I'm back and need help

Status
Not open for further replies.
for some reason spybot keeps scanning things and i keep getting pop ups on scans from live protection. i have to go in settings and deactivate it to stop it, then it shows i have partial coverage, is that ok? plus after spybot scans and i close it i get the run time error window. windows keeps prompting me spybot isn't running and to turn it on or choose an av to use.
I can see why but I don't know why. At the end of the FRST logs you can see many errors related to SpyBot

Description: Faulting application name: SDFSSvc.exe
Faulting application path: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
Description: Faulting application name: SDWelcome.exe
Faulting application name: SDSettings.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\rtl150.bpl
Description: Faulting application name: SDOnAccess.exe

The above are just a few. Is this something you can uninstall and reinstall?

Java 8 Update 112 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180112F0}) (Version: 8.0.1120.15 - Oracle Corporation)
The above needs to be uninstalled, very outdated.
~~~~~

Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


FRSTfix.JPG



start
CreateRestorePoint:
CloseProcesses:
ProxyEnable: [S-1-5-21-2107755742-302254199-1763176924-1001] => Proxy is enabled.
ProxyServer: [S-1-5-21-2107755742-302254199-1763176924-1001] => localhost:21320
ManualProxies: 1localhost:21320
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
C:\Users\Dad\SDAV.dll
Task: {0642325B-D49D-4797-BC3D-2F56533546BB} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
EmptyTemp:
End

Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
 
ok i uninstalled the java 112 update and ran the scan
Fix result of Farbar Recovery Scan Tool (x64) Version: 18-01-2017
Ran by Dad (20-01-2017 20:14:55) Run:2
Running from C:\Users\Dad\Desktop
Loaded Profiles: Dad (Available Profiles: Dad & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
ProxyEnable: [S-1-5-21-2107755742-302254199-1763176924-1001] => Proxy is enabled.
ProxyServer: [S-1-5-21-2107755742-302254199-1763176924-1001] => localhost:21320
ManualProxies: 1localhost:21320
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
C:\Users\Dad\SDAV.dll
Task: {0642325B-D49D-4797-BC3D-2F56533546BB} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => value removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
C:\Users\Dad\SDAV.dll => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0642325B-D49D-4797-BC3D-2F56533546BB} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0642325B-D49D-4797-BC3D-2F56533546BB} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask => key removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 308208 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 49085326 B
Java, Flash, Steam htmlcache => 17556 B
Windows/system/drivers => 361584 B
Edge => 0 B
Chrome => 0 B
Firefox => 373194841 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 8262 B
NetworkService => 0 B
Dad => 90556831 B
DefaultAppPool => 0 B

RecycleBin => 11540200 B
EmptyTemp: => 500.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:16:02 ====
 
it is doing far far better. a slow page now and then basically. i'm concerned about my spybot purchase with it doing things it hasn't. i purchased it here, can i uninstall it and reinstall it? thanks...or let me knoqw what i need to do

rb
 
I've inquired for the correct forum to send you to to see what the next step is.
 
ok, last night i ran spybot and this morning i got a prompt a problem occurred in BitDefender threat scanner and a file was created with that info. i can see the file at the location, just let me know what to do.
 
OK
This error is being reported through Spybot Search and Destroy having a problem itself.
It uses BitDefender....

Let's remove tools used and quarantine folders.

  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • -- This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
***************

Then I want you to post/start a new topic here
https://forums.spybot.info/forumdisplay.php?4-Spybot

If you would, supply this information too;
got a prompt a problem occurred in BitDefender threat scanner and a file was created with that info.
 
juliet i started the thread, if you see this before the thread can you tell me how to pull that file and get it here for review? it's a dmp file
 
juliet i did as you said and tashi took me right in! i just wanted to thank you again with all you did...you're the greatest! :oreo:: thanks:thanks again!
:present:
rb
 
Glad we could help.
Since this issue appears resolved ... this Topic is closed.
 
Status
Not open for further replies.
Back
Top