Good morning
Have you run the AdwCleaner scan?
How is the computer at the moment?
Good morning
Have you run the AdwCleaner scan?
How is the computer at the moment?
Windows Insider MVP Consumer Security 2009 - 2017
Please do not PM me for Malware help, we all benefit from posting on the open board.
aswMBR version 1.0.1.2252 Copyright(c) 2014 AVAST Software
Run date: 2022-09-27 17:12:46
-----------------------------
17:12:46.941 OS Version: Windows x64 6.2.9200
17:12:46.942 Number of processors: 8 586 0x1801
17:12:46.944 ComputerName: CRAPTOP UserName: 14153
17:12:48.080 Initialize success
17:12:48.154 VM: initialized successfully
17:12:48.156 VM: Amd CPU supported
17:14:14.120 The log file has been saved successfully to "C:\Users\14153\Desktop\aswMBR.txt"
ITS WORKING pretty6 good but ther keyboard keeps **** up every once in a while b but that could just be the hardware and not that.
Last edited by tashi; 2022-09-28 at 00:11. Reason: ****
Good, typically hardware or batteries for a wireless mouse.
Malwarebytes AdwCleaner
-------------------
The below is the Adwcleaner scan
- Please download AdwCleaner and save it to your Desktop
- Close all open programs and browsers
Double click AdwCleaner.exe to run it.
Click Scan Now ...
When the scan has finished a Scan Results window will open.
Click Cancel (at this point do not attempt to Quarantine anything that is found)
Now click the Log Files tab ...
Double click on the latest scan log (Scan logs have a [S0*] suffix, where * is replaced by a number, the latest scan will have the largest number)
A Notepad file will open containing the results of the scan.
Please post the contents of the file in your next reply.
Windows Insider MVP Consumer Security 2009 - 2017
Please do not PM me for Malware help, we all benefit from posting on the open board.
# -------------------------------
# Malwarebytes AdwCleaner 8.4.0.0
# -------------------------------
# Build: 08-30-2022
# Database: 2022-08-22.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 09-27-2022
# Duration: 00:00:15
# OS: Windows 11 (Build 22000.1042)
# Scanned: 32098
# Detected: 23
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
PUP.Optional.SysTweak C:\Users\14153\AppData\Roaming\Systweak
***** [ Files ] *****
No malicious files found.
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
PUP.Optional.Legacy HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}
PUP.Optional.Legacy HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
PUP.Optional.Legacy HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
PUP.Optional.Legacy HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
PUP.Optional.Legacy HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Hosts File Entries ] *****
No malicious hosts file entries found.
***** [ Preinstalled Software ] *****
Preinstalled.HPAudioSwitch Folder C:\Program Files (x86)\HP\HPAUDIOSWITCH
Preinstalled.HPCleanFLC Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|HPSEU_Host_Launcher
Preinstalled.HPCleanFLC Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run|HPSEU_Host_Launcher
Preinstalled.HPRegistrationService Folder C:\ProgramData\HP\HP REGISTRATION SERVICE
Preinstalled.HPSupportAssistant Folder C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Preinstalled.HPSupportAssistant Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSureConnect Folder C:\Program Files\HPCOMMRECOVERY
Preinstalled.HPSureConnect Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6468C4A5-E47E-405F-B675-A70A70983EA6}
Preinstalled.HPTouchpointAnalyticsClient Folder C:\ProgramData\HP\HP TOUCHPOINT ANALYTICS CLIENT
Preinstalled.HPTouchpointAnalyticsClient Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}
AdwCleaner[S00].txt - [4181 octets] - [27/09/2022 19:07:22]
AdwCleaner[S01].txt - [4242 octets] - [27/09/2022 19:12:25]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S02].txt ##########
[b
[/B]
The scan found quite a bit of preinstalled items. If you don't use these things, many people don't, you can open the tool and run the tool again and remove those off your machine.
From here I usually have people run an online scan to look for remnants but if your computer is doing good at this point I'll leave it up to you if you want to or not or we can remove tools and quarantine folders.
ESET Online Scanner
--------------------
Note: You can expect this process to take a long time, up to several hours or more.===================================================
- Download ESET Free Online Scanner and save it to your Desktop
- Right click on esetonlinescanner_enu.exe and select Run as administrator
- Click Computer Scan
- Click Full scan
- Select Enable ESET to detect and quarantine potentially unwanted applications
- Click Start scan
- Once completed click Save scan log and save it to your Desktop as ESETScan.txt
- Click Continue then finally click Close
- Copy and paste the ESETScan.txt file contents in your reply
Windows Insider MVP Consumer Security 2009 - 2017
Please do not PM me for Malware help, we all benefit from posting on the open board.
Use this tool to remove quarantined items:
Please download KpRm by Kernel-panik and save to your Desktop.
- Click on KpRm.exe to run the tool.
Vista/Windows 7/8/10 users right-click and select Run As Administrator.
- Put a check mark next to these items:
- Delete tools
- Delete now
- Click the "Run" button.
- When the tool has finished, it will create and open a log report and delete itself.
Windows Insider MVP Consumer Security 2009 - 2017
Please do not PM me for Malware help, we all benefit from posting on the open board.