View Full Version : Toshiba Satellite with Windows 10 has Virus

2017-10-11, 05:01
Hello! My computer has a virus (maybe several). I believe it has been on my computer for some time, but an alert recently appeared via Semantic Endpoint Protection that I am infected with the Trojan.Gen.2 virus. According to my computer, it is quarantined, but I am getting several popup messages that could be from the virus and my computer is incredibly slow. I am concerned about my information being compromised and the someone remotely accessing my computer using the virus. I am also concerned that my files on the computer are compromised and I am afraid to back them up onto my hard drive lest I spread the virus there.

Here is my FARBAR LOG:
2017-10-11, 13:38
Symantec Endpoint Protection <== does this supply antivirus protection as in security suite?
AVAST <== is an antivirus

If the computer has 2 antivirus, need to make a decision which to keep and which to uninstall.

Right click on the FRST icon and select Run as administrator
Highlight the below information then hit the Ctrl + C keys at the same time
Right click/highlight on the text below and select Copy.
beginning with Start:: and finishing with End::

HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
SearchScopes: HKU\S-1-5-21-2005569905-2985736349-4029353856-1001 -> {5A12A81B-0662-4DA4-93C5-CC96CA9431CB} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=B011US1214D20150816&p={SearchTerms}
SearchScopes: HKU\S-1-5-21-2005569905-2985736349-4029353856-1001 -> {B64FF99D-D9DC-4CC2-AED0-7586853EF92D} URL =
U3 aswbdisk; no ImagePath
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: Bitsadmin /Reset /Allusers

Press the Fix button.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


Malwarebytes version <== Your version is outdated

Open Malwarebytes Anti-Malware
Look for and click on the Update button
Allow it to update

Once the database update is complete, click on the Scan tab, then select the Threat Scan button and click on Start Scan
Let the scan run, the time required to complete the scan depends of your system and computer specs
Once the scan is complete, make sure that the first checkbox at the top is checked (which will automatically check every detected item), then click on the Quarantine Selected button

If it asks you to restart your computer to complete the removal, do so

Click on Export Summary after the deletion (in the bottom-left corner) and select Copy to Clipboard. Paste the content in your next reply


Follow the instructions below please.

http://i.imgur.com/zcMPezJ.pngAdwCleaner - Fix Mode

Download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/dl/125/) and move it to your Desktop
Right-click on AdwCleaner.exe and select http://i.imgur.com/Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
Accept the EULA (I accept), then click on Scan
Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button. This will kill all active processes
Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply

created by Aura
http://i.imgur.com/iT103hr.pngJunkware Removal Tool (JRT)

Download Junkware Removal Tool (JRT) (http://www.bleepingcomputer.com/download/junkware-removal-tool/dl/131/) and move it to your Desktop
Right-click on JRT.exe and select http://i.imgur.com/Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
Press on any key to launch the scan and let it complete
Credits : BleepingComputer.com
Once the scan is complete, a log will open. Please copy/paste the content of the output log in your next reply

created by Aura

Your next reply(ies) should therefore contain:

Copy/pasted AdwCleaner clean log
Copy/pasted JRT log

2017-10-12, 07:52

Fix result of Farbar Recovery Scan Tool (x64) Version: 11-10-2017
Ran by Imogen (12-10-2017 01:13:27) Run:2
Running from C:\Users\Imogen\Downloads
Loaded Profiles: Imogen (Available Profiles: Imogen)
Boot Mode: Normal

fixlist content:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
SearchScopes: HKU\S-1-5-21-2005569905-2985736349-4029353856-1001 -> {5A12A81B-0662-4DA4-93C5-CC96CA9431CB} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=B011US1214D20150816&p={SearchTerms}
SearchScopes: HKU\S-1-5-21-2005569905-2985736349-4029353856-1001 -> {B64FF99D-D9DC-4CC2-AED0-7586853EF92D} URL =
U3 aswbdisk; no ImagePath
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: Bitsadmin /Reset /Allusers


Processes closed successfully.
Restore point was successfully created.
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
HKU\S-1-5-21-2005569905-2985736349-4029353856-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5A12A81B-0662-4DA4-93C5-CC96CA9431CB} => key removed successfully
HKLM\Software\Classes\CLSID\{5A12A81B-0662-4DA4-93C5-CC96CA9431CB} => key not found.
HKU\S-1-5-21-2005569905-2985736349-4029353856-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B64FF99D-D9DC-4CC2-AED0-7586853EF92D} => key removed successfully
HKLM\Software\Classes\CLSID\{B64FF99D-D9DC-4CC2-AED0-7586853EF92D} => key not found.
HKLM\System\CurrentControlSet\Services\aswbdisk => key could not remove, key could be protected
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => key removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => key not found.

========= netsh advfirewall reset =========


========= End of CMD: =========

========= netsh advfirewall set allprofiles state ON =========


========= End of CMD: =========

========= ipconfig /flushdns =========

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

========= netsh winsock reset catalog =========

Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.

========= End of CMD: =========

========= Bitsadmin /Reset /Allusers =========

BITSADMIN version 3.0 [ 7.8.10586 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to cancel {E539BCAD-9628-4BA9-9850-5A8A5415B05C}.
0 out of 1 jobs canceled.

========= End of CMD: =========

=========== EmptyTemp: ==========

BITS transfer queue => 32768 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 1169735461 B
Java, Flash, Steam htmlcache => 1310 B
Windows/system/drivers => 257332927 B
Edge => 9451680 B
Chrome => 903682796 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 3416 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 36384 B
NetworkService => -656 B
Imogen => 1019399480 B

RecycleBin => 0 B
EmptyTemp: => 3.1 GB temporary data Removed.


Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 12-10-2017 01:21:24)

Result of scheduled keys to remove after reboot:

HKLM\System\CurrentControlSet\Services\aswbdisk => key could not remove, key could be protected

==== End of Fixlog 01:21:25 ====

AdwCleaner Log:

# AdwCleaner - Logfile created on Thu Oct 12 05:38:54 2017
# Updated on 2017/29/09 by Malwarebytes
# Running on Windows 10 Home (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

Deleted: C:\Users\All Users\Desktop\eBay.lnk
Deleted: C:\Users\Public\Desktop\eBay.lnk

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

No malicious registry entries deleted.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.


::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0


C:/AdwCleaner/AdwCleaner[S0].txt - [1033 B] - [2017/10/12 5:37:48]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########

JRT Log:

Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64
Ran by Imogen (Administrator) on Thu 10/12/2017 at 1:42:30.46

File System: 0

Registry: 0

Scan was completed on Thu 10/12/2017 at 1:45:43.46
End of JRT log

2017-10-12, 13:00
Did you update and run a scan with MalwareBytes?

http://i.imgur.com/G0tu5D9.pngEmsisoft Emergency Kit - Fix Mode
Follow the instructions below to run a scan using the Emsisoft Emergency Kit.

Download the Emsisoft Emergency Kit (https://www.emsisoft.com/en/software/eek/download/) and execute it. From there, click on the Install button to extract the program in the EEK folder;
Once the extraction is complete, the EEK folder will open. Right-click on http://i.imgur.com/G0tu5D9.pngstart emergency kit scanner.exe and select http://i.imgur.com/Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
After the restart, open EEK again (in the C:\EEK folder);
This time, click on Logs;
From there, go under the Quarantine Log tab, and click on the Export button;
Save the log on your desktop, then open it, and copy/paste its content in your next reply;

created by Aura

2017-10-13, 01:55
I did update and run a scan with Malwarebytes--- nothing came up. Here it is though (ran yesterday):


-Log Details-
Scan Date: 10/12/17
Scan Time: 1:26 AM
Log File: Malwarebytes.txt
Administrator: Yes

-Software Information-
Components Version: 1.0.160
Update Package Version: 1.0.2996
License: Free

-System Information-
OS: Windows 10 (Build 10586.1176)
CPU: x64
File System: NTFS

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 375593
Threats Detected: 0
(No malicious items detected)
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 6 min, 27 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)


Also, nothing came up on the EEK scan either, but my computer is still very slow and I find it difficult to believe that the virus that showed up on my Symantec (an app which I deleted in favor of keeping avast) just up and left.

EEK scan:
Emsisoft Emergency Kit - Version 2017.8
Last update: 10/12/2017 7:45:36 PM
User account: IMOGENCOMPUTER\Imogen
OS version: Windows 10x64

Scan settings:

Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files

Detect PUPs: On
Scan archives: Off
Scan mail archives: Off
ADS Scan: On
File extension filter: Off
Direct disk access: Off

Scan start: 10/12/2017 7:46:03 PM

Scanned 81011
Found 0

Scan end: 10/12/2017 7:50:52 PM
Scan time: 0:04:49

2017-10-13, 12:34
I have no idea where it went.

As for the computer moving slow
Let's check and see if there is a problem with updates

Check for and Install Windows Updates


Please Download Tweaking.com - Windows Repair from Here (http://www.tweaking.com/content/page/windows_repair_all_in_one.html)
Windows Repair (all in one) from here (http://www.bleepingcomputer.com/download/windows-repair-all-in-one-portable/).

Install and then run the program
Execute the instructions on Step 1 Important
Click Next on Step 2 Optional, do the Pre Scan skip Step 3 and 4 Optional for now.
On Step 5 Backup System Restore Do a Registry backup. When you have completed this click Next
Click Repairs - Open Repairs in the bottom right corner
Uncheck the All repair button then select just the item(s) listed below

01 - Repair Registry Permissions
03 - Reset Service permissions
04 - Register System Files
05 - Repair WMI
06 - Repair Windows Firewall
07 - Repair Internet Explorer
10 - Remove Policies Set By Infections
17 - Repair Windows Updates
19 - Repair Volume Shadow Copy Service
21 - Repair MSI (Windows Installer)
26 - Restore Important Windows Services
27 - Set Windows Service to Default Startup

Click the Start button and let the process run to completion. Copy any error messages into Notepad, Save it on your Desktop. ( Reboot if asked to do so)
Please copy and paste the Contents of this file on your next reply.

Restart the computer normally.

2017-10-17, 05:47
Hi, I haven't done the next steps yet--- I just wanted to check in about the 'Proper Power Reset' ---- according to the directions I have to remove the battery from my laptop. Is this true (it's just not an easy step for me as I'm at school and I don't have a screwdriver to remove the panel that keeps the battery in)?

2017-10-17, 11:35
I dont know anything about 'Proper Power Reset
I posted information on how to check for windows updates manually. On the link I supplied, scroll to the area 'Here's How:'

Did you run Windows Repair (all in one)?

2017-10-18, 06:25
The version I downloaded from the link provided (the second one, from Tweaking) doesn't offer a run button---- instead it gives steps that I'm supposed to run by myself (Including Proper Power Reset).

Part of the issue on my windows updates is that there's a problem updating. I definitely have apps that need updating, but the updates are never able to finish and never update automatically, even though they are set to do so.

2017-10-18, 11:18
Delete the version of All In One you have now, we'll try the download from a difference place.

Windows Repair (all in one) from here (http://www.bleepingcomputer.com/download/windows-repair-all-in-one-portable/).

Install and then run the program
Execute the instructions on Step 1 Important
Click Next on Step 2 Optional, do the Pre Scan skip Step 3 and 4 Optional for now.
On Step 5 Backup System Restore Do a Registry backup. When you have completed this click Next
Click Repairs - Open Repairs in the bottom right corner
Uncheck the All repair button then select just the item(s) listed below

01 - Repair Registry Permissions
03 - Reset Service permissions
04 - Register System Files
05 - Repair WMI
06 - Repair Windows Firewall
07 - Repair Internet Explorer
10 - Remove Policies Set By Infections
17 - Repair Windows Updates
19 - Repair Volume Shadow Copy Service
21 - Repair MSI (Windows Installer)
26 - Restore Important Windows Services
27 - Set Windows Service to Default Startup

Click the Start button and let the process run to completion. Copy any error messages into Notepad, Save it on your Desktop. ( Reboot if asked to do so)
Please copy and paste the Contents of this file on your next reply.

Restart the computer normally.

2017-10-27, 12:39
Still need help?

2017-11-05, 11:11
Since this issue appears resolved ... this Topic is closed.