New
#91
Here is the latest SysLook report.
Here is the latest SysLook report.
Let's give this a whirl...
Please open Notepad and paste the following text to it:
In Notepad, click File > Save as...Code:[HKEY_LOCAL_MACHINE\SOFTWARE\Dyn\Installed] "PureLeads"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\PureLeads]
Save the file to the Desktop
File name: PLfix2.reg
Make sure the Save as Type field says: All Files
Next, please go to the Desktop and double-click on PLfix2.reg
Click Yes to merge it in the Registry.
Now, please go back to Control Panel > Folder Options
Select: Show hidden files, folders, and drives
Uncheck: Hide protected operating system files
Please search for and remove the following folder:
C:\Program Files (x86)\PureLead
The following files:
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\plsapp64.lnk
...and let's see if we can remove this one:
C:\System Volume Information\SystemRestore\FRStaging\Windows\System32\plsapp64.dll
But, you need to open a Command Prompt as Administrator
At the Command Prompt:
Type: CD \
At the C:\ prompt, copy/paste with mouse:
takeown /f "C:\System Volume Information\SystemRestore\FRStaging\Windows\System32\plsapp64.dll"
Now, run the cacls command to give yourself full control rights to the file:
cacls "C:\System Volume Information\SystemRestore\FRStaging\Windows\System32\plsapp64.dll" /G user:F
The last part of the command needs the user name. I think in your case it is user??
When done, use SystemLook once gain, and provide the results.
When I tried to merge, this is what popped up.
The only one of those files I could find was the last one. The other ones were not able to be located by Windows or manually.
Image of file directory and latest syslook results.
Oooops!!
Brains are dense today! Sorry for the goof!!Code:REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Dyn\Installed] "PureLeads"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\PureLeads]
Which file did you find and remove?The only one of those files I could find was the last one.
Please use SystemLook once again, after doing the Registry merge above.
Thanks!
@ ChronicX, we see you have run Combofix..... can you find and post the log from
C:\Qoobox combofix.txt? please. Just copy and paste it in your next reply.
Hey, Cotton, sorry for the silence, real life always gets in the way. I will run the tests now. The image is of the path of the file I thought I'd deleted but as you can see it is still there. I manually deleted it but it's a sticky one apparently. The other files just were flat not located. Hope you are having a great day!
Hello, CX!
Heading for a Doctor's appt. and a few other things in a few minutes, so, will get back here later.
Please post some new results for SystemLook when you are done.
Please, do copy and paste them right on this thread, vs. attaching the results. Will be using my tablet while waiting, and it is easier to just look at the results on the tablet.
Thanks!