win32/Small.CA virus

veegee

New member
Member
Local time
12:46 AM
Messages
69
A little background info. Afew days ago I installed Easy Burner prog. from Soft Pedia in error and uninstalled it but parts of it did not uninstall. Did afew sys. restores, then PC wouldn't shut down & had to use power button to be able to restart again. Then Windows said that it detected a critical error and had to restart. I.E.'s were both not responding. Popup at bottom: MBAM successfuly blocked access to a potentially malicious website 207.232.22.60 -- Type: outgoing -- Port 5328 (but always a different port number) when opening I.E. Process: Avast svc.exe. Info on I.E. page indicated network problems so tried network diagnostics that they recommended and finally it said 'no problems'. I.E is now working.

Google Chrome is still unresponsive with "This website page is not available" at the top and the same popup as above from MBAM & Avast as was on I.E. Google Chrome has website www.searchnu.com sitting in the address bar. Is this a rogue site as I could not find any info about it?

Action Center reports this message: remove win32/Small.CA virus

Windows Fire Wall: There has never been any entries in the 'allow programs thro' firewall', as I was told that it wasn't necessary to configure it as the firewall just did it's thing. However, now there are over 30 entries of various kinds listed and some randomly checked under home/work & public. ??

None of these browsers have proxy enabled. Scans done -- complete MBAM, SAS, Avast & boot, MSRT, MSS, spybot. Did a lot of searching but am unsure what is safe to do. Would greatly appreciate some help. Thanks in advance.
 

My Computer

Computer Manufacturer/Model Number
Compaq-Presario
OS
Windows 7 Home Premium 64 bit SP1
CPU
AMD Athlon(tm) II x2 215 Processor
Memory
4.00 GB
Graphics Card(s)
Nividia GeForce 6150SE nForce 430
Monitor(s) Displays
Acer 21.5" - H213H 1920x1080
Hard Drives
466 GB 2 processor cores
Other Info
Avast free|SAS|MBAM pro|Spywareblaster|Spybot|Windows Defender|Windows Firewall
Download AdWareCleaner AdwCleaner Download to your desktop
1.Right-click on adwcleaner.exe and select Run As Administrator to launch the application.
2.Click on Delete button.
3.Confirm each time with OK.
4.Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.
Note: You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.

AdwareCleaner.jpg
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Thanks Jacee

Here is the ADWcleaner log file you requested:

# AdwCleaner v2.111 - Logfile created 02/08/2013 at 22:43:53
# Updated 05/02/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : - xxxxxx-PC
# Boot Mode : Normal
# Running from : C:\Users\xxxxxx\Desktop\AdwCleaner.exe
# Option [Delete]

***** [Services] *****

***** [Files / Folders] *****
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
Folder Deleted : C:\Program Files (x86)\search results toolbar
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\Users\xxxxxx\Documents\Inbox
***** [Registry] *****
Key Deleted : HKLM\SOFTWARE\Software
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.7601.17514
[OK] Registry is clean.
-\\ Google Chrome v24.0.1312.57
File : C:\Users\xxxxxx\AppData\Local\Google\Chrome\User Data\Default\Preferences
Deleted [l.11] : homepage = "hxxp://www.searchnu.com/421",
Deleted [l.15] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com/421" ]
Deleted [l.51] : keyword = "search-results.com",
Deleted [l.54] : search_url = "hxxp://dts.search-results.com/sr?src=crb&gct=ds&appid=101&systemid=421&apn_dtid[...]
Deleted [l.1707] : homepage = "hxxp://www.searchnu.com/421",
Deleted [l.1860] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com/421" ]
*************************
AdwCleaner[S1].txt - [1376 octets] - [08/02/2013 22:43:53]
########## EOF - C:\AdwCleaner[S1].txt - [1436 octets] ##########
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Compaq-Presario
OS
Windows 7 Home Premium 64 bit SP1
CPU
AMD Athlon(tm) II x2 215 Processor
Memory
4.00 GB
Graphics Card(s)
Nividia GeForce 6150SE nForce 430
Monitor(s) Displays
Acer 21.5" - H213H 1920x1080
Hard Drives
466 GB 2 processor cores
Other Info
Avast free|SAS|MBAM pro|Spywareblaster|Spybot|Windows Defender|Windows Firewall
veegee,

While Jacee gets here, is Action Center still reporting: remove win32/Small.CA virus?

Also, let's do some searching...

Next, please download SystemLook:
64-bit:
http://jpshortstuff.247fixes.com/SystemLook_x64.exe
Save to your Desktop.
Right-click on SystemLook.exe, and select: Run As Administrator

At the SystemLook program console, copy the content inside the following quote box into the main textfield:

:reg
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Click the Look button to start the scan.

When finished, a notepad window opens with the results of the scan.

Please post the SystemLook.txt (found on the Desktop) in your reply.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Cottonball- thanks for the reply
Action Center is still asking to remove win32/Small.CA virus

Here is the System Look results you requested:

SystemLook 30.07.11 by jpshortstuff
Log created at 23:44 on 09/02/2013 by xxxxxx
Administrator - Elevation successful
========== reg ==========
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"HPADVISOR"="C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(No values found)

-= EOF =-
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Compaq-Presario
OS
Windows 7 Home Premium 64 bit SP1
CPU
AMD Athlon(tm) II x2 215 Processor
Memory
4.00 GB
Graphics Card(s)
Nividia GeForce 6150SE nForce 430
Monitor(s) Displays
Acer 21.5" - H213H 1920x1080
Hard Drives
466 GB 2 processor cores
Other Info
Avast free|SAS|MBAM pro|Spywareblaster|Spybot|Windows Defender|Windows Firewall
Hmmm....

AdwCleaner got rid of the Searchnu fastidious entries.

Let's see what your system shows with the following short scan...


Please download RogueKiller:
Tlcharger RogueKiller (Site Officiel)

When you get to the website, go to where it says:
(Download link) Lien de téléchargement:
rendu2.png


Select the x64 version for your 64-bit system.
Click the dark-blue button to download.
Save to the Desktop.

Close all windows and browsers.
Right-click and select: Run as Administrator

Allow for the prescan to run. Under Status you see: Prescan finished
At the program console, press: SCAN

When done, a report opens on the Desktop: RKreport.txt

Please provide the RKreport.txt (Mode: Scan) in your reply.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Below is Rogue Killer reports:

RogueKiller V8.5.0 _x64_ [Feb 9 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : RogueKiller - Geeks to Go Forums
Website : Download RogueKiller (Official website)
Blog : tigzy-RK
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : xxxxxx [Admin rights]
Mode : Scan -- Date : 02/10/2013 01:06:25
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [NOT LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤

The quarantine report has nothing in the file except date & time. Hope I did this right!!
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Compaq-Presario
OS
Windows 7 Home Premium 64 bit SP1
CPU
AMD Athlon(tm) II x2 215 Processor
Memory
4.00 GB
Graphics Card(s)
Nividia GeForce 6150SE nForce 430
Monitor(s) Displays
Acer 21.5" - H213H 1920x1080
Hard Drives
466 GB 2 processor cores
Other Info
Avast free|SAS|MBAM pro|Spywareblaster|Spybot|Windows Defender|Windows Firewall
Please post the entire RKreport.txt

It seems as if it was cut off.

Thanks!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Sorry Cottonball - complete Rogue Killer report below:

RogueKiller V8.5.0 _x64_ [Feb 9 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : RogueKiller - Geeks to Go Forums
Website : Download RogueKiller (Official website)
Blog : tigzy-RK
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : xxxxxx [Admin rights]
Mode : Scan -- Date : 02/10/2013 01:06:25
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [NOT LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts



[...]

¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST350041 8AS SCSI Disk Device +++++
--- User ---
[MBR] 33ac8be5a0e2011f4ed30d4da523a415
[BSP] 7d4c6fd333c05d0f83c903ade30cb386 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 464857 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 952233984 | Size: 11981 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
Finished : << RKreport[1]_S_02102013_02d0106.txt >>
RKreport[1]_S_02102013_02d0106.txt
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Compaq-Presario
OS
Windows 7 Home Premium 64 bit SP1
CPU
AMD Athlon(tm) II x2 215 Processor
Memory
4.00 GB
Graphics Card(s)
Nividia GeForce 6150SE nForce 430
Monitor(s) Displays
Acer 21.5" - H213H 1920x1080
Hard Drives
466 GB 2 processor cores
Other Info
Avast free|SAS|MBAM pro|Spywareblaster|Spybot|Windows Defender|Windows Firewall
Please go back to Post #4, and run SystemLook once again.

This time, use the following text contained in the quote box below:

:reg
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc /sub


Then, post the results of the new SystemLook.txt (found on the Desktop) in your reply.

This looks at the Registry entries for the Action Center. We need to know what is happening there.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Second log for System Lock:

SystemLook 30.07.11 by jpshortstuff
Log created at 16:35 on 10/02/2013 by xxxxxx
Administrator - Elevation successful
No Context: HKLM\SYSTEM\CurrentControlSet\Services\wscsvc /sub
-= EOF =-
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Compaq-Presario
OS
Windows 7 Home Premium 64 bit SP1
CPU
AMD Athlon(tm) II x2 215 Processor
Memory
4.00 GB
Graphics Card(s)
Nividia GeForce 6150SE nForce 430
Monitor(s) Displays
Acer 21.5" - H213H 1920x1080
Hard Drives
466 GB 2 processor cores
Other Info
Avast free|SAS|MBAM pro|Spywareblaster|Spybot|Windows Defender|Windows Firewall
Second log for System Look:

SystemLook 30.07.11 by jpshortstuff
Log created at 16:45 on 10/02/2013 by xxxxx
Administrator - Elevation successful
No Context: HKLM\SYSTEM\CurrentControlSet\Services\wscsvc /sub
-= EOF =-
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Compaq-Presario
OS
Windows 7 Home Premium 64 bit SP1
CPU
AMD Athlon(tm) II x2 215 Processor
Memory
4.00 GB
Graphics Card(s)
Nividia GeForce 6150SE nForce 430
Monitor(s) Displays
Acer 21.5" - H213H 1920x1080
Hard Drives
466 GB 2 processor cores
Other Info
Avast free|SAS|MBAM pro|Spywareblaster|Spybot|Windows Defender|Windows Firewall
Strange...

Try the following:

:reg
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc

Or,

:reg
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc /sub

If no result, then, do the following:

Please download Farbar Service Scanner






Save to the Desktop
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press: Scan
  • FSS creates a log, FSS.txt, on the Desktop.
Please provide the FSS.txt in your reply.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Make sure the :reg is included in SystemLook.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
System Log report:

SystemLook 30.07.11 by jpshortstuff
Log created at 17:54 on 10/02/2013 by xxxxxx
Administrator - Elevation successful
========== reg ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc]
"DisplayName"="@%SystemRoot%\System32\wscsvc.dll,-200"
"ErrorControl"= 0x0000000001 (1)
"ImagePath"="%SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted"
"Start"= 0x0000000002 (2)
"Type"= 0x0000000020 (32)
"Description"="@%SystemRoot%\System32\wscsvc.dll,-201"
"DependOnService"="RpcSs WinMgmt"
"ObjectName"="NT AUTHORITY\LocalService"
"ServiceSidType"= 0x0000000001 (1)
"RequiredPrivileges"="SeChangeNotifyPrivilege SeImpersonatePrivilege"
"DelayedAutoStart"= 0x0000000001 (1)
"FailureActions"=80 51 01 00 00 00 00 00 00 00 00 00 03 00 00 00 14 00 00 00 01 00 00 00 c0 d4 01 00 01 00 00 00 e0 93 04 00 00 00 00 00 00 00 00 00 (REG_BINARY)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Parameters]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Security]

-= EOF =-

Every time I copied the KLM/system.....into system look, the HKey_Local_ would come up. Maybe restart and post the KLM again in another post?
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Compaq-Presario
OS
Windows 7 Home Premium 64 bit SP1
CPU
AMD Athlon(tm) II x2 215 Processor
Memory
4.00 GB
Graphics Card(s)
Nividia GeForce 6150SE nForce 430
Monitor(s) Displays
Acer 21.5" - H213H 1920x1080
Hard Drives
466 GB 2 processor cores
Other Info
Avast free|SAS|MBAM pro|Spywareblaster|Spybot|Windows Defender|Windows Firewall
HKLM is just shorthand for HKEY_Local_Machine
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
This is a tough ride...any entries we look into are OK.

BTW, you can XXX out your name anytime you wish.

If you had problems removing the Easy Burner program, and parts of it did not uninstall, see if the following finds anything pertaining to it:

Download and install the Revo Uninstaller (Freeware):
http://www.revouninstaller.com/download/revosetup.exe
Run Revo Uninstaller

At the console, select the program to remove (if there), and click the Uninstall icon.
2ev563d.gif

Now, select: Advanced
aubbd2.gif

Click Next, and follow the prompts.
2hdphqf.gif

Please click Select All (1.) and Delete (2.) to delete all Registry items, folders and files listed by Revo.
If asked to restart the computer, please do so.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Without regard to the outcome of Revo, try the Microsoft Safety Scanner (64-bit version):
Microsoft

Post back on what it finds..
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Installed Revo Uninstaller but could not find any traces of that Easy Burner. Do you ignore that Program Compatibility Assistant that comes up with Revo install that reads - Reinstall using recommended settings and below - This program installed correctly?

MSS scan - No infections MSRT - No infections

This sure has been a journey and Action Center still says to remove win32/Small.CA virus. Where in blazes could it be?

Farbar FSS.text log: (checked in those 6 items you listed)

Farbar Service Scanner Version: 10-02-2013
Ran by xxxxx (administrator) on 10-02-2013 at 22:14:24
Running from "C:\Users\xxxxxx\Desktop"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.

Windows Firewall:
=============
Firewall Disabled Policy:
==================

System Restore:
============
System Restore Disabled Policy:
========================

Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================

Windows Defender:
==============
Other Services:
==============

File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit

**** End of log ****
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Compaq-Presario
OS
Windows 7 Home Premium 64 bit SP1
CPU
AMD Athlon(tm) II x2 215 Processor
Memory
4.00 GB
Graphics Card(s)
Nividia GeForce 6150SE nForce 430
Monitor(s) Displays
Acer 21.5" - H213H 1920x1080
Hard Drives
466 GB 2 processor cores
Other Info
Avast free|SAS|MBAM pro|Spywareblaster|Spybot|Windows Defender|Windows Firewall
Well, we keep on rolling...

Please download the Junkware Removal Tool:
Junkware Removal Tool Download
Save to the Desktop.

Temporarily shut down your protection software to avoid potential conflicts.

Right-click JRT.exe and select: Run as Administrator

The tool opens and starts scanning the system. Please be patient as this can take a while...

When done, a report (JRT.txt) is saved on the Desktop.
Please post the contents of JRT.txt in your reply.



Next, please download Temp File Cleaner (TFC):
TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums

Double-click on TFC.exe to run the program.

Be sure to save any work in progress before running TFC!!

Click on Start to begin the cleaning process.
TFC closes all running programs, and may ask you to restart the computer.

When done, also check the Action Center.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Back
Top