Page 3 of 3 FirstFirst 123
Results 21 to 27 of 27

Thread: unwanted games windows

  1. #21
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Good deal

    C:\Program Files\Avira\AntiVir Desktop\offercast_avirav7_.exe a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application
    You have Avira, which bundles the Ask toolbar, so that can be left alone.


    Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
    Paste this into the open notepad. save it to the Desktop as fixlist.txt
    NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
    It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)

    start
    C:\Documents and Settings\millam\Application Data\Mozilla\Firefox\Profiles\nlv5wxzw.default\extensions\firefox@lemurleap.info\chrome\content\overlay.js
    C:\Documents and Settings\millam\My Documents\Downloads\ccsetup412(1).exe
    C:\Documents and Settings\millam\My Documents\Downloads\ccsetup412.exe
    C:\Documents and Settings\millam\My Documents\Downloads\code_calculator_by_cybergsm_v5_4_rapidshare_downloader.exe
    Reboot:
    end
    Run FRST/FRST64 and press the Fix button just once and wait.
    If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
    When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


    How's the computer now?
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  2. #22
    Member
    Join Date
    Sep 2008
    Location
    portsmouth
    Posts
    61

    Default

    hi Juliet
    still going fine. The only thing that gets me now is an "image" named in Task Manager "mbamservice.exe" uses my hard drive and most of the memory just as I was about to run FRST
    I think its mlwarebytes updating but I wish they would give us an indication as to what they are doing, I noticed avira does the same think sometime you aventually get a popup telling you its updated a bit late then.

    anyway thank you for your thoroughness if you are employed your employer is lucky to have you.

    I wish XP was around a lot longer. I have just found out my only DVD reader/writer does not like my windows 7 DVD. It must be one of those picky ones that don't like + or - disks, I will have to find out which and get my son to send me one it likes. I have a hard drive with windows 7 on it but for a very different machine, might just try fitting it and seeing what happens.

    anyway here is the logfile.


    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01
    Ran by millam at 2014-04-02 21:55:44 Run:2
    Running from C:\Documents and Settings\millam\Desktop
    Boot Mode: Normal

    ==============================================

    Content of fixlist:
    *****************
    start
    C:\Documents and Settings\millam\Application Data\Mozilla\Firefox\Profiles\nlv5wxzw.default\extensions\firefox@lemurleap.info\chrome\content\overlay.js
    C:\Documents and Settings\millam\My Documents\Downloads\ccsetup412(1).exe
    C:\Documents and Settings\millam\My Documents\Downloads\ccsetup412.exe
    C:\Documents and Settings\millam\My Documents\Downloads\code_calculator_by_cybergsm_v5_4_rapidshare_downloader.exe
    Reboot:
    end
    *****************

    C:\Documents and Settings\millam\Application Data\Mozilla\Firefox\Profiles\nlv5wxzw.default\extensions\firefox@lemurleap.info\chrome\content\overlay.js => Moved successfully.
    C:\Documents and Settings\millam\My Documents\Downloads\ccsetup412(1).exe => Moved successfully.
    C:\Documents and Settings\millam\My Documents\Downloads\ccsetup412.exe => Moved successfully.
    C:\Documents and Settings\millam\My Documents\Downloads\code_calculator_by_cybergsm_v5_4_rapidshare_downloader.exe => Moved successfully.


    The system needed a reboot.

    ==== End of Fixlog ====

  3. #23
    Member
    Join Date
    Sep 2008
    Location
    portsmouth
    Posts
    61

    Default

    Hi Juliet

    Sorry past my bet time us OAP's need our shut eye. will check again in the morning.

  4. #24
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Quote Originally Posted by bobbym View Post
    Hi Juliet

    Sorry past my bet time us OAP's need our shut eye. will check again in the morning.
    LOL
    Mine is coming soon.

    About the only way to be rid of the tools updating is to remove the tools....But you can't do without an antivirus and actually having layered security is what you want.
    MBAM seemingly does run quick, as least mine appears to. As for Antivirus. Microsoft Security Essentials mostly runs quietly in the back ground but when it updates it will hog resources for a short time like the others.
    It's never a win - win situation.

    OK, let's remove tools and quarantine folders and send you on your way.

    ****************

    Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
    Paste this into the open notepad. save it to the Desktop as fixlist.txt
    NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.

    Run FRST/FRST64 and press the Fix button just once and wait.
    no needed to post the log this time.


    start
    DeleteQuarantine:
    end
    ***********

    1. Download Delfix from here
    2. Ensure Remove disinfection tools is ticked
      Also tick:
      • Create registry backup
      • Purge system restore


    3. Click Run



    Any other tools and files found can simply be deleted or uninstall via Add/Remove Programs in the Control Panel etc.

    ***********************

    Your good to go, good job!

    Please take the time to read over a few of my preventive tips.

    Computer Security
    http://malwareremoval.com/forum/view...557960#p557960
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Be prepared for CryptoLocker:

    Cryptolocker Ransomware: What You Need To Know

    CryptoLocker Ransomware Information Guide and FAQ

    to help protect your computer in the future I recommend that you get the following free programmes:

    CryptoPrevent install this programme to lock down and prevent crypto ransome ware



    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Please navigate to Microsoft Windows Updates and download all the "Critical Updates" for Windows.


    Firefox 3
    The award-winning Web browser is now faster, more secure, and fully customizable to your online life. With Firefox 3, added powerful new features that make your online experience even better. It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
    *NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

    AdblockPlus
    • AdblockPlus, Surf the web without annoying ads!
    • Blocks banners, pop-ups and video ads - even on Facebook and YouTube
    • Protects your online privacy
    • Two-click installation, It's free!
    • click the icon that corresponds to your browser and download.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    WOT Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites - green to go, yellow for caution and red to stop, helping you avoid the dangerous sites. WOT has an addon available for both Firefox and IE.
    • Green should be good to go
    • Yellow for caution
    • Red to stop




    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    How to prevent Malware: Created by Miekiemoes


    WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
    See this article (http://www.forbes.com/sites/eliseack...-disable-java/
    and this article (http://www.nbcnews.com/technology/te...late-1B7938755

    I would recommend that you completely uninstall Java unless you need it to run an important software.
    In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser (http://www.geekstogo.com/2600/how-to...r-web-browser/) and How to unplug Java from the browser (http://krebsonsecurity.com/how-to-un...m-the-browser/))


    Avoid P2P

    P2P may be a great way to get lots of stuffs, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well.

    Please read these short reports on the dangers of peer-2-peer programs and file sharing.

    *********************************************
    Please read the following safe computing articles..

    Secure My Computer: A Layered Approach


    Free Antivirus-AntiSpyware-Firewall Software
    Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #25
    Member
    Join Date
    Sep 2008
    Location
    portsmouth
    Posts
    61

    Default

    hi Juliet

    have done what you asked. Thanks for the tips as well, I will share that information with my son and daughter.

    thanks again for all your help much appreciated.

  6. #26
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Happy to Help
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  7. #27
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Glad we could help.

    Since this issue appears resolved ... this Topic is closed.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •