How to get rid of this nasty virus?

January 21, 2016 at 11:11:28
Specs: Windows 7
Virus blocking all virus scans and also wont let me log on windows. I have to open task manager and end a strange looking process and then the black screen disapears and shows my desktop.

Ive tried many free scanners they all seem to stop scanning at a certain point.
Also Avira wont even install.


See More: How to get rid of this nasty virus?

Report •


#1
January 21, 2016 at 11:11:50
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 6:09:29 PM, on 21-Jan-16
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)

FIREFOX: 43.0.3 (x86 en-GB)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Company\gupdate\gupdate.exe
E:\Steam\Steam.exe
E:\Steam\bin\steamwebhelper.exe
C:\Users\JK\AppData\Local\Google\Chrome\User Data\SwReporter\5.39.1\software_reporter_tool.exe
C:\Users\JK\AppData\Local\Google\Chrome\User Data\SwReporter\5.39.1\software_reporter_tool.exe
C:\Users\JK\AppData\Local\Google\Chrome\User Data\SwReporter\5.39.1\software_reporter_tool.exe
C:\Users\JK\AppData\Local\Google\Chrome\User Data\SwReporter\5.39.1\software_reporter_tool.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\JK\AppData\Local\Google\Chrome\User Data\SwReporter\5.39.1\software_reporter_tool.exe
C:\Users\JK\AppData\Local\Google\Chrome\User Data\SwReporter\5.39.1\software_reporter_tool.exe
C:\Users\JK\AppData\Local\Google\Chrome\User Data\SwReporter\5.39.1\software_reporter_tool.exe
E:\Steam\GameOverlayUI.exe
C:\Users\JK\AppData\Local\Google\Chrome\User Data\SwReporter\5.39.1\software_reporter_tool.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\JK\AppData\Local\Google\Chrome\User Data\SwReporter\5.39.1\software_reporter_tool.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
E:\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?L...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?L...
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [gupdate] C:\Program Files (x86)\Company\gupdate\gupdate.exe
O4 - HKCU\..\Run: [Steam] "E:\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [uTorrent] "C:\Users\JK\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.hola.org
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ApplicationHosting - Unknown owner - C:\ProgramData\\ApplicationHosting\\ApplicationHosting.exe
O23 - Service: AppthgildeM - Unknown owner - C:\ProgramData\\AppthgildeM\\AppthgildeM.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Hola Better Internet Engine (hola_svc) - Hola Networks Ltd. - C:\Program Files\Hola\app\hola_svc.exe
O23 - Service: Hola Better Internet Updater (hola_updater) - Hola Networks Ltd. - C:\Program Files\Hola\app\hola_updater.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - E:\Origin\OriginClientService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8420 bytes


Report •

#2
January 21, 2016 at 12:02:30
HJT is too old to be of value - it also reports missing files because it is not up to date on current locations. Do NOT delete anything it reports. Run these three freebies in the order given:

AdwCleaner:
http://www.bleepingcomputer.com/dow...
(blue Download button near top - not anything else on the page).
Download and "Save" the file somewhere. Go to the saved file then double click it to run the program. Use the "Scan" button, followed by the "Cleaning" button.

Junkware Removal Tool (JRT)
http://www.bleepingcomputer.com/dow...
(blue Download button near top - not anything else on the page).
Download and "Save" the file somewhere. Go to the saved file then double click it to run JRT. It might appear to have stopped at times or flash the screen but sit tight until it has finished.

MalwareBytes:
https://www.malwarebytes.org/
Download the free version.
Install and Run the program but before doing its Scan go to "Settings > Detection and Protection" and put a checkmark in "Scan for rootkits". Quarantine anything it finds.

Please copy/paste the logs on here.

Always pop back and let us know the outcome - thanks


Report •

#3
January 21, 2016 at 12:04:17
ok! Thanks! will give it a run and report back.

Report •

Related Solutions

#4
January 21, 2016 at 12:24:59
Hey just realised it was fake windows malware.

I had a message in my bottom right corner saying "this copy of windows is not genuine."
adwCleaner got rid of it straight away. I ran malwarebytes and its found something called "pendis"

No problems here now.

Heres the log.

Malwarebytes Anti-Malware
www.malwarebytes.org


Protection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Malware Protection, Starting,
Protection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Malware Protection, Started,
Protection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Starting,
Protection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Started,
Update, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Manual, Rootkit Database, 2015.9.18.1, 2016.1.20.1,
Detection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Malware Protection, File, PUP.Optional.Hicosmea, C:\Users\JK\AppData\Roaming\pendis\unments.dll, Quarantine, [f1fc77bbd6b5b87e14cd713e4bb602fe]
Update, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Manual, IP Database, 2015.9.21.2, 2016.1.19.1,
Update, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Manual, Remediation Database, 2015.9.16.1, 2016.1.18.1,
Update, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Manual, Domain Database, 2015.9.22.3, 2016.1.21.3,
Update, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Manual, Malware Database, 2015.9.22.5, 2016.1.21.4,
Protection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Refresh, Starting,
Protection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Stopping,
Protection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Stopped,
Protection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Refresh, Success,
Protection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Starting,
Protection, 21-Jan-16 5:14 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Started,
Detection, 21-Jan-16 5:17 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 198.57.247.191, 64792, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Detection, 21-Jan-16 5:17 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 198.57.247.191, 64792, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Detection, 21-Jan-16 5:25 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 188.138.101.90, 49365, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Detection, 21-Jan-16 5:25 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 188.138.101.90, 49365, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Detection, 21-Jan-16 5:33 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 188.138.101.90, 50115, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Detection, 21-Jan-16 5:42 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 188.138.101.90, 50876, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Update, 21-Jan-16 5:45 PM, SYSTEM, JK-PC, Scheduler, Domain Database, 2016.1.21.3, 2016.1.21.4,
Protection, 21-Jan-16 5:45 PM, SYSTEM, JK-PC, Protection, Refresh, Starting,
Protection, 21-Jan-16 5:45 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Stopping,
Protection, 21-Jan-16 5:45 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Stopped,
Protection, 21-Jan-16 5:45 PM, SYSTEM, JK-PC, Protection, Refresh, Success,
Protection, 21-Jan-16 5:45 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Starting,
Protection, 21-Jan-16 5:45 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Started,
Detection, 21-Jan-16 5:57 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 188.138.101.90, 52615, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Detection, 21-Jan-16 5:57 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 188.138.101.90, 52615, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Detection, 21-Jan-16 6:02 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 188.138.101.90, 53193, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Detection, 21-Jan-16 6:02 PM, JK, JK-PC, Protection, Malware Protection, File, PUP.Optional.Hicosmea, C:\Users\JK\AppData\Roaming\pendis\presgen.dll, Quarantine Failed, 5, Access is denied. , [54f498a4633651e5f4661811c53c24dc]
Detection, 21-Jan-16 6:07 PM, JK, JK-PC, Protection, Malware Protection, File, PUP.Optional.Hicosmea, C:\Users\JK\AppData\Roaming\pendis\presgen.dll, Quarantine Failed, 5, Access is denied. , [54f498a4633651e5f4661811c53c24dc]
Detection, 21-Jan-16 6:09 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 188.138.101.90, 54505, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Protection, 21-Jan-16 7:10 PM, SYSTEM, JK-PC, Protection, Malware Protection, Starting,
Protection, 21-Jan-16 7:10 PM, SYSTEM, JK-PC, Protection, Malware Protection, Started,
Protection, 21-Jan-16 7:10 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Starting,
Protection, 21-Jan-16 7:10 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Started,
Protection, 21-Jan-16 7:10 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Stopping,
Protection, 21-Jan-16 7:10 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Stopped,
Protection, 21-Jan-16 7:10 PM, SYSTEM, JK-PC, Protection, Malware Protection, Stopping,
Protection, 21-Jan-16 7:10 PM, SYSTEM, JK-PC, Protection, Malware Protection, Stopped,
Protection, 21-Jan-16 7:14 PM, SYSTEM, JK-PC, Protection, Malware Protection, Starting,
Protection, 21-Jan-16 7:14 PM, SYSTEM, JK-PC, Protection, Malware Protection, Started,
Protection, 21-Jan-16 7:14 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Starting,
Protection, 21-Jan-16 7:14 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, Started,
Detection, 21-Jan-16 7:17 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 188.138.101.90, 50019, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Detection, 21-Jan-16 7:17 PM, SYSTEM, JK-PC, Protection, Malicious Website Protection, IP, 188.138.101.90, 50019, Outbound, C:\Program Files (x86)\Company\gupdate\gupdate.exe,
Detection, 21-Jan-16 7:19 PM, JK, JK-PC, Protection, Malware Protection, File, PUP.Optional.Hicosmea, C:\Users\JK\AppData\Roaming\pendis\presgen.dll, Quarantine Failed, 5, Access is denied. , [c3852715f7a21c1ab2a87eab9d640bf5]
Detection, 21-Jan-16 7:25 PM, SYSTEM, JK-PC, Protection, Malware Protection, File, PUP.Optional.Hicosmea, C:\Users\JK\AppData\Roaming\pendis\presgen.dll, Quarantine Failed, 5, Access is denied. , [c3852715f7a21c1ab2a87eab9d640bf5]

(end)

Thanks alot!

message edited by sKald_UK


Report •

#5
January 21, 2016 at 13:13:36
You might want to try a bootable rescue disc & run a scan from outside of Windows.

http://www.techspot.com/downloads/5...


Report •

#6
January 21, 2016 at 13:32:26
"Quarantine Failed, 5, Access is denied. , [c3852715f7a21c1ab2a87eab9d640bf5]"

Next step.

Run ESET Online Scanner, Copy and Paste the contents of the log in your reply please. This scan may take a very long while, so please be patient. Maybe start it before going to work or bed.
Make sure these options are checked/ticked in Advanced settings.
Remove found threats, Scan archives, Scan for potentially unsafe applications, Enable Anti-Stealth technology.
http://www.eset.com/us/online-scann...
http://www.eset.com/home/products/o...
If your comp is unbootable, or won't let you download, you will have to download ESET from a good computer, put it on a flash/thumb/pen/usb drive & run it from there.
Create a ESET SysRescue CD or USB drive
http://support.eset.com/kb2103/
How do I use my ESET SysRescue CD or USB flash drive to scan and clean my system?
http://support.eset.com/kb2612/
Configure ESET this way & disable your AV.
http://i.imgur.com/wZF1Ppi.gif
How to Temporarily Disable your Anti-virus
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
3: Which web browsers are compatible with ESET Online Scanner?
http://support.eset.com/kb405/?loca...
Online Scanner not working
http://support.eset.com/kb403/?loca...
My ESET product detected a threat—what should I do?
http://support.eset.com/kb117/
Once onto a machine, malware can disable antivirus programs, prevent antimalware programs from downloading updates, or prevent a user from running antivirus scans or installing new antivirus software or malware removal tools. At this point even though you are aware the computer is infected, removal is very difficult.
5: Why does the ESET Online Scanner run slowly on my computer?
http://support.eset.com/kb405/?view...
If you have other antivirus, antispyware or anti-malware programs running on your computer, they may intercept the scan being performed by the ESET Online Scanner and hinder performance. You may wish to disable the real-time protection components of your other security software before running the ESET Online Scanner. Remember to turn them back on after you are finished.
17: How can I view the log file from ESET Online Scanner?
http://support.eset.com/kb405/?view...
The ESET Online Scanner saves a log file after running, which can be examined or sent in to ESET for further analysis. The path to the log file is "C:\Program Files\ESET\EsetOnlineScanner\log.txt" (on 64-bit systems this directory will be "C:\Program Files (x86)\ESET\Esetonlinescanner\log.txt"). You can view this file by navigating to the directory and double-clicking it in Windows Explorer, or by copying and pasting the path specification above (including the quotation marks) into the Start > Run dialog box from the Start Menu on the Desktop.
If no threats are found, you will simply see an information window that no threats were found.
http://www.trishtech.com/security/s...


Report •

#7
January 23, 2016 at 07:26:34
Please note the first line of response #6. This is bad news because something which is unwanted is preventing quarantine. This means something undesirable is lurking in your computer, despite the improvements in the symptoms.

It could be doing something bad so I would therefore strongly advise you to follow the step suggested in #6.

Always pop back and let us know the outcome - thanks


Report •

#8
April 29, 2016 at 16:14:40
Download and install Avast Free Antivirus, it's a powerful antivirus and is one of the most up to date ones that I know about. Click the Link http://filejunkie.org/download/avas... and download it to your device. After downloading the file find it's location and double click to open the installer. It's quite easy to install so don't worry about it, just read through and follow the instructions.

After installation is complete, just open the program and click on a virus scan, it will scan your device and find and eliminate any viruses that it finds.

Best of luck to you.

message edited by bryan889


Report •

#9
April 29, 2016 at 16:21:05
I agree, thanks for the avast link. I'm gonna download it right away!

Thanks!!


Report •

#10
April 30, 2016 at 05:02:04
Avast is good but the issue posted would take more than Avast to fix it. A full clean of the computer was started in #6 but abandoned by the poster it seems (unless trey333 is the original poster with a new name).

Viruses can get through all Antivirus programs - none of them give total protection.

Please note this post is dated January 2016.

Always pop back and let us know the outcome - thanks


Report •

#11
May 27, 2016 at 00:16:41
Scan your computer. an update.
AVG AntiVirus is best high with independent testing labs, and also fares well in our hands-on tests. AVG is an Editors' Choice for free antivirus.

Report •

#12
May 27, 2016 at 06:55:20
I doubt any particular AV would sort this out properly although there is obviously nothing lost by trying. Note that this post is dated 21 Jan 2016. A full clean of the computer was offered but the poster seems to have declined, presumably because ADWCleaner "seemed" to have fixed it. However it would appear there are still remnants (see first line #6).

Always pop back and let us know the outcome - thanks


Report •


Ask Question