Solved error code 0x8000FFFF

Just for future reference, if you have an actual error code, plug it into bing or your search engine of choice, and you will soon know what it's all about.
 

My Computer

Computer Manufacturer/Model Number
Compaq Presario SR5518F (desktop)
OS
Windows 7 Home Premium 64bit
CPU
Intel Pentium Dual Core E2180 @2GHz
Motherboard
MSI "Boston"
Memory
4 GB
Graphics Card(s)
NVIDIA GeForce 8500 GT
Sound Card
Integrated - Realtek High Definition Audio
Monitor(s) Displays
Acer
Hard Drives
Hitachi HDP725025GLA380 ATA Device
Optiarc DVD RW AD-7201S5 ATA Device
Internet Speed
5 Mbps
Lets wait for Jacee to look into things first...I have messaged her to have a look for you.

In my opinion MSE and Malwarebytes is fine - it works for me.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Looks like 'adware' ....

Download DDS from one of these links:
DDS.com


DDS.pif
  • Disable any script blocking protection (anti-virus, etc)
  • Double click the dds icon to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt <--- will be minimized in the task tray
  • Save both reports to your desktop.
Include the contents of both logs in your next post. Please don't .ZIP! The scan will instruct you to post Attach.txt as an attachment.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi here are the DDS reports you requested.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64-Bit SP1
CPU
Intel Core i7 2600
Motherboard
Lenovo
Memory
8.00 GB Dual-Channel DDR3
Graphics Card(s)
1024MB GeForce GT 420
Sound Card
Intergrated Realtex ALC888S
Monitor(s) Displays
LG W40 series Widescreen
Screen Resolution
1920 by 1080 widescreen
Hard Drives
932GB Hitachi HDS TB
External drive 640 GB also
PSU
300W
Case
Tower
Cooling
yes came installed
Keyboard
Lenovo
Mouse
Laser wirless 5000
Antivirus
MBAM / Superantispyware pro paid for.
Browser
Google /
Other Info
PLDS DVD-RW DH16ABSH
I ran Mlwarebytes again and saved it to my desktop. it came back with more torjan's. I saved it as a text.file and will upload it as a text file. I had malwarebytes delete the Trojans but it will show in the text.file.

I hope these files will help with getting to the bottom of some of the problems with my system.

Jacee I am glad to see you are still here it has been about 3 years or so since I have been on the forum and so very much appreciate you looking at my problem and Golden you are great also as I know you have worked hard on this for me.

Golden and Jacee thank you so very much for hanging in there for me.

Americancritic...
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64-Bit SP1
CPU
Intel Core i7 2600
Motherboard
Lenovo
Memory
8.00 GB Dual-Channel DDR3
Graphics Card(s)
1024MB GeForce GT 420
Sound Card
Intergrated Realtex ALC888S
Monitor(s) Displays
LG W40 series Widescreen
Screen Resolution
1920 by 1080 widescreen
Hard Drives
932GB Hitachi HDS TB
External drive 640 GB also
PSU
300W
Case
Tower
Cooling
yes came installed
Keyboard
Lenovo
Mouse
Laser wirless 5000
Antivirus
MBAM / Superantispyware pro paid for.
Browser
Google /
Other Info
PLDS DVD-RW DH16ABSH
Okay, Looks like you have Trojan.Sirefef.C, which is a backdoor Trojan.
Trojan:Win32/Sirefef.C is the detection for a component of the Win32/Sirefef family- a multi-component family of malware that moderates your Internet experience by changing search results and generating pay-per-click advertising revenue for its controllers. The family consists of multiple parts that perform different functions, such as downloading updates and additional components, hiding existing components, or performing a payload.
]

These are the most dangerous, and most widespread, type of Trojan.
Backdoor Trojans provide the author or ‘master’ of the Trojan with remote ‘administration’ of victim machines. Unlike legitimate remote administration utilities, they install, launch and run invisibly, without the consent or knowledge of the user. Once installed, backdoor Trojans can be instructed to send, receive, execute and delete files, harvest confidential data from the computer, log activity on the computer and more.
****If your computer was used for online banking or has credit card information on it, all passwords should be changed immediately to include those used for email, eBay and forums.
You should consider them to be compromised.
****They should be changed by using a different computer and not the infected one, if not an attacker may get the new passwords and transaction information.
Banking and credit card institutions should be notified of the possible security breech!

Copy and paste these lines in Note pad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0


Save as flush.bat to your desktop.
Right click on the flush.bat file to run it as Administrator. Your computer will restart.


Please download AdwCleaner by Xplode and save to your Desktop.



Step 1.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
Step 2.
Using AdwCleaner v3: Scan & Clean:
This time click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
Copy and paste the contents of that logfile in your next reply.
A copy of that logfile will also be saved in the C:\AdwCleaner folder


******Post both .txt logs
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I have done what you asked and this is the file. # AdwCleaner v4.110 - Logfile created 10/02/2015 at 17:28:12
# Updated 05/02/2015 by Xplode
# Database : 2015-02-09.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Tom - TOM-PC
# Running from : C:\Users\Tom\Downloads\AdwCleaner.exe
# Option : Cleaning
***** [ Services ] *****

***** [ Files / Folders ] *****
Folder Deleted : C:\Users\Tom\Favorites\Links\Tutorials
Folder Deleted : C:\ProgramData\Online
Folder Deleted : C:\ProgramData\Uniblue
Folder Deleted : C:\ProgramData\Spyware Clear
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\iMesh Applications
Folder Deleted : C:\Program Files (x86)\DriverRestore
Folder Deleted : C:\Program Files (x86)\Spyware Clear
Folder Deleted : C:\Users\Tom\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Tom\AppData\Local\PackageAware
Folder Deleted : C:\Users\Tom\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Tom\AppData\Local\Pro_PC_Cleaner
Folder Deleted : C:\Users\Tom\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Tom\AppData\LocalLow\mediabarim
Folder Deleted : C:\Users\Tom\AppData\LocalLow\wincoreimband
Folder Deleted : C:\Users\Tom\AppData\Roaming\AnyProtectEx
Folder Deleted : C:\Users\Tom\AppData\Roaming\Optimizer Pro
Folder Deleted : C:\Users\Tom\AppData\Roaming\UpdaterEX
Folder Deleted : C:\Users\Tom\AppData\Roaming\Spyware Clear
Folder Deleted : C:\Users\Tom\Documents\Optimizer Pro
File Deleted : C:\Users\Tom\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\skj39lc5.default\user.js
File Deleted : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Scheduled tasks ] *****
Task Deleted : APSnotifierPP1
Task Deleted : APSnotifierPP2
Task Deleted : APSnotifierPP3
Task Deleted : ProPCCleaner_Start
Task Deleted : ProPCCleaner_Popup
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\Tom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\Tom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll
Key Deleted : HKLM\SOFTWARE\Classes\Applications\iMesh_V11_en_Setup.exe
Key Deleted : HKLM\SOFTWARE\Classes\Applications\iMeshV11.exe
Key Deleted : HKLM\SOFTWARE\Classes\driverscanner
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1066435
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Deleted : HKCU\Software\AnyProtect
Key Deleted : HKCU\Software\Compete
Key Deleted : HKCU\Software\eSupport.com
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Imesh
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\Tutorials
Key Deleted : HKCU\Software\UpdaterEX
Key Deleted : HKCU\Software\DriverRestore
Key Deleted : HKCU\Software\CoinisRS
Key Deleted : HKCU\Software\ProPCCleanerLanguage
Key Deleted : HKCU\Software\ProPCCleanerConfig
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\mediabarim
Key Deleted : HKCU\Software\AppDataLow\Software\TheBestDeals
Key Deleted : HKLM\SOFTWARE\CompeteInc
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\Tutorials
Key Deleted : HKLM\SOFTWARE\Uniblue
Key Deleted : HKLM\SOFTWARE\IGS
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\UpdaterEX
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Setup Support for Consumer Input
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IGS
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\ShopperPro
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17496

-\\ Mozilla Firefox v

-\\ Google Chrome v40.0.2214.111
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M8F602462-EE90-476B-B048-6C6F6DA58652&SearchSource=58&CUI=&UM=5&UP=SP5A6E20C2-0A82-4BE4-A80C-E6E583A71D44&q={searchTerms}&SSPV=&SSPV=
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M8F602462-EE90-476B-B048-6C6F6DA58652&SearchSource=58&CUI=&UM=5&UP=SP5A6E20C2-0A82-4BE4-A80C-E6E583A71D44&q={searchTerms}&SSPV=&SSPV=
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://binkiland.com/results.php?f=4&q={searchTerms}&a=bnk_coinis_15_06&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyByDtCyEyCzztCtAtA0AtN0D0Tzu0StCtCtAtBtN1L2XzutAtFyBtFyBtFyDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyEyEyB0ByCyCtAtDtGyCzyyE0CtGzyyBtBtDtGtDyD0C0BtGyC0FyC0CyCtAtByC0C0A0FtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0EtC0Czy0CtC0DyBtGzytC0D0FtGyE0CtAtAtG0AyCyEzztGyD0A0CtA0FzyzztByCzyyE0F2Q&cr=1505471931&ir=
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://taplika.com/results.php?f=4&q={searchTerms}&a=tlk_dnldstr_15_06_ie&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyByDtCyEyCzztCtAtA0AtN0D0Tzu0StCtCtAtAtN1L2XzutAtFyBtFtBtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyBzy0E0CyEtC0DyDtG0EyEyB0EtGtD0Fzy0CtGyC0DzzyDtGtDyBtD0E0CyB0CtAyEtD0DyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0FtC0Azz0E0EtCtGyB0A0DyCtGyE0A0AtAtGzzzyzzzytGtAzytBzztAyD0Dzz0BtA0FtC2Q&cr=583196304&ir=
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://taplika.com/results.php?f=4&q={searchTerms}&a=tlk_dnldstr_15_06_ie&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyByDtCyEyCzztCtAtA0AtN0D0Tzu0StCtCtAtAtN1L2XzutAtFyBtFtBtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyBzy0E0CyEtC0DyDtG0EyEyB0EtGtD0Fzy0CtGyC0DzzyDtGtDyBtD0E0CyB0CtAyEtD0DyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0FtC0Azz0E0EtCtGyB0A0DyCtGyE0A0AtAtGzzzyzzzytGtAzytBzztAyD0Dzz0BtA0FtC2Q&cr=583196304&ir=
[C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www-searching.com/search.aspx?s=F28ztutdk0000,21a894c9-f508-45d8-badf-00bb6302354d,&q={searchTerms}
*************************
AdwCleaner[R0].txt - [15460 bytes] - [10/02/2015 17:21:56]
AdwCleaner[S0].txt - [15188 bytes] - [10/02/2015 17:28:12]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15248 bytes] ##########

How ever the adware deleted all my favorites files.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64-Bit SP1
CPU
Intel Core i7 2600
Motherboard
Lenovo
Memory
8.00 GB Dual-Channel DDR3
Graphics Card(s)
1024MB GeForce GT 420
Sound Card
Intergrated Realtex ALC888S
Monitor(s) Displays
LG W40 series Widescreen
Screen Resolution
1920 by 1080 widescreen
Hard Drives
932GB Hitachi HDS TB
External drive 640 GB also
PSU
300W
Case
Tower
Cooling
yes came installed
Keyboard
Lenovo
Mouse
Laser wirless 5000
Antivirus
MBAM / Superantispyware pro paid for.
Browser
Google /
Other Info
PLDS DVD-RW DH16ABSH
How ever the adware deleted all my favorites files.

We'll get them back, later. :)

I'd like you to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi Jacee I'm so glad you are here. I followed your instructions to the letter and it did not save anything to my desktop. I also tried to see if it was in notepad. Eset found 47 different things on my system including Trojans. I will try and find the report.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64-Bit SP1
CPU
Intel Core i7 2600
Motherboard
Lenovo
Memory
8.00 GB Dual-Channel DDR3
Graphics Card(s)
1024MB GeForce GT 420
Sound Card
Intergrated Realtex ALC888S
Monitor(s) Displays
LG W40 series Widescreen
Screen Resolution
1920 by 1080 widescreen
Hard Drives
932GB Hitachi HDS TB
External drive 640 GB also
PSU
300W
Case
Tower
Cooling
yes came installed
Keyboard
Lenovo
Mouse
Laser wirless 5000
Antivirus
MBAM / Superantispyware pro paid for.
Browser
Google /
Other Info
PLDS DVD-RW DH16ABSH
Were you able to give the .txt file a name before you lost it?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Yes it was ESETScan
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64-Bit SP1
CPU
Intel Core i7 2600
Motherboard
Lenovo
Memory
8.00 GB Dual-Channel DDR3
Graphics Card(s)
1024MB GeForce GT 420
Sound Card
Intergrated Realtex ALC888S
Monitor(s) Displays
LG W40 series Widescreen
Screen Resolution
1920 by 1080 widescreen
Hard Drives
932GB Hitachi HDS TB
External drive 640 GB also
PSU
300W
Case
Tower
Cooling
yes came installed
Keyboard
Lenovo
Mouse
Laser wirless 5000
Antivirus
MBAM / Superantispyware pro paid for.
Browser
Google /
Other Info
PLDS DVD-RW DH16ABSH
I found it in my pictures.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64-Bit SP1
CPU
Intel Core i7 2600
Motherboard
Lenovo
Memory
8.00 GB Dual-Channel DDR3
Graphics Card(s)
1024MB GeForce GT 420
Sound Card
Intergrated Realtex ALC888S
Monitor(s) Displays
LG W40 series Widescreen
Screen Resolution
1920 by 1080 widescreen
Hard Drives
932GB Hitachi HDS TB
External drive 640 GB also
PSU
300W
Case
Tower
Cooling
yes came installed
Keyboard
Lenovo
Mouse
Laser wirless 5000
Antivirus
MBAM / Superantispyware pro paid for.
Browser
Google /
Other Info
PLDS DVD-RW DH16ABSH
Okay, delete all found with Eset, then delete everything in the 'recycle' bin.

Reboot, and tell me what's going on with your computer.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
It rebooted the way it should and I deleted everything you told me to do, my system is blazing fast again. Thank you both very much.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64-Bit SP1
CPU
Intel Core i7 2600
Motherboard
Lenovo
Memory
8.00 GB Dual-Channel DDR3
Graphics Card(s)
1024MB GeForce GT 420
Sound Card
Intergrated Realtex ALC888S
Monitor(s) Displays
LG W40 series Widescreen
Screen Resolution
1920 by 1080 widescreen
Hard Drives
932GB Hitachi HDS TB
External drive 640 GB also
PSU
300W
Case
Tower
Cooling
yes came installed
Keyboard
Lenovo
Mouse
Laser wirless 5000
Antivirus
MBAM / Superantispyware pro paid for.
Browser
Google /
Other Info
PLDS DVD-RW DH16ABSH
You're welcome! :) Keep AdwCleaner and update it from time to time.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi I spoke to soon it is doing it again, after I type my password to log on the screen goes black and won't let me do anything. The only thing I can do after that is to turn it off and start over and try it again.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64-Bit SP1
CPU
Intel Core i7 2600
Motherboard
Lenovo
Memory
8.00 GB Dual-Channel DDR3
Graphics Card(s)
1024MB GeForce GT 420
Sound Card
Intergrated Realtex ALC888S
Monitor(s) Displays
LG W40 series Widescreen
Screen Resolution
1920 by 1080 widescreen
Hard Drives
932GB Hitachi HDS TB
External drive 640 GB also
PSU
300W
Case
Tower
Cooling
yes came installed
Keyboard
Lenovo
Mouse
Laser wirless 5000
Antivirus
MBAM / Superantispyware pro paid for.
Browser
Google /
Other Info
PLDS DVD-RW DH16ABSH
Oh drat!!

Did you change all passwords using a 'known clean' computer (not the infected one)?

Uninstall Lavasoft --- AdAware. It may be preserving the infection.

Do you have a fresh copy of Malware bytes? If not, download the free version from Malwarebytes | Free Anti-Malware Detection & Removal Software
* Double-click mbam-setup.exe and follow the prompts to install the program.Right click to run as Administrator, using Windows 7 or Vista.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. Copy and Paste that log into your next reply.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi Jacee

I don't want to get in your way but I have some thoughts.

1. Was a external device plugged in again that might of re-infected the system?

2. Was all restore points remove and a new one made after the computer was cleaned.

3. What new has been downloaded after the computer was clean?

I will go back to watching and get out of the way.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
I will try and upload the files, cause I ran ESET and DM again. Last night when I went to turn my computer of it said do not unplug your computer and don't turn it off. I saw 16 things it was trying to install when I did not download anything so it was to late I already hit the shut down icon.

I also ran ESET and id had at least 1 Trojan.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64-Bit SP1
CPU
Intel Core i7 2600
Motherboard
Lenovo
Memory
8.00 GB Dual-Channel DDR3
Graphics Card(s)
1024MB GeForce GT 420
Sound Card
Intergrated Realtex ALC888S
Monitor(s) Displays
LG W40 series Widescreen
Screen Resolution
1920 by 1080 widescreen
Hard Drives
932GB Hitachi HDS TB
External drive 640 GB also
PSU
300W
Case
Tower
Cooling
yes came installed
Keyboard
Lenovo
Mouse
Laser wirless 5000
Antivirus
MBAM / Superantispyware pro paid for.
Browser
Google /
Other Info
PLDS DVD-RW DH16ABSH
Hi Jacee I re-ran the tests you gave me before and ESET found another Trojan along with malware here are the files. Oh there are no externals hooked up. I did not delete the restore points should I do that now or wait till you tell me to. Thank you again for coming to my rescue. I am going to do a snip of all the software so you can see.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo
OS
Windows 7 Home Premium 64-Bit SP1
CPU
Intel Core i7 2600
Motherboard
Lenovo
Memory
8.00 GB Dual-Channel DDR3
Graphics Card(s)
1024MB GeForce GT 420
Sound Card
Intergrated Realtex ALC888S
Monitor(s) Displays
LG W40 series Widescreen
Screen Resolution
1920 by 1080 widescreen
Hard Drives
932GB Hitachi HDS TB
External drive 640 GB also
PSU
300W
Case
Tower
Cooling
yes came installed
Keyboard
Lenovo
Mouse
Laser wirless 5000
Antivirus
MBAM / Superantispyware pro paid for.
Browser
Google /
Other Info
PLDS DVD-RW DH16ABSH
Back
Top