WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


[INACTIVE] NetUtils2016: PC badly affected after installing program

2 posters

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program Empty[INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
I had installed a program,(Glarysoft Malware Hunter) that was given to me,and 24 hours later i am still having major problems.
I have a desktop running Windows 10 home.

When installing the program, I unclicked all of the unwanted options that came with the program,but it appeared that they all installed anyway. I have since uninstalled that program. 

Since then, I have had approx 12-15 other programs installed  which i have removed with IObit Uninstaller, I have done two rootkit scans after avast internet security told me i had problems.

 I have run Adware removal tool 3 times and removed 46 problems initially,then the last 2 times,the same 2 problems showed and were removed.


Microsoft edge is loading dozens  of spam web pages continually and i can no longer use google chrome(which was my chosen browser) as it will not function.

I am using a laptop to communicate with you as i cannot get any sense out of my desktop at present.

Please help!!!

I have attached the OTL logs.

thank you

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello there, I'm analyzing your logs and will be back with a fix soon.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Thank you

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello again,

Did not mean to delay this... Let's go ahead and begin with the following tools:
Disable CD Emulation Programs Temporarily

To disable CD Emulation programs using DeFogger please perform these steps:
  1. Please download DeFogger to your desktop.
  2. Once downloaded, double-click on the DeFogger icon to start the tool.
  3. The application window will now appear.  You should now click on the Disable button to disable your CD Emulation drivers
  4. When it prompts you whether or not you want to continue, please click on the Yes button to continue
  5. When the program has completed you will see a Finished! message. Click on the OK button to exit the program.
  6. If CD Emulation programs are present and have been disabled, DeFogger will now ask you to reboot the machine.  Please allow it to do so by clicking on the OK button.

Junkware Removal Tool

Please download Malwarebytes' Junkware Removal Tool and save the file to your desktop.
  • Right-click on the JRT.exe or Junkware Removal Tool icon and select Run as Administrator to start the tool.
  • Follow the prompts and let this process run uninterrupted.
  • This scan can take a while, depending on your System specs.
  • Upon completion, a log (JRT.txt) will open on your desktop.

Please include the contents of that file in your reply.

Do not forget to re-enable your previously switched off protection software!
Please also manually reboot your machine after this procedure.
Scan with AdwCleaner to ensure we got it all

Please download Malwarebytes' AdwCleaner onto your Desktop.
  • Double click on AdwCleaner_xxxx.exe to run the tool.
  • Click on Scan.
  • After done scanning, please hit Logfile. Locate the logfile in the Scan tab, double-click on it, copy the information inside of it, and paste it into your next reply.
  • You can find the logfile at C:\AdwCleaner[Sx].txt as well.

Malwarebytes' Scanner

If this program is already installed: Skip the installation and run only the scan!
Download and install: Please download Malwarebytes' scanner to your desktop.
  • Double-click mb3-setup-consumer-3.x.x.xxxx and follow the prompts to install the program.
  • Click Finish.
  • On the Dashboard, click the 'Check for Updates' button.
  • After the update completes, click the 'Scan Now' button.
  • A Threat Scan will begin. Please allow it to progress through the scanning process.
  • When the scan is complete, if there have been detections, click Quarantines Selected button to allow the program to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

How to get logs: (Export log to save as txt)

  • After the restart once you are back at your desktop, open Malwarebytes once more.
  • Click on the Reports tab > Scan Report. (if you have done more than one scan in the past, select the most recent that shows the Date and time of the scan just performed. Press View Report button.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • Find the log on your Desktop and Attach that saved log to your next reply.

(Copy to clipboard for pasting into forum replies or tickets)

In your next reply, please include the following:

  • Log from Junkware Removal Tool
  • Log from AdwCleaner tool
  • Log from Malwarebytes Scanner

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello once more
Have followed your directions and i seem to be stuck on Malwarebytes free Threat scan Heuristics analysis , Checking for updates, for approx an hour. Is this normal? 
I will post the logs when it completes.
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Give it a bit longer and let me know how it does

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,
I have been unable to complete the Malwarebytes Free Threat Scan.
The first time it remained on Heuristics Analysis for approx 2 hours and froze at 'checking for updates' for almost  an hour and a half. It did not change in that time.

It was showing 243 Threats Identified. I could not remove them as the program would not respond any further.

I uninstalled malwarebytes free  using  mbam-clean.exe and then reinstalled the program again. I have now run adware cleaner again and Malwarebytes also again. This time I removed 94 infections with adware cleaner. 
Malwarebytes is now stuck in Heuristics Analysis again after being stuck for over 1.50 hours. It is now showing 100 threats identified but  shows no sign of ending with the only activity being the time elapsed timing and the Heuristics Analysis wheel rotating.

I will now shut it down for today and return again tomorrow. Hopefully with some better results.

I have attached 

  • Log from Junkware Removal Tool log

  • Log from AdwCleaner tool log ( both logs)

  • The Malwarebytes log is not available as it has failed to finish.


Thanks for you help today.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please run in order Junkware Removal Tool, AdwCleaner, and then the following please:

ComboFix scan

Please download ComboFix1 - [INACTIVE] NetUtils2016: PC badly affected after installing program Combofix by sUBs
From BleepingComputer.com

Please save the file to your Desktop.

Important information about ComboFix

After the download:

  • Close any open browsers.
  • Very Important: Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results". Please visit here if you don't know how.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until ComboFix has completely finished.
  • If there is no Internet connection after running ComboFix, then restart your computer to restore back your connection.

Running ComboFix:

  • Double click on ComboFix.exe & follow the prompts.
  • When ComboFix finishes, it will produce a report for you.
  • Please post the report, which will launch or be found at "C:\Combo-Fix.txt" in your next reply.

Troubleshooting ComboFix

Safe Mode:

If you still cannot get ComboFix to run, try booting into Safe Mode, and run it there.

(To boot into Safe Mode, tap F8 after BIOS, and just before the Windows
logo appears. A list of options will appear, select "Safe Mode.")

Re-downloading:

If this doesn't work either, try the same method (above method), but try to download it again, except name
ComboFix.exe to iexplore.exe, explorer.exe, or winlogon.exe.

Malware is known for blocking all "user" processes, except for its whitelist of system important processes such as iexplore.exe, explorer.exe, winlogon.exe.

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello
It appears ComboFix will not work on Windows 10.
Do you have another I should use.
Thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Whoops, I overlooked that, because I had another ticket that a user had Windows 7. Goofy Apologies.

Scan with Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool x64 and save it to your Desktop.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • When the tool opens click Yes to disclaimer.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please copy and paste their content into your next reply.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi.
I have carried out the Farbar Recovery Scan and have attached both scans 
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
There are many program entries in the logs for your computer for WildTangent games... Do you want to keep those? I ask, because they are showing a “hidden” flag next to them, which is suspicious activity unless you installed them yourself.

I also have noticed the use of P2P and cracks/keygens in your logs. This is highly unsafe, and the source of infection, including, as of recent, the prevalence of ransomware. Ransomware is a highly dangerous infection, which locks down your files/folders/PC requiring you to pay the hacker in order to restore access to your system. In addition, antivirus and anti-malware software cannot always “catch” an infection to block it... Therefore, I recommend the removal of uTorrent and any other programs related to torrenting. You'll be glad you did...! Smile...

Oh and did you upgrade from Windows XP to Windows 10?

Fix with Farbar Recovery Scan Tool
Notice to outside readers: This fix was created for this user for use on that particular machine.Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work! Therefore, if you placed FRST.exe in your “Geek Police” folder, then make sure fixlist.txt goes in the same location as FRST.exe.


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart of your computer, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,
Thank you for your advice and instructions. I will make those changes regarding utorrent.
I bought the pc with Windows 10 preinstalled.
I didn't install Wild Tangent Games or had any idea that it was installed on my pc. How do i remove that ?
I have carried out your instructions regarding Farbar recovery scan tool and I have attached the Fixlog.txt.
I await your comments
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Very well... Now for the WildTangent Games, go to Start > type in appwiz.cpl and hit enter or choose the result from the search list. Then, in that list, look for the following entry: WildTangent Games. Please uninstall that, and it should remove all of the games along with it.

Then, please do the following:
Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.




Malwarebytes' scanner
If this program is already installed: Skip the installation and run only the scan!
Download and install: Please download Malwarebytes' scanner to your desktop.

  • Double-click mb3-setup-consumer-3.x.x.xxxx and follow the prompts to install the program.
  • Click Finish.
  • On the Dashboard, click the 'Check for Updates' button.
  • After the update completes, then, on the Dashboard, select Settings.
  • Click on Protection.
  • Ensure that Scan for rootkits is checked. If not, check it.
  • Return to the Dashboard and click the 'Scan Now' button.
  • A Threat Scan will begin. Please allow it to progress through the scanning process.
  • When the scan is complete, if there have been detections, click Quarantines Selected button to allow the program to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

How to get logs: (Export log to save as txt)

  • After the restart once you are back at your desktop, open Malwarebytes once more.
  • Click on the Reports tab > Scan Report. (if you have done more than one scan in the past, select the most recent that shows the Date and time of the scan just performed. Press View Report button.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • Find the log on your Desktop and Attach that saved log to your next reply.

(Copy to clipboard for pasting into forum replies or tickets)




Please read carefully and follow these steps.

  • Download TDSSKiller and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    1 - [INACTIVE] NetUtils2016: PC badly affected after installing program TDSSKillernumber1


  • If an infected file is detected, the default action will be Cure, click on Continue.

    1 - [INACTIVE] NetUtils2016: PC badly affected after installing program TDSSKillernumber2

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    1 - [INACTIVE] NetUtils2016: PC badly affected after installing program TDSSKillernumber3


  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.

    1 - [INACTIVE] NetUtils2016: PC badly affected after installing program TDSSKillerlastone3


  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents the report here.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
I have deleted all Wild Tangent games as per your instructions.
I have run Farbar Recovery Scan Tool again and attached logs.
I ran Malwarebytes once more and again it stuck on Heuristics Analysis with no sign of activity,so i closed it again. I have attached a screen capture of the 9 threats identified that couldn't be removed due to the scan sticking.The screen capture will be in a separate message that will follow this one.
I ran TDSSKiller.exe and it found no problems. The log is attached.
I await your comments.
Thank you again

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I have been unable to post the screen capture due to size restrictions. The 9 threats found are all PUP files,process modules and registry keys.  Is there another program like Malwarebytes i could use instead?
thanks.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Okay, let's see what we can do here... This will be a bit rigorous...

Please download the latest version of Hitman Pro

  • After the download completes please double click the program to run it.
  • Accept the terms of the license agreement and click Next
  • Let the scan run. It will not take long
  • When the scan finishes, and all the files have been uploaded to the Scan Cloud, click Next
  • Click Next again. At the bottom left you will see Export Scan Results To XML File. Click that and save it in a convenient location
  • Upload log.xml here for review please


Sophos Virus Removal Tool
Download Sophos Free Virus Removal Tool and save it to your desktop.

  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View log file... (bottom left hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program


Scan with herdProtect

Please download herdProtect by Reason Software (portable edition) and save the file to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on the HerdProtect icon and select Run as Administrator to install the scanner.
  • It will ask for the location - leave the default one (%ProgramFiles%) or select another, convenient one.
  • Agree to the terms, select Launch herdProtect and click Finish.
  • Click Scan. It may take a while, depending on your system and connection specs. Please be patient.
  • When it finishes click on Save Results.
  • A Notepad with a report should open.

Please include the contents of that report in your next reply.
This type of scan often produces false positives. In any case do not remove on your own any of its findings! Removal will be made after the careful analysis of the scan results.
Upon completion of the cleaning you may remove HerdProtect if you wish so. To do it just delete its directory (chosen by you when installing the tool).

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,

Should I remove malicious software that Hitman Pro has discovered?  The scan has completed and is asking me to activate their product which i can do with a 30 day free  license.
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Yes, go ahead with that. However, only herdProtect you should not remove anything right now, please. Smile...

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi.
 I have run Hit man Pro. The log is attached. 
 I have run Sophos Virus removal Tool. The Scan found 1 threat which i removed. It showed an error message when i clicked Details,then View Log File.I Could not retrieve a log.
 I have run herdProtect as requested and have left the scan open on the desktop after completion. The log is attached. I have not attempted anything further with herdProtect. I have split this log into 5 individuals files due to the size of the initial log. I will send part 5 separately.
 I await your response.
  thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please find attached part 5

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Thanks for letting me know the progress, the system is still heavily infected...

Fix with Farbar Recovery Scan Tool

This fix was created for this user for use on that particular machine.Running it on another one may cause damage and render the system unstable.

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart of your computer, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.




RogueKiller Scan


  • Download RogueKiller from the following link and save it on your desktop:
    TechSpot
    Official Site (alternative)
  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ...
  • Click on Scan

1 - [INACTIVE] NetUtils2016: PC badly affected after installing program RGKRScan


  • Wait for the end of the scan.
  • The report has been created on the desktop.
  • Click on the Delete button.

1 - [INACTIVE] NetUtils2016: PC badly affected after installing program RGKRDelete


  • The report has been created on the desktop.


  • Next click on the ShortcutsFix

    1 - [INACTIVE] NetUtils2016: PC badly affected after installing program RGKRShortcutsFix
  • The report has been created on the desktop.

Please post:

All RKreport.txt text files located on your desktop.




CKScanner

Please download CKScanner by askey127 from here
Save it to your desktop.

  • Doubleclick CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify that the file is saved.
  • Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,
I have followed your instructions regarding the Farbar Recovery Scan Tool. The Fixlog.txt is attached to this message.
I have run RogueKiller and after the completion  I opened the report and copied it to the desktop. I have attached same here.
The version of RogueKiller I used was 12.9.7.0 and the layout is different to the one you supplied. It is still open on my desktop. Should i check each item before i select the 'Remove Selected' button.
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Yes, please do remove those items.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I will send you the CKFiles log shortly when it completes
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Okay. I'll be online for quite a while longer. Smile...

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I have tried to send the CKFile log as a txt and it will not accept it as a 267kb single text document and it won't accept 3 individual smaller text documents.
 It shows 'Could not upload file : exceeded user allowed storage. (Free space : 0) .
Do you have a solution?
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please upload it to www.mediafire.com and post the download link here. Smile...

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Thanks,
Here is the link - http://www.mediafire.com/file/rds7uzt1wv9lcs7/ckfiles.zip

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
You're welcome and thanks for the upload. I got the info just fine. Smile...

To free up space on your attachments account here on the forums, press the Profile button in the navigation bar near the top of the page: 1 - [INACTIVE] NetUtils2016: PC badly affected after installing program Profil12, then hit the Attachments tab.

You should see a page like this: 1 - [INACTIVE] NetUtils2016: PC badly affected after installing program Attach10

You are free to checkmark and delete any of your attachments in there, as they have already been reviewed by me or the staff, so they are no longer necessary. If you would rather not do this, then feel free to continue to use a free file upload site.




As far as the deletions go, any kind of potentially illegal software and other possibly infected resources will be deleted.

Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.




After that, please run CKScanner again and post a new log, as well as the following please (don't worry we'll delete all these tools afterward) - Re-run Junkware Removal Tool and AdwCleaner and post fresh logs from those tools! Right On!

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
Thanks for the advice on removing previous messages. 

I have carried out fresh scans using  Farbar Recovery Scan Tool and I have attached the fixlog.

I have run CKScanner again and the log is attached.

I have run Junkware Removal Tool and that log is attached.

Finally,I have just run Adw Cleaner and that log is attached. 

I look forward to your reply.

 thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Looks like we're wrapping things up...  Awesome (sparkly)

Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.




Remove the Adware

  • Please close all open programs and internet browsers.
  • Double click on adwcleaner_xxxx.exe to run the tool.
  • Press Scan, wait for it to finish.
  • Ensure to only check the following items (uncheck all others):
    Chrome pref Found:  [C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Web data] - uk.ask.com
    Chrome pref Found:  [C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - hxxp://uk.search.yahoo.com?type=512435&fr=spigot-yhp-ch.
  • Then hit the Clean button.
  • Your computer will be rebooted automatically. If it does not, please reboot the computer manually.
  • Re-run AdwCleaner as before and post a new log please.





Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.

  • Once it is restarted and you're back in Windows, double-click adwcleaner_xxxx.exe, hit "Logfile." On the Cleaning tab, double-click the latest logfile, copy the contents, and paste it into your next reply.
  • You can find the logfile at C:\AdwCleaner[Sx].txt as well.





In your next reply, please include these logs:


  1. Fixlog.txt from FRST
  2. Fresh AdwCleaner log
  3. Fresh FRST scan log
  4. Also, let me know how your device is doing. Thanks for your patience also, this has been a challenge worth my youth!


Last edited by Dr Jay on 11th February 2017, 10:02 pm; edited 1 time in total

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,
 I cannot see any attachment for fixlog.txt with your last message, or am i to use a previous one?
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Sorry, I just fixed the download hub system, as we added new functions to the forums...

This should work or click on the attachment above I just created: http://www.geekpolice.net/download.forum?id=533

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello Again,
I have carried out the FRST scan and I have attached the Fixlog.txt

I have also run adwcleaner,scanned the pc and followed your instructions relating to only checking those 2 items. My problem was that i could not see those two items in the scan. The scan found 5 items, as below.
Under Services it found NetUtils2016.
 Files It found C:\WINDOWS\SysNative\NetUtils2016.dll
 Files it found C:\WINDOWS\SysNative\drivers\NetUtils2016.sys
 Registry it found HKLM64\SOFTWARE\HDWallpaper
 Chrome it found C;\Users\paull\AppData\Local\Google\Chrome\User Data\Default
I made the assumption that the last item was the one you referred to and have checked it  and  hit the clean button.
I have attached the adwcleaner log also.

I have re-run FRST again and have attached the log as well

I have found my pc to be still having problems with Google Chrome,it freezes which causes me to use Task Manager to close it, and i am finding Chrome not opening after clicking on the desktop icon.

I have installed Opera which appears to be running better.

With reference to NetUtils, it seems to be the cause of problems using Chrome as i am finding it opening pages as well as getting 'reimage plus' opening regularly.

I have found Avast notifying me of potential malware that they have stopped when i have been carrying out adwclweaner scans too.

I hope i make sense with all this info.

I look forward to your reply
Thank you so much.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please download and run the Google Chrome Software Cleaner.



CCleaner Temporary Files Cleaning

NOTE: If you already have this installed, you don't have to reinstall it.

Please download CCleaner

When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
Follow the prompts to install the program.


  • Double-click the CCleaner shortcut on the desktop to start the program.
  • A prompt will ask you if you want CCleaner to do a check to see what cookies it needs to keep. Allow that operation.
  • On the Cleaner tab, click on Run Cleaner on the bottom-right to run the program.
  • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner, or it will ask if you want the program to close them for you (when you do this, all unsaved data may be lost in the browser).


Caution: Only use the Registry feature if you are very familiar with the registry.
Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

SystemLook
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    Code:


    :filefind
    *netutils*


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
I have run CC Cleaner as requested 
I have also run System Look and that log is attached.
thank you.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Well, I'm now made well aware that the infection on your PC is simply a rare one. I am going to change the name of your topic slightly, as it will make it useful for visitors to find helpful information. You see, one file that was missed in the fixes by me kept reinstalling the other malicious system file, which made the machine reinfect. It may be the cause of it reappearing. Smile...

Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply. Also, please run SystemLook as we did above, and let's see a new log. Right On!

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
I have carried out the FRST as you instructed and the fixlog is attached
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please do this part now:
Also, please run SystemLook as we did above, and let's see a new log.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please find a fresh scan of SystemLook attached
thank you

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Persistent lot, isn't it?
Look at this: C:\Windows\System32\drivers\NetUtils2016.sys    --a---- 909944 bytes    [19:00 13/02/2017]    [19:00 13/02/2017] 9EE21F7D46BD2B0F128E0907BABC7D28




Let's target it a bit more... We need a different approach... Bear with me here. Smile...

Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply. Also, attach MBRDUMP.txt to your next reply, which will be located within the same area of FRST.




Avast Browser Cleanup Tool


  1. Please download this free tool and save it to your desktop.
  2. Install the program by double-clicking on avast-browser-cleanup-sfx.exe.
  3. This cleanup tool will search and list if unwanted entries were found. If found, it will display a button ‘Remove all add-ons listed below and cleanup browser.’ You may remove all or delete one entry at a time.
  4. Avast Browser Cleanup will confirm before it permanently deletes the add-on. Please click Yes to proceed with removal of bad add-ons on the affected browser.





Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.




In your next reply, please include the following:

  • Fixlog.txt for FRST fix
  • MBRDUMP.txt
  • FRST.txt and Addition.txt for the re-run of FRST.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
Please find attached the logs as you requested,
The MBRDUMP log is empty and as such I have been unable to send it.
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Couple of questions... Did you make these restrictions on the OS:

GroupPolicy: Restriction - Chrome <======= ATTENTION
HKLM\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKLM\...\Policies\Explorer: [NoResolveSearch] 1
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKLM\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-2138326613-2610238322-1334748225-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-2138326613-2610238322-1334748225-1001\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-2138326613-2610238322-1334748225-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION


Second question... Did you install or want these Google Chrome extensions:
CHR Extension: (Google Translate) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2017-02-09]
CHR Extension: (Nimbus Screenshot App) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\aecjogkncpbkjfobfnoaiepipllcadhe [2017-02-09]
CHR Extension: (File Converter) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\alblmaecejifbilchdofkdanifpmnmfk [2017-02-09]
CHR Extension: (BeFunky Photo Editor) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\apfkepiiddolifkgjmfdgpnipgnfejab [2017-02-09]
CHR Extension: (TV) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2017-02-09]
CHR Extension: (Nimbus Screenshot and Screencast) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpconcjcammlapcogcnnelfmaeghhagj [2017-02-09]
CHR Extension: (Replace New Tab Page) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkhddihkmmiiclaipbaaelfojkmlkja [2017-02-09]
CHR Extension: (Pixlr-o-matic) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2017-02-09]
CHR Extension: (Tetriz Challenge) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\emidddocikgklceeeifefomdnbkldhng [2017-02-09]
CHR Extension: (AudioRecorder) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\enhfkjkjfhhdibpgjmiamdcdgmcjpplk [2017-02-09]
CHR Extension: (Audio Downloader Prime) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\flainkeonkoanoijnkojmiiihnfdhipd [2017-02-09]
CHR Extension: (Trevx - Music Downloader) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpmaepaboafhefdejcbiciklgjogoghf [2017-02-09]
CHR Extension: (AdBlock) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-09]
CHR Extension: (A Journey through Middle-earth) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjgkjeheegjnnmheaflhdocglkiegoni [2017-02-09]
CHR Extension: (Where Am I? - VPN Checker) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbgdaefcalonegdjkhfaeabgodpahimo [2017-02-09]
CHR Extension: (Blocky Minecraft Sniper 3D) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\hclgbbaloijjnkpigapgmocdpoblnlec [2017-02-09]
CHR Extension: (Tate Art Slideshow) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgfbniacchiboaeoaoaejhggfepbbmkj [2017-02-09]
CHR Extension: (New Tab Redirect) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\icpgjfneehieebagbmdbhnlpiopdcmna [2017-02-11]
CHR Extension: (The Weather Channel for Chrome) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\iflpcokdamgefbghpdipcibmhlkdopop [2017-02-09]
CHR Extension: (90`s Games) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\illbbfoihflomkbpcaaakhijinbnejom [2017-02-09]
CHR Extension: (iPiccy Photo Editor) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\imokeandodnlammaoenbgcnbhigjbpjh [2017-02-09]
CHR Extension: (Pixect) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgdeoagndhabdnoenpdcagbkkmjeibmh [2017-02-09]
CHR Extension: (Webcam Toy) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2017-02-09]
CHR Extension: (Google Maps) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2017-02-09]
CHR Extension: (Screencastify (Screen Video Recorder)) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2017-02-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-07]
CHR Extension: (New Tab Changer) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\occbjkhimchkolibngmcefpjlbknggfh [2017-02-09]
CHR Extension: (SetupVPN - Lifetime Free VPN) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\oofgbpoabipfcfjapgnbbjjaenockbdp [2017-02-08]
CHR Extension: (Rollip - Photo Effects) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooikhmcdpofogemaldinihdhidaokcmp [2017-02-09]
CHR Extension: (Pop Art Studio Online) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\oompiimecpnflklhlnmdpddcjdmiibkf [2017-02-09]
CHR Extension: (Chrome Media Router) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-07]



With that aside, we're going to have to take a bit more extreme measures, because with all that fix, the malware came right back.

Let's do the following first please...

GMER

Note about this tool:

  • This program may freeze. Do not reboot the computer, unless it has been frozen for over 30 minutes.
  • This program may cause a blue screen of death. If it does, do not scan, and then reply to let me know.
  • No matter what is in the log, please post all the information/contents of the log.
  • These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT"


Please download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.

  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
Thanks again for your help.
In answer to your first question: No, I haven't made any restrictions or changes to the OS.  My knowledge of pc's is basic and I wouldn't know where to start.
In answer to what seems to be a large amount of extensions in Google Chrome, I have installed some of those from the Google Chrome Store,like  Adblock,Google Translate,Nimbus, Where am i VPN Checker, SetUp VPN and New tab redirect.  There seems to be an awful lot that I have no knowledge of having acquired however there are a few i may have had and removed from the Chrome page. The ones I mentioned, I regularly use but I am happy to remove the remainder.
Please find attached,the results of the GMER.txt
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
You're welcome. Please do not give up... I know we will have this soon... Just many of these tools have inabilities that we cannot help, so we are trying to find the best solution.

Please feel free to remove any Chrome addons that you do not want anymore, since it is difficult for me to decide what to remove, as many to most of them are safe. In case you need to know, hit the menu button   and select Settings > Extensions > Press the trash can button on each extension you do not wish to keep.

Let us continue with FRST, but please disable your Antivirus and IObit software before proceeding with this next fix...




Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.



NOTE: ONLY DO THE FOLLOWING AFTER THE SYSTEM HAS REBOOTED FIRST!
Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I have followed your advice and run the FRST scans as you stated.
Please find the relevant logs attached.
I have removed all but 6 of the extensions by following your instructions. I did not  see the majority of the ones that were in your previous message,like 90's games, Pixect  Rollip,etc. The only ones that remain are extensions that i use.
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
And yet it is back. What a drag...

Let's do the following please:

Reboot your computer, and when the first screen appears, immediately tap F8 to bring up the Startup Options. Use the keys to select Safe Mode with Networking.

Then please do the following:

Please launch Malwarebytes scanner which you have installed on your computer.

  • On the Dashboard, select Settings.
  • Click on Protection.
  • Ensure that Scan for rootkits is checked. If not, check it.
  • If you are notified the Database is out of date, click Update Now.
  • Click Scan now.
  • When completed, click the down arrow on Export Log and select Text file (*.txt).
  • Save the file to your desktop as MBAM.txt.
  • Click Apply Actions, then restart your computer, if requested.
  • Please copy and paste the contents of MBAM.txt into your next reply. Also, indicate if it was successful.




Emsisoft Emergency Kit

  • Please download Emsisoft Emergency Kit and save it to your desktop.

    Double click on Emsisoft Emergency Kit file on your desktop.  1 - [INACTIVE] NetUtils2016: PC badly affected after installing program 687474703a2f2f6936382e70686f746f6275636b65742e636f6d2f616c62756d732f6933352f6361726e33732f656d7369736f6674253230335f7a70736f6f783675786d6a2e706e67

    When the installation starts you see a image like the one below, click on Install.

    1 - [INACTIVE] NetUtils2016: PC badly affected after installing program 687474703a2f2f6936382e70686f746f6275636b65742e636f6d2f616c62756d732f6933352f6361726e33732f456d7369736f6674253230375f7a70736d62756f6c6b39722e706e67

    The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates. Please click Yes so that it downloads the latest database updates.

    When the update is complete, click on MALWARE SCAN under Scan.  When asked if you want the scanner to scan for Potentially Unwanted Programs, click Yes.

    1 - [INACTIVE] NetUtils2016: PC badly affected after installing program 687474703a2f2f6936382e70686f746f6275636b65742e636f6d2f616c62756d732f6933352f6361726e33732f456d7369736f66742532307363616e5f7a7073696671796f7a68662e706e67

    Emsisoft Emergency Kit will start scanning.

    When the scan is completed click on Quarantine.

    When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.  Copy the log and paste it in your topic.

    Please save the log in Notepad on your desktop, and post the contents in your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I have run Malwarebytes Scanner in Safe mode,however it stuck again in Heuristics Analysis and didn't move for 2 hours,at that point i ended the scan.

  It did find 7 problems and i got a screen grab of those problems. As the program wouldn't end, I was unable to remove them or provide you with a log.

The screen grab that i generated  is available here http://www.mediafire.com/file/n9hb5sn661k3vkj/screenshot-newtab-2017-02-15-10-36-04.zip

 I have run   Emsisoft Emergency Kit and on completion I could see from the lists that Netutils is still there.

At the completion of the Emsisoft scan,  a window automatically opens and access to any other part of Emsisoft is not possible as the program wants to restart the system.

I have quarenteened those items

 At the restart i was able to see that 2 NetUtils items had been removed at the restart,but they appear to be back again. I have run 2 scans and the results are attached.
thanks

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Thanks for the information...

Apologies for the brevity here, but please reboot into just Safe Mode (no networking or command prompt). Open Malwarebytes, press the Scan tab on the left, choose Custom Scan, press "Configure Scan," and only select these checkboxes (deselect others): Scan Memory Objects, Scan Startup and Registry Settings, and C: checked on right as well. Also, under Potentially Unwanted Program, choose the drop down and select "Treat Detections as Malware." Do the same for underneath Potentially Unwanted Modification.

Once that is complete, save the log as you usually would, and access it when you reboot back to Normal Mode, and then post it in your next reply. If that does not function again, you may send a screenshot.

description1 - [INACTIVE] NetUtils2016: PC badly affected after installing program EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum