Password reset and notification emails are now sending correctly.
If you recently requested a password reset, please check your inbox (and spam folder just in case).
You can now reset your password and log in as normal.
Welcome back to PCHF, and thank you for your patience during our migration process!
— The PCHF Team
Welcome to PC Help Forum!
You’re viewing our community as a guest.
That means you can browse posts, but can’t yet reply or start new topics.
Join us today — it's completely free!
As a member, you'll be able to:
✅ Get personalized tech support from trusted volunteers
🦠 Work one-on-one with our Malware Removal Specialists
I suppose your helper is out of town or something. sorry for the delay… Let’s get some FRST logs, and @gus will be assisting you.
Please run Farbar Recovery Scan Tool to give me a fresh look at your system.
Please download the FRST 32 bit or FRST 64bit version to suit your operating system. It is important FRST is downloaded to your desktop.
If you are unsure if your operating system is 32 or 64 Bit please go HERE.
[ul]
[li]Right-click on FRST icon and select Run as Administrator to start the tool.[/li](XP users click run after receipt of Windows Security Warning - Open File).
[li]Make sure that Addition option is checked, as well as Shortcut.txt[/li][li]Press Scan button and wait.[/li][li]The tool will produce three logfiles on your desktop: FRST.txt, and Addition.txt – & Shortcut.txt[/li][/ul]
Please Copy & Paste them into your next reply. But attach Shortcut.txt
I suppose your helper is out of town or something. sorry for the delay… Let’s get some FRST logs, and @gus will be assisting you.
Please run Farbar Recovery Scan Tool to give me a fresh look at your system.
Please download the FRST 32 bit or FRST 64bit version to suit your operating system. It is important FRST is downloaded to your desktop.
If you are unsure if your operating system is 32 or 64 Bit please go HERE.
[ul]
[li]Right-click on FRST icon and select Run as Administrator to start the tool.[/li](XP users click run after receipt of Windows Security Warning - Open File).
[li]Make sure that Addition option is checked, as well as Shortcut.txt[/li][li]Press Scan button and wait.[/li][li]The tool will produce three logfiles on your desktop: FRST.txt, and Addition.txt – & Shortcut.txt[/li][/ul]
Please Copy & Paste them into your next reply. But attach Shortcut.txt
Sorry..never saw a place that said run as Adm.. I know it is a 32 bit and clicked that..box came uo asking to run or save…hit run and here is what I got…they ended up in note pad..have no idea where that is..so can’t see how to send them to you..it must not be right because there were only two of them..
You know by now you are dealing with a computer idiot
Also got something from Gus I broke a rule..not sure what I did but apologise…
Hello Hefs,
As per the instructions above, you should have downloaded FRST to the desktop and run it (as administrator) from there. It would have then produced 3 files on the desktop
[ol]
[li]FRST.txt[/li][li]Addition.txt[/li][li]Shortcut.txt[/li][/ol]
Once you have these files please copy and paste the contents of FRST.txt and Addition.txt in your next post. Also attach Shortcut.txt
Originally posted by Hilton Heflin
Also got something from Gus I broke a rule..not sure what I did but apologise..
It’s all good, your second newly created member account has been removed because you are only allowed to have one account, and making another thread about the same topic is not helpful, but rest assured we will help you get your issues sorted out(y)
If you are unsure about any of the above instructions please give me a shout.
[HEADING=1]Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-03-2017
Ran by hilton (13-04-2017 12:35:25)
Running from C:\Users\hilton\Downloads
Microsoft Windows 7 Professional Service Pack 1 (X86) (2016-06-29 20:30:51)
Boot Mode: Normal[/HEADING]
==================== Accounts: =============================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
FW: Avast Antivirus (Enabled) {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4}
Name: avast! SecureLine TAP Adapter v3
Description: avast! SecureLine TAP Adapter v3
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: TAP-Windows Provider V9
Service: aswTap
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click “Action”, and then click “Enable Device”. This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
[HEADING=1]Application errors:[/HEADING]
Error: (04/13/2017 12:33:33 PM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver
Error: (04/13/2017 11:10:02 AM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver
Error: (04/13/2017 11:08:16 AM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver
Error: (04/12/2017 04:06:07 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for “C:\Program Files\DriverUpdate\MFC80U.DLL”.
Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture=“x86”, publicKeyToken=“1fc8b3b9a1e18e3b”,type=“win32”,ver sion=“8.0.50608.0” could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (04/12/2017 04:05:49 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for “C:\Program Files\DriverUpdate\MFC80U.DLL”.
Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture=“x86”, publicKeyToken=“1fc8b3b9a1e18e3b”,type=“win32”,ver sion=“8.0.50608.0” could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (04/12/2017 04:03:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/12/2017 03:19:46 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-3292114827-816517840-1514174382-1000.bak). hr = 0x80070539, The security ID structure is invalid.
.
Error: (04/12/2017 03:19:44 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1533) (User: NT AUTHORITY)
Description: Windows cannot delete the profile directory C:\Users\TEMP. This error may be caused by files in this directory being used by another program.
DETAIL - The directory is not empty.
Error: (04/12/2017 03:18:15 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for “C:\Program Files\DriverUpdate\MFC80U.DLL”.
Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture=“x86”, publicKeyToken=“1fc8b3b9a1e18e3b”,type=“win32”,ver sion=“8.0.50608.0” could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (04/12/2017 03:18:09 PM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (3740) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.
[HEADING=1]System errors:[/HEADING]
Error: (04/13/2017 10:34:20 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 20.
Error: (04/13/2017 10:34:13 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 20.
Error: (04/12/2017 03:18:25 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The HomeGroup Listener service terminated with service-specific error %%-2147023143 = There are no more endpoints available from the endpoint mapper..
Error: (04/12/2017 03:07:57 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (04/12/2017 03:07:54 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (04/12/2017 03:07:34 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (04/12/2017 03:07:31 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (04/12/2017 03:07:05 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (04/12/2017 03:07:03 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (04/12/2017 03:02:45 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
==================== Memory info ===========================
Processor: Intel(R) Core™2 CPU 6300 @ 1.86GHz
Percentage of memory in use: 44%
Total physical RAM: 3316.61 MB
Available physical RAM: 1847.67 MB
Total Virtual: 6631.55 MB
Available Virtual: 5076.47 MB
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-03-2017
Ran by hilton (administrator) on HILTON-PC (13-04-2017 12:34:55)
Running from C:\Users\hilton\Downloads
Loaded Profiles: hilton (Available Profiles: hilton)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
Hello Hefs, just so you know I am training here in malware removal and before I can present any fix to you they will have to be checked by my teacher. That should not be such a bad thing because two pairs of eyes may be better than one, even though it may be a little slower than usual. Hope you are OK with this and I hope you stay with us until we give you the all clear.
I see you have already used some tools, and when we finish I will help you remove them all. Don’t be concerned about the stuff Malwarebytes found and quarantined, it’s safe there and will be dealt with.
Also where possible please download and run any tools from your desktop as previously requested. Whilst I check your log files can you please follow the instructions below and we will clean up your shortcuts.
As you ran FRST from your downloads folder the Shortcut.txt file will be there. Can you please move it to your desktop?
Download ClearLNK save it to your desktop.
Drag the file Shortcut.txt made with FRST earlier.
As per picture.
A report on the work as a file ClearLNK- .log
Will be produced, post that log please
Hello Hefs, We will return to your shortcuts after we have cleaned your machine. In the meantime you can recreate any necessary ones.
FRST fix.
[ul]
[li]Please download the attached Fixlist.txt file to your desktop.[/li][li]It is important that both the Fixlist file and FRST are in the same location or the fix will not work.[/li][li]Run FRST and click the button marked fix once.[/li][li]FRST will take a while to run the fix and at the completion will reboot your PC, please allow this.[/li][li]When your computer restarts FRST will generate a log file on your desktop called Fixlog.txt[/li][li]Can you please Copy and paste the contents of that file in your next reply.[/li][li]PLEASE NOTE: this script was specifically written for use on this particular machine. Running this fix on another machine may permanently damage the operating system.[/li][/ul]
Adware Cleaner Scan.
Please download AdwCleaner by Malwarebytes onto your desktop.
[ul]
[li]Close all open programs and internet browsers.[/li][li]Double click on adwcleaner.exe to run the tool.[/li][li]Click on Scan button.[/li][li]When the scan has finished click on Clean button.[/li][li]Your computer will be rebooted automatically. A text file will open after the restart.[/li][li]Please post the contents of that logfile with your next reply.[/li][li]You can find the logfile at C:\AdwCleaner[S1].txt as well.[/li][/ul]
Malwarebytes.
[ul]
[li]Download MalwareBytes Anti-Malware : https://www.malwarebytes.com/mwb-download/ take the free version ( on the left )[/li][li]Perform the installation[/li][li]Uncheck “Enable Free Trial of Malwarebytes Anti-Malware Premium” if it’s asked[/li][li]Malwarebytes will update, let this update,[/li][li]Click on the “Settings” tab and then on the “Detection and Protection” tab, Check the box “Search for Rootkits”[/li][li]Click on the “Analysis” tab and then on “Start analysis”[/li][li]Once the review is complete, check that all detections are checked and then click [Delete Selection][/li][li]If Malwarebytes asks you to restart your PC, click “Yes”[/li][li]When restarting your PC, restarts Malwarebytes[/li][li]Opens the “History” tab and then “Application logs”[/li][li]Double click on the last Scan Log in date (the one above)[/li][li]At the bottom click [Export] → select “Text file (* .txt)”[/li][li]In the explorer selects the desktop, name it mbam.txt, click [Save][/li][/ul]
Your next reply should contain the contents of
[ol]
[li]Fixlog.txt[/li]
[li]AdwCleaner[xx].txt[/li]
[li]mbam.txt[/li][/ol]
Should you have any questions or difficulty with these instructions, please ask
Hello Hefs, We will return to your shortcuts after we have cleaned your machine. In the meantime you can recreate any necessary ones.
[COLOR=rgb(255, 0, 0)]FRST fix.[/COLOR][COLOR=rgb(255, 0, 0)]
[ul]
[li]Please download the attached Fixlist.txt file to your desktop.[/li][li]It is important that both the Fixlist file and FRST are in the same location or the fix will not work.[/li][li]Run FRST and click the button marked fix once.[/li][li]FRST will take a while to run the fix and at the completion will reboot your PC, please allow this.[/li][li]When your computer restarts FRST will generate a log file on your desktop called Fixlog.txt[/li][li]Can you please Copy and paste the contents of that file in your next reply.[/li][li][COLOR=rgb(255, 0, 0)]PLEASE NOTE: this script was specifically written for use on this particular machine. Running this fix on another machine may permanently damage the operating system.[/li][/ul]
Please download AdwCleaner by Malwarebytes onto your desktop.
[ul]
[li]Close all open programs and internet browsers.[/li][li]Double click on adwcleaner.exe to run the tool.[/li][li]Click on Scan button.[/li][li]When the scan has finished click on Clean button.[/li][li]Your computer will be rebooted automatically. A text file will open after the restart.[/li][li]Please post the contents of that logfile with your next reply.[/li][li]You can find the logfile at C:\AdwCleaner[S1].txt as well.[/li][/ul]
[COLOR=rgb(255, 0, 0)]Malwarebytes.[/COLOR][COLOR=rgb(255, 0, 0)]
[ul]
[li]Download MalwareBytes Anti-Malware : https://www.malwarebytes.com/mwb-download/ take the free version ( on the left )[/li][li]Perform the installation[/li][li]Uncheck “Enable Free Trial of Malwarebytes Anti-Malware Premium” if it’s asked[/li][li]Malwarebytes will update, let this update,[/li][li]Click on the “Settings” tab and then on the “Detection and Protection” tab, Check the box “Search for Rootkits”[/li][li]Click on the “Analysis” tab and then on “Start analysis”[/li][li]Once the review is complete, check that all detections are checked and then click [Delete Selection][/li][li]If Malwarebytes asks you to restart your PC, click “Yes”[/li][li]When restarting your PC, restarts Malwarebytes[/li][li]Opens the “History” tab and then “Application logs”[/li][li]Double click on the last Scan Log in date (the one above)[/li][li]At the bottom click [Export] → select “Text file (* .txt)”[/li][li]In the explorer selects the desktop, name it mbam.txt, click [Save][/li][/ul]
[COLOR=rgb(0, 0, 255)]Your next reply should contain the contents of
[ol]
[li][COLOR=rgb(255, 0, 0)]Fixlog.txt[/li]
[li][COLOR=rgb(255, 0, 0)]AdwCleaner[xx].txt[/li]
[li][COLOR=rgb(255, 0, 0)]mbam.txt[/li][/ol]
Should you have any questions or difficulty with these instructions, please ask
[/COLOR][/COLOR][/COLOR][/COLOR][/color][/color][/COLOR][/color]
[COLOR=rgb(255, 0, 0)][COLOR=rgb(255, 0, 0)][COLOR=rgb(255, 0, 0)][COLOR=rgb(255, 0, 0)][COLOR=rgb(0, 0, 255)][COLOR=rgb(255, 0, 0)][COLOR=rgb(255, 0, 0)][COLOR=rgb(255, 0, 0)]
ok..thanks for the info..will be home all day tomorrow and will work on this..
Thanks,
hefs[/color][/color][/color][/color][/color][/color][/color][/color]
ok..thanks for the info..will be home all day tomorrow and will work on this..
Thanks,
hefs
ok..downloaded both fixit.txt and frst to computer..they went into desktop download folder… put them over on desktop…ran scan on frst and when it finished I ran FIX..that was an hour ago and it is still running…normal ???
We process personal data about users of our site, through the use of cookies and other technologies, to deliver our services, personalize advertising, and to analyze site activity. We may share certain information about our users with our advertising and analytics partners. For additional details, refer to our Privacy Policy.
By clicking "I AGREE" below, you agree to our Privacy Policy and our personal data processing and cookie practices as described therein. You also acknowledge that this forum may be hosted outside your country and you consent to the collection, storage, and processing of your data in the country where this forum is hosted.
Comment