Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan:win32/dynamer!ac


  • This topic is locked This topic is locked
15 replies to this topic

#1 johnsev

johnsev

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:33 AM

Posted 21 March 2017 - 08:23 PM

Hello experts, I would like to ask for your help regarding this trojan, Just like any case I've searched from the internet. I scanned using windows defender and it detected Trojan:win32/dynamer!ac, i clicked Clean PC. after few hours it said your PC is protected, but when I look at the status it is still not removed. So again I scanned using WD, same situation. Then I searched google for possible solution. I came accross this website https://malwaretips.com/blogs/trojan-win32-dynamer-ac-removal/ I FOLLOWED EVERY STEP. then scanned again using WD. again it detected the dynamer. i checked the location it is in drive C/program files(x86)/HPGAMES. What I did was delete the entire HPGAMES folder. it did not solve the problem, and when I scanned again the trojan is in this location now. containerfile:D:\preload\install.wim
file:D:\preload\install.wim->(Image62978)\Program Files (x86)\HP Games\FATE The Cursed King\Fate-WT.exe->(EXEEmb)->(EXEEmb)
What should I do?
 
Thank you
 


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 39,531 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:33 PM

Posted 23 March 2017 - 07:27 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Please download Malwarebytes Anti-Malware from here
  • Right-click on the MBAM icon and select Run as administrator to run the tool.
  • Click Yes to accept any security warnings that may appear.
  • Once the MBAM dashboard opens, on the right detail pane click on the word "Current" under the Scan Status to update the tool database.
  • On the left menu pane click the Settings tab, and then select the Protection tab on the top.
  • Under the Scan Options, turn on the button Scan for rootkits.
  • Click the Scan tab on the right detail pane, select Threat Scan and click the Start Scan button
  • Note: The scan may take some time to finish, so please be patient.
  • If potential threats are detected, ensure to checkmark all the listed items, and click the Quarantine Selected button.
  • While still on the Scan tab, click the View Report button, and in the window that opens click the Export button, select Text file (*.txt), and save the log to your Desktop.
  • The log can also be viewed by clicking the log to select it, then clicking the View Report button.
Please post the log for my review.

Note: If asked to restart the computer, please do so immediately.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the LogFile button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleanerCx.txt (x is a number).
===

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
attachlogs.png

Attach the file.
Select the "Choose a File" navigate to the location of the File.
Click the file you wish to Attach.

Click the Add reply button.
===


Please post the logs.

Let me know what problems persists.
==============================

#3 johnsev

johnsev
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:33 AM

Posted 23 March 2017 - 06:25 PM

Hello Nasdaq, 

 

Thank you for your response, attached herewith are the reports of MBAM, ADWCLEANER, and FRST.

 

Thank you

Attached Files



#4 nasdaq

nasdaq

  • Malware Response Team
  • 39,531 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:33 PM

Posted 24 March 2017 - 07:36 AM

ATTENTION: System Restore is disabled
Check "winmgmt" service or repair WMI.


ATTENTION: System Restore is disabled
Turn your System Restore ON - Windows Help
https://support.microsoft.com/en-us/help/17228/windows-protect-my-pc-from-viruses

Let me know if this does not work.
===

Remove this program in bold via the Control Panel > Programs > Programs and Features.
MagniPic (HKLM\...\{D696A0D5-5603-40E3-A208-1E210D758223}) (Version: 1.0 - ) <==== ATTENTION

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to a new file.


Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:


HKLM-x32\...\Run: [] => [X]
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
CHR HKU\S-1-5-21-2379114402-190712098-819625162-1006\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
URLSearchHook: [S-1-5-21-2379114402-190712098-819625162-1001] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKU\S-1-5-21-2379114402-190712098-819625162-1006 -> DefaultScope {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
SearchScopes: HKU\S-1-5-21-2379114402-190712098-819625162-1006 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
Toolbar: HKU\S-1-5-21-2379114402-190712098-819625162-1006 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
CHR HomePage: Default -> hxxp://tuvaro.com/ws/?source=4c3f95e5&tbp=homepage&toolbarid=base&u=68eff43a0000000000006894230e1ae3
CHR StartupUrls: Default -> "hxxp://tuvaro.com/ws/?source=4c3f95e5&tbp=homepage&toolbarid=base&u=68eff43a0000000000006894230e1ae3","hxxp://us.yahoo.com?fr=fpc-comodo"
CHR Extension: (Chrome Web Store Payments) - C:\Users\JOHNKEANE\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-12]
CHR Extension: (Chrome Media Router) - C:\Users\JOHNKEANE\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08]
S3 dbx; system32\DRIVERS\dbx.sys [X]
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job =>  <==== ATTENTION
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job =>  <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [119]
AlternateDataStreams: C:\ProgramData\Temp:A1EDB939 [114]
AlternateDataStreams: C:\Users\JOHNKEANE\Desktop\20170206_155013.jpg:com.dropbox.attributes [168]

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

ADOBE SHOCKWARE is outdated.

Navigate to this page and follow the instructions and get the latest version.
https://www.adobe.com/shockwave/welcome/

=====
If still present remove this old version in bold via the Control Panel > Programs > Programs and Features.
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.9.149 - Adobe Systems, Inc.)
===

Please let me know what problem persists with this computer.

#5 johnsev

johnsev
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:33 AM

Posted 27 March 2017 - 01:24 AM

Hi 

 

1. I checked the settings and the check box for system restore is CHECKED.

2. I already deleted the magnipic app.

3. I attached the fixlog from Farbar.

4. About the Shockwave player, I'll just delete it because I cant find the update.

 

I can't scan using windows defender because it is turned off, and I can't turn it on.

Thank you.

Attached Files


Edited by johnsev, 27 March 2017 - 03:13 AM.


#6 nasdaq

nasdaq

  • Malware Response Team
  • 39,531 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:33 PM

Posted 27 March 2017 - 08:53 AM

Download Farbar's Service Scanner utility
http://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/
and Save to your Desktop.
If using Windows 7 or Vista, Right-Click on fss.exe and select Run As Administrator.
If using XP, double-click to start.
Answer Yes to ok when prompted.
If your firewall then puts out a prompt, again, allow it to run.
Once FSS is on-screen, be sure the following items are checkmarked:
Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update
Windows Defender


Click on "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.
Copy & Paste contents of FSS.txt into your reply.

#7 johnsev

johnsev
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:33 AM

Posted 27 March 2017 - 11:40 AM

Farbar Service Scanner Version: 27-01-2016
Ran by Joyce (administrator) on 28-03-2017 at 00:39:30
Running from "C:\Users\JOHNKEANE\Desktop"
Microsoft Windows 8.1  (X64)
Boot Mode: Normal
****************************************************************
 
Internet Services:
============
 
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
 
 
Windows Firewall:
=============
 
Firewall Disabled Policy: 
==================
 
 
System Restore:
============
 
System Restore Policy: 
========================
 
 
Action Center:
============
 
 
Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Demand. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.
 
 
Windows Autoupdate Disabled Policy: 
============================
 
 
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend: ""%ProgramFiles%\Windows Defender\MsMpEng.exe"".
 
 
Windows Defender Disabled Policy: 
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
 
 
Other Services:
==============
 
 
File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MsMpEng.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
 
 
**** End of log ****


#8 nasdaq

nasdaq

  • Malware Response Team
  • 39,531 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:33 PM

Posted 28 March 2017 - 07:18 AM

Please Download Tweaking.com - Windows Repair from Here

  • Install and then run the program
  • Execute the instructions on Step 1 Important
  • Click Next on Step 2 Optional, do the Pre Scan skip Step 3 and 4 Optional for now.
  • On Step 5 Backup System Restore Do a Registry backup. When you have completed this click Next
  • Click Repairs - Open Repairs in the bottom right corner
  • Uncheck the All repair button then select just the item(s) listed below

  • 01 - Repair Registry Permissions
    03 - Reset Service permissions
    05 - Repair WMI
    06 - Repair Windows Firewall
    10 - Remove Policies Set By Infections
    17 - Repair Windows Updates
    21 - Repair MSI (Windows Installer)
    26 - Restore Important Windows Services
    27 - Set Windows Service to Default Startup
    
  • Click the Start button and let the process run to completion. Copy any error messages into Notepad, Save it on your Desktop. ( Reboot if asked to do so)
  • Please copy and paste the Contents of this file on your next reply.

  • ===

    Restart the computer normally.

    How is the computer running now?


#9 johnsev

johnsev
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:33 AM

Posted 28 March 2017 - 06:41 PM

Log:
Tweaking.com - Windows Repair v3.9.27
────────────────────────────────────────────────────────────────────────────────
 
System Variables
────────────────────────────────────────────────────────────────────────────────
OS: Windows 8.1
OS Architecture: 64-bit
OS Version: 6.3.9600.18619
OS Service Pack: 
Computer Name: JAKE
Windows Drive: C:\
Windows Path: C:\WINDOWS
Program Files: C:\Program Files
Program Files (x86): C:\Program Files (x86)
Current Profile: C:\Users\Joyce
Current Profile SID: S-1-5-21-2379114402-190712098-819625162-1001
Current Profile Classes: S-1-5-21-2379114402-190712098-819625162-1001_Classes
Profiles Location: C:\Users
Profiles Location 2: C:\WINDOWS\ServiceProfiles
Local Settings AppData: C:\Users\Joyce\AppData\Local
────────────────────────────────────────────────────────────────────────────────
 
System Information
────────────────────────────────────────────────────────────────────────────────
System Up Time: 0 Days 00:10:51
 
Process Count: 84
Commit Total: 1.98 GB
Commit Limit: 8.64 GB
Commit Peak: 2.11 GB
Handle Count: 27488
Kernel Total: 412.65 MB
Kernel Paged: 334.30 MB
Kernel Non Paged: 78.35 MB
System Cache: 2.79 GB
Thread Count: 954
────────────────────────────────────────────────────────────────────────────────
 
Memory Before Cleaning with CleanMem
────────────────────────────────────────────────────────────────────────────────
Memory Total: 7.89 GB
Memory Used: 2.00 GB(25.3104%)
Memory Avail.: 5.89 GB
────────────────────────────────────────────────────────────────────────────────
 
Cleaning Memory Before Starting Repairs...
 
Memory After Cleaning with CleanMem
────────────────────────────────────────────────────────────────────────────────
Memory Total: 7.89 GB
Memory Used: 1.64 GB(20.7413%)
Memory Avail.: 6.25 GB
────────────────────────────────────────────────────────────────────────────────
 
Starting Repairs...
   Started at (3/29/2017 7:10:12 AM)
 
Setting Any Missing 'InstallDate' From Uninstall Sections Before Running Repair...
Total Missing 'InstallDate' Fixed: 0
 
01 - Reset Registry Permissions
   Restore Windows 7/8/10 Default Registry Permissions
   Start (3/29/2017 7:10:17 AM)
 
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\8.1\hku.7z
Done,  0.88 seconds.
 
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\8.1\hku.7z
Done,  0.8 seconds.
 
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\8.1\hklm.7z
Done,  6.83 seconds.
 
   Running Repair Under System Account
   Done (3/29/2017 7:15:45 AM)
 
03 - Reset Service Permissions
   Start (3/29/2017 7:15:45 AM)
 
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (3/29/2017 7:17:57 AM)
 
05 - Repair WMI
   Start (3/29/2017 7:17:57 AM)
 
   Starting Security Center So We Can Export The Security Info.
 
   Exporting Antivirus Info...
   Windows Defender Exported.
   Malwarebytes Exported.
 
   Exporting AntiSpyware Info...
   Malwarebytes Exported.
   Windows Defender Exported.
 
   Exporting 3rd Party Firewall Info...
   No Firewall Products Reported.
 
   Running Repair Under Current User Account
   Done (3/29/2017 7:28:49 AM)
 
06 - Repair Windows Firewall
   Start (3/29/2017 7:28:49 AM)
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\8.1\services.7z
Done,  0.22 seconds.
 
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (3/29/2017 7:29:25 AM)
 
10 - Remove Policies Set By Infections
   Start (3/29/2017 7:29:25 AM)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (3/29/2017 7:29:33 AM)
 
17 - Repair Windows Updates
   Start (3/29/2017 7:29:33 AM)
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\8.1\services.7z
Done,  0.23 seconds.
 
   Running Repair Under Current User Account
   Running Repair Under System Account
   Setting Windows Updates Files That Are In Use To Be Removed At Next Boot.
   Done (3/29/2017 7:30:09 AM)
 
26 - Restore Important Windows Services
   Start (3/29/2017 7:30:09 AM)
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\8.1\services.7z
Done,  0.22 seconds.
 
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (3/29/2017 7:30:23 AM)
 
27 - Set Windows Services To Default Startup
   Start (3/29/2017 7:30:23 AM)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (3/29/2017 7:31:51 AM)
 
Cleaning up empty logs...
 
All Selected Repairs Done.
   Done at (3/29/2017 7:31:51 AM)
   Total Repair Time: 00:21:43
 
 
...YOU MUST RESTART YOUR SYSTEM...
 
 
I can't see any signs that my computer has a virus except for the Windows Defender which detects the trojan win32ac. I can't check if the trojan is still in my computer because my WD is currently turned off.
 
Thank you

Attached Files



#10 nasdaq

nasdaq

  • Malware Response Team
  • 39,531 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:33 PM

Posted 29 March 2017 - 07:26 AM


Navigate to this Microsoft article.

https://www.microsoft.com/security/portal/threat/Encyclopedia/Entry.aspx?Name=Trojan:Win32/Dynamer!ac

Download and run the Windows Defender Offline.

Make sure that your computer his restarted after the Scan.

===

How is it now?

#11 johnsev

johnsev
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:33 AM

Posted 03 April 2017 - 02:35 AM

I did the instructions, but the Windows Defender offline wont launch.  I opened the files in my usb drive and can't manually launch any of the files in it. What should I do?

 

Thank you



#12 nasdaq

nasdaq

  • Malware Response Team
  • 39,531 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:33 PM

Posted 03 April 2017 - 07:34 AM


Have you tried the suggestions on this page?
http://www.tomsguide.com/faq/id-2375524/enable-windows-defender-windows-windows.html

Did you ever installed and then remove some 3rd party Security Anti-virus software?
===


Copy the text IN THE QUOTE BOX below to notepad. Save it as fixme.reg to your desktop.
Be sure the "Save as" type is set to "all files" Once you have saved Right click the .reg file and allow it to merge with the registry.

[quote]
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=-


Restart the computer when completed.

You can delete the fixme.reg file when done.


Is Windows Defender working?

#13 johnsev

johnsev
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:33 AM

Posted 06 April 2017 - 08:11 PM

windows defender is working. I tried windows defender offline, but I can't boot using the USB Flash Drive, after choosing the USB option during start up this message appears "the image did not authenticate". what should I do? Thank You



#14 nasdaq

nasdaq

  • Malware Response Team
  • 39,531 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:33 PM

Posted 07 April 2017 - 09:02 AM

As this is a HP computer you may find your solution in this article.

https://appuals.com/selected-boot-image-did-not-authenticate/

I suggest you look at Method 1: Change from secure boot to legacy boot in your BIOS settings

DO NOT DOWNLOAD OR RUN THE Reimage plus program.
Read about it.
http://forums.anvisoft.com/viewtopic-66-27572-0.html

You may just want to look at your settings before proceeding.

===

The instructions on Method 1 may be good. However I do not have the expertise to advise you to proceed.

If you really need to start Windows Defender from the USB I suggest you ask the Experts in the Internal Hardware Forum if the instructions are good or not for your need.

https://www.bleepingcomputer.com/forums/f/7/internal-hardware/

Edited by nasdaq, 07 April 2017 - 09:02 AM.


#15 johnsev

johnsev
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:10:33 AM

Posted 07 April 2017 - 10:41 AM

would you suggest that I reformat my laptop? will my external hard drive get virus if I connect it to my laptop to get my important files then reformat it? thanks






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users