GeekPolice Tech TutorialsLog in

 

[INACTIVE] NetUtils2016: PC badly affected after installing program

Share

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please find a fresh scan of SystemLook attached
thank you
Attachments
SystemLook.txt

You don't have permission to download attachments.

(4 Kb) Downloaded 1 times

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Persistent lot, isn't it?
Look at this: C:\Windows\System32\drivers\NetUtils2016.sys    --a---- 909944 bytes    [19:00 13/02/2017]    [19:00 13/02/2017] 9EE21F7D46BD2B0F128E0907BABC7D28




Let's target it a bit more... We need a different approach... Bear with me here. Smile...

Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply. Also, attach MBRDUMP.txt to your next reply, which will be located within the same area of FRST.




Avast Browser Cleanup Tool


  1. Please download this free tool and save it to your desktop.
  2. Install the program by double-clicking on avast-browser-cleanup-sfx.exe.
  3. This cleanup tool will search and list if unwanted entries were found. If found, it will display a button ‘Remove all add-ons listed below and cleanup browser.’ You may remove all or delete one entry at a time.
  4. Avast Browser Cleanup will confirm before it permanently deletes the add-on. Please click Yes to proceed with removal of bad add-ons on the affected browser.





Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.




In your next reply, please include the following:

  • Fixlog.txt for FRST fix
  • MBRDUMP.txt
  • FRST.txt and Addition.txt for the re-run of FRST.
Attachments
fixlist.txt

You don't have permission to download attachments.

(1 Kb) Downloaded 1 times

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
Please find attached the logs as you requested,
The MBRDUMP log is empty and as such I have been unable to send it.
thanks
Attachments
Fixlog.txt

You don't have permission to download attachments.

(2 Kb) Downloaded 3 times

FRST.txt

You don't have permission to download attachments.

(48 Kb) Downloaded 2 times

Addition.txt

You don't have permission to download attachments.

(41 Kb) Downloaded 1 times

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Couple of questions... Did you make these restrictions on the OS:

GroupPolicy: Restriction - Chrome <======= ATTENTION
HKLM\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKLM\...\Policies\Explorer: [NoResolveSearch] 1
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKLM\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-2138326613-2610238322-1334748225-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-2138326613-2610238322-1334748225-1001\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-2138326613-2610238322-1334748225-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION


Second question... Did you install or want these Google Chrome extensions:
CHR Extension: (Google Translate) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2017-02-09]
CHR Extension: (Nimbus Screenshot App) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\aecjogkncpbkjfobfnoaiepipllcadhe [2017-02-09]
CHR Extension: (File Converter) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\alblmaecejifbilchdofkdanifpmnmfk [2017-02-09]
CHR Extension: (BeFunky Photo Editor) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\apfkepiiddolifkgjmfdgpnipgnfejab [2017-02-09]
CHR Extension: (TV) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2017-02-09]
CHR Extension: (Nimbus Screenshot and Screencast) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpconcjcammlapcogcnnelfmaeghhagj [2017-02-09]
CHR Extension: (Replace New Tab Page) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkhddihkmmiiclaipbaaelfojkmlkja [2017-02-09]
CHR Extension: (Pixlr-o-matic) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2017-02-09]
CHR Extension: (Tetriz Challenge) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\emidddocikgklceeeifefomdnbkldhng [2017-02-09]
CHR Extension: (AudioRecorder) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\enhfkjkjfhhdibpgjmiamdcdgmcjpplk [2017-02-09]
CHR Extension: (Audio Downloader Prime) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\flainkeonkoanoijnkojmiiihnfdhipd [2017-02-09]
CHR Extension: (Trevx - Music Downloader) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpmaepaboafhefdejcbiciklgjogoghf [2017-02-09]
CHR Extension: (AdBlock) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-09]
CHR Extension: (A Journey through Middle-earth) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjgkjeheegjnnmheaflhdocglkiegoni [2017-02-09]
CHR Extension: (Where Am I? - VPN Checker) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbgdaefcalonegdjkhfaeabgodpahimo [2017-02-09]
CHR Extension: (Blocky Minecraft Sniper 3D) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\hclgbbaloijjnkpigapgmocdpoblnlec [2017-02-09]
CHR Extension: (Tate Art Slideshow) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgfbniacchiboaeoaoaejhggfepbbmkj [2017-02-09]
CHR Extension: (New Tab Redirect) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\icpgjfneehieebagbmdbhnlpiopdcmna [2017-02-11]
CHR Extension: (The Weather Channel for Chrome) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\iflpcokdamgefbghpdipcibmhlkdopop [2017-02-09]
CHR Extension: (90`s Games) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\illbbfoihflomkbpcaaakhijinbnejom [2017-02-09]
CHR Extension: (iPiccy Photo Editor) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\imokeandodnlammaoenbgcnbhigjbpjh [2017-02-09]
CHR Extension: (Pixect) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgdeoagndhabdnoenpdcagbkkmjeibmh [2017-02-09]
CHR Extension: (Webcam Toy) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2017-02-09]
CHR Extension: (Google Maps) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2017-02-09]
CHR Extension: (Screencastify (Screen Video Recorder)) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2017-02-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-07]
CHR Extension: (New Tab Changer) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\occbjkhimchkolibngmcefpjlbknggfh [2017-02-09]
CHR Extension: (SetupVPN - Lifetime Free VPN) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\oofgbpoabipfcfjapgnbbjjaenockbdp [2017-02-08]
CHR Extension: (Rollip - Photo Effects) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooikhmcdpofogemaldinihdhidaokcmp [2017-02-09]
CHR Extension: (Pop Art Studio Online) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\oompiimecpnflklhlnmdpddcjdmiibkf [2017-02-09]
CHR Extension: (Chrome Media Router) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-07]



With that aside, we're going to have to take a bit more extreme measures, because with all that fix, the malware came right back.

Let's do the following first please...

GMER

Note about this tool:

  • This program may freeze. Do not reboot the computer, unless it has been frozen for over 30 minutes.
  • This program may cause a blue screen of death. If it does, do not scan, and then reply to let me know.
  • No matter what is in the log, please post all the information/contents of the log.
  • These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT"


Please download the GMER Rootkit Scanner . Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.

  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
Thanks again for your help.
In answer to your first question: No, I haven't made any restrictions or changes to the OS.  My knowledge of pc's is basic and I wouldn't know where to start.
In answer to what seems to be a large amount of extensions in Google Chrome, I have installed some of those from the Google Chrome Store,like  Adblock,Google Translate,Nimbus, Where am i VPN Checker, SetUp VPN and New tab redirect.  There seems to be an awful lot that I have no knowledge of having acquired however there are a few i may have had and removed from the Chrome page. The ones I mentioned, I regularly use but I am happy to remove the remainder.
Please find attached,the results of the GMER.txt
thanks
Attachments
GMER.txt

You don't have permission to download attachments.

(15 Kb) Downloaded 2 times

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
You're welcome. Please do not give up... I know we will have this soon... Just many of these tools have inabilities that we cannot help, so we are trying to find the best solution.

Please feel free to remove any Chrome addons that you do not want anymore, since it is difficult for me to decide what to remove, as many to most of them are safe. In case you need to know, hit the menu button   and select Settings > Extensions > Press the trash can button on each extension you do not wish to keep.

Let us continue with FRST, but please disable your Antivirus and IObit software before proceeding with this next fix...




Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.



NOTE: ONLY DO THE FOLLOWING AFTER THE SYSTEM HAS REBOOTED FIRST!
Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.
Attachments
fixlist.txt

You don't have permission to download attachments.

(6 Kb) Downloaded 2 times

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I have followed your advice and run the FRST scans as you stated.
Please find the relevant logs attached.
I have removed all but 6 of the extensions by following your instructions. I did not  see the majority of the ones that were in your previous message,like 90's games, Pixect  Rollip,etc. The only ones that remain are extensions that i use.
thanks
Attachments
Fixlog.txt

You don't have permission to download attachments.

(14 Kb) Downloaded 1 times

FRST.txt

You don't have permission to download attachments.

(46 Kb) Downloaded 2 times

Addition.txt

You don't have permission to download attachments.

(41 Kb) Downloaded 2 times

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
And yet it is back. What a drag...

Let's do the following please:

Reboot your computer, and when the first screen appears, immediately tap F8 to bring up the Startup Options. Use the keys to select Safe Mode with Networking.

Then please do the following:

Please launch Malwarebytes scanner which you have installed on your computer.

  • On the Dashboard, select Settings.
  • Click on Protection.
  • Ensure that Scan for rootkits is checked. If not, check it.
  • If you are notified the Database is out of date, click Update Now.
  • Click Scan now.
  • When completed, click the down arrow on Export Log and select Text file (*.txt).
  • Save the file to your desktop as MBAM.txt.
  • Click Apply Actions, then restart your computer, if requested.
  • Please copy and paste the contents of MBAM.txt into your next reply. Also, indicate if it was successful.




Emsisoft Emergency Kit

  • Please download Emsisoft Emergency Kit and save it to your desktop.

    Double click on Emsisoft Emergency Kit file on your desktop. 

    When the installation starts you see a image like the one below, click on Install.



    The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates. Please click Yes so that it downloads the latest database updates.

    When the update is complete, click on MALWARE SCAN under Scan.  When asked if you want the scanner to scan for Potentially Unwanted Programs, click Yes.



    Emsisoft Emergency Kit will start scanning.

    When the scan is completed click on Quarantine.

    When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.  Copy the log and paste it in your topic.

    Please save the log in Notepad on your desktop, and post the contents in your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I have run Malwarebytes Scanner in Safe mode,however it stuck again in Heuristics Analysis and didn't move for 2 hours,at that point i ended the scan.

  It did find 7 problems and i got a screen grab of those problems. As the program wouldn't end, I was unable to remove them or provide you with a log.

The screen grab that i generated  is available here http://www.mediafire.com/file/n9hb5sn661k3vkj/screenshot-newtab-2017-02-15-10-36-04.zip

 I have run   Emsisoft Emergency Kit and on completion I could see from the lists that Netutils is still there.

At the completion of the Emsisoft scan,  a window automatically opens and access to any other part of Emsisoft is not possible as the program wants to restart the system.

I have quarenteened those items

 At the restart i was able to see that 2 NetUtils items had been removed at the restart,but they appear to be back again. I have run 2 scans and the results are attached.
thanks
Attachments
scan_170215-105206.txt

You don't have permission to download attachments.

(2 Kb) Downloaded 1 times

scan_170215-112432.txt

You don't have permission to download attachments.

(2 Kb) Downloaded 1 times

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Thanks for the information...

Apologies for the brevity here, but please reboot into just Safe Mode (no networking or command prompt). Open Malwarebytes, press the Scan tab on the left, choose Custom Scan, press "Configure Scan," and only select these checkboxes (deselect others): Scan Memory Objects, Scan Startup and Registry Settings, and C: checked on right as well. Also, under Potentially Unwanted Program, choose the drop down and select "Treat Detections as Malware." Do the same for underneath Potentially Unwanted Modification.

Once that is complete, save the log as you usually would, and access it when you reboot back to Normal Mode, and then post it in your next reply. If that does not function again, you may send a screenshot.

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
I have run Malwarebytes again as requested and once again it stuck in Heuristics ananlysis for just over 6 hours.
I have come out of safe mode and have attached the screen grab here, http://www.mediafire.com/file/9ruzpu1xdmrwhf3/screenshot-newtab-2017-02-16-01-05-01.jpg.
thank you once more.

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I'm going to do some investigation closer.

I will be back after several hours with the next instructions... For now, please do the following, which will help me decide what to do later:

First, Re-run Junkware Removal Tool and AdwCleaner as before and post logs from them.




Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that every checkbox has a checkmark beside it! <<< NEW INSTRUCTIONS
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.




Re-run SystemLook

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    Code:

    :filefind
    *Avg*
    *McAfee*
    *NetUtils*
    *NetUtils2016*
    *dot4*
    *smw*
    *smp*
    *startgo123*

    :folderfind
    *Avg*
    *McAfee*
    *NetUtils*
    *NetUtils2016*
    *sstmp*
    *dot4*
    *smw*
    *smp*
    *startgo123*

    :Regfind
    NetUtils
    NetUtils2016
    startgo123


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt




WVCheck
Please download WVCheck from Latest EXE Download .

  • Double click WVCheck.exe. (If you downloaded the zipped version you will need to extract it.)
  • As indicated by the prompt, This program can take a while depending on your hard drive space.
  • Once the program is done, copy the contents of the notepad file and send me a private message with the information. This is important since much of the information is unique to you as an individual.





OTHER NOTES:
Confirm with me whether you ran the Chrome Browser Cleanup Tool early on and Avast Browser Cleanup. If this was not done, then this has caused the reinfection.

If you have accounts on Mozilla for Firefox, and Google for Chrome and other accounts, then you can easily sync your data, and completely reinstall the profiles for each browser, which may or may not help this process. I can help you do this of course, but I want to ensure you do not lose browser settings, bookmarks, list of addons, etc., which would easily be "sync-able".

Lastly, did you create the folders on the desktop named "AAA - *" (where * is the suffix, like personal files, video, etc.)?

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,
 I have run FRST as requested with the new instructions and it stuck on 'Scanning Edge' for approx 5 hours with no sign of ending. I started it at 09.33and at 13.22 it is still running.
At that point I ended the scan. The FRST log is attached. The Additions log is not available as the scan did not complete.
I then ran SystemLook and the results are attached here.
WV check has run and I have sent a pm with the info.
In answer to your questions, I can confirm that I ran Avast Browser Cleanup, but i can't recall running Chrome Browser Cleanup tool unless you asked me to,in which case I have followed all of your directions.
I have synced my bookmarks for Chrome and Opera. 
The folders on my desktop named AAA are mine  and contain all kinds of personal items.
thanks
Attachments
FRST.txt

You don't have permission to download attachments.

(8 Kb) Downloaded 1 times

System Look Part 1.txt

You don't have permission to download attachments.

(36 Kb) Downloaded 1 times

System Look Part 2.txt

You don't have permission to download attachments.

(64 Kb) Downloaded 1 times

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Okay, let's get on the offensive here toward the infection... Since the bookmarks and other things are synced, we would need to work out the following... In order of course:

Please download and run RKill.

Download mirror 1 - Download mirror 2 - Download mirror 3


  • Save it to your Desktop.
  • Double click the RKill desktop icon.
  • It will quickly run and launch a log. If it does not launch a log, try another download link until it does.
  • Please post its log in your next reply.
  • After it has run successfully, delete RKill.

Note: This tool only kills the active infection, the actual infection will not be gone. Once you reboot the infection will be active again! Please do not reboot until instructed further to do so.



Please download ZHPcleaner to your desktop.

  • Double click on ZHPCleaner to run the tool.
  • If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
  • Please click
  • Then press ''Repair'' button.
  • Browsers will automatically shut down.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.





Scan with Shortcut Cleaner:

Please download Shortcut Cleaner to your Desktop.

Right-click on sc-cleaner.exe and select Run as Administrator >> follow the prompts and post the contents of sc-cleaner.txt in your next reply.

Note: The log can also be located at C: >> sc-cleaner.txt

Next
When completed the above, please post back the following in the order asked for:

  • Shortcut Cleaner Log.





Re-run of Malwarebytes scanner
!!NEW INSTRUCTIONS: IF Malwarebytes does not work, re-run RKILL above, and try again until it does so, please.

Please re-open Malwarebytes, and press Scan. If there is an update, allow it to do so.

  • When the scan is complete, if there have been detections, click Quarantines Selected button to allow the program to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

How to get logs: (Export log to save as txt)

  • After the restart once you are back at your desktop, open Malwarebytes once more.
  • Click on the Reports tab > Scan Report. (if you have done more than one scan in the past, select the most recent that shows the Date and time of the scan just performed. Press View Report button.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • Find the log on your Desktop and Attach that saved log to your next reply.

(Copy to clipboard for pasting into forum replies or tickets)

descriptionRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
 I have carried out your requests and have run RKill,that log is attached  
 I have run ZHP cleaner and that log is attached
 I have run shortcut cleaner and that log is attached
 Malwarebytes is currently running and i will post the log when it has finished.
thanks
Attachments
Rkill.txt

You don't have permission to download attachments.

(2 Kb) Downloaded 1 times

ZHPCleaner.txt

You don't have permission to download attachments.

(5 Kb) Downloaded 1 times

sc-cleaner.txt

You don't have permission to download attachments.

(2 Kb) Downloaded 1 times

Permissions in this forum:
You cannot reply to topics in this forum