Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Web Protect Adware removal help!


  • This topic is locked This topic is locked
3 replies to this topic

#1 buckeyesandy

buckeyesandy

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:12:11 AM

Posted 19 October 2014 - 10:00 PM

Hello,
Our internet would not work and ran our virus program.  We detected Web Protect Adware on our computer and are having trouble deleting it.  I saw a similar post on your forum and ran the ComboFix program.  Combo Fix found Rootkit, and the adware that we had found was Web Protect (MyOSProtect).  Here are the results of our ComboFix scan:
Any ideas what else we need to do to get internet access and make sure all viruses/adware/malware are gone?  Internet will still not work!  Thanks!!
 
ComboFix 14-10-15.01 - Morton 3 10/19/2014  22:20:05.1.2 - x86
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.3037.1969 [GMT -4:00]
Running from: E:\ComboFix.exe
AV: McAfee VirusScan Enterprise *Enabled/Outdated* {ADA629C7-7F48-5689-624A-3B76997E0892}
FW: McAfee Host Intrusion Prevention Firewall *Disabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
SP: McAfee VirusScan Enterprise Antispyware Module *Enabled/Outdated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
 * Resident AV is active
.
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\programdata\2308189059
c:\users\Morton 3\g2mdlhlpx.exe
c:\users\Morton 3\GoToAssistDownloadHelper.exe
c:\windows\$NtUninstallKB11680$
c:\windows\$NtUninstallKB11680$\2825438025
.
.
(((((((((((((((((((((((((   Files Created from 2014-09-20 to 2014-10-20  )))))))))))))))))))))))))))))))
.
.
2014-10-20 00:15 . 2014-10-20 00:15 -------- d-----w- c:\users\Morton 3\AppData\Roaming\Roxio
2014-10-08 12:30 . 2014-10-08 12:30 -------- d-sh--w- c:\users\Morton 3\AppData\Local\EmieUserList
2014-10-08 12:30 . 2014-10-08 12:30 -------- d-sh--w- c:\users\Morton 3\AppData\Local\EmieSiteList
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-08 07:02 . 2014-10-08 07:02 74240 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-10-08 07:02 . 2014-10-08 07:02 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-10-08 07:02 . 2014-10-08 07:02 62464 ----a-w- c:\windows\system32\tdc.ocx
2014-10-08 07:02 . 2014-10-08 07:02 454656 ----a-w- c:\windows\system32\vbscript.dll
2014-10-08 07:02 . 2014-10-08 07:02 1812992 ----a-w- c:\windows\system32\wininet.dll
2014-10-08 07:02 . 2014-10-08 07:02 139264 ----a-w- c:\windows\system32\wextract.exe
2014-09-25 13:17 . 2014-09-11 18:30 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-09-25 13:17 . 2014-09-11 18:30 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-09-25 13:17 . 2014-09-10 08:42 3675824 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-09-25 01:40 . 2014-10-01 07:04 519680 ----a-w- c:\windows\system32\qdvd.dll
2014-09-10 09:10 . 2014-09-10 15:08 52376 ----a-w- c:\windows\system32\drivers\{5eeb83d0-96ea-4249-942c-beead6847053}Gw.sys
2014-09-09 21:47 . 2014-09-24 07:03 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-09 12:14 . 2014-09-09 18:34 52416 ----a-w- c:\windows\system32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}Gw.sys
2014-09-05 01:52 . 2014-09-10 09:51 445952 ----a-w- c:\windows\system32\aepdu.dll
2014-09-05 01:47 . 2014-09-10 09:51 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-09-01 18:29 . 2014-09-09 17:37 20480 ----a-w- c:\windows\system32\drivers\pcwatch.sys
2014-08-29 12:26 . 2010-06-24 15:33 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-23 01:46 . 2014-08-28 09:11 305152 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 00:42 . 2014-08-28 09:11 2352640 ----a-w- c:\windows\system32\win32k.sys
2014-08-18 21:30 . 2014-10-09 07:01 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-08-12 05:16 . 2014-09-12 14:46 43352 ----a-w- c:\windows\system32\drivers\FireNfcp.sys
2014-08-01 11:35 . 2014-09-10 09:51 793600 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-07-25 16:55 . 2014-09-10 15:34 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-07-25 06:35 . 2014-07-25 06:35 875688 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4562944]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]
"DLPSP"="c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE" [2010-06-01 886152]
"DLUPDR"="c:\program files\Dell Printers\Additional Color Laser Software\Updater\DLUPDR.EXE" [2010-06-01 566680]
"DLQLU"="c:\program files\Dell Printers\Additional Color Laser Software\Launcher\DLQLU.EXE" [2010-06-01 1127744]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"IndexSearch"="c:\program files\Dell Printers\paperport\PaperPort\IndexSearch.exe" [2010-03-17 46368]
"PaperPort PTD"="c:\program files\Dell Printers\paperport\PaperPort\pptd40nt.exe" [2010-03-17 29984]
"PDFHook"="c:\program files\Dell Printers\paperport\PDFViewer\pdfpro5hook.exe" [2010-03-05 636192]
"PDF5 Registry Controller"="c:\program files\Dell Printers\paperport\PDFViewer\RegistryController.exe" [2010-03-05 62752]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2014-01-16 243560]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2011-12-22 362432]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-10-21 138808]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-10-21 172088]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-10-21 173624]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2013-12-04 337440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2014-07-25 256896]
"McAfee Host Intrusion Prevention Tray"="c:\program files\McAfee\Host Intrusion Prevention\FireTray.exe" [2013-12-18 219216]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-07-16 307768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HUD 3.6.0.lnk - c:\program files\Fonality\HUD3.6\HUD3.exe [2013-4-18 315392]
NWepo.lnk - c:\program files\Network Associates\NWePO.exe [2010-3-6 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
R2 LiveUpdateSvc;LiveUpdate;c:\program files\IObit\LiveUpdate\LiveUpdate.exe [2014-05-04 2152736]
R2 Update SmarterPower;Update SmarterPower;c:\program files\SmarterPower\updateSmarterPower.exe [x]
R2 Util SmarterPower;Util SmarterPower;c:\program files\SmarterPower\bin\utilSmarterPower.exe [x]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\Drivers\CtAudDrv.sys [2009-05-28 134144]
R3 Firehk;McAfee NDIS Intermediate Filter;c:\windows\system32\DRIVERS\firehk.sys [x]
R3 FirehkMP;FirehkMP;c:\windows\system32\DRIVERS\firehk.sys [x]
R3 FireNfcp;McAfee Inc. FireNfcp;c:\windows\system32\drivers\FireNfcp.sys [2014-08-12 43352]
R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [2013-12-18 149864]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-10-08 108032]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2014-06-13 93144]
R3 MyOSProtect;MyOSProtect;c:\program files\Web Protect\MyOSProtect.exe [x]
R3 rcmirror;rcmirror;c:\windows\system32\DRIVERS\rcmirror.sys [2010-01-18 3200]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2013-03-18 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-31 1343400]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2014-06-13 213872]
S1 {5eeb83d0-96ea-4249-942c-beead6847053}Gw;{5eeb83d0-96ea-4249-942c-beead6847053}Gw;c:\windows\system32\drivers\{5eeb83d0-96ea-4249-942c-beead6847053}Gw.sys [2014-09-10 52376]
S1 {9d5747ee-0448-4681-8337-1555de75a3b6}Gw;{9d5747ee-0448-4681-8337-1555de75a3b6}Gw;c:\windows\system32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}Gw.sys [2014-09-09 52416]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2011-06-29 66776]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2013-12-17 67400]
S1 NEOFLTR_740_31481;Juniper Networks TDI Filter Driver (NEOFLTR_740_31481);c:\windows\system32\Drivers\NEOFLTR_740_31481.SYS [2014-06-07 92272]
S1 pcwatch;pcwatch service;c:\windows\system32\Drivers\pcwatch.sys [2014-09-01 20480]
S2 DLSDB;Dell Printer Status Database;c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE [2010-06-01 226696]
S2 enterceptAgent;McAfee Host Intrusion Prevention Service;c:\program files\McAfee\Host Intrusion Prevention\FireSvc.exe [2013-12-18 525144]
S2 HipMgmt;McAfee Host Intrusion Prevention lpc Service;c:\program files\McAfee\Host Intrusion Prevention\HipMgmt.exe [2013-12-18 153832]
S2 McAfee SiteAdvisor Enterprise Service;McAfee SiteAdvisor Enterprise Service;c:\program files\McAfee\SiteAdvisor Enterprise\McSACore.exe [2011-05-12 324928]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2013-12-17 169800]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2014-06-13 174968]
S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files\Dell Printers\paperport\PaperPort\PDFProFiltSrvPP.exe [2010-03-17 144672]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-08-21 143936]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2013-12-17 365928]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2014-07-08 716504]
S3 VIACRX86;VIACRX86;c:\windows\system32\DRIVERS\viacr.sys [2009-07-14 59392]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ    Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2014-10-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-11 13:17]
.
2014-10-10 c:\windows\Tasks\G2MUpdateTask-S-1-5-21-2180362347-1613900095-221235112-1000.job
- c:\program files\Citrix\GoToMeeting\1767\g2mupdate.exe [2014-09-28 08:49]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
IE: Copy to &Lightning Note - c:\program files\Corel\WordPerfect Office X6\Programs\WPLightningCopyToNote.hta
IE: Open with WordPerfect - c:\program files\Corel\WordPerfect Office X6\Programs\WPLauncher.hta
LSP: c:\windows\system32\MyOSProtect.dll
Trusted Zone: agencyanywhere.agency.ni.nwie.net
Trusted Zone: nationwide.com
Trusted Zone: skilldialogue.com
Trusted Zone: skillport.com
Trusted Zone: skillwsa.com
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{10921475-03CE-4E04-90CE-E2E7EF20C814} - c:\program files\IObit\IObit Uninstaller\UninstallExplorer32.dll
Toolbar-Locked - (no file)
SafeBoot-pcwatch.sys
SafeBoot-mcmscsvc
SafeBoot-MCODS
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,38,12,26,bd,a8,
   0a,e6,f4,22,0e,f1,4c,12,2a,bb,94,a4,70
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=hex:51,66,7a,6c,4c,1d,38,12,11,7f,11,
   d0,78,5b,08,05,de,bb,01,03,dd,4c,30,54
"{C66A678D-5E6C-4AF9-8F57-C6192F42CF74}"=hex:51,66,7a,6c,4c,1d,38,12,e3,64,79,
   c2,5e,10,97,0f,f0,41,85,59,2a,1c,8b,60
"{551A852F-39A6-44A7-9C13-AFBEC9185A9D}"=hex:51,66,7a,6c,4c,1d,38,12,41,86,09,
   51,94,77,c9,01,e3,05,ec,fe,cc,46,1e,89
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{7DB2D5A0-7241-4E79-B68D-6309F01C5231}"=hex:51,66,7a,6c,4c,1d,38,12,ce,d6,a1,
   79,73,3c,17,0b,c9,9b,20,49,f5,42,16,25
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
   94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{A235E1E3-6296-4710-AF39-104A7FAA6C7C}"=hex:51,66,7a,6c,4c,1d,38,12,8d,e2,26,
   a6,a4,2c,7e,02,d0,2f,53,0a,7a,f4,28,68
"{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,38,12,47,ea,77,
   b5,84,ef,68,0f,ce,12,6f,90,ec,54,cc,eb
"{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}"=hex:51,66,7a,6c,4c,1d,38,12,e3,94,1f,
   be,3b,97,d8,0c,d0,f4,c8,9e,21,03,83,f2
"{BD7C9B62-A7D9-4405-BE51-7FD633F08791}"=hex:51,66,7a,6c,4c,1d,38,12,0c,98,6f,
   b9,eb,e9,6b,01,c1,47,3c,96,36,ae,c3,85
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{F236CA79-3123-4AFB-9F74-E98117AD5625}"=hex:51,66,7a,6c,4c,1d,38,12,17,c9,25,
   f6,11,7f,95,0f,e0,62,aa,c1,12,f3,12,31
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:51,da,33,44,0a,cd,cf,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,65,34,32,f5,c5,1d,0d,41,bb,9d,44,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,65,34,32,f5,c5,1d,0d,41,bb,9d,44,\
.
[HKEY_USERS\S-1-5-21-2180362347-1613900095-221235112-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2180362347-1613900095-221235112-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
c:\windows\system32\WLANExt.exe
c:\program files\Dell\Dell Wireless WLAN Card\bcmwltry.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\program files\McAfee\VirusScan Enterprise\mfeann.exe
c:\windows\system32\conhost.exe
c:\windows\system32\msiexec.exe
c:\program files\Visioneer\OneTouch 4.0\OtService.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Common Files\McAfee\SystemCore\mfefire.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\program files\Citrix\ICA Client\Receiver\Receiver.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Citrix\ICA Client\wfcrun32.exe
c:\windows\system32\sppsvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2014-10-19  22:46:38 - machine was rebooted
ComboFix-quarantined-files.txt  2014-10-20 02:46
.
Pre-Run: 252,644,810,752 bytes free
Post-Run: 252,108,378,112 bytes free
.
- - End Of File - - 2E69CC99C87B1C356F3C5736E8ACBBE8
5C616939100B85E558DA92B899A0FC36

Edited by Budapest, 20 October 2014 - 12:41 AM.
Moved from Win7 ~Budapest


BC AdBot (Login to Remove)

 


#2 LiquidTension

LiquidTension

  • Malware Response Team
  • 1,278 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:11 AM

Posted 23 October 2014 - 03:02 PM

Hello buckeyesandy, welcome to Bleeping Computer's Malware Removal forum!
 
My username is LiquidTension, but you can call me Adam. I will be assisting you with your malware-related problems.
If you would allow me to call you by your first name I would prefer that. smile.png
 
======================================================
 
Please read through the points below to ensure this process moves as quickly and efficiently as possible.

  • Please read through my instructions thoroughly, and ensure you carry out each step in the order specified.
  • Please do not post logs using the CODEQUOTE or ATTACHMENT format. Logs should be posted directly in plain text. If you receive an error whilst posting, please break the log in half and use multiple posts.
  • Please do not run any tools or take any steps other than those I provide for you. Independent efforts may make matters worse, and will affect my ability in ascertaining the current situation and providing the best set of instructions for you.
  • Please backup important files before proceeding with my instructions. Malware removal can be unpredictable.  
  • If you come across any issues whilst following my instructions, please stop and inform me of the issue in as much detail as possible. Please do not hesitate to ask before proceeding.
  • Topics are locked if no response is made after 4 days. Please inform me if you require additional time to complete my instructions.
  • Ensure you are following this topic. Click etYzdbu.png at the top of the page. 
     

======================================================
 

Do you have a USB drive and access to a clean computer?


Posted Image

#3 LiquidTension

LiquidTension

  • Malware Response Team
  • 1,278 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:11 AM

Posted 26 October 2014 - 06:02 AM

Hello, 

 

Do you still require assistance? 


Posted Image

#4 LiquidTension

LiquidTension

  • Malware Response Team
  • 1,278 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:11 AM

Posted 27 October 2014 - 08:36 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users