Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Windows 8.1 Random Task Switching and other issues


  • Please log in to reply
10 replies to this topic

#1 magictj

magictj

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:19 AM

Posted 16 August 2015 - 03:52 AM

Hi,
 
My issue is a difficult one to explain but I shall try my best. For about the past month now I have had 3 main real issues and no matter what I have tried so far nothing has worked:
 
Issue 1: Windows task will randomly switch or flash upon another application. To explain I could be on chrome and my desktop would flash up on screen, sometimes it will completely switch me across to the desktop. This happens very frequently. It also stops me from being able to select other applications on my task bar which are open. For example being on chrome and I am trying to open a already open word, it will not come to the top. 
 
Issue 2: I cannot select file of type: . When selecting say a file extension .png in the file of type box, when I click the arrow for all extensions the box closes as soon as it opens. This again happens with any program.
 
issue 3: I constantly have non responding programs but they only don't respond for usually under a second. It again is just a flashing not responding (I know the program is though), usually this happens 3-4 times a second the flashing not responding. This once again happens randomly, however I can get it to do it by trying to quickly select a file of type and managing too. It will then spam not responding along the top and the opaque white screen appears.
 
I would greatly appreciate any help offered. Here is a previous article on issue 1 but it did not solve it for me http://www.bleepingcomputer.com/forums/t/545088/active-windowprogram-switches-randomly-without-user-prompt-windows-81/

Edited by Queen-Evie, 16 August 2015 - 10:10 AM.
moved from Windows 8 to Am I Infected


BC AdBot (Login to Remove)

 


#2 dc3

dc3

    Bleeping Treehugger


  • Members
  • 30,365 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:09:19 PM

Posted 16 August 2015 - 08:58 AM

 
 
 
 
Please run sfc /scannow
 
The sfc /scannow command scans all protected system files and replaces corrupted and incorrect versions with correct Microsoft versions.
 
To run sfc /scannow in Windows 8 you will need to open the Elevated Command Prompt.  The easiest way to do this is to press the Windows key windowskey_zps092d5c75.png and the X key.   A menu will open with the option Command Prompt (Admin), click on this.
 
You will see a window similar to the one below.
 
command%20prompt%20w8_zpsxjmewau9.png
 
When the Elevated Command Prompt opens type in sfc /scannow (please note the space between sfc and /scannow), then press Enter.
 
If the scan finds no integrity  problems in the first portion of the scan it should stop, to be sure that the scan has stopped wait five minutes, then type in exit and press Enter to stop the scan.
 
If it does find integrity problems the scan will continue.  This will take a while, please have patience and allow it finish.  
 
When the scan is finished please post the log of this scan.
 
To find sfc /scannow log, reopen the Elevated Command Prompt using the Windows key windowskey_zps092d5c75.png and the X key method outlined in the instructions above. 
 
When the Elevated Command Prompt opens copy and paste the following in the Command Prompt, then press Enter.  
 
findstr /c:"[SR]" %windir%\logs\cbs\cbs.log >"%userprofile%\Desktop\sfcdetails.txt"
 
This will place a new icon on the desktop titled sfcdetails.  Click/tap on this to open the log, copy it and paste it in your topic.

Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 


#3 magictj

magictj
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:19 AM

Posted 16 August 2015 - 09:38 AM

Hi,

 

I did the sfc / scannow with the result: Windows Resource Protection did not find any integrity violations



#4 dc3

dc3

    Bleeping Treehugger


  • Members
  • 30,365 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:09:19 PM

Posted 16 August 2015 - 10:03 AM

Let's run some scans for viruses or malware.  These tools can not be used in the Windows forums, so this topic will be moved to the Am I Infected forum.  If nothing malicious is found it can be moved back to the Windows forum.

 

 
mbam1_zps95cc812c.png
 
Click on Update Now, after Malwarebytes is updated click on Scan.
 
If this isn't the first time you have run this version, then you will see an image like the one below.  Click on Scan
 
mbam1_zps98e7fba9.png
 
You will be prompted to update Malwarebytes, to do so click on Update Now.
 
 mbam2_zps85f38f0c.png
 
3)  The scan will automatically run now.
 
malwarerun_zps9abd4ef1.png
 
4)  When the scan is complete the results will be displayed.  Click on Delete All.
 
malwarenew_zps34b58fdc.png
 
5)  Please post the Malwarebytes log.
 
To find your Malwarebytes log,download mbam-check.exe from here and save it to your desktop.
 
To open the log double click on mbam-check.exe on your desktop.  Copy and paste the log in your topic.
 
================
 

 
Please run TDSSKiller.
 
Please download TDSSKiller from here and save it to your Desktop.
 
The log for the TDSSKiller can be very long.  If you go to the bottom of the log to where you find Scan finished you will see the results of the scan.  If it shows Detected object count: 0 and Actual detected object count: 0, this means that nothing malicious was found and you will not need to post the log.
 
1.  Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
 
tdss1_zps90132559.png
 
2.  Check Loaded Modules, Verify Driver Digital Signature, and Detect TDLFS file system.
 
If you are asked to reboot because an "Extended Monitoring Driver is required" please click Reboot now.
 
tdsskillermultiple_zps472c18eb.png
 
3.  Click Start Scan and allow the scan process to run.
 
tdss4_zps6792a13c.png
 
4.  If threats are detected select Cure (if available) for all of them unless otherwise instructed.
 
***Do NOT select Delete!
 
Click on Continue.
 
tdss5_zps98fc5887.png
 
5.  Click on Reboot computer.
 
Please copy the TDSSKiller.[Version]_[Date]_[Time]_log.txt file found in your root directory (typically c:\) and paste it into your next reply.
 
Note:  The log may be very long.  You may need to break it into parts to post the whole log.
 
==================
 

Please run AdwCleaner
 
Please download AdwCleaner and install it.
 
When AdwCleaner opens you will see an image like the one below.
 
adwcleaner11_zps48314883.png
 
Click on Scan to start the scan.
 
Once the search is complete a list of the pending items will be displayed.  If you see any which you do not want removed, remove the check mark next to it.  
 
Click on Clean to remove the selected items.  If you have any questions about any items in the list please copy and paste the list in your topic so we can review it.  
 
You will receive a message telling you that all programs will be closed so that the infections can be removed.  Click on OK.  The computer will be restarted to complete the cleaning process.
 
When the cleaning process is complete a log of what was removed will be presented.  Please copy and the paste this log in your topic.

Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 


#5 magictj

magictj
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:19 AM

Posted 16 August 2015 - 10:51 AM

Here is the malware log: 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 16/08/2015
Scan Time: 16:05
Logfile: malware.txt
Administrator: Yes
 
Version: 2.1.8.1057
Malware Database: v2015.08.16.01
Rootkit Database: v2015.08.06.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Thomas
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 395335
Time Elapsed: 25 min, 56 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
For the TDSSkiller there were no threats and so there is no log to post

The same goes for the adwcleaner 


 


#6 dc3

dc3

    Bleeping Treehugger


  • Members
  • 30,365 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:09:19 PM

Posted 16 August 2015 - 11:03 AM

I need to see the logs, not your assessment.
 
Emsisoft Emergency Kit
 
Please download Emsisoft Emergency Kit and save it to your desktop. Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop. Leave all settings as they are and click the Extract button at the bottom. A folder named EEK will be created in the root of the drive (usually c:\).
  • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
  • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates. Please click Yes so that it downloads the latest database updates.
  • When update is complete, click Malware Scan. When asked if you want the scanner to scan for Potentially Unwanted Programs, click Yes. Emsisoft Emergency Kit will start scanning.
  • When the scan is completed click Quarantine selected objects. Note:  This option is only available if malicious objects were detected during the scan.  If this is the case select Delete selected.
  • When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
  • Please save the log in Notepad on your desktop and post the contents in your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.

  • Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

     

     

     

     


    #7 magictj

    magictj
    • Topic Starter

    • Members
    • 6 posts
    • OFFLINE
    •  
    • Local time:05:19 AM

    Posted 16 August 2015 - 11:18 AM

    Here is the Emsisoft Emergency Kit report:
     

    Emsisoft Emergency Kit - Version 10.0
    Last update: 16/08/2015 17:11:27
    User account: TOM\Thomas
     
    Scan settings:
     
    Scan type: Malware Scan
    Objects: Rootkits, Memory, Traces, Files
     
    Detect PUPs: Off
    Scan archives: Off
    ADS Scan: On
    File extension filter: Off
    Advanced caching: On
    Direct disk access: Off
     
    Scan start: 16/08/2015 17:12:43
    Key: HKEY_USERS\S-1-5-21-918015090-3866727977-1607725896-1001\SOFTWARE\WEBAPP detected: Application.Toolbar (A)
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN detected: Setting.NoRun (A)
    Value: HKEY_USERS\S-1-5-21-918015090-3866727977-1607725896-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN detected: Setting.NoRun (A)
    Value: HKEY_USERS\S-1-5-21-918015090-3866727977-1607725896-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS detected: Setting.NoFolderOptions (A)
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS detected: Setting.NoFolderOptions (A)
     
    Scanned 75324
    Found 7
     
    Scan end: 16/08/2015 17:16:44
    Scan time: 0:04:01
     
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS Quarantined Setting.NoFolderOptions (A)
    Value: HKEY_USERS\S-1-5-21-918015090-3866727977-1607725896-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS Quarantined Setting.NoFolderOptions (A)
    Value: HKEY_USERS\S-1-5-21-918015090-3866727977-1607725896-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN Quarantined Setting.NoRun (A)
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN Quarantined Setting.NoRun (A)
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS Quarantined Setting.DisableRegistryTools (A)
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR Quarantined Setting.DisableTaskMgr (A)
    Key: HKEY_USERS\S-1-5-21-918015090-3866727977-1607725896-1001\SOFTWARE\WEBAPP Quarantined Application.Toolbar (A)
     
    Quarantined 7
     
     
    I am re-doing it right now to scan for PUP's. I do not know how to delete this post

    Edited by magictj, 16 August 2015 - 11:20 AM.


    #8 dc3

    dc3

      Bleeping Treehugger


    • Members
    • 30,365 posts
    • OFFLINE
    •  
    • Gender:Male
    • Location:Sierra Foothills of Northern Ca.
    • Local time:09:19 PM

    Posted 16 August 2015 - 11:28 AM

    You don't need to delete the post.


    Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

     

     

     

     


    #9 magictj

    magictj
    • Topic Starter

    • Members
    • 6 posts
    • OFFLINE
    •  
    • Local time:05:19 AM

    Posted 16 August 2015 - 01:01 PM

    Emsisoft Emergency Kit - Version 10.0
    Last update: 16/08/2015 17:11:27
    User account: TOM\Thomas
     
    Scan settings:
     
    Scan type: Custom Scan
    Objects: Rootkits, Memory, Traces, C:\, D:\
     
    Detect PUPs: On
    Scan archives: On
    ADS Scan: On
    File extension filter: Off
    Advanced caching: On
    Direct disk access: Off
     
    Scan start: 16/08/2015 17:24:32
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.dll.vir  detected: Gen:Variant.Adware.Crossrider.2 (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdate.exe.vir  detected: Adware.Agent.POG (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdateCrashHandler.exe.vir  detected: Adware.Agent.POG (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdateBroker.exe.vir  detected: Application.Win32.AdGoog (A)
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/232.js  detected: Adware.JS.Agent.AM (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdateOnDemand.exe.vir  detected: Application.Win32.AdGoog (A)
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/339.js  detected: Adware.JS.Crossrider.B (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/180.js  detected: Adware.JS.Crossrider.B (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll.vir  detected: Application.Win32.AdGoog (A)
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll.vir  detected: Application.Win32.AdGoog (A)
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/179.js  detected: Adware.JS.Agent.AN (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/200.js  detected: Adware.JS.Crossrider.B (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll.vir  detected: Application.Win32.AdGoog (A)
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/242.js  detected: Adware.JS.Agent.AM (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/231.js  detected: Adware.JS.Agent.AM (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\globalupdate.exe.vir  detected: Adware.Agent.POG (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/195.js  detected: Adware.Agent.PSO (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/252.js  detected: Adware.JS.Crossrider.E (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/263.js  detected: Adware.JS.Crossrider.B (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/380.js  detected: Adware.JS.Crossrider.B (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/262.js  detected: Adware.JS.Crossrider.B (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/223.js  detected: Adware.JS.Crossrider.B (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/184.js  detected: Adware.JS.Crossrider.B (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/102.js  detected: Adware.JS.Crossrider.B (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir -> extensionData/plugins/356.js  detected: Adware.Agent.PSO (B )
    C:\AdwCleaner\Quarantine\C\Users\Thomas\AppData\Roaming\nMt0wEGZsAeJ7aAmrBwjl7.vir -> background.js  detected: Adware.JS.Crossrider.D (B )
    C:\Users\Thomas\AppData\Local\Microsoft\Outlook\myemailhere.ost -> [Time: 2015/06/15 11:14:49][Subject: New Doc][From: Will Kinghan] -> New doc.doc  detected: Trojan.Doc.Downloader.CV (B )
    C:\Users\Thomas\AppData\Local\Microsoft\Outlook\myemailhere.ost -> [Time: 2015/07/28 09:31:48][Subject: Your Air France boarding documents on 3Aug][From: Air France] -> Boarding-documents.docm -> word/vbaProject.bin  detected: W97M.Downloader.VZ (B )
    C:\Users\Thomas\AppData\Local\Microsoft\Outlook\myemailhere.ost -> [Time: 2015/08/05 11:12:48][Subject: Booking Confirmation - Accumentia (16/9/15)][From: David Nyaruwa] -> Accumentia Booking (16-9-15).doc  detected: Trojan.Msword.NSD (B )
    C:\Users\Thomas\AppData\Local\Microsoft\Outlook\myemailhere.ost -> [Time: 2015/08/04 12:26:33][Subject: Need your attention: GH-0301/737599][From: Christie Branch] -> tom_OM_3768.doc -> (BASE64)  detected: w97m.Downloader.WT (B )
    C:\Users\Thomas\AppData\Local\Microsoft\Outlook\myemailhere.ost -> [Time: 2015/08/06 09:18:39][Subject: RE: Voice message from 07773403290][From: tel: 07773403290] -> message_01983527496.wav.zip -> message_01983527496.exe  detected: Trojan.GenericKD.2624009 (B )
    C:\Users\Thomas\AppData\Local\Microsoft\Outlook\myemailhere.ost -> [Time: 2015/08/10 09:34:45][Subject: Premium Charging MI Package for Merchant 17143013][From: GEMS@Worldpay.com] -> 17143013 01.docm  detected: Trojan.Doc.Agent.F (B )
    C:\Users\Thomas\AppData\Local\Microsoft\Outlook\myemailhere.ost -> [Time: 2015/08/12 09:22:00][Subject: Invoice for 415 Litmus][From: angela_lrc772631@btinternet.com] -> 415 Litmus Cleaning invoice.docm  detected: W97M.Downloader.XP (B )
    C:\Users\Thomas\AppData\Local\Microsoft\Outlook\myemailhere.ost -> [Time: 2015/08/14 10:26:16][Subject: Invoice][From: Roger Luke] -> 140238.XLS  detected: W97M.Downloader.XZ (B )
    C:\Users\Thomas\AppData\Roaming\Ocj7hAniWu8J -> background.js  detected: Adware.JS.Crossrider.D (B )
    C:\Users\Thomas\AppData\Roaming\UGB8XkqgphXVzmrHopGmCfax -> background.js  detected: Adware.JS.Crossrider.D (B )
     
    Scanned 475591
    Found 36
     
    Scan end: 16/08/2015 18:55:55
    Scan time: 1:31:23
     
    C:\Users\Thomas\AppData\Roaming\UGB8XkqgphXVzmrHopGmCfax Quarantined Adware.JS.Crossrider.D (B )
    C:\Users\Thomas\AppData\Roaming\Ocj7hAniWu8J Quarantined Adware.JS.Crossrider.D (B )
    C:\Users\Thomas\AppData\Local\Microsoft\Outlook\myemailhere.ost Quarantined W97M.Downloader.XZ (B )
    C:\AdwCleaner\Quarantine\C\Users\Thomas\AppData\Roaming\nMt0wEGZsAeJ7aAmrBwjl7.vir Quarantined Adware.JS.Crossrider.D (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\globalupdate.exe.vir Quarantined Adware.Agent.POG (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll.vir Quarantined Application.Win32.AdGoog (A)
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll.vir Quarantined Application.Win32.AdGoog (A)
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll.vir Quarantined Application.Win32.AdGoog (A)
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdateOnDemand.exe.vir Quarantined Application.Win32.AdGoog (A)
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdateCrashHandler.exe.vir Quarantined Adware.Agent.POG (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdateBroker.exe.vir Quarantined Application.Win32.AdGoog (A)
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdate.exe.vir Quarantined Adware.Agent.POG (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.dll.vir Quarantined Gen:Variant.Adware.Crossrider.2 (B )
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Cinema_Plus-1.2V07.07\8cfa3635-99f6-41ff-923a-57126dc7beae.crx.vir Quarantined Adware.JS.Crossrider.B (B )
     
    Quarantined 14
     
    Sorry it took so long, the scan was very thorough. Please note I replaced my email.ost with 'myemailhere' just for privacy, i hope that is alright.


    #10 dc3

    dc3

      Bleeping Treehugger


    • Members
    • 30,365 posts
    • OFFLINE
    •  
    • Gender:Male
    • Location:Sierra Foothills of Northern Ca.
    • Local time:09:19 PM

    Posted 16 August 2015 - 01:13 PM

    You have to do what you have to in order to protect yourself.

     

    Is the computer running any better?


    Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

     

     

     

     


    #11 magictj

    magictj
    • Topic Starter

    • Members
    • 6 posts
    • OFFLINE
    •  
    • Local time:05:19 AM

    Posted 16 August 2015 - 01:52 PM

    It is a bit, I can now select file types thank you. However the screens switching is still happening and the constant non responding is as well.






    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users