 namespace does not exist. The query will be ignored.

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __SystemEvent" whose target class "__SystemEvent" in //./root/subscription namespace does not exist. The query will be ignored.

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __SystemEvent" whose target class "__SystemEvent" in //./root namespace does not exist. The query will be ignored.

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __SystemEvent" whose target class "__SystemEvent" in //./root/CIMV2 namespace does not exist. The query will be ignored.

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __NamespaceOperationEvent" whose target class "__NamespaceOperationEvent" in //./root/subscription namespace does not exist. The query will be ignored.

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __NamespaceOperationEvent" whose target class "__NamespaceOperationEvent" in //./root namespace does not exist. The query will be ignored.

System errors:
=============
Error: (05/06/2014 05:10:45 PM) (Source: DCOM) (User: Fran)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (05/06/2014 05:10:15 PM) (Source: DCOM) (User: Fran)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (05/06/2014 04:49:49 PM) (Source: Service Control Manager) (User: )
Description: The yewimmxqbs64 service failed to start due to the following error:
%%2

Error: (05/06/2014 04:49:44 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the RBClientService service to connect.

Error: (05/06/2014 04:48:07 PM) (Source: DCOM) (User: Fran)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (05/06/2014 04:48:07 PM) (Source: DCOM) (User: Fran)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (05/06/2014 04:48:07 PM) (Source: DCOM) (User: Fran)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (05/06/2014 04:47:33 PM) (Source: DCOM) (User: Fran)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (05/06/2014 04:47:33 PM) (Source: DCOM) (User: Fran)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (05/06/2014 04:47:33 PM) (Source: DCOM) (User: Fran)
Description: 1084WSearchUnavailable{9E175B6D-F52A-11D8-B9A5-505054503030}

Microsoft Office Sessions:
=========================
Error: (05/06/2014 04:46:57 PM) (Source: SideBySide)(User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Fran's\Desktop\2014\esetsmartinstaller_enu.exe

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)
Description: //./rootselect * from __InstanceModificationEvent where targetinstance isa '__ArbitratorConfiguration'0x80041033

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)
Description: $Coreselect * from __TimerEvent__TimerEvent//./root/subscription

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)
Description: $Coreselect * from __TimerEvent__TimerEvent//./root

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)
Description: $Coreselect * from __TimerEvent__TimerEvent//./root/CIMV2

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)
Description: $Coreselect * from __SystemEvent__SystemEvent//./root/subscription

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)
Description: $Coreselect * from __SystemEvent__SystemEvent//./root

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)
Description: $Coreselect * from __SystemEvent__SystemEvent//./root/CIMV2

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)
Description: $Coreselect * from __NamespaceOperationEvent__NamespaceOperationEvent//./root/subscription

Error: (05/06/2014 03:25:39 PM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)
Description: $Coreselect * from __NamespaceOperationEvent__NamespaceOperationEvent//./root

CodeIntegrity Errors:
===================================
  Date: 2014-05-06 16:04:18.502
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 16:04:18.408
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 16:00:30.197
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 16:00:30.103
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 15:42:07.805
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 15:42:07.727
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 15:27:18.082
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 15:27:17.972
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 15:16:39.324
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 15:16:39.230
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements.

=========================== Installed Programs ============================

 clear.fi SDK - Video 2 (Version: 2.1.1925)
 clear.fi SDK- Movie 2 (Version: 2.1.2008)
Acer Backup Manager (Version: 4.0.0.0059)
Acer Instant Update Service (Version: 1.00.3013)
Acer Power Management (Version: 7.00.3007)
Acer Recovery Management (Version: 6.00.3011)
AcerCloud (Version: 2.01.3115)
AcerCloud Docs (Version: 1.00.3201)
Agatha Christie - Death on the Nile (Version: 2.2.0.98)
Aloha TriPeaks (Version: 2.2.0.98)
Backup Manager v4 (Version: 4.0.0.0059)
Bejeweled 3 (Version: 2.2.0.98)
BlockAndSurf
Citrix Online Launcher (Version: 1.0.183)
clear.fi Media (Version: 2.01.3108)
clear.fi Photo (Version: 2.01.3108)
ContentExplorer (Version: 7.0)
coupon downloader (Version: 2.0.1)
Cradle Of Egypt Collector's Edition (Version: 2.2.0.98)
CyberLink MediaEspresso 6.5 (Version: 6.5.3103_44819)
Delicious: Emily's True Love Premium Edition (Version: 2.2.0.98)
DesktopWeatherAlerts (Version: 1.0.29.0)
Dolby Advanced Audio v2 (Version: 7.2.8000.13)
Dora's World Adventure (Version: 2.2.0.95)
Driver Support (Version: 8.1)
ETDWare PS/2-X64 11.6.10.001_WHQL (Version: 11.6.10.001)
Google Chrome (Version: 34.0.1847.131)
Google Update Helper (Version: 1.3.23.9)
HID Monitor (Version: 1.1.3)
HP ENVY 5530 series Basic Device Software (Version: 32.0.1180.44630)
HP ENVY 5530 series Help (Version: 30.0.0)
HP Photo Creations (Version: 1.0.0.7702)
HP Update (Version: 5.005.002.002)
Identity Card (Version: 2.00.3004)
Intel® Management Engine Components (Version: 8.1.0.1252)
Intel® Processor Graphics (Version: 10.18.10.3316)
Intel® Rapid Storage Technology (Version: 11.5.4.1001)
Intel® SDK for OpenCL - CPU Only Runtime Package (Version: 2.0.0.37149)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
Jewel Match 3 (Version: 2.2.0.98)
Launch Manager (Version: 7.0.6)
Live Updater (Version: 2.00.3004)
Microsoft Office (Version: 14.0.6120.5004)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual Studio 2005 Tools for Office Runtime (Version: 8.0.60940.0)
Mystery P.I. - Curious Case of Counterfeit Cove (Version: 2.2.0.98)
MyWinLocker (Version: 4.0.14.35)
MyWinLocker 4 (Version: 4.0.14.35)
MyWinLocker Suite (Version: 4.0.14.24)
NTI Media Maker 9 (Version: 9.0.2.9008)
Office Addin (Version: 2.01.3200)
OpenSoftwareUpdater
Peggle Nights (Version: 2.2.0.98)
Penguins! (Version: 2.2.0.98)
Plants vs. Zombies - Game of the Year (Version: 2.2.0.98)
Polar Bowler (Version: 2.2.0.97)
Polar Golfer (Version: 2.2.0.98)
Product Improvement Study for HP ENVY 5530 series (Version: 32.0.1180.44630)
Qualcomm Atheros Bluetooth Suite (64) (Version: 8.0.0.210)
Qualcomm Atheros WiFi Driver Installation (Version: 11.15)
Realtek Ethernet Controller Driver (Version: 8.2.612.2012)
Realtek High Definition Audio Driver (Version: 6.0.1.6690)
Realtek PCIE Card Reader (Version: 6.2.8400.27028)
Right Backup (Version: 2.1.1000.3945)
Shared C Run-time for x64 (Version: 10.0.0)
Shredder (Version: 2.0.8.9)
Spotify (Version: 0.8.4.99.ga249b5f1)
Spybot - Search & Destroy (Version: 2.3.39)
Tales of Lagoona (Version: 2.2.0.110)
TeamViewer 9 (Version: 9.0.28223)
Update Installer for WildTangent Games App
Visual Studio 2005 Tools for Office Second Edition Runtime
Visual Studio Tools for the Office system 3.0 Runtime
Visual Studio Tools for the Office system 3.0 Runtime (Version: 9.0.30729)
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (Version: 1)
VLC media player 2.0.5 (Version: 2.0.5)
WildTangent Games (Version: 1.0.3.0)
WildTangent Games App (Version: 4.0.9.3)
Zuma's Revenge (Version: 2.2.0.98)

========================= Devices: ================================

Name: Bluetooth LWFLT Device
Description: Bluetooth LWFLT Device
Class Guid: {c7c038ad-1f2d-44d4-b2fe-d912be20e6d5}
Manufacturer: Qualcomm Atheros Communications
Service: BTATH_LWFLT
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Bluetooth Audio Device
Description: Bluetooth Audio Device
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Qualcomm Atheros Communications
Service: BTATH_A2DP
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Virtual Bluetooth Support (Include Audio)
Description: Virtual Bluetooth Support (Include Audio)
Class Guid: {c7c038ad-1f2d-44d4-b2fe-d912be20e6d5}
Manufacturer: Qualcomm Atheros Communications
Service: AthBTPort
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

========================= Memory info: ===================================

Percentage of memory in use: 27%
Total physical RAM: 5939.6 MB
Available physical RAM: 4308.64 MB
Total Pagefile: 6899.6 MB
Available Pagefile: 5055.63 MB
Total Virtual: 4095.88 MB
Available Virtual: 3976.2 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:449.42 GB) (Free:411.54 GB) NTFS
2 Drive d: (HP EN5530) (CDROM) (Total:0.39 GB) (Free:0 GB) CDFS

========================= Users: ========================================

User accounts for \\FRAN

Administrator            Fran's                   Guest                   

**** End of log ****



#6 Alex&Vanko

Alex&Vanko

  • Banned
  • 1,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:26 PM

Posted 06 May 2014 - 09:47 PM

You do not have antivirus software.

Uninstall standard way from Programs and Features:
BlockAndSurf
ContentExplorer
Spybot - Search & Destroy

After that:

Please download AdwCleaner by Xplode HERE onto your desktop.

    Close all open programs and internet browsers.
    Double click on AdwCleaner.exe to run the tool.
    Click on Scan.
    After the scan is complete click on "Clean"
    Confirm each time with Ok.
    Your computer will be rebooted automatically. A text file will open after the restart.
    Please post the content of that logfile with your next answer.
    You can find the logfile at C:\AdwCleaner[S1].txt as well.

 

Thank you!


Edited by Alex&Vanko, 06 May 2014 - 09:48 PM.


#7 Robs2014

Robs2014
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 06 May 2014 - 10:14 PM

# AdwCleaner v3.207 - Report created 06/05/2014 at 23:10:59
# Updated 05/05/2014 by Xplode
# Operating System : Windows 8.1  (64 bits)
# Username : Fran's - FRAN
# Running from : C:\Users\Fran's\Downloads\AdwCleaner (1).exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Systweak
Folder Deleted : C:\Users\Fran's\AppData\Roaming\Systweak
Folder Deleted : C:\Users\Fran's\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKCU\Software\systweak
Key Deleted : HKLM\Software\systweak

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17037

-\\ Google Chrome v34.0.1847.131

[ File : C:\Users\Fran's\AppData\Local\Google\Chrome\User Data\Default\preferences ]

*************************

AdwCleaner[R0].txt - [18546 octets] - [06/05/2014 16:45:37]
AdwCleaner[R1].txt - [1197 octets] - [06/05/2014 23:10:19]
AdwCleaner[S0].txt - [16436 octets] - [06/05/2014 16:47:31]
AdwCleaner[S1].txt - [1087 octets] - [06/05/2014 23:10:59]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1147 octets] ##########



#8 Alex&Vanko

Alex&Vanko

  • Banned
  • 1,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:26 PM

Posted 06 May 2014 - 10:35 PM

Please download Junkware Removal Tool HERE to your desktop.

    Shut down your protection software now to avoid potential conflicts.
    Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    The tool will open and start scanning your system.
    Please be patient as this can take a while to complete depending on your system's specifications.
    On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    Post the contents of JRT.txt into your next message.

 

Thank you!



#9 Robs2014

Robs2014
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 07 May 2014 - 12:06 AM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Fran's on Wed 05/07/2014 at  0:54:27.62
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

~~~ Services

 

~~~ Registry Values

 

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\systweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B200F60D-DB59-494D-85CB-2AE78E23CC31}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B913DEC7-5724-4B38-B7D1-F845D3FCC88D}

 

~~~ Files

 

~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\systweak"
Successfully deleted: [Folder] "C:\Users\Fran's\AppData\Roaming\systweak"

 

~~~ Event Viewer Logs were cleared

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 05/07/2014 at  0:58:33.99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



#10 Alex&Vanko

Alex&Vanko

  • Banned
  • 1,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:26 PM

Posted 07 May 2014 - 11:46 AM

Hallo Robs 2014!

The pop ups are not only in browsers but on the desktop also?

I am not sure it will be helpful but let`s try this:

  Download Malwarebytes' Anti-Malware Free 2 HERE to your desktop.
    - Do not accept the Free Trial Version at this time -
    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform quick scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

 

Thank you!



#11 Robs2014

Robs2014
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 10 May 2014 - 10:26 PM

I tried the above an it stopped the internet from working, it gave me a Proxy server error messge in the Internet browsers. I have fixed it now and all seems fine. Thank you for the help on fixing this.



#12 Alex&Vanko

Alex&Vanko

  • Banned
  • 1,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:26 PM

Posted 11 May 2014 - 08:01 AM

Why you need  MVPS Hosts File?

To block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and even most hijackers?

Thank you!






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users