NETWORK SHIELD POPUP

121205 NETWORK SHIELD POPUP

hi, i am wondering how to stop the darn pop up for the network shield.
all the pop ups started recently. seemed to happen between any avast downloads, to i don’t know how it started.

have to say wth, as a serious problem, i have to do work and every 5 seconds another darn? pop up.
help please… thanks.

and what does the popup say?

a screen shot would help :wink:

my post / internet was kicked right when posted, seen some of same symptoms.

i copied text though:

i do not know how to make a pic download for those formats: txt,jpg,gif,png,log

XXXXXXXXXXXX

121205
working, pending, in a word document ok? done, looking for attachments here …

note: have problems finding things can let know asa see them, instead of separate posts for such? (product review specialist… tech 3 2 1 enough said).

  • might put attachements option where expect to see it, up with other buttons, make it a button
  • could use a 'my log on name" hilited for a jump to a summary screen of my posts (else oblivion?) thanks
i do not know how to make a pic download for those formats: txt,jpg,gif,png,log
google how to take screen shot... or do the same in youtube for a how to do it video...

for now, text in document with screen shots (including text in avast popups)

THE SAME MAYBE 10, has just started last 2 days, other symptoms:

  • after reboots, some site gets around to disabling my ad blocker program
    other symptoms, would have to make a list of.

  • my volume control being messed with 2 - 3 times in a row, 2 -3 times per day.
    (some one turning 2nd ms volume off, other equilizer volumes to mute
    came up with troubleshooting steps:

  1. open volume control, options, props, show / click all controls, see if any volumes are down to bottom or any mute boxes checked.
    close volume control & reopen. (settings may be hidden from current view)
    (set all to top except: volume control & wave (HACK: wave getting reset to 0), set vol half way.

volume getting hit repeatedly. if volume is open, but not working, have to close volume & reopen to see malice.

  1. svcs, win audio svc, check if stopped.
    OR: rc mypc, manage, services & applications

  2. cp, sounds & aud devices props (click), sounds tab, program events select: device connect & sounds: win xp hw insert, apply
    audio tab: select your default dev, apply
    vol tab: place icon in taskbar, advanced: see step 0 above.

SITE THESE POPUPS:

MALICIOUS URL BLOCKED
avast! Network Shield has blocked a harmful site.

Objects:  see below
infction:  URL:Mal
Process:  C:\WINDOWS\System32\svchoste.exe

hxtp://novemberrainx.com/x/
hxtp://wewillrocknow.com/x/

hxtp://79.143.186.52/x/

other ip addresses ?
others for: insurance sales, car sales, etc

Objects: see below infction: URL:Mal Process: C:\WINDOWS\System32\svchoste.exe
if you have this in a pop up, it could mean you are infected....

Follow this guide and attach the logs here…not copy and paste http://forum.avast.com/index.php?topic=53253.0

AdwCleaner
Malwarebytes
OTL
aswMBR

when done a malware expert will look at your logs and help you remove any infection found

Monitoring

121205 INFECTIONS (note: i have some tech background, hardware, application support & technical writing).

  • working on steps, got this info in mean time

NOTE: hope you use this idea: i had to copy down all the steps. since not in a quick copy-paste format,
i really reccommend supplying so anyone can make a quicker day of it. (spent last 1.5-2 hours getting this info down awa some symptoms)
that is for the post that has the steps: http://forum.avast.com/index.php?topic=53253.0

they’re great / thanks, but tech speaking they are unusable for the actual physical doing it if cannot get
copied / pasted down quick. (suggest both in text file & ready copy paste version for those with maladies preventing 1/ other).

  • if don’t mind, tech writing paragraph form always skips steps, don’t see that here but other as sequential steps in 1 line…
  • gobblegook is a tech writing term :), all if you that extraneous words/ whole sentences, put into steps where can. just saying. thanks.

(putting copy of what did in a 2nd reply so not to mix with this).

XXXXXXXXXX

other symptoms:

  • i do not use add on tool bars (for hacks sake).

  • mbam paid/ 1month trial copy. (free copy great), paid version to take over pc, cannot stop procceses from running. cannot unload all the way.
    (now ms unescap.exe, spelling?, always runs at reboot, have been stopping task to get other things to work), about time having problems.

  • volume control being turned to zero. mutes being set.

  • adblocker not working after reboot, after while, ads all over the place

  • MS RESTORE corrupt, no restores possible, restore?/ system idle process running all the time. stopped restore. pc quiet.

  • hourly? manually delete files from 2 folders, inet & prefetch.
    inet: can get as much as 500 cookies from 1 site visit (wth)
    C:\Documents and Settings\A\Local Settings\Temporary Internet Files

prefetch: stopped working? nothing gets posted there except file: NTOSBOOT-B00DFAAD.pf
do not know how to repair prefetch.

HOW DO I / WHICH METHOD IS BEST TO ATTACH LOG, i can look procedure up. just don’t think ms paint is goint to cut it.

had done some work on post: http://forum.avast.com/index.php?topic=53253.0
so can have steps handy, think might make easier to copy paste just the text, for others. thanks

XXXXXXXXXX

DO:
1 AdwCleaner by xplode: http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/2-adwcleaner
dl to dt, run / select delete, reboot, attach log to avast

2 MBAM: (either of 2 sites)
http://fileforum.betanews.com/detail/Malwarebytes-AntiMalware/1186760019/1
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

mbam-setup.exe to install the application. update app, run quick scan, ok: show results, select all & remove.

•When completed, a notepad log will open, you may be prompted to Restart.(See Extra Note)
•The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
•Copy&Paste the entire report in your next reply.
If MBAM finds a file difficult to remove, 2 choices: click OK to either and let MBAM proceed, if asked to restart, do so immediately.

3 OTL: http://oldtimer.geekstogo.com/OTL.exe
or Secondary link www.itxassociates.com/OT-Tools/OTL.exe

•Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

PASTE:
netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
CREATERESTOREPOINT

•Run Scan, Do not change any settings unless told to, scan will not take long.
will open 2 notepads: OTL.Txt, Extras.Txt. are saved in same location as OTL.

•Attach both logs: Within the post select: Additional opts, Browse, Locate the OTL log, Select OTL log. all logs saved in ANSI format.

(see if my copy of tilda symbol good in next:
4 aswMBR.exe: http://public.avast.com/~gmerek/aswMBR.exe
save to your desktop, run aswMBR.exe, scan, done: save log to dt & post in next reply.
(HOW: paste text?)

5 RogueKiller: http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
SPECIFIC INFECTIONS LOGS
If you have the hard drive infection and are no longer able to see your files/folders/start menu then do not run any temporary file cleaners
NOTE: If using IE8 or better Smartscreen Filter will need to be disabled
•Quit all progs, Start RogueKiller.exe Wait for Prescan to finish, Scan, Wait for the end of scan, report gets created on dt, Click on Delete.

•The report has been created on the desktop. (said twice? or 3 times, deleting)
•Next click on the ShortcutsFix

post: All RKreport.txt text files located on your desktop.

6 farbar service scanner: http://download.bleepingcomputer.com/farbar/FSS.exe
(for: inet connect or firewall probs, or have a sirfef: consrv.dll infection)

Run farbar service scanner

Tick “All” options, press scan, creates log: FSS.txt, in same directory tool is run.
copy and paste the log to your reply.

7 If cannot Boot computer, print these instructions so you know what to do.
YOU MUST HAVE A FLASH DRIVE? download.

OTLPENet.exe: same tool as step 3 above
OTL: http://oldtimer.geekstogo.com/OTL.exe
or: http://www.itxassociates.com/OT-Tools/OTL.exe

as well as:
http://dowload.bleepingcomputer.com/farbar/FRST.exe

INSTRUCTIONS:
•Download OTLPENet.exe to desktop, Download Farbar Recovery Scan Tool and save it to a FLASH DRIVE.
•have a blank CD in the drive, start OTLPENet.exe will open: imgburn to burn the file to CD
•Reboot using the boot CD you just created.

Note: If you do not know how to set your computer to boot from CD, follow the steps:
•this may take some time as CD needs to detect your hardware and load the operating system.

•now see display a Reatogo (spelling? / on your? desktop. Note : running from CD is slow.
•Insert the flash drive with FRST on it, Locate the flash drive and run: FSRT

•Press Scan, will make log: FRST.txt on the flash drive. Please copy and paste it to your reply.

XXXXXXXXXX

With the current crop of malware it is prudent to do the following

(what?: if you have?)
Warning!!
You have an information stealing trojan installed on your computer.
Backdoor Trojans, IRCBots, keyloggers and Infostealers are very dangerous. they provide a way of accessing a computer system that
bypasses security mechanisms and can steal sensitive information like passwords, personal and financial data which they send back to the hacker.

Remote attackers use backdoor Trojans as part of an exploit to to gain unauthorized access to a computer and take control of it without your knowledge.
If your computer was used for online banking, has credit card information or other sensitive data on it, do the following:

•Change all passwords to include those used for banking, email, eBay and forums.
You should consider them to be compromised. They should be changed using a different computer and not the infected one.
(If you use the infected computer, an attacker may get the new passwords and transaction information).
•Banking and credit card institutions should be notified of the possible security breach.

I have done it that way as it includes pictures for the non tech types, we need to cater for all skill levels

thanks, no, i get that (works for me too). just ‘must have’ a quick copy.

one problem i might have for not wanting to wasting your time… is how to attach files (not sure i can do yet, no idea)
some steps say paste here, some say attach. just covering detail that is goint to hit me. thanks.

Attach all logs please as the posting limit on this forum is too small

question re page for aswMBR, do i click on FIX MBR ?

http://forum.avast.com/index.php?topic=53253.0

or just collect up log to pass to here? thanks

buttons are:

scan

fixmbr ?? (letters hilited like available)
fix (not hilited)
save log (did)
exit

check box trace disk to io calls already selected
had let do default quick scan

guesse can always rescan again tomarrow (thurs 121206). seeing if can load multiple text files…
combined 2 small files into one

mbam: had zero objects

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.12.05.09

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
A :: HAL [administrator]

12.12.05 5:08 PM
mbam-log-2012-12-05 (17-08-26).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 184607
Time elapsed: 6 minute(s), 27 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

No please do not use FixMBR

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF


:Files
C:\RECYCLER\S-1-5-18\$767fbea4dc5ad3cfb50a0ca7a4e6191f

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download the latest version of TDSSKiller from here and save it to your Desktop.

[*]Doubleclick on TDSSKiller.exe to run the application

https://dl.dropbox.com/u/73555776/tdss%20start.JPG

[*]Then click on Change parameters.

https://dl.dropbox.com/u/73555776/tdss%20Change%20param.JPG

[*]Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

[*]Click the Start Scan button.

[*]If a suspicious object is detected, the default action will be Skip, click on Continue.

https://dl.dropbox.com/u/73555776/tdss%20threat.JPG

[*]If malicious objects are found, they will show in the Scan results and offer three (3) options.
[*]Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

[*]Get the report by selecting Reports

https://dl.dropbox.com/u/73555776/tdss%20report.JPG

[*]Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

Please attach the log on your next reply.

FINALLY

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

thanks for the reply, am working on now. not results post yet, but have info been combining notes on to give status of all happening that can see. and to show importance of work… really wouldn’t mind knowing what the cause is by time done. thanks.


XXXXXXXXXX NEW POST:

see please advise (note) below. is for your info on what had occurred for emails. thanks.

SYMPTOMS: (generally in order of occurance, oldest at top)

  • MAJOR PROBLEM: told by ms that an over zealous security app may be problem for excel file problems,
  • many variations of: will not save file after about 5 line updates/ cut-pastes: file already open, duplicate file cannot save, file sharing violation…
    (see mbam txt file, has copy of avast email received same time. re: conflict. did not get around to following up on).

EMAILS FROM MBAM & AVAST (next posting from here), previously sent. had not followed up on, have been swamped by extra work of symptom:
excel file keeps crashing, having to hit save after every record update (crashes anywhere from 0 to 10 single line cut-paste updates)
ms says maybe security app working over-time. need to follow up on this issue with avast, see email below.

  • i do not use add on tool bars (too many hacks).

  • SBSD had major problem: Spybot S&D immunize tab (NO ESCAPE, if not offline / no ie8 windows open = crewed),

    • fix: disconnect inet, close all IE windows, rerun immunize, reboot. had no symptoms can remember (except sbsd says left open otherwise)

THEE PROBLEM?: (is at least ‘A’ major problem, since forced not to use mbam free, what happened to quarentined items ???)

  • MBAM TRIAL copy. (not free copy: great), trial version will not go away, cannot stop procceses from running. cannot unload all the way.

    • 4 errors?:
    1. if no mbam installed, at login (b4 desktop loads) error:
      windows cannot find: c:\prog2\mbam\mbamgui.exe make sure you typed the name correctly and try again (WHERE),
      to search for file click start & search (sorry, app removed, directory deleted…)

    2. ms unescapp.exe, always runs at reboot as a task in tm, have been stopping task to get other things to work: needing ram),

      • after reinstall mbam free: no popup at user login: (mbamgui.exe error gone), but do not want loaded:
    3. apps: mbagui.exe 7.5M, mbamscheduler.exe 6.5M, mbamservice.exe 97.5M, mbam scan has its own task: mbam.exe 95M
      (THESE APPS WILL NOT GO AWAY).

    • unsecapp.exe (ms startup error app): 5M, for mbamgui.exe not present? is still running in tm. 2 reboots, still there.
    1. TRIAL VERSION TRAY ICON WILL NOT GO AWAY (is from old install), left click: load with windows will not uncheck / processes will not go away.

    2. if mbam not installed, damn mbam icon tray saying you are no longer protected / your trial period has expired (yea no kidding, unloaded after 1d).

    3. what mean: sbsd (spybot) popup protection: system startup value deleted: mbamgui.exe/install/silent, did hit ok. still have problems.

PLEASE ADVISE ON THESE EMAILS: (separate post following this one with email contents from mbam & avast, had not acted on either yet)
NOTE: i contacted MBAM & AVAST about a couple of issues. i did not follow up on emails. mbam had some steps similar to here. run their asav & post.
- did not get to steps yet, pending avast suggestion for steps already underway.

SYMPTOMS Continued:

  • volume control being turned to zero. mutes being set.

  • adblocker not working until after reboot. after while: ads all over the place again.

  • MS RESTORE corrupt, no restores possible, restore?/ system idle process running all the time. stopped restore. pc quiet.

  • hourly? (long time / always) manually delete files from 2 folders, inet & prefetch. prefetch stopped working about 121001, +/- 1mo.
    inet: can get as much as 500 cookies from 1 site visit (wth) C:\Documents and Settings\A\Local Settings\Temporary Internet Files
    prefetch: stopped working? nothing gets posted there except file: NTOSBOOT-B00DFAAD.pf do not know how to repair prefetch.
    run CCleaner same hourly

  • logon to internet. intermittent access from 1st attempt, run tool connections, support tab, repair: few items: ip address, arp cache, dns… then comes up
    (dns cache fail, because utility installed: SMART RAM, iobits; cleaned iobits malware; new pc install with just smartram component files seems ok).

    • works after use connection tool: cp, nw connects, nw connects, local connects, support, repair. (maybe reinstall inet provider… ?)
    • notice intelligent intervention on same web address (same 1st internet attempt prob, but then can only use 2 or 3 times, then that site blocked
      (after tweak address just to change, works 2-3 more times that hour/day, then stops again.
  • backup restore was not working, i had turned off restore on about 121204. continuous cpu runaway on tm: system idle process stopped running constantly.

    • restore back on, no continous cpu run on app: system idle process.

  • files seen, would take help on stopping - blocking:
    bing.com
    search.live.com
    flash updates running processes on my pc without my consent

utilities in use, if have see security problems? some worry about xneat (only button manager that works).

APPS IN USE:
Avast
MBAM: usually have free version. was unable to use with interference remained after removed full trial version, would not unload all the way.

  • maybe around time problems started.
  • could not reload free version before, wo major problems (trial version loaded 3 processes that takes much ram, reason for uninstall trial & since still

present for reload free ver, forced to uninstall free version as well).

FIREFOX removed long time ago.

GMER ROOTKIT used occasionally
SPYBOT SD, teatimer (works good on protect settings),

  • item destroys ie settings just going to tab: immunize, if inet windows not all closed first, you’re crewed, cancel = run… go figure.
  • fix: must close everything down now, close: inet connection, all ie8 windows, reapply. (nice bug)
  • may have left me open to attacks.

ADFENDER
GLARY UTIL, for registry cleaner, have not used in last week, did adwcleaner run ok
Index.date Suite rarely used, has loosene up problem malware before. sub mbam clean ups etc to fix problems.
MRU Blaster, deletes x once each hour. scan & clean mru lists in registry. (problem: does not start / load manually, works on startup only, must contact).
PROCESS TAMER, cpu - task priority manager, ie8 seems not to want to be elevated to above normal, by this app (been doing manually for ie8)
SMARTRAM (from iobits, yes comes with malware: hand take smart ram associated files, no problem after clean…)
SPYWARE BLASTER, no processes, just plug ports, must have.
XNEAT, taskbar manager, some concern on priveledges allowed, some security apss show red (stm, sec task manager, not installed now)

HAVE MADE USE OF MVP HOSTS FILE, 435kb: have not checked in awhile

XXXXXXXXXX NEW POST STOP

EMAILS FROM MBAM & AVAST, previously sent. had not followed up on, have been swamped by extra work of symptom:
excel file keeps crashing, having to hit save after every record update (crashes anywhere from 0 to 10 single line cut-paste updates)
ms says maybe security app working over-time. need to follow up on this issue with avast, see email below.

i have not acted on either yet, waiting to do items here / yours suggestions

MBAM:

121206 dl email fm mbam dtd: 121019 subj: malwarebytes support ticket #281486

Ron Lewis, Oct 19 02:55 am (PDT):
Hello Dave,

Well it sounds like you may be infected or having some other odd issues going on.

Please run the following mbam-check tool so that we can get a better look at what’s going on.

Create an mbam-check log:

Download mbam-check.exe from here and save it to your desktop
http://downloads.malwarebytes.org/file/mbam_check

Double-click on mbam-check.exe to run it. When done it should then open a log file

Please attach the log to your next reply, it should be on your desktop as “CheckResults.txt”

Next, please download DDS from one of the locations below and save it to your desktop.
here: http://download.bleepingcomputer.com/sUBs/dds.scr
or
here: http://download.bleepingcomputer.com/sUBs/dds.com

Temporarily disable any script blocker if your Anti-Virus/Anti-Malware has it.
Once downloaded you can disconnect from the Internet and disable your Ant-Virus temporarily if needed.
Then double click dds.scr or dds.com to run the tool, on Vista or Win 7 right click and select Run as administrator
Click the Run button if prompted with an Open File - Security Warning dialog box.
A black DOS console should open and run for a moment.

When done, DDS will open two (2) logs:

DDS.txt
Attach.txt

Save both reports to your desktop
Please attach the following logs in your next reply: DDS.txt and Attach.txt
You can ignore the note about zipping the Attach.txt file and just attach it to your reply.

Thank you

Ron Lewis
Malwarebytes Corporation
www.malwarebytes.org


Dave xxx, Oct 18 08:24 pm (PDT):
Name: dave
Version: 1.65
Operating System: Windows XP

121018 davebyfram@yahoo.com
October 18, 2012, URGENT
I have tried to unload the 1 month? trial of the full version form MBAM. the free version worked fine for me.

as i am having some major problems with MS Excel & Avast (some kind of problem, with cannot save excel, avast? corrupting file name paths, for macro’s shortcuts in header paths becomming corrupt, ms says over-zealous security app)…

i a running into a problem with MBAM full version loading processes, that seem to have no options to turn off.
removing the program, and trying to install the basic version did not work. removing all again did not work. removing all references on pc / registry to mbam does not work.

is there some reason this has to be such hell. have to run another application to kill mbam, (that would think has been “micro” removed).

HOW - DO - I - REMOVE MBAM PROCESSES, so i can reload the mbam basic / free.

am trying to run a business here, I NEED ALL MY CPU CYCLES FOR MY WORK.

thanks in advance.

XXXXXXXXXX XXXXXXXXXX

121206 dl email fm avast dtd: 121022 subj: ASW #XZG-908021: possible conflicet with avast & ms excel

[ASW #XZG-908021]: possible conflict with Avast & MS Excel
1 recipientsCC: recipientsYou More
BCC: recipientsYou Show Details FROM:Petr Bucek TO:davebyfram@yahoo.com Message starred Monday, October 22, 2012 10:33 AM Hello,

Thank you for contacting our support center with your concerns.

There are three parts of the program, where exclusion can be dealt.
It depends on which one you need to use.

First is File system shield that takes care of real time protection. Click on REAL-TIME SHIELDS - File system shield and press Expert Settings button. Choose Exclusions and modify existing list or add any other files to be excluded according to your needs.

If you want to exclude files from on demand scan, click on Settings button in the main Interface window and choose Exclusion and type any path to be excluded from scanning.

Last exclusion concerns web sites. In “REAL-TIME SHIELDS”, click on the Web shield icon and then on Settings button on the right side of the screen.
Then choose Exclusions and tick URL´s to exclude. Enter any desired url/s and confirm it clicking on “Add” button.

If I can be of any further assistance, please do not hesitate to contact me again.

With Kind Regards,

Petr Bucek
2nd level Technical Support

AVAST Software a. s.
Budejovická 1518/13A
140 00 Prague, Czech Republic

www.avast.com

You can also have a look at our knowledgebase link

http://support.avast.com

Ticket Details

Ticket ID: XZG-908021
Department: 2nd Level Tech Supp
Priority: Urgent
Status: On Hold

A lot of these problems should disappear once you have run the two programmes

Use MBAMClean to remove all of MBAM http://downloads.malwarebytes.org/file/mbam_clean

hi, thanks… will try the mbam fix when seems good… if that is the fix for that would want to say one thing: thakyou thankyou thankyou…

otherwise: even with some tech have… with all things covering did not get to thinking if i need to close all apps??, be offline ?? for the OTX.
if it matters, had a couple of notepad windows open, 1 internet window, couple of file explorer windows.

what happened was OTX screen stayed frozen on blank desktop screen for about 3 hours, with (something like): “cancelling all processes, stand by”. the only way to cancel could come up with was to pull the power plug.

was alittle concerned. had some back up file problems before, think just favorite links with unusable (to back up/ zip) file characters.
working on backups… try this again tomarrow. thanks.