New
#21
Quick correction - I'm not using Chrome. KP
Quick correction - I'm not using Chrome. KP
You should remove all,
The site/ s will install new ones next time you visit/ sign in...
These type of harmless cookies build up and make browsers slow
Run eset and report back,
Cheers.
I ran ESET late last night, got tired of waiting for it to finish and went to bed. After scanning 37%, it had found 41 problem files.
Got up this morning, checked the PC, and couldn't find any sign that it had run. ESET was gone.
So what does it do when it finishes, disappears? I thought I'd get a report or something.
KP
The path to the log file is "C:\Program Files (x86)\ESET\EsetOnlineScanner\log.txt"
Please attach the ESET log to a post (use the paperclip icon on the post window menu bar)
Since ESET found a bunch more, please run another on demand scanner. This is a scan only - it will not clean any malware at this point. FRST is very thorough and if it finds anything, I'll need to ask for help from members of the SF security team. They know how to remediate malware using FRST.
Download the Farbar Recovery Scan Tool (FRST) Click here
- Select the version that applies to your system: 32-bit OR 64-bit
.- Click the Save button
Default save location is your Downloads folder
If the SmartFilter bar is presented, click the Actions button and click Don't Run (saves FRST but does not run it)
.- Double-click FRST or FRST64 to launch the utility
FRST is the 32-bit version / FRST64 is the 64-bit version
- Click the Yes button to confirm UAC
.- Click the Yes button on the Warranty disclaimer window.
.- Tick [a] all Whitelist checkboxes
.- Tick [a] Addition.txt in the Optional scan list
.- Click the Scan button to begin scanning.
.- FRST creates two logs when the scan has finished, they are located in the same folder where FRST was launched
- FRST.txt and
- Addition.txt
- Attach both logs to a post on your thread and a SevenForums member will analyze the output.
See: Screenshots and Files - Upload and Post in Seven Forums
Thanks
Enjoy!
Have fun!
K3yP1ayer
Please download http://www.bleepingcomputer.com/down...-tool/Junkware Removal Tool to your desktop.
- Shut down your protection software now to avoid potential conflicts.
- Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
- The tool will open and start scanning your system.
- Please be patient as this can take a while to complete depending on your system's specifications.
- On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
- Post the contents of JRT.txt into your next message.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Vernon on Thu 07/03/2014 at 22:54:36.94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\msntask_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\msntask_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\softonic-us-silent-2_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\softonic-us-silent-2_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\msntask_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\msntask_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\softonic-us-silent-2_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\softonic-us-silent-2_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ABD3B5E1-B268-407B-A150-2641DAB8D898}
~~~ Files
Successfully deleted: [File] "C:\Windows\Tasks\driver robot.job"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\pc1data"
Successfully deleted: [Folder] "C:\Users\Vernon\AppData\Roaming\getrighttogo"
Successfully deleted: [Folder] "C:\Program Files (x86)\Common Files\homepage protection"
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{0168461C-C66A-4B12-9433-238681FF7AC1}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{05CD32AB-00B2-4D03-BBA0-E63C064CA667}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{0E9A29C7-ACCD-4967-A291-9ED9D4E8B95F}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{0EAC6C0F-38D1-4087-9D0B-16B335BCEDCB}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{1CAA3ECC-9662-4F59-ACB9-A015FDE33922}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{55E43807-3894-47B6-BABD-27CE10CE59A9}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{6793885D-18C5-47F5-ACAB-60E738C4E401}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{856A1986-5E60-4DC3-B7ED-490CE5A077F4}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{8A45A695-6134-48A3-B0B9-99ECE5A270D9}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{A5ED9C69-E062-4638-A214-D8431740A450}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{B07DA9AF-A1CA-48C3-B71D-4C2E600E73D9}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{B15DFFED-C6D8-45E4-A419-0745D5E8BF9F}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{BDABD5B6-431E-4321-9D1C-47CACA62D01B}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{C4587529-C584-4B27-B237-DE3EB15291FF}
Successfully deleted: [Empty Folder] C:\Users\Vernon\appdata\local\{E04D7FCA-394C-4552-AFDF-70F5E73A53F0}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 07/03/2014 at 23:01:49.96
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Run TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forum and save it to your desktop.
Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.
REBOOT!
Tell me how your computer is running now.
my PC is running as fast as it did when it was brand-new.
Thanks for the help. TFC removed 426Mb of temp files in about 5 minutes.
KP