PDA

View Full Version : Windows won't update - is it malware?



alx21
2016-02-13, 22:55
Hi

My PCs are set to notify me of Windows Updates so that I can choose which ones to download and install. For several months I haven't had any notifications of newly released updates and thought nothing of it. However, two days ago I decided to do a manual check and there were 11 updates available dated 11th August 2015. Whenever I try to download them, the screen just says “Downloading updates, 0kb total, 0% complete”, regardless of how long I spend trying to download e.g. one hour, 90 minutes etc.

So I decided to try just one update for IE and after about 30 minutes it downloaded and installed. There are now 30 pending updates and at this rate it will take 15 hours to download and install them. I also know that updating Windows when infected creates difficulties at a later stage.

I have scanned with Malwarebytes and SuperAntiSpyware and the PCs seem clean, but a few strange things have been happening; sometimes when reading a PDF the document closes abruptly, and also my Canon scanner gets stuck through a scan, something that never happened before, and I also get the occasional blank IE page.

Am I infected? My logs are below. Thanks.

Dakeyras
2016-02-14, 01:30
Hi and welcome back to Safer Networking. :)

After reviewing the logs provided(in future please do not attach them but merely post unless advised otherwise, thank you) nothing particularly malicious seems to be the root cause. Though I do advise you consider uninstalling this utter dross:

Toolwiz Time Freeze 2014

As it is not something I would personally advise anyone download/install/use etc as it has the potential to render a machine little more than a expensive doorstop. My humble opinion however and your call. Anyway to err on the side of caution before considering other root causes lets rule out malware as follows shall we...

Next:

For the duration of the below two scans, temp' disable/shut down your protection software now to avoid potential conflicts, how to do so can be read here (http://www.bleepingcomputer.com/forums/topic114351.html).

Scan with JRT:

Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/) to your desktop.


Right-click on JRT.exe and select Run as Administrator to launch the application >> follow the on-screen prompt.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next reply.

Scan with Zoek:

Please download Zoek (http://download.bleepingcomputer.com/smeenk/zoek.exe) and save to the desktop.


Right-click on zoek.exe and select Run as Administrator .
Once the GUI(graphical user interface) has loaded >> click on the More Options tab >> select Auto Clean only.
Ensure the option Scan All Users is selected >> now click on the Run Script tab.
Zoek will momentary close and a new GUI will appear and the scan will commence.
Please be patient as the scan may take some time depending on the specifications of your computer.
Once the scan is completed a log file named zoek-results.log will open via notepad, post the contents in your next reply.
If the system requires a reboot after the aforementioned scan, click on OK at the prompt(the log will appear after the reboot).
The zoek-results.log can also be found on your system drive.

Note: Do not forget to re-enable your Security software after running the above scans!

Next:

When completed the above, please post back the following in the order asked for:


How is your computer performing now, any further symptoms and or problems encountered?
Junkware Removal Tool Log.
Zoek Log.

alx21
2016-02-14, 23:44
Hi Dakeyras

Thanks for your help and sorry about the attachments; I completely forgot. The PC is running ok and not showing any more odd symptoms, but I haven't attempted any more updates, I will wait for your prompt. The JRT and Zoek logs are below-

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.2 (01.06.2016)
Operating System: Windows 7 Home Premium x86
Ran by USER (Administrator) on 14/02/2016 at 20:59:31.55
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

File System: 8

Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\08G6DIIW (Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2S00M8CO (Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E0RIN9YF (Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ERVM4ZDC (Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GSO6AD2Z (Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IE2SDBRZ (Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L61HB3AJ (Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OJME0V0Y (Folder)

Registry: 0

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14/02/2016 at 21:00:47.63
End of JRT log

Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by USER on 14/02/2016 at 21:01:47.89.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\USER\Desktop\zoek.exe [Scan all users] [Checkboxes used]

==== System Restore Info ======================

14/02/2016 21:02:51 Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\Program Files\AGEIA Technologies deleted successfully
C:\Users\USER\AppData\Local\VirtualStore deleted successfully
C:\Users\USER2\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3911347883-1701421413-189546050-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9A9F603B-51A8-4630-AE99-4BBF01675575} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Program Files\AGEIA Technologies not found
"C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\Gj0neWhS.default\extensions\abs@avira.com" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"quickprint@hp.com"="C:\Program Files\Hewlett-Packard\SmartPrint\QPExtension" [26/01/2011 14:27]

==== Firefox Extensions ======================

==== Firefox Plugins ======================


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
flliilndjeohchalpbbcdekjklbdgfkk - No path found[]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.com/?gfe_rd=cr&ei=mTEsVKTNJOGq8wfem4HADQ&gws_rd=ssl"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.com/?gfe_rd=cr&ei=mTEsVKTNJOGq8wfem4HADQ&gws_rd=ssl"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02"

==== Empty IE Cache ======================

C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\USER2\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\USER2\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=112 folders=25 2484024 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\USER\AppData\Local\Temp will be emptied at reboot
C:\Users\USER2\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\USER\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 14/02/2016 at 21:21:53.09 ======================

Dakeyras
2016-02-15, 00:23
Hi. :)

Thanks for your help and sorry about the attachments; I completely forgot.
You're welcome, fair play re the attachments.

The PC is running ok and not showing any more odd symptoms,
Acknowledged.

I haven't attempted any more updates, I will wait for your prompt.
Please visit this page How do I reset Windows Update components? (https://support.microsoft.com/en-us/kb/971058), under the heading Windows 8.1, Windows 8, and Windows 7, click on:

Run now

At the prompt, save to your desktop. Once downloaded, double click on WindowsUpdateDiagnostic.diagcab >> once the GUI(graphical user interface) appears/loads >> select Windows Update

Then click on Next >> follow the prompts. Once completed reboot your machine if not prompted and then check for Windows Updates(do not download any/install etc).

Next:

Let myself know the outcome of the above when ready and we will then go from there, thank you.

alx21
2016-02-16, 18:59
I have run the Windows Update Diagnostic troubleshooter, rebooted and searched for new updates, but none was found after 60 minutes, and again after 45 minutes. The 30 updates which were present but won't download have also disappeared. The troubleshooter posted the following message-

Problems found-

1. Service registration is missing or corrupt – not fixed.
2. Windows Update error 0x8007005 (2016-02-15-T_11_38_55P) – not fixed.
3. Problems installing recent updates – fixed.
4. Problems installing recent updates – fixed.
5. Problems installing recent updates – fixed.

Which way forward?

Dakeyras
2016-02-17, 20:45
Hi. :)

My apologies for the delay. All acknowledged, lets carry out a benign scan as follows shall we to further try and ascertain what may be the actual problem...

Scan with FSS:

Please download Farbar Service Scanner (http://download.bleepingcomputer.com/farbar/FSS.exe)and save to your Desktop.


Right-click FSS.exe and select Run as Administrator to start the program >> click on Yes at the prompt.
Select all available options.
Then click on the Scan tab.
When the scan is complete, it will produce a log named FSS.txt.
Post the contents in your next reply.

alx21
2016-02-19, 00:37
Hi Dakeyras

The FSS scan results -

Farbar Service Scanner Version: 27-01-2016
Ran by USER (administrator) on 18-02-2016 at 23:11:38
Running from "C:\Users\USER\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Attempt to access Google IP returned error. Google IP is unreachable
Attempt to access Google.com returned error: Other errors
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\system32\nsisvc.dll => File is digitally signed
C:\Windows\system32\Drivers\nsiproxy.sys => File is digitally signed
C:\Windows\system32\dhcpcore.dll => File is digitally signed
C:\Windows\system32\Drivers\afd.sys => File is digitally signed
C:\Windows\system32\Drivers\tdx.sys => File is digitally signed
C:\Windows\system32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\system32\dnsrslvr.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\mpssvc.dll => File is digitally signed
C:\Windows\system32\bfe.dll => File is digitally signed
C:\Windows\system32\Drivers\mpsdrv.sys => File is digitally signed
C:\Windows\system32\SDRSVC.dll => File is digitally signed
C:\Windows\system32\vssvc.exe => File is digitally signed
C:\Windows\system32\wscsvc.dll => File is digitally signed
C:\Windows\system32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\system32\wuaueng.dll => File is digitally signed
C:\Windows\system32\qmgr.dll => File is digitally signed
C:\Windows\system32\es.dll => File is digitally signed
C:\Windows\system32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\system32\ipnathlp.dll => File is digitally signed
C:\Windows\system32\iphlpsvc.dll => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed


**** End of log ****

Dakeyras
2016-02-19, 01:15
Hi. :)


The FSS scan results
Thanks, all appears fine apart form the Connection Status results which may be a possible cause. Please bare with myself as Windows Updates issues are not the easiest to rectify. Plus as primarily I actually only provide Anti-Malware support we may have to consider say a referral to specialist forum for such issues and or say a Windows 7 Repair Install for example.

Anyway lets proceed as follows shall we...

Scan with MTB:

Please download MiniToolBox (http://download.bleepingcomputer.com/farbar/MiniToolBox.exe) and save your desktop.


Right-click on MiniToolBox.exe and select Run as Administrator to start the program >> click on Yes at the prompt.
Check/select the option Select All
Then click on Go and post the result (Result.txt) in your next reply.

Note: If the log generated is too large to post conventionally merely attach it to your reply.

alx21
2016-02-19, 21:13
Hi Dakeyras

I completely understand and thanks for the help so far. I had serious Windows Update issues several years ago and finally resolved it by resetting Windows File Resource Center. I am very relieved I'm unlikely to be infected as failure to update Windows is the quickest way to malware; incidentally I am a member of a Windows 7 Operating System forum so should the need be let me know and I'll pass this onto them. The MTB log is attached.

Dakeyras
2016-02-19, 22:24
Hi. :)

All acknowledged/you're welcome!

Check Hard Disk For Errors:


Open Notepad.
Copy and Paste everything from the Code Box below into Notepad:

@echo off
cmd /c chkdsk c: |find /v "percent" >> "%userprofile%\desktop\checkhd.txt"
del %0
Go to File >> Save As
Save File name as Dakeyras.bat
Change Save as Type to All Files and save the file to your Desktop.
It should look similar to this: http://i280.photobucket.com/albums/kk173/Dakeyras_album2/vista-rh.gif

Now right-click on the desktop Dakeyras.bat and select Run as Administrator to run the batch file. It will self-delete when completed.

A file icon named checkhd.txt should appear on your Desktop. Please post the contents of this file in your next reply.

Windows 7 - System File Checker:

Click on Start(Windows 7 Orb).
Click on All Programs >> Accessories
Right click on Command Prompt and select Run as Administrator.
Click on Continue at the UAC prompt.
At the Command Prompt C:\Windows\System32> type in the following exactly:
cd c:\

Then depress the Enter/Return key, then type in the following exactly:
sfc /scannow

Then depress the Enter/Return key.

Note: This may take awhile to finish. When completed close the Administrator Command Prompt window, via typing Exit then depress the Enter/Return key.

alx21
2016-02-22, 00:13
Hi Dakeyras

The checkhd.txt results -

The type of the file system is NTFS.

WARNING! F parameter not specified.
Running CHKDSK in read-only mode.

CHKDSK is verifying files (stage 1 of 3)...
File verification completed.
374 large file records processed.

0 bad file records processed.

0 EA records processed.

60 reparse records processed.

CHKDSK is verifying indexes (stage 2 of 3)...
Index verification completed.
0 unindexed files scanned.

0 unindexed files recovered.

CHKDSK is verifying security descriptors (stage 3 of 3)...
Security descriptor verification completed.
17242 data files processed.

CHKDSK is verifying Usn Journal...
Usn Journal verification completed.
Windows has checked the file system and found no problems.

147796991 KB total disk space.
62173824 KB in 66898 files.
44100 KB in 17243 indexes.
0 KB in bad sectors.
215399 KB in use by the system.
65536 KB occupied by the log file.
85363668 KB available on disk.

4096 bytes in each allocation unit.
36949247 total allocation units on disk.
21340917 allocation units available on disk.


I will conduct the System File Checker shortly and let you know the results.

Dakeyras
2016-02-22, 18:42
Acknowledged. :)

alx21
2016-02-22, 19:08
Hi Dakeyras

Just completed the sfc /scannow command. It said Windows Resource Protection found corrupt files but was unable to fix some of them, and it then gives details of where the results log can be found.

Dakeyras
2016-02-23, 22:31
Hi. :)


Just completed the sfc /scannow command. It said Windows Resource Protection found corrupt files but was unable to fix some of them, and it then gives details of where the results log can be found.
Fair play and rather than myself proving instructions for the scan results retrieval. Lets try something else SFC wise that may rectify the corrupt file issues and in turn also provide a log for my review etc.

Scan with SFCFix:

Please download SFCFix (http://www.sysnative.com/niemiro/apps/SFCFix.exe) and save your desktop.


Close all open windows before proceeding any further, as otherwise may hinder the tools functionality.
Right-click on SFCFix.exe and select Run as Administrator to start the program.
Follow the on-screen prompts...
Upon completion a log file will have been created on the desktop named SFCFix.txt.
Post the contents in your next reply.

alx21
2016-02-25, 20:36
Hi Dakeyras

The SFCFix scan results are below. Sorry for the delay as I have been unwell; much better now.

SFCFix version 2.4.9.2 by niemiro.
Start time: 2016-02-25 19:09:56.644
Microsoft Windows 7 Service Pack 1 - x86
Not using a script file.




AutoAnalysis::
FIXED: Corruption at C:\Windows\winsxs\x86_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_a1c93a736552d277\utc.app.json has been successfully repaired from C:\Windows\winsxs\x86_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_a25f4c9e7e688992\utc.app.json.
FIXED: Corruption at C:\Windows\winsxs\x86_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_a1c93a736552d277\telemetry.ASM-WindowsDefault.json has been successfully repaired from C:\Windows\winsxs\x86_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_a25f4c9e7e688992\telemetry.ASM-WindowsDefault.json.




SUMMARY: All detected corruptions were successfully repaired.
AutoAnalysis:: directive completed successfully.




Successfully processed all directives.
SFCFix version 2.4.9.2 by niemiro has completed.
Currently storing 2 datablocks.
Finish time: 2016-02-25 19:11:07.156
----------------------EOF-----------------------

Dakeyras
2016-02-26, 15:34
Hi. :)


Sorry for the delay as I have been unwell; much better now.
Not a problem and pleased you are feeling better.


SFCFix scan results
Favourable outcome, so please check if any Windows Updates(do not download any/install etc) are now detected/become available. All good merely inform myself, if not refer to the below only if Windows Updates are still not being detected.

Download/Install SURT:

Please download the installer for the System Update Readiness Tool from here (http://download.microsoft.com/download/4/7/A/47A0F7B9-1F0F-41B0-AA42-00FD16337268/Windows6.1-KB947821-v34-x86.msu) and save to the desktop.

Double-click on Windows6.1-KB947821-v34-86.msu >> follow the prompts to install.

Note: This may take some time to be processed/fully install.

alx21
2016-02-26, 21:52
The Windows Update icon on the taskbar says "new updates are available for your computer", so I checked for updates as instructed for 45 minutes, but none showed up as being available for download. So I installed SURT (Windows Update Standalone Installer) and it said "searching for updates for this updates on this computer". After 90 minutes, it said "the update is not applicable to your computer", "OK", so I clicked OK and the installer closed.

Dakeyras
2016-02-26, 23:34
Hi. :)

Try my prior advise in post #4 (https://forums.spybot.info/showthread.php?73252-Windows-won-t-update-is-it-malware&p=468827&viewfull=1#post468827) again please.

alx21
2016-02-28, 00:56
I ran the Windows Update Troubleshooter and it said:

Problems found -

Service registration is missing or corrupt - fixed.

Problems installing recent updates - fixed.

so I rebooted and the internet connection light on my router started to blink rapidly, and this is usually a strong indication that a successful connection has been made to Microsoft's Windows Update servers. However, after 2 hours nothing had been found so I discontinued the update search in case there may be a problem. When I started to have update problems the light did not blink at all when searching for updates, indicating that there was no connection to the update server. As I type this the Internet connection light is blinking rapidly as if the PC is successfully connected to the update server, although sometimes the blinking light is because the Internet Service Provider (ISP) is carrying out routine maintenance on the network.:confused:

Dakeyras
2016-02-28, 22:16
Hi. :)

I'm afraid at this juncture the best advise I can now impart is what I mentioned about in post #8 (https://forums.spybot.info/showthread.php?73252-Windows-won-t-update-is-it-malware&p=468919&viewfull=1#post468919)...

1 - Seek further support at Sysnative Windows Update (https://www.sysnative.com/forums/windows-update/). By all means include a link to this topic:

https://forums.spybot.info/showthread.php?73252-Windows-won-t-update-is-it-malwareIf you so wish.

2 - Consider a Windows 7 Repair Install (http://www.sevenforums.com/tutorials/3413-repair-install.html).

Clean-Up with DelFix:

Please download DelFix (https://toolslib.net/downloads/viewdownload/2-delfix) to your desktop.


Right-click on delfix.exe and select Run as Administrator to launch the application.
Referring to the image below, select the three options denoted:

http://i223.photobucket.com/albums/dd202/Dakeyras_album/DF2.gif


Then click on Run.
Once it has finished processing, a notepad file named DelFix.txt will open. Post the contents in your next reply for my review.
The log can also be located at the root of the system drive, C:\DelFix.txt.
After you have posted the aforementioned DelFix.txt, delete it and empty the Recycle Bin.

Note: The above application/overall process will flush old System Restore points and create a new clean one. It should also clean up and remove the vast majority of scanners used and logs created etc.

Any left over merely delete yourself and empty the Recycle Bin.

Now some advice for on-line safety:

The below is worth reading/bookmarking for future referance:

Computer Security - a short guide to staying safer online (http://www.malwareremoval.com/forum/viewtopic.php?f=4&t=54766)

Next:

Any questions? Feel free to ask, if not stay safe!

alx21
2016-02-29, 17:41
Hi Dakeyras

Thanks for the pointers, and many, many thanks for your help and patience. :thanks:

Dakeyras
2016-02-29, 22:09
Acknowledged and you're most welcome!

Regardless which ever option you decide upon, do ensure you download and run DelFix etc. :)

Dakeyras
2016-03-02, 18:22
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh set of both awsMBR and FRST logs plus a link to your previous thread.

If it has been less than three days since your last response and you need the thread re-opened, please send a private message (pm). A valid, working link to the closed topic is required.