2013-12-07, 06:36
Hello forum,

All folders on an external hard drive look like shortcuts, and none of them can be opened. When trying to open them, the following message is shown:
Windows cannot find F:\.Trashes\814ec2e4.pif. Make sure you typed the name correctly, and then try again.
Please help me with this problem. The HDD contains so many family pictures and videos.

The registry saved using ERUNT.

DDS log:

I'll attach txt if that is OK.

Sorry for the delay. Your thread was most likely overlooked because it looks like a windows problem and this forum is for Malware Removal Only I see a lot of junk toolbars on your system, lets clean you up and run a few scans and when we deem your system clean and your still having those file issues than I can refer you to a windows forum for help.

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) by Xplode and save to your Desktop.

Double click on AdwCleaner.exe to run the tool.
Vista/Windows 7/8 users right-click and select Run As Administrator (http://windows.microsoft.com/en-US/windows7/How-do-I-run-an-application-once-with-a-full-administrator-access-token).
Click on the Scan button.
AdwCleaner will begin...be patient as the scan may take some time to complete.
After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
Copy and paste the contents of that logfile in your next reply.
A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

Dear Friend,
Thank you for helping us!
I followed your instructions
below is the report:

# AdwCleaner v3.016 - Report created 31/12/2013 at 23:03:04
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : jennet - JENNET-PC
# Running from : C:\Users\jennet\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : CltMngSvc

***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\Discount Buddy
Folder Deleted : C:\Program Files (x86)\Discount Buddy
Folder Deleted : C:\Program Files (x86)\Searchprotect
Folder Deleted : C:\Program Files (x86)\Discount Buddy
Folder Deleted : C:\windows\SysWOW64\Searchprotect
Folder Deleted : C:\Users\jennet\AppData\Local\Discount Buddy
Folder Deleted : C:\Users\jennet\AppData\Local\Searchprotect
Folder Deleted : C:\Users\jennet\AppData\Local\Temp\AskSearch
Folder Deleted : C:\Users\jennet\AppData\Roaming\Mail.Ru
[x] Not Deleted : C:\Users\jennet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mail.Ru
File Deleted : C:\Users\jennet\AppData\Local\Temp\Uninstall.exe

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0026766.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0026766.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0026766.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0026766.Sandbox.1
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [AlterGeoUpdater]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110211671166}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220222672266}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550255675566}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660266676666}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440244674466}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211671166}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110211671166}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110211671166}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211671166}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211671166}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211671166}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31111111-1111-1111-1111-110211671166}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550255675566}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660266676666}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Value Deleted : HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist [1]
Key Deleted : HKCU\Software\installedbrowserextensions
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\Discount Buddy
Key Deleted : HKLM\Software\Discount Buddy
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Discount Buddy
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\jennet\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : search_url
Deleted : keyword


AdwCleaner[R0].txt - [7868 octets] - [31/12/2013 22:58:27]
AdwCleaner[R1].txt - [7926 octets] - [31/12/2013 23:02:00]
AdwCleaner[S0].txt - [6463 octets] - [31/12/2013 23:03:04]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6523 octets] ##########

Hi, I am glad what we removed needed to go because all I wanted to see was the report, but that's ok

http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

Run Junkware Removal first then run Malwarebytes and let me see both reports please

Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by jennet on Wed 01/01/2014 at 8:00:49.94

~~~ Services

~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{958E0069-72AF-44AB-9459-1C7DD3E624EE}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DCDA2D45-CA0E-4782-8D01-8690F1A67BB5}

~~~ Files

~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\jennet\appdata\local\apn"
Successfully deleted: [Folder] "C:\Program Files (x86)\discount buddy"
Successfully deleted: [Folder] "C:\Program Files (x86)\w3i, llc"
Successfully deleted: [Folder] "C:\windows\syswow64\ai_recyclebin"
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{0760030A-5351-4439-A620-59AB64C09712}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{0880517D-41ED-4457-BF9F-8F7FFB27AC8A}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{0CC83897-DE82-4410-BEF4-64F2786EC561}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{0CFF26AB-E0A3-449D-89BF-03299F1E77DD}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{0ED05534-9F91-46EB-A60D-C2376485BFDF}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{12530588-0EDF-466C-9D6F-AC61F7AEF9ED}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{1346EE9E-1A82-466F-9A37-2FE47163A02E}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{142C4CA8-C879-4FF7-9B3E-57960448D01C}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{15DBBB9A-DDB3-4FAE-A567-98F1077AE19E}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{1953A023-33DF-4D9A-86F8-82CE079A8133}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{1A77FF96-E455-4D71-9A69-B1968D166274}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{1DADCD23-48A2-44E8-AD25-7BD799876D60}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{1F8DD43D-85BE-415D-87DF-801EC0396DCA}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{1FBAAA5C-22A6-45B1-9454-B2AF25E39FB9}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{2BAAAC76-C186-445E-9563-C4292EBD8BCA}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{2C98FE21-7BDD-41FE-959A-0AE52586BD64}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{2FFC428B-1D4C-40E8-92C7-72DAD7072424}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{324843E5-551A-436B-89EC-7D8F921A9848}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{3D00175D-59EB-4865-8330-8F6EF1B6B213}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{415EEF0C-32F5-40B3-92AD-DE20FEE24BD0}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{47F10554-E45B-492B-8A91-917A8C0E0910}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{48D72065-8FD8-4740-B032-859B4AE9E799}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{4BAED267-1E86-4EF1-AE5B-1DB454667AE7}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{4C5C9703-420A-4865-AC01-9B5841D68BD3}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{4E7DA545-EE27-4F86-9887-D9924D950087}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{4FC93630-FF9C-4D3A-B901-D020BE19CC1F}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{514ADB5D-9E72-4E3B-9F9C-15EF4097DC1F}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{57058C34-EFA8-4EFA-A1E0-AA130B002D30}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{5C19A3C7-0749-45CD-9888-B294C40357B9}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{5E867044-1F96-4FA8-9912-D306CBCD6EBC}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{6374F17C-1C95-4072-97AB-3E7A17344815}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{674064EB-FFBF-45F7-B84D-13CE3552DE97}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{67FEE050-45CA-47A7-9608-FFDFE3C81427}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{6ACB261F-2B0D-4A54-A752-E60DB466945D}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{6C8EC748-D71F-41FB-A1CD-5CA3F945395B}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{734B0862-42AE-4D65-A953-92BE4EE4DE7D}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{76FF2234-FD45-42F7-8F87-80AAF6EAA1FE}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{78FB3063-38A2-46D9-87D5-4E2A5FB684C5}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{7D7BFD3E-010D-4571-8146-B611454A7956}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{80FBEC22-6E4E-4877-B7DB-45B36CC3777B}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{87C96657-81C6-455D-B2D2-BD5A458B6296}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{8C67164A-4C22-4BE6-A201-3A71BB503D03}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{8CDF4FAC-85D0-4CF2-AADC-8059D2173BC7}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{91724768-AB3A-4BFA-A709-165C7E3DEC54}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{92138520-9545-49E6-8079-6B2B79009BF4}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{954C4C32-3E7B-4B48-B9B6-4F4D38D2F350}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{97BCB8B1-3DBC-4160-834E-92EAC5D51435}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{9C490CE1-59A0-40B9-A215-166DCE51C4B0}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{9D492466-6D74-46EB-8B5E-6E7068F8379D}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{A029BFEF-EA0D-4227-9932-F68AE5AE1887}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{A1235600-B511-4C97-9AE1-6306CF19806B}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{A4DFB94C-93F2-40F0-B170-A5E5A679F3F4}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{AA4AA1F5-B03F-476C-A679-794341D40B93}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{B0EAE4B0-B03E-431F-A40D-DBF25FA8BEE0}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{B6E18023-DFC4-4F33-B7F4-CC2BABC50759}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{B81696BD-C7A0-4BD3-AEA6-ECAF79B1428F}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{BAB7AD6B-412F-40C0-9F8B-4392F5E68229}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{C8894966-B5C7-463F-AE76-52C26904C80A}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{C977BBDD-E8EB-4665-8626-0B8B8AD60376}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{CAED5672-AD75-43D7-88F4-53C5CE916625}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{CDA605CB-47F4-4CE4-AC7E-1414D141CAD6}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{D1E44F11-C983-4AE2-97A5-63CEA0528507}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{D297B9BF-6591-4995-8C9F-B489F5FD88D2}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{DD468F00-0D18-4F9D-91C7-A26AD3609398}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{E02FD73A-84CF-4E34-929A-A8513D4CE8B1}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{E8A700A4-D97E-4E5B-82CB-44D4605F3243}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{EA7FC888-43E2-44CB-9477-FC583316B0CB}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{EF6A386A-B4D9-4DE1-B36E-1ABC450537B5}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{EF86D443-CEE3-4E84-8F04-88C770522BD2}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{F82E7E6A-0781-411A-97FF-EC718CD5136E}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{FB2DCE41-1F15-4246-8A14-F3F73B144251}
Successfully deleted: [Empty Folder] C:\Users\jennet\appdata\local\{FF163C11-B874-407E-84CD-CD21A51752CB}

~~~ Chrome

Successfully deleted: [Folder] C:\Users\jennet\appdata\local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh

~~~ Event Viewer Logs were cleared

Scan was completed on Wed 01/01/2014 at 8:07:31.02
End of JRT log

Malwarebytes Anti-Malware (Trial)

Database version: v2013.12.30.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
jennet :: JENNET-PC [administrator]

Protection: Enabled

1/1/2014 8:15:32 AM
mbam-log-2014-01-01 (08-15-32).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 242958
Time elapsed: 7 minute(s), 37 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 4
HKCR\TypeLib\{ABB8A8A5-FF98-40F6-B573-5841B063EA37} (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
HKCR\Interface\{02F878DF-E2BE-4B85-8CB4-A0D2D4E2ED7F} (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3A9EB81F-8FDD-4512-9AA1-D0679FD0B439} (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
HKCR\CLSID\{DD260902-9420-4055-A956-9152EB4F3E6A} (PUP.Optional.FindWide) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\Users\jennet\AppData\Local\TNT2\ (PUP.Optional.FindWide) -> Quarantined and deleted successfully.

Files Detected: 52
C:\Users\jennet\AppData\Local\Temp\nso5C8F.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\Temp\nst59EF.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\Temp\nst80A4.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\Temp\nst87A8.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\Temp\nsz5F3F.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\Temp\nsz846D.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\Temp\SPSetup.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\Temp\utt1725.tmp.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Windows\Temp\nsa5E2E.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Windows\Temp\nsa9A83.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Windows\Temp\nsl5E1F.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Windows\Temp\nsv96BC.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\jennet\Local Settings\Temporary Internet Files\Content.IE5\ALL92K4P\SPSetup[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\jennet\Local Settings\Temporary Internet Files\Content.IE5\LY5KK8BX\spstub[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\pinnedSearch_FindWide.htm (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\Autorun.inf (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\crx.tar (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\ffassist.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\GLOBALUNINSTALL.TNT (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\hmac.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\ie8starter.exe (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\iehpr.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\iestage2.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\IEToolbar.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\IEToolbar64.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\INSTALL.TNT (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\LastSession.log (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\log.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\npTNT2.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\npTNT2Ghost.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\OldStyleSB.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\PARTNER.TNT (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\passport.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\passport64.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\pinnedSearch.htm (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\progress.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\regsvr.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\RemoteSkin.wms (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\sqlite.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\tnt2chrome.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\TNT2User.exe (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\TNT2UserPS.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\TNT2UserPS64.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\TntMagicDel.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\UnInjLib.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\UnInjLib64.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\UNINSTALL.TNT (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\UninstallDlg.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\untar.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\UPDATE.TNT (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\xpi.tar (PUP.Optional.FindWide) -> Quarantined and deleted successfully.
C:\Users\jennet\AppData\Local\TNT2\\zipunzip.1.dll (PUP.Optional.FindWide) -> Quarantined and deleted successfully.


Lets run this scanner and take I final look

OTL by OldTimer

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the "Scan All Users" checkbox.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

OTL logfile created on: 1/2/2014 8:29:18 PM - Run 1
OTL by OldTimer - Version Folder = C:\Users\jennet\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.78 Gb Total Physical Memory | 1.90 Gb Available Physical Memory | 50.29% Memory free
7.56 Gb Paging File | 5.02 Gb Available in Paging File | 66.41% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 186.30 Gb Total Space | 103.57 Gb Free Space | 55.59% Space Free | Partition Type: NTFS
Drive D: | 254.36 Gb Total Space | 87.44 Gb Free Space | 34.38% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 741.31 Gb Free Space | 79.58% Space Free | Partition Type: NTFS

Computer Name: JENNET-PC | User Name: jennet | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
"{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}" = ASUS Instant Connect
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{8FF3891F-01B5-4A71-BFCD-20761890471C}" = Windows Live Messenger
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{903EDF14-4E28-4463-AA5E-4AEE71C0263B}" = Windows Live Movie Maker
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1
"{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
"{A0B91308-6666-4249-8FF6-1E11AFD75FE1}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{AB61A2E9-37D3-485D-9085-19FBDF8CEF4A}" = Windows Live Messenger
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.8) MUI
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{AF356B04-F542-4261-8515-6B0B25343CCE}" = Update for Html5 geolocation provider
"{B0002707-4F7E-4745-88A7-852DA8A88635}" = ASUS Sonic Focus
"{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BAEE89D5-6E87-4F89-9603-A1C100479181}" = Windows Live Messenger
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D299197D-CDEA-41A6-A363-F532DE4114FD}" = Windows Live UX Platform Language Pack
"{D39F0676-163E-4595-A917-E28F99BBD4D2}" = ASUS AI Recovery
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}" = Controlo ActiveX do Windows Live Mesh para Ligações Remotas
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E62E0550-C098-43A2-B54B-03FB1E634483}" = Windows Live Writer
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{EEF99142-3357-402C-B298-DEC303E12D92}" = Windows Live 影像中心
"{EF7EAB13-46FC-49DD-8E3C-AAF8A286C5BB}" = Windows Live 程式集
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{F992409C-9D10-4AE2-BAEB-B5409AD3785E}" = 用于远程连接的 Windows Live Mesh ActiveX 控件(简体中文)
"{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update
"{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AmUStor" = Alcor Micro USB Card Reader
"Asus Vibe2.0" = AsusVibe2.0
"ASUS WebStorage" = ASUS WebStorage
"AsusScr_K3 Series_ENG" = AsusScr_K3 Series_ENG
2014-01-01, 15:40
Happy New Year, hope your doing well

AskPartnerNetwork <--This came bundled with another program you installed and is not needed. Unless you installed and use it we can leave it be, but if you did not than see if you can uninstall it via Programs and Features in the Control Panel. Let me know what you decided.

BitTorrent <-- Looking at this on your system, P2P ( File Sharing ) is a very dangerous concept. Your downloading that file from an unknown source and not all but the greater percentage of them contain malware of some sort. Its like playing Russian Roulete malwarewise. I would strongly urge you to uninstall it also and stay away from any form or file sharing

Let me know what you want to do

2014-01-01, 17:10
I cannot AskPartnerNetwork.
I deleted BitTorrent.
looking forward for your next instruction.
I appreciate your help very much.

2014-01-01, 17:10
I cannot find AskPartnerNetwork.
I deleted BitTorrent.
looking forward for your next instruction.
I appreciate your help very much.[/QUOTE]

2014-01-01, 18:03
AskPartnerNetwork comes bundled with Avira Free Anti Virus and from what I have been reading if we remove this program than Avira may not work, its not malicious so we can leave it be

Open OTL.exe

Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL


CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPAB21DC4E-87C4-4580-BEBF-A8848BF5514B&q={searchTerms}&SSPV=
O4 - HKU\S-1-5-21-3557737060-444853815-290058489-1001..\Run: "C:\Users\jennet\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED File not found



ipconfig /flushdns /c

[start explorer]

Then click the [b]Run Fix button at the top. <--Not run Scan
Let the program run unhindered, reboot when it is done
Then post the results of the log it produces

Then run a new scan with OTL and post the new log please

2014-01-01, 18:54
2014-01-01, 19:06
2014-01-01, 19:07
Open up Chrome and click on the 3 bars up on the top right and when it opens go to settings > Manage Search Engines and click on Conduit and remove it

Have you tried your External Drive, any improvement ?

If not what i would do is to hook it up to another computer and see if it works , then we can determine if its a windows problem on your computer or if its a problem with your drive itself

2014-01-01, 19:10
sorry I wasn't sure if I should tick all users and LOP Check and Purity Check.
So i started the scan again with ticked all users, LOP check and Purity Check and will post it.
Sorry if it has caused inconvenience :(

2014-01-01, 19:14
2014-01-01, 19:18
Did you see my post about editing chome and removing conduit and also about your external drive

2014-01-01, 19:27
I am sorry I am slow in computers. So i did delete conduit search engine , and I've tried to open hard drive after each of your instructions. still the same. I've just tried to open it on another computer. the same error.

2014-01-01, 19:46
Your doing just fine :)

This is what I would do since this forum is for Malware Removal only and we are not set up to diagnose software or hardware problems, all us forums work together so post in this nice site that can help you sort out the problems your having with your external drive.

First go here and create an account , use the same user name your using here so I will be able to find you and follow along, like Safer Networking this site is also free.

Once your registered than go here and post in there hardware forum, you can tell them you posted here and i was helping you if you wish and also give them a link to this forum so they can see what we have done. Just explain the problem to them, besure to tell them that you got the same error with the drive hooked up to a different computer, and lets see what they say. Also let them know that right now your system is clean , there is no malware on it


Good luck, hope they can sort it out for you

Ken :)

2014-01-01, 19:47
While trying external hard drive on another computer I've noticed two folders which could be opened, 1st one is folder recycler and second is an icon software offer. So I clicked on both of them and Software offer asked for installation I rejected this offer. Then I went back to the External Hard Drive and all the folders with pictures disappeared, but the space occupied on the EHD is the same 741 GB is free out of 931 GB. So in complete shock i attached this EHD back to my computer and it is the same. Worried that folders with pics disappeared. Complete shock :(((:banghead:

2014-01-01, 19:51
Dear Ken,
I will do as you say.
I really appreciate your time and help. You are really great and patient.
I am not Guych as you could notice, I am his wife and without you detailed and dumy friendly instruction we wouldn't make it :)
I hope there is still hope.
Will let you know once we register on another website.
Thank Thank Thank you very much!

2014-01-01, 20:01
Your welcome , lets see what they say, if you like post back here and let me know when you registered at WTT