Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help with weird items in startup / task manager


  • Please log in to reply
14 replies to this topic

#1 jneez

jneez

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:31 AM

Posted 06 May 2017 - 03:02 PM

Had some malware issued that have been resolved AFAIK...but saw this in my startup, namely the two "-" and one "program" that i've disbaled. How do I locate/findotu what these are. Thank you.

 

It wont let me insert image. Link here: http://imgur.com/a/oALfX

Thank you in advance



BC AdBot (Login to Remove)

 


#2 DannyBoyRP

DannyBoyRP

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:11:31 AM

Posted 06 May 2017 - 03:24 PM

I got you homie 

 

38qrUZ55T.png

38rIJrmmn.png



#3 jneez

jneez
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:31 AM

Posted 06 May 2017 - 03:26 PM

Thanks that worked...but now I have this: http://imgur.com/a/U5XdR

 

How do i remove those?



#4 DannyBoyRP

DannyBoyRP

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:11:31 AM

Posted 06 May 2017 - 03:32 PM

I assume they are just leftovers registered into your startup, that means that their source is deleted and the startup items are no longer effective besides just being written down on your startup list just like in a shopping list 

But thats just my opinion.

 

And If the path under the "Program" is a software youre not familiar with, you should give it a visit and see whats the folder contain and do a research of some of the files within.

 

I'd still recommend checking what the Advisor has to say but they dont seem to be around as much



#5 buddy215

buddy215

  • Moderator
  • 13,130 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:03:31 AM

Posted 06 May 2017 - 03:34 PM

Welcome to BC....

 

You can submit the content of those files to VirusTotal - Free Online Virus and Malware Scan to be scanned by numerous security programs.

Use the programs below to clean and removing adware and malware.

 

Use CCleaner to remove Temporary files, program caches, cookies, logs, etc. Use the Default settings. No need to use the

Registry Cleaning Tool...risky. Pay close attention while installing and UNcheck offers of toolbars....especially Google.

After install, open CCleaner and run by clicking on the Run Cleaner button in the bottom right corner.

CCleaner - PC Optimization and Cleaning - Free Download

 

Download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  • download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message

Edited by buddy215, 06 May 2017 - 03:36 PM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#6 jneez

jneez
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:31 AM

Posted 06 May 2017 - 04:25 PM

# AdwCleaner v6.046 - Logfile created 06/05/2017 at 16:40:24
# Updated on 24/04/2017 by Malwarebytes
# Database : 2017-05-05.1 [Server]
# Operating System : Windows 10 Pro  (X64)
# Username : Jneezy - DESKTOP-2F0S065
# Running from : C:\Users\Jneezy\Downloads\adwcleaner_6.046.exe
# Mode: Clean
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
[-] Folder deleted: C:\Users\Jneezy\AppData\Local\AdvinstAnalytics
[-] Folder deleted: C:\Users\Jneezy\AppData\Roaming\Microleaves
[-] Folder deleted: C:\Windows\SysWOW64\SSL
 
 
***** [ Files ] *****
 
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKLM\SOFTWARE\Microleaves
[-] Value deleted: HKU\S-1-5-21-347968258-2215609881-26927009-1001\Software\Microsoft\Windows\CurrentVersion\Run [Itibiti.exe]
[-] Value deleted: HKU\S-1-5-21-347968258-2215609881-26927009-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Itibiti.exe]
[#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Itibiti.exe]
[#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Itibiti.exe]
[-] Value deleted: HKU\S-1-5-21-347968258-2215609881-26927009-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Interstatnogui]
 
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Jneezy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Jneezy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [1837 Bytes] - [06/05/2017 16:40:24]
C:\AdwCleaner\AdwCleaner[S0].txt - [2033 Bytes] - [06/05/2017 16:38:55]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1983 Bytes] ##########
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 10 Pro x64 
Ran by Jneezy (Administrator) on Sat 05/06/2017 at 17:11:17.02
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 1 
 
Successfully deleted: C:\Users\Jneezy\AppData\Roaming\Mozilla\Firefox\Profiles\xShqkDmb.default\extensions\trash (Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 05/06/2017 at 17:13:14.24
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#7 jneez

jneez
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:31 AM

Posted 06 May 2017 - 04:28 PM

"program" is now gone.

 

the two "-" are still there.



#8 buddy215

buddy215

  • Moderator
  • 13,130 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:03:31 AM

Posted 06 May 2017 - 04:34 PM

Post the three lists mentioned below using CCleaner.

Open CCleaner and click on Tools. Choose Startups. On that page you will see a list of Windows Startups and at the top tabs for each browser and Scheduled Tasks.

At the bottom right of that page you will see a button when clicked will allow you to Copy and Paste the list of Windows Startups and Scheduled Tasks into your next

post. Please do that.

 

Open CCleaner and click on Tools. Choose Uninstall. On that page you will see a list of programs installed on your computer and at the bottom right of that page you

will see a button when clicked will allow you to Copy and Paste that list in your next post. Please do that.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#9 jneez

jneez
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:31 AM

Posted 06 May 2017 - 04:44 PM

Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
No HKCU:Run OneDrive Microsoft Corporation "C:\Users\Jneezy\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
Yes HKCU:Run Skype Skype Technologies S.A. "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
Yes HKCU:Run SUPERAntiSpyware SUPERAntiSpyware C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
No HKCU:Run Windows Defender -
Yes HKLM:Run avgnt Avira Operations GmbH & Co. KG "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
Yes HKLM:Run Avira SystrayStartTrigger Avira Operations GmbH & Co. KG "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
Yes HKLM:Run Malwarebytes TrayApp Malwarebytes C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
Yes HKLM:Run MSIRegister Micro-Star INT'L CO., LTD. "C:\MSI\MSIRegister\MSIRegister.exe"
Yes HKLM:Run Nahimic2UILauncher A-Volute C:\Program Files\Nahimic\Nahimic2\UserInterface\Nahimic2UILauncher.exe /noUI
No HKLM:Run Razer Synapse Razer Inc. "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
Yes HKLM:Run RTHDVCPL Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
No HKLM:Run WindowsDefender -
Yes Startup Common Killer Network Manager.lnk Rivet Networks C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe
 
Yes Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Yes Task GIGABYTE OC GURU "C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe"
Yes Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
Yes Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Yes Task OneDrive Standalone Update Task v2 Microsoft Corporation %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Yes Task SamsungMagician Samsung Electronics. "C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe" /AUTOHIDE
 
3D Builder Microsoft Corporation 4/18/2017 14.0.1031.0
Alarms & Clock Microsoft Corporation 4/27/2017 10.1704.1013.0
App Installer Microsoft Corporation 2/18/2017 1.0.10332.0
Avira Antivirus Avira Operations GmbH & Co. KG 5/6/2017 642 MB 15.0.26.48
Avira Connect Avira Operations GmbH & Co. KG 5/6/2017 17.0 MB 1.2.83.46341
Calculator Microsoft Corporation 3/14/2017 10.1703.601.0
Camera Microsoft Corporation 3/28/2017 2017.214.20.0
CCleaner Piriform 5/6/2017 19.0 MB 5.29
Drawboard PDF Drawboard 4/16/2017 5.1.60.0
Facebook Facebook Inc 4/8/2017 81.832.151.0
Feedback Hub Microsoft Corporation 4/21/2017 1.1703.971.0
Get Office Microsoft Corporation 4/18/2017 17.8107.7600.0
Google Chrome Google Inc. 5/6/2017 58.0.3029.96
Groove Music Microsoft Corporation 4/27/2017 10.17032.10331.0
Intel® Management Engine Components Intel Corporation 1/8/2017 11.0.6.1194
Intel® Serial IO Intel Corporation 1/8/2017 30.63.1519.7
Intel® Security Assist Intel Corporation 1/8/2017 2.50 MB 1.0.1.620
Killer Performance Suite Rivet Networks 1/8/2017 1.1.57.1125
Mail and Calendar Microsoft Corporation 5/3/2017 17.8126.42377.0
Malwarebytes version 3.0.6.1469 Malwarebytes 5/5/2017 127 MB 3.0.6.1469
Maps Microsoft Corporation 3/29/2017 5.1703.762.0
Messaging Microsoft Corporation 1/6/2017 3.19.1001.0
Microsoft OneDrive Microsoft Corporation 3/15/2017 84.8 MB 17.3.6798.0207
Microsoft Solitaire Collection Microsoft Studios 4/8/2017 3.16.3302.0
Microsoft Sticky Notes Microsoft Corporation 4/8/2017 1.8.0.0
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 1/8/2017 1.04 MB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 1/8/2017 876 KB 9.0.30729.6161
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 1/9/2017 20.5 MB 11.0.61030.0
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 Microsoft Corporation 1/6/2017 20.5 MB 12.0.21005.1
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 Microsoft Corporation 1/6/2017 17.1 MB 12.0.21005.1
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 Microsoft Corporation 1/8/2017 22.5 MB 14.0.23506.0
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 Microsoft Corporation 3/2/2017 19.5 MB 14.0.24215.1
Minecraft: Windows 10 Edition Microsoft Studios 5/5/2017 1.0.801.0
Movies & TV Microsoft Corporation 5/6/2017 10.17032.10341.0
Mozilla Firefox 53.0.2 (x86 en-US) Mozilla 5/6/2017 88.3 MB 53.0.2
Mozilla Maintenance Service Mozilla 4/26/2017 257 KB 53.0
MSI Afterburner 4.3.0 MSI Co., LTD 1/8/2017 4.3.0
Nahimic 2 Nahimic 1/8/2017 65.4 MB 2.2.11
News Microsoft Corporation 4/22/2017 4.20.1102.0
NVIDIA 3D Vision Controller Driver 369.04 NVIDIA Corporation 1/7/2017 8.58 MB 369.04
NVIDIA 3D Vision Driver 376.53 NVIDIA Corporation 2/8/2017 30.6 MB 376.53
NVIDIA GeForce Experience 3.5.0.76 NVIDIA Corporation 5/5/2017 2.56 MB 3.5.0.76
NVIDIA Graphics Driver 376.53 NVIDIA Corporation 2/8/2017 565 MB 376.53
NVIDIA HD Audio Driver 1.3.34.17 NVIDIA Corporation 2/8/2017 8.89 MB 1.3.34.17
NVIDIA PhysX System Software 9.16.0318 NVIDIA Corporation 1/7/2017 406 MB 9.16.0318
OneNote Microsoft Corporation 5/6/2017 17.8067.57781.0
Online Application 1/5/2017
Paid Wi-Fi & Cellular Microsoft Corporation 1/6/2017 1.1607.6.0
People Microsoft Corporation 4/7/2017 10.2.831.0
Photos Microsoft Corporation 5/5/2017 17.425.10010.0
qBittorrent 3.3.10 The qBittorrent project 1/8/2017 93.4 MB 3.3.10
Razer Synapse Razer Inc. 1/5/2017 30.2 MB 2.20.15.1104
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 1/8/2017 45.6 MB 6.0.1.7855
Revo Uninstaller Pro 3.1.8 VS Revo Group, Ltd. 5/6/2017 39.9 MB 3.1.8
RivaTuner Statistics Server 6.5.0 Unwinder 1/8/2017 6.5.0
Royal Revolt 2 flaregames GmbH 5/4/2017 3.2.0.0
Skype Skype 5/1/2017 11.14.675.0
Skype™ 7.34 Skype Technologies S.A. 5/5/2017 172 MB 7.34.103
Store Microsoft Corporation 4/5/2017 11701.1001.99.0
Store Purchase App Microsoft Corporation 1/6/2017 11608.1000.2431.0
SUPERAntiSpyware SUPERAntiSpyware.com 4/13/2017 10.4 MB 6.0.1232
TAP-Windows 9.21.2 1/6/2017 9.21.2
Tips Microsoft Corporation 4/3/2017 5.0.13.0
Twitter Twitter Inc. 5/3/2017 5.7.1.0
Voice Recorder Microsoft Corporation 4/25/2017 10.1704.952.0
Vulkan Run Time Libraries 1.0.26.0 LunarG, Inc. 2/8/2017 1.66 MB 1.0.26.0
Weather Microsoft Corporation 4/22/2017 4.20.1102.0
WinRAR 5.40 (64-bit) win.rar GmbH 1/8/2017 5.73 MB 5.40.0
Xbox Microsoft Corporation 5/2/2017 28.28.28008.0
Xbox Identity Provider Microsoft Corporation 1/6/2017 11.19.19003.0
 


#10 buddy215

buddy215

  • Moderator
  • 13,130 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:03:31 AM

Posted 06 May 2017 - 05:07 PM

download MiniToolBox and run it.

Checkmark following boxes:

  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List Devices (do NOT change any settings here)
  • List Users, Partitions and Memory size
  • Click Go and post the result.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#11 jneez

jneez
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:31 AM

Posted 06 May 2017 - 05:09 PM

MiniToolBox by Farbar  Version: 17-06-2016
Ran by Jneezy (administrator) on 06-05-2017 at 18:08:44
Running from "C:\Users\Jneezy\Downloads"
Microsoft Windows 10 Pro  (X64)
Model: MS-7977 Manufacturer: MSI
Boot Mode: Normal
***************************************************************************
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
========================= FF Proxy Settings: ============================== 
 
========================= Hosts content: =================================
 
========================= Devices: ================================
 
Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Device ID: ACPI\PNP0303\0
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: Microsoft PS/2 Mouse
Description: Microsoft PS/2 Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Device ID: ACPI\PNP0F03\0
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
========================= Memory info: ===================================
 
Percentage of memory in use: 16%
Total physical RAM: 16343.69 MB
Available physical RAM: 13617.04 MB
Total Virtual: 32727.69 MB
Available Virtual: 29682.71 MB
 
========================= Partitions: =====================================
 
1 Drive c: () (Fixed) (Total:465.27 GB) (Free:197.78 GB) NTFS
2 Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
3 Drive e: () (Fixed) (Total:279.36 GB) (Free:26.53 GB) NTFS
5 Drive g: (HP) (Fixed) (Total:580.44 GB) (Free:92.01 GB) NTFS
6 Drive h: (FACTORY_IMAGE) (Fixed) (Total:15.73 GB) (Free:2.22 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\DESKTOP-2F0S065
 
Administrator            DefaultAccount           defaultuser0             
Guest                    Jneezy                   
 
 
**** End of log ****


#12 buddy215

buddy215

  • Moderator
  • 13,130 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:03:31 AM

Posted 06 May 2017 - 05:32 PM

Are you able to find those two items on the computer? If so...try to have them scanned at VirusTotal - Free Online Virus and Malware Scan


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#13 jneez

jneez
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:31 AM

Posted 06 May 2017 - 05:33 PM

I am not sure how to find them? There is no command line path. Please see the 2nd image I linked.



#14 buddy215

buddy215

  • Moderator
  • 13,130 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:03:31 AM

Posted 06 May 2017 - 05:36 PM

I think they are just leftovers but I think you would feel better about if you start a new topic in the Malware Removal forum.

 

Please follow the instructions in the Malware Removal and Log Section Preparation Guide starting at Step 6.

  • If you cannot complete a step, then skip it and continue with the next.
  • In Step 6 there are instructions for downloading and running FRST which will create two logs.

When you have done that, post your logs in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team.

Start a new topic, give it a relevant title and post your log(s) along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. If you cannot produce any of the required logs...start the new topic anyway. Explain that you followed the Prep. Guide, were unable to create the logs, and describe what happened when you tried to create them. A member of the Malware Removal Team will walk you through, step by step, on how to clean your computer.

After doing this, please reply back in this thread with a link to the new topic so we can close this one.

 

DO NOT bump your new topic. Wait for a response from one of the Team Members.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#15 jneez

jneez
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:31 AM

Posted 07 May 2017 - 03:04 AM

I think the two "-" are windows defender. But windows defender is turned off by security policy?






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users