WiredWX Hobby Weather ToolsLog in

 


Possible Virus

2 posters

descriptionSolvedRe: Possible Virus

more_horiz
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 7 Home Premium x64
Ran by mansoor (Administrator) on Sat 07/08/2017 at 16:30:35.82
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 50

Successfully deleted: C:\ProgramData\browser (Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\076cf75d74629217cb24028a2f99be8b (File)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0KD9SCAL (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2ADM4XRC (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6N7AD80M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7XXTF66G (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8AVXPGTP (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B0Q82J7T (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FQED5RRT (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GCP9VXC5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HD9GJQ5T (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I5JA2ALR (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K777O6VO (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L0D744HU (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NE90I7XS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NPX75CEH (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OD1RG6MC (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OZH791DL (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QDU44FHS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QI8PLFEQ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V17RG836 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mansoor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X9VHOPVA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0KD9SCAL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2ADM4XRC (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6N7AD80M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7XXTF66G (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8AVXPGTP (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B0Q82J7T (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FQED5RRT (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GCP9VXC5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HD9GJQ5T (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I5JA2ALR (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K777O6VO (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L0D744HU (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NE90I7XS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NPX75CEH (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OD1RG6MC (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OZH791DL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QDU44FHS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QI8PLFEQ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V17RG836 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X9VHOPVA (Temporary Internet Files Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 07/08/2017 at 16:33:07.75
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

descriptionSolvedRe: Possible Virus

more_horiz
Results of screen317's Security Check version 1.014 --- 12/23/15 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled! 
Microsoft Security Essentials  
Norton Internet Security       
 Antivirus up to date! 
`````````Anti-malware/Other Utilities Check:`````````
 Mozilla Firefox (54.0.1)
 Google Chrome (59.0.3071.115)
 Google Chrome (SetupMetrics...)
````````Process Check: objlist.exe by Laurent```````` 
 Microsoft Security Essentials MSMpEng.exe
 Microsoft Security Essentials msseces.exe
 iolo Common Lib ioloServiceManager.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 1%
````````````````````End of Log``````````````````````

descriptionSolvedRe: Possible Virus

more_horiz
Hi SuperDave,
Please find all the logs above.
Thanks.

descriptionSolvedRe: Possible Virus

more_horiz
The Security Log now shows that Norton Internet Security is running. Is this a program that you have paid for and do you still want to keep it? If you don't want it, you should uninstall it.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the Possible Virus - Page 2 EsetOnline button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


  • Click on Possible Virus - Page 2 EsetSmartInstall to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the Possible Virus - Page 2 EsetSmartInstallDesktopIcon-1 icon on your desktop.

•Check Possible Virus - Page 2 EsetAcceptTerms
•Click the Possible Virus - Page 2 EsetStart button.
•Accept any security warnings from your browser.


  • Leave the check mark next to Remove found threats.

•Check Possible Virus - Page 2 EsetScanArchives
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push Possible Virus - Page 2 EsetListThreats
•Push Possible Virus - Page 2 EsetExport, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the Possible Virus - Page 2 EsetBack button.
•Push Possible Virus - Page 2 EsetFinish
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

descriptionSolvedRe: Possible Virus

more_horiz
Hi,
Please find the results.

C:\AdwCleaner\quarantine\files\eukowzssjuodidlsijshnhhnfstuxoch\bin\D10\netengine.exe    a variant of MSIL/Adware.PullUpdate.P application    cleaned by deleting
C:\AdwCleaner\quarantine\files\gkbssezmblywctqmgzcwjwvcchboduia\Arcadeparlor.dll    a variant of Win32/ArcadeParlor.B potentially unwanted application    cleaned by deleting
C:\AdwCleaner\quarantine\files\gkbssezmblywctqmgzcwjwvcchboduia\broker.exe    Win32/ArcadeParlor.A potentially unwanted application    cleaned by deleting
C:\AdwCleaner\quarantine\files\gkbssezmblywctqmgzcwjwvcchboduia\versioncheck.exe    a variant of Win32/ArcadeParlor.B potentially unwanted application    cleaned by deleting
C:\AdwCleaner\quarantine\files\gkeauwbksrxoyqdgtommmaxhaqjjfndc\keepmysettingsx.zip    a variant of Win32/InstallIQ.A potentially unwanted application    deleted
C:\AdwCleaner\quarantine\files\mxulsdwbyfmcjmtukwobyipkrasixbho\1.0.7.1\loolkaah.exe    a variant of MSIL/Adware.PullUpdate.P application    cleaned by deleting
C:\AdwCleaner\quarantine\files\qjebasqpmqafueeywrxjgwuoehlfpokf\Client.exe    a variant of MSIL/Adware.iBryte.F application    cleaned by deleting
C:\AdwCleaner\quarantine\files\qjebasqpmqafueeywrxjgwuoehlfpokf\Tasks.exe    a variant of MSIL/Adware.iBryte.X application    cleaned by deleting
C:\AdwCleaner\quarantine\files\qjebasqpmqafueeywrxjgwuoehlfpokf\Uninstall.exe    a variant of MSIL/Adware.iBryte.X application    cleaned by deleting
C:\AdwCleaner\quarantine\files\qjebasqpmqafueeywrxjgwuoehlfpokf\Updater.exe    a variant of MSIL/Adware.iBryte.X application    cleaned by deleting
C:\AdwCleaner\quarantine\files\qubwuzxckacbwawbnbgtjfqohryaextq\uninstall.exe    a variant of MSIL/Adware.PullUpdate.J.gen application    cleaned by deleting
C:\AdwCleaner\quarantine\files\zuqykfekeldgafukoryhedxmlfhpknwd\Client.exe    a variant of MSIL/Adware.iBryte.AA application    cleaned by deleting
C:\AdwCleaner\quarantine\files\zuqykfekeldgafukoryhedxmlfhpknwd\Tasks.exe    a variant of MSIL/Adware.iBryte.AA application    cleaned by deleting
C:\AdwCleaner\quarantine\files\zuqykfekeldgafukoryhedxmlfhpknwd\Uninstall.exe    a variant of MSIL/Adware.iBryte.AA application    cleaned by deleting
C:\AdwCleaner\quarantine\files\zuqykfekeldgafukoryhedxmlfhpknwd\Updater.exe    a variant of MSIL/Adware.iBryte.AA application    cleaned by deleting
C:\Temp\valueappsinst.exe    a variant of Win32/Conduit.SearchProtect.N potentially unwanted application,a variant of Win32/Toolbar.Conduit.AR potentially unwanted application,a variant of Win32/Toolbar.Conduit.AL potentially unwanted application    cleaned by deleting
C:\Temp\user\valueappsinstaller.exe    a variant of Win32/Conduit.SearchProtect.N potentially unwanted application,a variant of Win32/Toolbar.Conduit.AR potentially unwanted application,a variant of Win32/Toolbar.Conduit.AL potentially unwanted application    cleaned by deleting

descriptionSolvedRe: Possible Virus

more_horiz
Is there any change in your browsers now?

descriptionSolvedRe: Possible Virus

more_horiz
Hi SuperDave,
I have just now logged into my system.I will let u know if the issue still exists after waiting for a couple of hours  because earlier the problem seems to revert back every few hours.Will keep u posted.

Thanks.

descriptionSolvedRe: Possible Virus

more_horiz
Hi Super Dave,

Thank you very much now chrome and opera are working fine I have to check IE.

descriptionSolvedRe: Possible Virus

more_horiz
That is good news. Let me know.

descriptionSolvedRe: Possible Virus

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum