Quantcast
Channel: Tech Support Guy - Virus & Other Malware Removal
Viewing all 4746 articles
Browse latest View live

New to removing Viruses, Spyware and Malware on Windows 7. Please help

$
0
0
Hello. My name is Joseph. I'm new to understanding how to remove malicious threats. I started this thread to find out how the step by step procedure works when it comes to removing threats from a Windows 7 operating system.

If someone would be kind enough to teach me the process from basics to advanced that would be nice. I suspect I have a virus on this system now. I would like to find a way to remove this threat, if I do actually have one. But keep in mind this is to teach me how to get rid of these threats more than just removing them.

The problem I seem to face is that my system slows down after awhile of use. also after I format my computer with windows 7 my internet speed slows down. One thing I did notice is that I see alot of unusual activity after I format. As in files will download when I did not ask them to.

My computer habbits are usually downloading online (torrents.) And browsing the internet with light gaming. When it comes to torrents I really want to start staying away from them because of being told they are flooded with viruses and such. So that should change. But the reason I mention that is so that you know that my idea is that I downloaded a very powerful virus that just keeps coming back to my system even after a format have been made. Other than that, that is all I can say about my computer.

So without further adieu I will post my system info like I was requested when I sign up for the site.

Thank you very much your all your help.

Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM)2 Duo CPU P8700 @ 2.53GHz, Intel64 Family 6 Model 23 Stepping 10
Processor Count: 2
RAM: 6143 Mb
Graphics Card: NVIDIA GeForce GTX 260M, 1024 Mb
Hard Drives: C: Total - 461940 MB, Free - 412325 MB;
Motherboard: ASUSTeK Computer INC., G72GX
Antivirus: None

Zym.tollbahsuburban.com need help to remove

$
0
0
I need help get rid of Tollbahsuburban from my nieces:confused: laptop
please help

PXE messages, BSOD, etc -- a malware issue?

$
0
0
My Gateway NE56R is having bad problems involving BSOD, PXE-E61 and PXE-MOF error messages, system crashes and hangs. The trouble started a few days ago after I foolishly clinked on a spam email link that may have been malware/spyware bait. When I realized I may have downloaded a virus, I used my Windows Recovery Partition to delete my entire operating system and restore the computer to factory default settings. The BSOD/PXE crashes came back, though.

I am now wondering if the problem is that my hard drive is dying on me due to age (I bought the computer two years ago) or if malware/virus may have infected the system restore software that resides in the Windows Recovery Partition. I suspect the latter cause, because my computer has never been exposed to any trauma that would break moving parts. I've only been using the computer for two years. Either way, I'm not sure, though.

MY QUESTION

Is there any way I can run some tests to find out which is the problem here? I'm not a techie. I'd appreciate any advice offered.

SYSTEM SPECS

Gateway NE56R
Windows 7 (Service Pack 1)
Intel (R) Pentium (R) CUP B950 @ 2.10 Ghz 2.10 GHz
4.00 GB (3.84 GB available)
64 bit OS

ERROR MESSAGES

1. BSOD - flashes for about two seconds on my screen; I never have time to read all the details before it closes. It says something like, "System shut down due to a problem."

2. When I try to restart the computer, I'm frequently blocked by PXE-E61 (meia test failure, check cable) and PXE-MOF (exiting....?....no bootable device....insert boot desk and press a key).

3. I usually power down after getting PXE, then get the option of restarting in safe mode, etc.

4. When restoring a fresh OS system from the recovery partition (I've done it about two or three times now), I get blocked during "Windows Updates" downloads. I get the "Failure configuring Windows updates. Redirecting changes. Do not turn off your computer."

Annoying Adware

$
0
0
hello I've been having this problem for a while now.

theres an adware that looks like this


luckily i have my adblock on googlechrome and it looks like this


i rightclicked it and selected inspect element, came up with this


i already scanned my pc with avast, adwarecleaner and malwarebytes.

Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, 32 bit
Processor: AMD Athlon(tm) Dual Core Processor 4450e, x64 Family 15 Model 107 Stepping 2
Processor Count: 2
RAM: 3070 Mb
Graphics Card: NVIDIA GeForce GT 610, 2047 Mb
Hard Drives: C: Total - 305142 MB, Free - 93792 MB;
Motherboard: ECS, Iris8
Antivirus: None

Internet connection blocked unless in safe mode with networking

$
0
0
I have a windows 8 desktop that has its internet connection blocked by malware. Everything runs fine including the internet in safe mode with networking. My anti-virus is AVG. I have malwarebytes and superantispyware update and working on it. When I run these in safe mode they fine lots of malware and remove it. But then when i boot back into normal mode they find nothing and the internet doesn't work. In safe mode they are finding things called search dial, PUP objects etc..

100% CPU Usage! explorer.exe

$
0
0
I found the problem today.
My Cpu Usage is 100%, but there is only my windows running.
The explorer.exe process use 50-80% of the Cpu.

It hase to be a virus, but my antimalware software Malwarebytes Anti-Malware and Avira din't find anything.

Need help! I can't work with that problem.

Greetings,
KokoNane

16 bit application error

power.exe virus problems

$
0
0
"Powershell has stopped working"

and when I click on "problem details" it shows this:

Problem signature:
Problem Event Name: PowerShell
NameOfExe: powershell.exe
FileVersionOfSystemManagementAutomation: 6.0.6002.18111
InnermostExceptionType: System.AccessViolationException
OutermostExceptionType: System.AccessViolationException
DeepestPowerShellFrame: tem.Management.Automation.MethodInformation.Invoke
DeepestFrame: t.Invoke
ThreadName: Pipeli..ution Thread
OS Version: 6.0.6002.2.2.0.768.3
Locale ID: 1033

Read our privacy statement:
http://go.microsoft.com/fwlink/?link...3&clcid=0x0409

Cant get rid of this virus please help

$
0
0
I have been trying to get rid of this virus of a very long time. Can anyone find my problem?

After I format it just comes right back. Im not sure if its because I continue to login to the same sites or if its just still on my computer some where.

The infection causes my computer to slow down. Then the internet download bandwidth starts to decrease until it becomes unusable. also when I use firefox it always acts up by downloading things I never even clicked on. randomly after I clean firefox, firefox downloads a file without permission. This is why I believe I have a Virus or spyware or malware of some kind. Please help.

Thank you so such.

Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM)2 Duo CPU P8700 @ 2.53GHz, Intel64 Family 6 Model 23 Stepping 10
Processor Count: 2
RAM: 6143 Mb
Graphics Card: NVIDIA GeForce GTX 260M, 1024 Mb
Hard Drives: C: Total - 461940 MB, Free - 410849 MB;
Motherboard: ASUSTeK Computer INC., G72GX
Antivirus: None

DNS Hijack?

$
0
0
Hi

for the last month I noticed a very odd behavior in my browser: it would time out and not load random pages including many known websites (like microsoft.com and so on). Those same websites would be accessible though from other machines on my home network. Trying to find out why I tried the following steps: reinstalled chrome, firefox and safari; full scan of system with antivirus and two malware checkers as well as TDSSKiller, added OpenDNS and Google DNS servers. It was not until I looked at the DNS listing obtained from cmd/ipconfig all to check that the new DNS setting were operational that I noticed two strange servers at the top of the list of servers: 75.126.206.18 and 184.173.169.186. Flush DNS would not get rid of them and a quick search revealed that they are connected to instances of DNS Hijack. DDS log available on request. Hope you guys can help me solve this.

hijacked home page - Firefox

$
0
0
I've just noticed that firing up FF through Run... (firefox.exe -P), I do not get the redirect. If I fire it up through the Taskbar, I do. Is the Toolbar FF link easy to change?

may be infected, advice please

$
0
0
Please say exactly what is wrong and why think that you might be infected

"Windows Installer" constantly pops up

Toshiba & CenLink were no help:CPU usage 100-limited connectivity only on laptop

$
0
0
Whatever it is is getting worse. PLEASE HELP!!

Unwanted website link keeps appearing

$
0
0
Have spent about ten minutes going to various websites and so far no sign of "rogue" items! Will give it a day or so and then come back - hopefully with a "Solved" report. Thanks for all your input.

Very slow laptop, then have 3 decrpytion fies show up.

$
0
0
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 03/10/2014
Scan Time: 4:47:14 PM
Logfile: m.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.24.06
Rootkit Database: v2014.08.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Trevor
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 335518
Time Elapsed: 37 min, 58 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 3
CryptoWall.Trace, C:\Users\Trevor\Desktop\DECRYPT_INSTRUCTION.HTML, , [73f39b2f087384b25f2d86612ed420e0],
CryptoWall.Trace, C:\Users\Trevor\Desktop\DECRYPT_INSTRUCTION.TXT, , [9acc4a803d3e6ec8eca0be29738f9a66],
CryptoWall.Trace, C:\Users\Trevor\Desktop\DECRYPT_INSTRUCTION.URL, , [8fd7e7e376052e080983ce1962a0936d],
Physical Sectors: 0
(No malicious items detected)

(end)

Possible Virus or malware

$
0
0
I recently had to update my anti-virus program. It was on 9-21-14. I had Kaspersky's Internet Security 2014. I had downloaded from CD disk. When I upgraded this year I downloaded Internet Security 2015 from the internet. I had completely taken the 2014 version off thru the Control Panel. Every since doing that, the computer has been very slow to boot up and go from program to program. It takes several minutes to load a website page. That problem come and goes though. Another problem I'm having is I keep getting pop ups that tell me I need to upgrade my version of Internet Explorer and Firefox. I have done that and the computer says I'm running the current versions of both. Thank you. Tenntod


Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz, Intel64 Family 6 Model 42 Stepping 7
Processor Count: 4
RAM: 4002 Mb
Graphics Card: Intel(R) HD Graphics Family, 1809 Mb
Hard Drives: C: Total - 593551 MB, Free - 533477 MB;
Motherboard: TOSHIBA, PEQAA
Antivirus: Kaspersky Internet Security, Updated and Enabled

Virus

$
0
0
how do I remove whatever this thing is from my computer it pops up when I go to generic sites with this popup claiming o be from whatever generic site I visit be it YouTube or something else.

Attached Images
File Type: jpg virus.jpg (333.4 KB)

M...LOCKER/Personal file is this a virus

$
0
0
Sorry for long delay in replying. Moved house on 16th September. Just finding our feet.

Here is the fixlist log

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-10-2014 01
Ran by Marie at 2014-10-04 16:21:39 Run:2
Running from C:\Users\Marie\Downloads
Loaded Profile: Marie (Available profiles: Marie)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Users\Marie\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\5PUNW1AB\home.mcafee[1].xml
C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee HIPS Driver.cat
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\ Cookies\marie-pc$@mcafee[2].txt
C:\Program Files\McAfee.com
c:\PROGRA~2\mcafee
c:\PROGRA~1\mcafee
c:\PROGRA~1\COMMON~1\mcafee
C:\Program Files (x86)\Common Files\McAfee

Reg: reg delete HKEY_CURRENT_USER\Software\McAfee
Reg: reg delete HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\McAfee Trust
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mfe
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{B48A23C6-434F-43bc-B98E-AF5B21A92964}
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CB58125-ED4E-4125-B72E-BA3435AC4421}\InProcServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1DD7B920-0AAE-457B-8A6B-077A92933F82}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32DE22BD-FA4F-42C4-AE35-A07A77F81098}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F936876-EB3C-4C5B-810D-05E1F36CB130}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{629DEAAC-2F4F-4C37-95F0-16FC6EDD0C0E}\InProcServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83EEF1DB-16A2-426F-843D-85A5348337C1}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{861C8C71-ABFF-48A0-B8CE-A6E8B0CF53F0}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B83A062E-59F2-4BB3-86A8-C289691A412E}\InProcServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C88F5D3A-EBE1-4513-AFC9-CE98CBD96A74}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90134D2-4AE9-407A-919A-4A2EF09C6C51}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CD009C4C-EAAC-4A03-9C44-4342D4CFABA9}
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CD009C4C-EAAC-4A03-9C44-4342D4CFABA9}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE480D09-9DD2-49A8-A3C3-B8B4B4F84F19}\InProcServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\844C97FE649617D41843 300487880C45\SourceList /v LastUsedSource
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\844C97FE649617D41843 300487880C45\SourceList\Net /v 1
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{35B517DE-7993-46D7-BCF5-CD00A3A03D65}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{35B517DE-7993-46D7-BCF5-CD00A3A03D65}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{495373CD-333F-4FC0-98A7-4B4E09689138}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{495373CD-333F-4FC0-98A7-4B4E09689138}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7F8123B7-1B40-4B4C-8D07-7E0C5BE1896D}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7F8123B7-1B40-4B4C-8D07-7E0C5BE1896D}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{97503958-F660-45DF-BFB4-E94B8752043F}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{97503958-F660-45DF-BFB4-E94B8752043F}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9B51EF78-BA1B-41FC-AFD3-5CED0802A7CE}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9B51EF78-BA1B-41FC-AFD3-5CED0802A7CE}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C7D12FC5-40EE-4288-BE78-94A8C65D0ECB}\1.0\0\win32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C7D12FC5-40EE-4288-BE78-94A8C65D0ECB}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0CB58125-ED4E-4125-B72E-BA3435AC4421}\InProcServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2F4C0E0C-80AD-4105-9A0F-4BA90BB64296}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{601D72B9-326F-46CD-815E-12D5D15761BA}\LocalServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F7520A2F-82E1-4DD5-A4BF-9D56BCF1D743}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{B48A23C6-434F-43bc-B98E-AF5B21A92964}
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{35B517DE-7993-46D7-BCF5-CD00A3A03D65}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{35B517DE-7993-46D7-BCF5-CD00A3A03D65}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{495373CD-333F-4FC0-98A7-4B4E09689138}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{495373CD-333F-4FC0-98A7-4B4E09689138}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{7F8123B7-1B40-4B4C-8D07-7E0C5BE1896D}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{7F8123B7-1B40-4B4C-8D07-7E0C5BE1896D}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{97503958-F660-45DF-BFB4-E94B8752043F}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{97503958-F660-45DF-BFB4-E94B8752043F}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9B51EF78-BA1B-41FC-AFD3-5CED0802A7CE}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9B51EF78-BA1B-41FC-AFD3-5CED0802A7CE}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{C7D12FC5-40EE-4288-BE78-94A8C65D0ECB}\1.0\0\win32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{C7D12FC5-40EE-4288-BE78-94A8C65D0ECB}\1.0\HELPDIR
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DAABE21E-DB8C-49b8-9511-9E6547ECBC6F}" /v AppPath
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Use r Data\S-1-5-18\Products\844C97FE649617D41843300487880C45\InstallProperties" /v Contact
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Use r Data\S-1-5-18\Products\844C97FE649617D41843300487880C45\InstallProperties" /v InstallSource
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Use r Data\S-1-5-18\Products\844C97FE649617D41843300487880C45\InstallProperties" /v Publisher
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers" /v C:\Program Files\McAfee.com\Agent\mcagent.exe
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fheoggkfdf chfphceeifdbepaooicaho /v path
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DAABE21E-DB8C-49b8-9511-9E6547ECBC6F}" /v AppPath
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\In ternet Settings\5.0\User Agent\Post Platform /v McAfee
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions /v {4ED1F68A-5463-4931-9384-8FFF5ED91D92}
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{0CB58125-ED4E-4125-B72E-BA3435AC4421}\InProcServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{2F4C0E0C-80AD-4105-9A0F-4BA90BB64296}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{601D72B9-326F-46CD-815E-12D5D15761BA}\LocalServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{F7520A2F-82E1-4DD5-A4BF-9D56BCF1D743}\InprocServer32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{B48A23C6-434F-43bc-B98E-AF5B21A92964}
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{B48A23C6-434F-43bc-B98E-AF5B21A92964} /v LocalService
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{35B517DE-7993-46D7-BCF5-CD00A3A03D65}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{35B517DE-7993-46D7-BCF5-CD00A3A03D65}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{495373CD-333F-4FC0-98A7-4B4E09689138}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{495373CD-333F-4FC0-98A7-4B4E09689138}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{7F8123B7-1B40-4B4C-8D07-7E0C5BE1896D}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{7F8123B7-1B40-4B4C-8D07-7E0C5BE1896D}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{97503958-F660-45DF-BFB4-E94B8752043F}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{97503958-F660-45DF-BFB4-E94B8752043F}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9B51EF78-BA1B-41FC-AFD3-5CED0802A7CE}\1.0\0\win64
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9B51EF78-BA1B-41FC-AFD3-5CED0802A7CE}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{C7D12FC5-40EE-4288-BE78-94A8C65D0ECB}\1.0\0\win32
Reg: reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{C7D12FC5-40EE-4288-BE78-94A8C65D0ECB}\1.0\HELPDIR
Reg: reg delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CFWIDS\0000 /v DeviceDesc
Reg: reg delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MFERKDET\0000 /v DeviceDesc
Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\mclo g event" /v EventMessageFile
Reg: reg delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CFWIDS\0000 /v DeviceDesc
Reg: reg delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MFERKDET\0000 /v DeviceDesc
Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\eventlog\Application\mclo g event" /v EventMessageFile
Reg: reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CFWIDS\0000 /v DeviceDesc
Reg: reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MFERKDET\0000 /v DeviceDesc
Reg: reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\m clogevent /v EventMessageFile
Reg: reg delete "HKEY_USERS\.DEFAULT\Software\Microsoft\SystemCertificates\McAfee Trust"
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\IEHelpers" /v McAfee SiteAdvisor BHO
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\IEHelpers" /v McAfee SiteAdvisor
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Run" /v C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee SiteAdvisor Service
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee Personal Firewall Service
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee Services
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee VirusScan Announcer
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee Network Agent
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee Scanner
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee Proxy Service
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee McShield
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee Firewall Core Service
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee Validation Trust Protection Service
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\BillP Studios\WinPatrol\Services" /v McAfee Application Installer Cleanup (0107241372222174)
Reg: reg delete HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\McAfee
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\Microsoft\Internet Explorer\TypedURLs" /v url1
Reg: reg delete "HKEY_USERS\S-1-5-21-2583139604-823116366-500879084-1001\Software\Microsoft\SystemCertificates\McAfee Trus"
Reg: reg delete "HKEY_USERS\S-1-5-18\Software\Microsoft\SystemCertificates\McAfee Trust"

*****************

C:\Users\Marie\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\5PUNW1AB\home.mcafee[1].xml => Moved successfully.
C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee HIPS Driver.cat => Moved successfully.

PCMatic Ads

$
0
0
The adds for PCMatic are continuing at full speed. I see that strange looking guy with the weird hair in the black t-shirt everywhere: on TV, internet sites, newspapers ... I expect on billboards next.

Most folks, sooner or later, find their computers running slow, or generally misbehaving. They look for a quick fix and the PCMatic commercial promises to do this for $50/year. It appears to be a promise that they cannot deliver.:down:

People have really a desperate need for a product that can fix most computer problems. One time it was thought snake oil would cure constipation and lumbago.
Viewing all 4746 articles
Browse latest View live




Latest Images