W7 PC Infected ? FarBar Attached

My daughter has old DELL Inspiron PC…Celeron 2Ghz…which she doesn’t use much since she has new MAC.
I however keep it updated and runs Avast, MBAM & MBAE.
I “think” my young son got on it and was on Web where he shouldn’t be. >:(
MBAM is clear & ran Adwcleaner and BOTH clean.
However Avast take HOURS & HOURS to run and while system is not fastest it is almost unusably slow.
I keep Defrag run once a week and not much running…latest O/S updates.

Anyway, ran Farbar…attached…can expert take look and see if something jumps out ?

Thx !

Logs didn’t make it? Can you try again?

This is how bad it is…I was posting this thread while running FRST and figuring the logs would be ready.
It is STILL running…making progress…but still running…going on 20 minutes.
I’ll post logs when done…ugh. :frowning:

No rush on my account!

Took for flippin EVER but here they are…thx !!!

FIRST >>>>

Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed):

QuickTime 7
Tabula Digita DimensionM™ Single Player Mission 1.0.6.0

To do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window.

Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software.

SECOND >>>>

Open notepad by pressing the Windows Key + R Key, typing in Notepad in the Run dialog and then pressing Enter. Please copy the contents of the Code box below. To do this highlight the contents of the box by clicking [Select] next to Code: , then right click on any of the highlighted text and select copy. Paste this into the open notepad. Save it to your desktop as fixlist.txt



Start
CreateRestorePoint:
CloseProcesses:
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
C:\Program Files (x86)\QuickTime
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3869557245-3801628309-1913999693-1002 -> {3557D455-8897-4C02-B9C0-FFC8D4D4AC5D} URL = 
SearchScopes: HKU\S-1-5-21-3869557245-3801628309-1913999693-1002 -> {88B7D999-F143-400F-B243-04A1BBEBBCC4} URL = 
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
CHR Extension: (Google Drive) - C:\Users\Ashley K\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-28]
CHR Extension: (Google Search) - C:\Users\Ashley K\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-28]
CHR Extension: (Google Wallet) - C:\Users\Ashley K\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-28]
S2 ShieldClientService; C:\Program Files (x86)\Shield\shieldclnt.exe [X]
C:\Program Files (x86)\Shield\shieldclnt.exe
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
C:\Windows\system32\DRIVERS\Rts516xIR.sys
C:\Windows\system32\DRIVERS\RtsUCcid.sys
File: C:\Windows\system32\html.iec
C:\Users\Ashley K\AppData\Local\Temp\Quarantine.exe
cmd: ipconfig /flushdns
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state on
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
CMD: bitsadmin /reset /allusers
RemoveProxy:
EmptyTemp:
Reboot:
end

NOTE. It’s important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST64 by right clicking on the FRST64.exe file, selecting “Run as Administrator…”. The User Account Control may open up; if it does, select Yes to continue to let FRST open and load.

The tool will check for an updated version of itself every time it loads; please allow it to do this and the program will either inform you it is downloading an updated copy (and to wait until it is safe to continue) or show nothing (meaning there is no update found) and you can continue on. Press the Fix button just once and wait. The tool will create a restore point, process the script and ask for a restart of your system.

http://i1351.photobucket.com/albums/p785/dbreeze2/just%20stuff/Press%20the%20FIX%20button_zpsdd5zi3mt.png

If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.

When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply post. Also, tell me how your system is running now.

THIRD >>>>

It looks like the Windows Search service is having problems. See if any of the help in this article fixes the issue.

Here is FIXLOG.
Seems to run quicker but have not put thru paces yet…having to run out for the day…but wanted to post.
I also ran FRST64 again and posted log for you to see…which this time took ~10 minutes instead of HOURS. ;D

I’ll have to look into Windows Search…but note, I do disable the Indexing function on a lot of these older PCs…too slow and too much thrashing…would rather the search be longer for few times used. Would that be what you saw ?

If you look towards the end of the Addition.txt log file, you will see some of the current errors in the Windows Events logs. Windows Search Service is ‘complaining’ about the indexing (makes sense now that I know you turned Indexing off). I was just trying to suggest that if that was turned off (or the index / corruption fixed) it may result in a lessening of the CPU usage.

It runs faster…thx…but won’t download the Windows updates…just scrolls with “download” forever.
I will look into the Windows Search to see if that makes any difference.
Any ideas let me know.

This might help:
http://www.howtogeek.com/255435/how-to-update-windows-7-all-at-once-with-microsofts-convenience-rollup/

Well Windows Search did not help.
So, I’ve started to uninstall all old crud programs and also Avast 9.
I’m going to use this machine as test bench for new Avast version.
I loaded and runs quicker…think I need to defrag too.
I’ll use the BULK Windows update link you gave me but first a FULL SYSTEM SCAN with Avast…something just seems wrong besides what is appearing as SLOW…get the feeling still have some virus/malware/etc. lurking about.

I’ll post another FRST log when I make some progress.

Another tool for the update problem is WinUpdateFix 1.3 by xPlode ( available here ).

Note that most of the tools we use to remove malware are not virus removal tools since once the binary code of an executable is changed it is very hard to repair the file. Just an FYI …

I’ve decided to do an in-place upgrade to see how that does.
This PC, while W7, is fairly old and my daughter used, and son…so just ordinary CRUD it probably over years has accumulated.
I’m deleting all non-needed programs…going to bare mins, in-place upgrade, delete all TEMPS/PRE-FETCHES, do CCleaner on Reg, Defrag, etc.
We will see how that works. :slight_smile:

It appears this is not in English and also not sure how to use…can you let me know ?
PC is better (faster) but Windows Update still mucked up.
I used this one in this thread and it ran to completion…I put in aggressive mode.
http://answers.microsoft.com/en-us/windows/forum/windows_vista-update/a-one-click-fix-for-windows-update-problems-how-do/bfbdec70-e928-47ee-b073-665c4851bf4c?auth=1
I am now running MBAM Full San and will run Avast FULL after.

I’ll post a FARBAR log too when I can get that far.

MBAM FULL run & clean.
Will run FULL Avast next but wanted to post FARBAR for review in mean time…let me know. Thx !!!

Nothing showing in those logs with the exception of the following (your choice on these):
FF Extension: All Aboard - C:\Users\Ashley K\AppData\Roaming\Mozilla\Firefox\Profiles\27dcl0zs.default\Extensions@all-aboard-v1 [2016-07-18] - related to network connection sharing ???

Task: {451C4470-E880-44E3-9441-EA2C2C1DCBE0} - \SidebarExecute → No File <==== ATTENTION - Windows Sidebar is recommended to be disabled due to gadgets not being secured

Well defrag ran all day and barely got thru the analyze phase.
Windows update even after FIXIT still shows to RETRY with RED X…
I’m trying the bulk update MSI you gave me link on…letting it run over night.
If this does not process then I’m going to go ahead and just reload the O/S (Format & Clean Install).
Something has this machine hosed down and a In-Place Upgrade and these other efforts have had little result.
The PC is old and not much on it.

I’ll let you know if Windows Update finally runs.

I disabled Windows Gadgets: http://www.howtogeek.com/howto/3255/disable-sidebar-desktop-gadgets-on-windows-7/
I just installed FF…what is the issue there to fix ?

OK…thins are in good order except Windows Update does not work.
If I stop or disable the Windows Update Service the PC “springs” to life…call it even quick…wow !
If I enable/start the service the “update checking” runs for hours with no result and PC SLLLLOOOOOOOWWWWWW. :-[
Here is thread I’ve been reading.
http://superuser.com/questions/951960/windows-7-sp1-windows-update-stuck-checking-for-updates
Funny thing is I downloaded the single KB3161664 update and it ran and installed quickly.
The Windows Update screen in Control Panel show Red X with message to update to latest updates.
The history shows the one KB above.
I could expect this since I use the reset Wizard.
Think I may try some manual updates and see.
Any thoughts ?

This tool has the ability to reset / repair quite a few errors (deals with files / permissions / registry fixes). While it CAN do quite a lot at one time, I would suggest you try just the Registry Permissions, Windows update and WMI fixes (#1, 17 and 21).


Please download “Windows Repair - All in One” from here. Please choose “Save file…” if you get options to open the file. Once the download is complete, run the file and install the program on your system. Please use the default settings for locations as it will help with log retrieval and fixing the registry should anything be needed.

Right click on the desktop shortcut for “Tweaking.com - Windows Repair” and select ‘Run as administrator’.

The program will run a self check to make sure that all the correct files are in place for it to run and then it will load the program. As you can see, there are many steps to take in using this program. Mainly, the first few steps involve checking for proper Windows files and backing up the system as a precaution.

http://i1351.photobucket.com/albums/p785/dbreeze2/Windows%20Repair%20All%20in%20One/WEAIO%20v3_5/Step1_zpswsvkpwps.png

You can read the notes on the first screen but the important thing to do is click on “ReBoot to Safe Mode” and allow the system to restart itself. Once the system is started in safe mode and you have logged in (using an administrative level account), restart the program and move onto the Step2 screen.

http://i1351.photobucket.com/albums/p785/dbreeze2/Windows%20Repair%20All%20in%20One/WEAIO%20v3_5/Step2_PreScan_Check_zpsz4jtz5na.png

Please click on “Open Pre-Scan” to load a utility to verify some Windows resource / build files and settings.

http://i1351.photobucket.com/albums/p785/dbreeze2/Windows%20Repair%20All%20in%20One/WEAIO%20v3_5/Step2_PreScan_Start_zpsqsnaduax.png

Click on “Start Scan” and allow the routine to run. You can see the status of the checks in the window.

http://i1351.photobucket.com/albums/p785/dbreeze2/Windows%20Repair%20All%20in%20One/WEAIO%20v3_5/Step2_PreScan_Finish_zpscticsthm.png

When the routine is finished, it will report on any problems found and you can click on the appropriate repair button if needed. Once this is done, you can close this window and click on Step3.

http://i1351.photobucket.com/albums/p785/dbreeze2/Windows%20Repair%20All%20in%20One/WEAIO%20v3_5/Step3_CheckDisk_zpsn3dmzb3p.png

Click on the “Check” to see if a repair disk check routine needs to run. A Command Prompt window will open and you can view the status of the routine. If the routine finds that repairs need to be made, please select “Open Disk Check at Next Boot” and then click on the “Reboot To Safe Mode” button. Once the routine(s) completes, please select Step4.

http://i1351.photobucket.com/albums/p785/dbreeze2/Windows%20Repair%20All%20in%20One/WEAIO%20v3_5/Step4_SFCscan_zpsrgf8dxrt.png

Please click on “Do It” to run a SFC /scannow routine. If the routine makes any repairs, please reboot your system (again into Safe Mode). If the routine does not make any repairs, please move onto Step5.

http://i1351.photobucket.com/albums/p785/dbreeze2/Windows%20Repair%20All%20in%20One/WEAIO%20v3_5/Step5_Backup_zpsu1i9cqxu.png

Once there, click on “Backup” under the 1. Registry Backup. This will make a complete backup of the current registry which can be reloaded should anything go wrong with the repairs that are going to be made. Next, click on the “Create” under 2. System Restore. Once both of these backups are made, select Repairs.

http://i1351.photobucket.com/albums/p785/dbreeze2/Windows%20Repair%20All%20in%20One/WEAIO%20v3_5/Step6_Repairs_Tips_zpspmp4g2yh.png

I would suggest that you read the Tips For The Best Repairs Results. Once this is done, click on “Open Repairs”.

http://i1351.photobucket.com/albums/p785/dbreeze2/Windows%20Repair%20All%20in%20One/WEAIO%20v3_5/Step6_Repairs_Start_zpsoiow1cxf.png

On this screen, click the following: Defaults. The screen and options should look very much like the picture above. Click “Start Repairs” and confirm that the program starts running the fixes. This will take a while to run, so you can let it run unattended if you like. Log files are being recorded as the repairs are being executed. Once the repairs are finished, reboot your system (normal boot now) and tell me how it is running now.

Thx…I will get to that tool…but first…

I found a Macrium Image backup from mid 2015…nothing really changes a lot on this PC and have tons of attempts to fix Windows Update I punted and did the image restore. The PC was VERY quick. So I decided to uninstall Avast 9 and put new one on. I also uninstalled a lot of old programs too to clean things up…plus, your suggestion on Q7.
All done…have not run MBAM or Avast scan or ADWCleaner…or SFC or Defrag…but wanted to run a FRST log to have you clean up items first. See attached.

It runs better but funny thing not as fast after the re-image.

I also have not tried Windows Update "search "but Control Panel does not have Red X…maybe good sign.