PDA

View Full Version : Banyan Malware can not be removed by system



katok
2015-01-22, 16:59
Spybot has tried 5 times..need help. Thank you.

katok
2015-01-22, 20:36
Scan file and additional txt file

Juliet
2015-01-22, 22:54
Our recommendation is to remove this program.
Yet Another Cleaner!
Remove it using the Add/Remove programs

Let me supply you with known good antivirus tools.


http://1-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/8fj6i2U.png.pagespeed.ce.RUYs43FaJ5.pngavast! Free Anti-Virus (http://www.avast.com/en-gb/download-thank-you.php?product=FA-ONLINE&locale=en-gb) (free)
http://1-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/8fj6i2U.png.pagespeed.ce.RUYs43FaJ5.pngAvira AntiVir Personal - Free Antivirus (http://www.free-av.com/en/products/1/avira_antivir_personal__free_antivirus.html)
http://1-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/xUbJpW95.png.pagespeed.ic.Eg8QK7Uzqf.jpg (http://windows.microsoft.com/en-us/windows/security-essentials-all-versions) Microsoft Security Essentials (http://windows.microsoft.com/en-us/windows/security-essentials-all-versions) (free)
http://2-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/GzlsbnV.png.pagespeed.ce.SLxxSJVib_.png (http://www.eset.co.uk/Download/Software/Home) ESET NOD32 Anti-Virus (http://www.eset.co.uk/Download/Software/Home) (paid)
http://2-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/YARWD1t.png.pagespeed.ce.nvhmVeYDe3.png[/img (http://www.kaspersky.co.uk/home-products) Kaspersky Anti-Virus (http://www.kaspersky.co.uk/home-products) (paid)
http://2-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/x7D2ig3K.png.pagespeed.ic.x4TC1AK8OX.jpgEmsisoft Internet Security (http://www.emsisoft.de/en/software/internetsecurity/) (paid)

As for which free versus paid for Antivirus I have to leave this up to you but, I've always stayed with a free version, that use less resources and consumes less time in updating. This is my personal opinion and also with free versions of Antivirus, firewall is not included.

~~~~~~~~~
Please go to your downloads folder and locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop and select PASTE
Farbar Recovery Scan Tool should now be on your desktop.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG




start
CloseProcesses:
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <===== ATTENTION
HKU\S-1-5-21-1210306022-1181859764-3225192987-1001\...\Winlogon: [Shell] - <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1210306022-1181859764-3225192987-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKU\.DEFAULT -> {035707D0-FAF1-4D36-8C40-C6734EB967DF} URL =
R2 iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [118048 2014-10-28] (Elex do Brasil Participações Ltda)
R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [248488 2014-10-28] (Elex do Brasil Participações Ltda)
S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [45224 2014-10-28] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [99496 2014-10-28] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [65704 2014-10-28] (Elex do Brasil Participações Ltda)
R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [51880 2014-10-26] (Elex do Brasil Participações Ltda)
2015-01-21 09:04 - 2015-01-21 09:04 - 00001930 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\YAC.lnk
2015-01-21 09:04 - 2015-01-21 09:04 - 00001924 _____ () C:\Users\Public\Desktop\YAC.lnk
2015-01-21 09:04 - 2015-01-21 09:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC
2015-01-21 09:04 - 2015-01-21 09:04 - 00000000 ____D () C:\Program Files (x86)\Elex-tech
2015-01-21 09:04 - 2014-10-28 06:31 - 00045224 _____ (Elex do Brasil Participações Ltda) C:\WINDOWS\system32\Drivers\iSafeKrnlBoot.sys
2015-01-21 09:04 - 2014-10-26 21:02 - 00051880 _____ (Elex do Brasil Participações Ltda) C:\WINDOWS\system32\Drivers\iSafeNetFilter.sys
2015-01-21 09:02 - 2015-01-21 09:02 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Elex-tech
2015-01-21 09:01 - 2015-01-21 09:02 - 16474920 _____ (Elex do Brasil Participações Ltda) C:\Users\Tim\Downloads\yet_another_cleaner_cnt.exe
C:\ProgramData\adwcleaner_4.106.exe
C:\Users\Tim\AppData\Local\Temp\jre-8u31-windows-au.exe
EmptyTemp:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~``

Download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) to your desktop.


Windows XP : [I]Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"




http://i1269.photobucket.com/albums/jj590/OCD-WTT/MBAMDashboard_zpsddef9b5f.gif (http://s1269.photobucket.com/user/OCD-WTT/media/MBAMDashboard_zpsddef9b5f.gif.html)



On the Dashboard click on Update Now
Go to the Setting Tab
Under Setting go to Detection and Protection
Under PUP and PUM make sure both are set to show Treat Dections as Malware
Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
Then on the Dashboard click on Scan
Make sure to select THREAT SCAN
Then click on Scan
When the scan is finished and the log pops up...select Copy to Clipboard
Please paste the log back into this thread for review
Exit Malwarebytes

katok
2015-01-23, 00:03
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 1/22/2015
Scan Time: 4:45:38 PM
Logfile:
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.01.22.11
Rootkit Database: v2015.01.14.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Tim

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 415461
Time Elapsed: 8 min, 0 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
Adware.Finix, C:\Users\Tim\Downloads\Comcast_Desktop_Software_1401.exe, , [6c0767938603cd69ccb54bc7e022f10f],

Physical Sectors: 0
(No malicious items detected)


(end)

Juliet
2015-01-23, 01:03
Fixlog.txt ?

Since we have removed some malicious files, how's the computer?

katok
2015-01-23, 01:41
:cool:

katok
2015-01-23, 01:44
Thank you thank you very much! Sorry about the multiple posts, I have trouble focusing and with short term memory since stroke:heart:

Juliet
2015-01-23, 01:54
Thank you thank you very much! Sorry about the multiple posts, I have trouble focusing and with short term memory since stroke:heart:

Your doing fine.

How's your computer now?


What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.


Go here (http://www.eset.com/us/online-scanner/) to run an online scannner from ESET. Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator

Note:
For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
Turn off the real time scanner of any existing antivirus program while performing the online scan. Here's how (http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html).
Click the blue Run ESET Online Scanner button
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
Click on Advanced Settings
Make sure that the option Remove found threats is unticked.
Ensure these options are ticked

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology


Click Start
Wait for the scan to finish
When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
Close the ESET online scan.

katok
2015-01-23, 16:30
I ran the scans, but I may have inadvertently taken some action. I may have been on a different menu then you were referring to, it did not have ticks for "take no action but instead had a slide scale action, no action, which I chose. Found variant of Win32/Elex.as. Software said it "cleaned file because it contained body of infection"? Since I am out of my arena, I will turn this over to you to determine how badly I performed. The Smartscan log is too big to upload:red:

Juliet
2015-01-23, 18:23
was the file you posted, come from the Eset Online scan?
From what I can tell it actually found a quarantine folder which we will remove in the end.

Tell me how the computer is now.

katok
2015-01-23, 19:09
was the file you posted, come from the Eset Online scan?
From what I can tell it actually found a quarantine folder which we will remove in the end.

Tell me how the computer is now.

Juliet - No it came from Eset Nod32 AV 0 day tral software. When I did the Eset Online Scan it started without any input by me. Knowing that I needed to have options ("No action") I stopped scan looked for opportunity to alter setting,found none, then installed trial version. Ran SmartScan. Sent First scan results.

katok
2015-01-23, 19:11
Typng just became diffcult

katok
2015-01-23, 19:23
just we back to Online Scanner and found options you described Juliet:sick: am running now

katok
2015-01-23, 20:22
See attached

Juliet
2015-01-23, 21:47
OK, I went back over the logs and right now things look good.

The scan produced the same file which is held in FRST quarantine.

You can keep the trial antivirus or you can uninstall it and chose one from this list.

Let me supply you with known good antivirus tools.


http://1-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/8fj6i2U.png.pagespeed.ce.RUYs43FaJ5.pngavast! Free Anti-Virus (http://www.avast.com/en-gb/download-thank-you.php?product=FA-ONLINE&locale=en-gb) (free)
http://1-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/8fj6i2U.png.pagespeed.ce.RUYs43FaJ5.pngAvira AntiVir Personal - Free Antivirus (http://www.free-av.com/en/products/1/avira_antivir_personal__free_antivirus.html)
http://1-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/xUbJpW95.png.pagespeed.ic.Eg8QK7Uzqf.jpg (http://windows.microsoft.com/en-us/windows/security-essentials-all-versions) Microsoft Security Essentials (http://windows.microsoft.com/en-us/windows/security-essentials-all-versions) (free) <-- I personally use.
http://2-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/GzlsbnV.png.pagespeed.ce.SLxxSJVib_.png (http://www.eset.co.uk/Download/Software/Home) ESET NOD32 Anti-Virus (http://www.eset.co.uk/Download/Software/Home) (paid)
http://2-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/YARWD1t.png.pagespeed.ce.nvhmVeYDe3.png[/img (http://www.kaspersky.co.uk/home-products) Kaspersky Anti-Virus (http://www.kaspersky.co.uk/home-products) (paid)
http://2-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/x7D2ig3K.png.pagespeed.ic.x4TC1AK8OX.jpgEmsisoft Internet Security (http://www.emsisoft.de/en/software/internetsecurity/) (paid)

As for which free versus paid for Antivirus I have to leave this up to you but, I've always stayed with a free version, that use less resources and consumes less time in updating. This is my personal opinion and also with free versions of Antivirus, firewall is not included.

~~~~~~~~~~~~~~~~~~`

Let's remove the tools I had you download and their quarantine folders.

[img]http://i.imgur.com/AFZxnZc.jpg DelFix

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix) and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools
Create registry backup



Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).

katok
2015-01-23, 22:12
Typing problems persist. Windows blinking and missing keystrokes:oreo:

Juliet
2015-01-23, 22:42
Are you working with a wireless mouse?, and if so is your touchpad listed as on?


Some of the tools I'll list to use might not work on Windows 8.1
Try each one, if they wont work go to the next


Please download ServicesRepair (http://kb.eset.com/library/ESET/KB%20Team%20Only/Malware/ServicesRepair.exe) and save it to your desktop.

Double-click ServicesRepair.exe.
If security notifications appear, click Continue or Run and then click Yes when asked if you want to proceed.
Once the tool has finished, you will be prompted to restart your computer. Click Yes to restart.


After restart wait a few minutes until the system settled down.



~~~~~~~~~~~~

Please download MiniToolBox http://www.bleepingcomputer.com/download/minitoolbox/
save it to your desktop and run it.

Checkmark the following check-boxes:


List last 10 Event Viewer log
List Devices
List Minidump Files

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Juliet
2015-01-23, 22:54
Also, have you experimented to see if these issues still happen in safe?

katok
2015-01-23, 23:16
I am not using wireless mouse and problem has gone away after Restart and Windows Update. Might of run out of memory? Just to be sure - I have not cleaned up the infected files found by ESET Will install tools above if problem returns in future

Juliet
2015-01-24, 00:01
Good
The Delfix tool will take out the FRST tool and quarantine folder.

Use the computer for a while and post back to let me know if anything else pop ups.

Juliet
2015-01-26, 11:38
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.

Juliet
2015-02-02, 16:30
Topic reopened


Do you have any exclamation points/error icons in Device Manager? To get to Device Manager: Log in as an administrative user -> Start Menu -> Control Panel -> Hardware and Sound -> Device Manager
Look for yellow exclamation points or red indicators.


Also please download Windows Repair (all in one) from here (http://www.tweaking.com/content/page/windows_repair_all_in_one.html)

http://www.bleepstatic.com/download/screenshots/w/windows-repair-all-in-one-portable/step-4-tab.jpg
Install the program then go to step 4 and create a new system restore point and new registry backup.

Go to Step 2 and allow it to run CheckDisk by clicking on Do It button:
http://i1.ifrm.com/228/109/upload/p22001645.gif



NEXT
On the the Start Repairs tab => Click the Start
http://www.bleepstatic.com/download/screenshots/w/windows-repair-all-in-one-portable/start-repairs-tab.jpg


Please ensure that ONLY items seen in the image below are ticked as indicated (they're all checked by default):
http://i1.ifrm.com/228/109/upload/p22001647.gif

Click on box next to the Restart System when Finished. Then click on Start.

Juliet
2015-02-02, 16:31
Also please do this

http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif Malwarebytes Anti-Rootkit

Download Malwarebytes Anti-Rootkit (http://downloads.malwarebytes.org/file/mbar)
Once the file has been downloaded, right click on the downloaded file and select the Extract all menu option.
Follow the instructions to extract the ZIP file to a folder called mbar-versionnumber on your desktop.
Once the ZIP file has been extracted, open the folder and when that folder opens, double-click on the mbar folder.
Double-click on the mbar.exe file to launch Malwarebytes Anti-Rootkit.
After you double-click on the mbar.exe file, you may receive a User Account Control (UAC) message if you are sure you wish to allow the program to run. Please allow to start Malwarebytes Anti-Rootkit correctly.
Malwarebytes Anti-Rootkit will now install necessary drivers that are required for the program to operate correctly.
If you receive a DDA driver message like could not load DDA driver, click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer and will start automatically.

http://i1269.photobucket.com/albums/jj590/OCD-WTT/MBAMAnti-Rootkit1_zps4613be8c.png


Please click by the introduction screen on the Next button to continue.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/MBAMAnti-Rootkit2update_zpsf85fca28.png


Next you will see the Update Database screen.
Click on the Update button so Malwarebytes Anti-Rootkit can download the latest definition updates.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/MBAMAnti-Rootkitupdatecomplete_zpscf9f4cdb.png


When the update has finished, click on the Next button.

http://i1269.photobucket.com/albums/jj590/OCD-WTT/MBAMAnti-Rootkitscan_zps9b346fe7.png


Next you can select some basic scanning options. Make sure the Drivers, Sectors, and System scan targets are selected before you click on the Scan button.
Malwarebytes Anti-Rootkit will now start scanning your computer for rootkits. This scan can take some time, so please be patient.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/MBAMAnti-Rootkitscan-results_zps9f0fdf8e.png


When the scan with Malwarebytes Anti-Rootkit is finished, the program will display a screen with the results from the scan.
Make sure everything is selected and that the option to create a restore point is checked.
Next click on the Cleanup button. Malwarebytes Anti-Rootkit will then prompt you to reboot your computer.
Click on Yes button to restart your computer.


There will now be two log files created in the mbar folder called system-log.txt and one that starts with mbar-log.
The mbar-log file will always start with mbar-log, but the rest will be named using a timestamp indicating the time it was run.

For example, mbar-log-2012-11-12 (19-13-32).txt corresponds to mbar-log-year-month-day (hour-minute-second).txt.


The system-log.txt contains information about each time you have run MBAR and contains diagnostic information from the program.




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

katok
2015-02-02, 21:01
Device Manager reports no errors (no yellow or red exclamation points)

MalwareBytes Rootkit Scan reports no malware

Juliet
2015-02-02, 22:22
Some of the tools I'll list to use might not work on Windows 8.1
Try each one, if they wont work go to the next

Did you run Windows Repair (all in one)

~~~~~~~~~~~

Please download ServicesRepair (http://kb.eset.com/library/ESET/KB%20Team%20Only/Malware/ServicesRepair.exe) and save it to your desktop.

Double-click ServicesRepair.exe.
If security notifications appear, click Continue or Run and then click Yes when asked if you want to proceed.
Once the tool has finished, you will be prompted to restart your computer. Click Yes to restart.


After restart wait a few minutes until the system settled down.



~~~~~~~~~~~~

Please download MiniToolBox http://www.bleepingcomputer.com/download/minitoolbox/
save it to your desktop and run it.

Checkmark the following check-boxes:


List last 10 Event Viewer log
List Devices
List Minidump Files

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

katok
2015-02-02, 23:09
I also just ran Mini toolbox and Services Repair. Since running Windows Repair earlier today my "windows" have stopped blinking and I have not dropped any characters while typing:cool: The Result.txt is attached

Juliet
2015-02-02, 23:42
hey, my fingers are crossed.

Use it a day or two without any heavy special activities and let see how she does?

katok
2015-02-03, 00:29
hey, my fingers are crossed.

Use it a day or two without any heavy special activities and let see how she does?

I will be kickin the tires the next few days and will report any recurrences

My Dell hardware warranty expires in about a week, can we rule out hardware failure(for now)? Any other tests you could recommend to assure?

I also ran a SB scan and I keep getting the same 7 results even just an hour after previous scans and applied fixes: Driver Installation Paths, Recent File History, Cookies, Cache. Is that normal?

These scans , the scans they smell like like victory....or am I overly optimistic again and we've just begun the fight?

Juliet
2015-02-03, 01:26
My Dell hardware warranty expires in about a week, can we rule out hardware failure(for now)? Any other tests you could recommend to assure?

I also ran a SB scan and I keep getting the same 7 results even just an hour after previous scans and applied fixes: Driver Installation Paths, Recent File History, Cookies, Cache. Is that normal?
No, we can not rule out hardware yet. If all scans keep coming back clean and the computer screen/window continues to flash, the keyboard doesn't type, then in my mind it becomes hardware related.
And if we get to that point, I would have to send you to a forum that knows how to inspect your machine for that because I really don't have any training in that field.

Can you show me the log for the 7 files that keep showing up?
Is it possible they are from tools we've run and they are located in quarantine folders?

katok
2015-02-03, 15:05
No, we can not rule out hardware yet. If all scans keep coming back clean and the computer screen/window continues to flash, the keyboard doesn't type, then in my mind it becomes hardware related.
And if we get to that point, I would have to send you to a forum that knows how to inspect your machine for that because I really don't have any training in that field.

Can you show me the log for the 7 files that keep showing up?
Is it possible they are from tools we've run and they are located in quarantine folders?

My Windows are blinking and characters dropped while typing again

Juliet
2015-02-03, 17:04
That is nothing to worry.
The found items are just usage tracks, Usage Tracks,and some may return as you use your computer,even if they were fixed originally:

I want you to go here http://forums.whatthetech.com/index.php?showforum=126
Register, and post a new topic.
Include the link to this topic and give a description.


They want need any of the tools we've used here and let's remove those so they are not flagged by your antivirus later.

http://i.imgur.com/AFZxnZc.jpg DelFix

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix)
or from here http://www.bleepingcomputer.com/download/delfix/ and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools
Create registry backup
Purge system restore
Reset system settings


Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).

katok
2015-02-03, 18:04
I re-ran Windows Repair and my difficulties with Typing and Drop down menus disappearing before selection can be made have once again ended:snorkle:

katok
2015-02-03, 20:53
Were still going without troubles recurring:lip:

Juliet
2015-02-03, 22:35
I want to say Yipee!
But, experience says that might be to early :)

Juliet
2015-02-05, 12:39
still with me?

Ready to remove tools and quarantine folders?

katok
2015-02-05, 15:50
still with me?

Ready to remove tools and quarantine folders?

Delfix was run 4 days ago? Do it again?
:confused:

Computer blinking again, typing difficult. Dell wants to wipe computer reinstall Windows.
Is this my best option?

Juliet
2015-02-05, 19:21
Computer blinking again, typing difficult. Dell wants to wipe computer reinstall Windows.
Is this my best option?

When we remove all malware found, try to research and apply fixes that don't work to fix what might be hardware or software related, we might be at that point where this is your last resort.

Wish I could do more.

katok
2015-02-11, 14:17
When we remove all malware found, try to research and apply fixes that don't work to fix what might be hardware or software related, we might be at that point where this is your last resort.

Wish I could do more.

Sorry it took me so long to reply. I have attempted to reply previously but could not type! Same at the Hardware forum. I borrowed Services Repair to fix my typing problems and came straight in. It seems to affect repairs for about a day before acting up again? TY for all your help. I am sorry I got you involved in this losing proposition. You were great throughout:oreo: Hopefully I will get this fixed and wiped clean

Juliet
2015-02-11, 17:52
We're glad to help :)

Juliet
2015-02-14, 03:34
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.