I am seeking help for my son-in-law’s computer. It is an HP model A6419FH running Windows Vista Home Premium 32 bit SP2. The initial signs of infection involved the following:
Sometimes cannot access the internet even though IE security settings are set to default level.
Over time it turns off some or all of the Avast shields.
Can no longer uninstall programs.
Runs extremely slow even though nothing is accessing the internet.
I have generated the various log files required for help in this forum by running MBAM, FRST, and aswMBR. The files are attached.
Since installing and running MBAM I have noticed the speed of the computer has improved. I find it odd that I am able to uninstall MBAM if I desire, but no other program installed on the computer from the Control Panel.
I would like to request a resident expert review of the attached logs to see if anything there suggests the presence of malware. If so, could a fixlist be generated? Thank you.
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.
I just noticed the MBAM log file I sent is the wrong one. Is it still possible to recover the scan log file? There were no malware items detected, all were PUP.Optional.
The FRST fix has been run and AdwCleaner has been run. Requested logs are attached.
I have looked a little closer at programs that cannot be uninstalled. Some can and some cannot. For example, Java cannot, but Apple product software can be uninstalled. It’s as if something is preventing uninstallation. I don’t know if this is a part of the system design or malware at work.
When you try to uninstall them what error do you get ?
: Keep Java Updated :
WARNING:Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article
I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disableJava in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)
If you do need to keep Java then download JavaRa
Run the programme and select Remove Java Runtime. Uninstall all versions of Java present
Once done then run it again and select Update Java runtime > Download and install Latest version
There is no error. When a program is selected in the Programs and Features window, there is no “Uninstall” selection in the menu bar at the top of the list.
Thanks, I will look into that. Otherwise, the computer is more stable. Takes a while to boot up, but it could be from so many installed programs that I can’t currently uninstall. Internet access is good and Avast shields stay up.
A funny thing, I can’t log into my Avast account from that computer. The orange progress bar hangs part way across. Minor issue. I will have the people here use it for the next several days and see if they are happy with it. Thanks for the help, I’ll be in touch.
eb,
Running Revo and a little nervous about it because it wants selection of registry items by the user. Is it safe to select the bold items or should each be analyzed before deletion?
Regarding my previous observation that I couldn’t log into my Avast account from the Aaron computer, is this true of any computer that isn’t in my devices list?
Still waiting for screenshot. Want to make sure I’m doing this right.
I ended up cancelling the uninstall at the registry edit step. The program now has the “uninstall” selection available in Programs and Features. I noticed while using Revo that it indicated it had restored the uninstall feature of the original program. Do you know if I can now just uninstall it normally without using Revo?
Yes you can uninstall normally now. So far the programmes I have uninstalled have left nothing behind, which is a bummer. I will download a known programme and then uninstall it as I am sure this question will come up again
Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder
Right click on the Unchecky_setup and choose to Run as Administrator
Once open click the Install button.
Then click on Finish
Unchecky is now installed and will help you keep unwanted check boxes unchecked, this is a fire and forget programme
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.
To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe
Cleanup completed. CryptoPrevent and Unchecky have been installed as recommended.
I found there were remnants of a program called CryptoDefense that was still trying to run from the Family user. The error message indicated it couldn’t find the file to run, so I’m confident this malware was removed. I manually removed the command from the registry and all related files from the AppData folder.
The computer is running optimally now. Thank you for your help on this. It is much appreciated.