Author Topic: W7 PC Infected ? FarBar Attached  (Read 6601 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
W7 PC Infected ? FarBar Attached
« on: July 15, 2016, 11:09:22 PM »
My daughter has old DELL Inspiron PC.....Celeron 2Ghz.....which she doesn't use much since she has new MAC.
I however keep it updated and runs Avast, MBAM & MBAE.
I "think" my young son got on it and was on Web where he shouldn't be.  >:(
MBAM is clear & ran Adwcleaner and BOTH clean.
However Avast take HOURS & HOURS to run and while system is not fastest it is almost unusably slow.
I keep Defrag run once a week and not much running....latest O/S updates.

Anyway, ran Farbar.....attached......can expert take look and see if something jumps out ?

Thx !

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: W7 PC Infected ? FarBar Attached
« Reply #1 on: July 15, 2016, 11:11:16 PM »
Logs didn't make it?  Can you try again?
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: W7 PC Infected ? FarBar Attached
« Reply #2 on: July 15, 2016, 11:17:29 PM »
Logs didn't make it?  Can you try again?

This is how bad it is......I was posting this thread while running FRST and figuring the logs would be ready.
It is STILL running.....making progress...but still running....going on 20 minutes.
I'll post logs when done....ugh.  :(

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: W7 PC Infected ? FarBar Attached
« Reply #3 on: July 15, 2016, 11:19:21 PM »
No rush on my account!
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: W7 PC Infected ? FarBar Attached
« Reply #4 on: July 15, 2016, 11:39:30 PM »
Took for flippin EVER but here they are......thx !!!

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: W7 PC Infected ? FarBar Attached
« Reply #5 on: July 16, 2016, 03:29:48 AM »


FIRST >>>>

Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed):

QuickTime 7
Tabula Digita DimensionMâ„¢ Single Player Mission 1.0.6.0


To do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window. 

Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software.


SECOND >>>>

Open notepad by pressing the Windows Key + R Key, typing in Notepad in the Run dialog and then pressing Enter.  Please copy the contents of the Code box below.  To do this highlight the contents of the box by clicking [Select] next to Code: , then right click on any of the highlighted text and select copy.  Paste this into the open notepad. Save it to your desktop as fixlist.txt
 
Code: [Select]

Start
CreateRestorePoint:
CloseProcesses:
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
C:\Program Files (x86)\QuickTime
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3869557245-3801628309-1913999693-1002 -> {3557D455-8897-4C02-B9C0-FFC8D4D4AC5D} URL =
SearchScopes: HKU\S-1-5-21-3869557245-3801628309-1913999693-1002 -> {88B7D999-F143-400F-B243-04A1BBEBBCC4} URL =
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
CHR Extension: (Google Drive) - C:\Users\Ashley K\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-28]
CHR Extension: (Google Search) - C:\Users\Ashley K\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-28]
CHR Extension: (Google Wallet) - C:\Users\Ashley K\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-28]
S2 ShieldClientService; C:\Program Files (x86)\Shield\shieldclnt.exe [X]
C:\Program Files (x86)\Shield\shieldclnt.exe
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
C:\Windows\system32\DRIVERS\Rts516xIR.sys
C:\Windows\system32\DRIVERS\RtsUCcid.sys
File: C:\Windows\system32\html.iec
C:\Users\Ashley K\AppData\Local\Temp\Quarantine.exe
cmd: ipconfig /flushdns
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state on
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
CMD: bitsadmin /reset /allusers
RemoveProxy:
EmptyTemp:
Reboot:
end

NOTE. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST64 by right clicking on the FRST64.exe file, selecting "Run as Administrator..".  The User Account Control may open up; if it does, select Yes to continue to let FRST open and load. 

The tool will check for an updated version of itself every time it loads; please allow it to do this and the program will either inform you it is downloading an updated copy (and to wait until it is safe to continue) or show nothing (meaning there is no update found) and you can continue on.  Press the Fix button just once and wait.  The tool will create a restore point, process the script and ask for a restart of your system.



If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.

When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply post.  Also, tell me how your system is running now.


THIRD >>>>

It looks like the Windows Search service is having problems.  See if any of the help in this article fixes the issue.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: W7 PC Infected ? FarBar Attached
« Reply #6 on: July 16, 2016, 04:35:28 PM »
Here is FIXLOG.
Seems to run quicker but have not put thru paces yet....having to run out for the day....but wanted to post.
I also ran FRST64 again and posted log for you to see....which this time took ~10 minutes instead of HOURS.  ;D

I'll have to look into Windows Search.....but note, I do disable the Indexing function on a lot of these older PCs....too slow and too much thrashing.....would rather the search be longer for few times used.  Would that be what you saw ?
« Last Edit: July 16, 2016, 05:17:28 PM by thekochs »

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: W7 PC Infected ? FarBar Attached
« Reply #7 on: July 16, 2016, 08:20:36 PM »
If you look towards the end of the Addition.txt log file, you will see some of the current errors in the Windows Events logs.  Windows Search Service is 'complaining' about the indexing (makes sense now that I know you turned Indexing off).  I was just trying to suggest that if that was turned off (or the index /  corruption fixed) it may result in a lessening of the CPU usage.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: W7 PC Infected ? FarBar Attached
« Reply #8 on: July 17, 2016, 02:36:47 AM »
It runs faster.....thx.....but won't download the Windows updates.....just scrolls with "download" forever.
I will look into the Windows Search to see if that makes any difference.
Any ideas let me know.
« Last Edit: July 17, 2016, 05:11:10 AM by thekochs »

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: W7 PC Infected ? FarBar Attached
« Reply #10 on: July 17, 2016, 03:54:29 PM »
Well Windows Search did not help.
So, I've started to uninstall all old crud programs and also Avast 9.
I'm going to use this machine as test bench for new Avast version.
I loaded and runs quicker....think I need to defrag too.
I'll use the BULK Windows update link you gave me but first a FULL SYSTEM SCAN with Avast......something just seems wrong besides what is appearing as SLOW.....get the feeling still have some virus/malware/etc. lurking about.

I'll post another FRST log when I make some progress.

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: W7 PC Infected ? FarBar Attached
« Reply #11 on: July 17, 2016, 09:29:26 PM »
Another tool for the update problem is WinUpdateFix 1.3 by xPlode ( available here ).

Note that most of the tools we use to remove malware are not virus removal tools since once the binary code of an executable is changed it is very hard to repair the file.  Just an FYI ....
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: W7 PC Infected ? FarBar Attached
« Reply #12 on: July 18, 2016, 03:02:52 PM »
I've decided to do an in-place upgrade to see how that does.
This PC, while W7, is fairly old and my daughter used, and son......so just ordinary CRUD it probably over years has accumulated.
I'm deleting all non-needed programs.....going to bare mins, in-place upgrade, delete all TEMPS/PRE-FETCHES, do CCleaner on Reg, Defrag, etc.
We will see how that works. :)

REDACTED

  • Guest
Re: W7 PC Infected ? FarBar Attached
« Reply #13 on: July 18, 2016, 03:33:08 PM »
Another tool for the update problem is WinUpdateFix 1.3 by xPlode ( available here ).

Note that most of the tools we use to remove malware are not virus removal tools since once the binary code of an executable is changed it is very hard to repair the file.  Just an FYI ....

It appears this is not in English and also not sure how to use.....can you let me know ?
PC is better (faster) but Windows Update still mucked up.
I used this one in this thread and it ran to completion...I put in aggressive mode.
http://answers.microsoft.com/en-us/windows/forum/windows_vista-update/a-one-click-fix-for-windows-update-problems-how-do/bfbdec70-e928-47ee-b073-665c4851bf4c?auth=1
I am now running MBAM Full San and will run Avast FULL after.

I'll post a FARBAR log too when I can get that far.
« Last Edit: July 18, 2016, 05:45:35 PM by thekochs »

REDACTED

  • Guest
Re: W7 PC Infected ? FarBar Attached
« Reply #14 on: July 18, 2016, 07:08:49 PM »
MBAM FULL  run & clean.
Will run FULL Avast next but wanted to post FARBAR for review in mean time....let me know.  Thx !!!