Get rid of the hit.gemius.pl PUP

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #31
    Originally posted by bbdra
    I think it happend because some files are missing due the fix we made in FRST.
    No, I double checked that, nothing in the fix would cause this issue.

    I have never heard of the all in one repair tool deleting anything, this is the first time EVER this has happened.

    It seems that the issue is your HDD.

    Honestly. I’d run a checkdisk on the machine as suggested then run a repair install.



    If this fails to solve your issue, then we need to check on the HDD further, as I think this has a lot to do with your issue.

    Comment

    • Malnutrition
      PCHF Moderator
      • Jul 2016
      • 7041

      #32
      We can also pull up what is in FRST quarantine and restore anything if necessary, but as I said there is nothing that was removed that would cause these issue.

      Download the Everything search engine.
      Type [COLOR=rgb(0, 0, 0)].xbad [/COLOR][COLOR=rgb(0, 0, 0)][/color][COLOR=rgb(0, 0, 0)]into the search window.
      Then click Edit.
      Then Select All.
      Then right click on the highlighted items.
      Copy full name to clipboard.
      Post that here in your next reply.

      ================================================== =

      To look in the Quick Diag Quarantine.
      Type [COLOR=rgb(0, 0, 0)].quickscript[COLOR=rgb(0, 0, 0)] into the search window.
      Then click Edit.
      Then Select All.
      Then right click on the highlighted items.
      Copy full name to clipboard.
      Post that here in your next reply.

      ================================================== =========================

      Scan the HDD for errors.

      Download HD Tune and save the file.
      Install HD Tune and restart it after installation.
      Then go to the tab Error Scan , select the hard drive you want to check and press Start .
      The check can be quite time consuming take depends on the size of the hard drive check.
      Take a screen shot of the result and save it.
      Upload it to IMGUR for us. Post the link here.

      Do Not tick the quick scan!![/COLOR][/COLOR][/color]

      Comment

      • bbdra
        PCHF Member
        • May 2019
        • 89

        #33
        chkdsk C:
        The type of the file system is NTFS.

        WARNING! /F parameter not specified.
        Running CHKDSK in read-only mode.

        Stage 1: Examining basic file system structure …
        517120 file records processed.
        File verification completed.
        18640 large file records processed.
        0 bad file records processed.

        Stage 2: Examining file name linkage …
        862 reparse records processed.
        639530 index entries processed.
        Index verification completed.
        0 unindexed files scanned.
        0 unindexed files recovered to lost and found.
        862 reparse records processed.

        Stage 3: Examining security descriptors …
        Security descriptor verification completed.
        61206 data files processed.
        CHKDSK is verifying Usn Journal…
        34157216 USN bytes processed.
        Usn Journal verification completed.

        Windows has scanned the file system and found no problems.
        No further action is required.

        468286463 KB total disk space.
        308526656 KB in 389038 files.
        234944 KB in 61207 indexes.
        0 KB in bad sectors.
        638571 KB in use by the system.
        65536 KB occupied by the log file.
        158886292 KB available on disk.
        Code:
          4096 bytes in each allocation unit.
        117071615 total allocation units on disk.
        39721573 allocation units available on disk.

        Comment

        • bbdra
          PCHF Member
          • May 2019
          • 89

          #34
          [ATTACH type=“full” alt=“4984”]4984[/ATTACH]

          Comment

          • Malnutrition
            PCHF Moderator
            • Jul 2016
            • 7041

            #35
            I do not need a screen shot, please re-read the instructions.

            Type .xbad into the search window.
            Then click Edit.
            Then Select All.
            Then right click on the highlighted items.
            Copy full name to clipboard.
            Post that here in your next reply.

            ================================================== =

            To look in the Quick Diag Quarantine.
            Type .quickscript into the search window.
            Then click Edit.
            Then Select All.
            Then right click on the highlighted items.
            Copy full name to clipboard.
            Post that here in your next reply.

            Comment

            • bbdra
              PCHF Member
              • May 2019
              • 89

              #36
              Originally posted by Malnutrition
              Type [COLOR=rgb(0, 0, 0)].quickscript into the search window.
              [/COLOR]
              [COLOR=rgb(0, 0, 0)]
              Where I find it please?[/color]

              Comment

              • Malnutrition
                PCHF Moderator
                • Jul 2016
                • 7041

                #37
                Same as you did for FRST ===== .xbad in the everything search.

                Comment

                • Malnutrition
                  PCHF Moderator
                  • Jul 2016
                  • 7041

                  #38
                  Originally posted by bbdra
                  WARNING! /F parameter not specified.
                  Running CHKDSK in read-only mode.
                  Instructions were not followed correctly. I also need you to re-read and complete this correctly please. Your machine will need to reboot, and checkdisk needs to be performed outside of windows.

                  Comment

                  • bbdra
                    PCHF Member
                    • May 2019
                    • 89

                    #39
                    C:\FRST\Quarantine\C\Windows\system32\drivers\aswE lam.sys.xBAD
                    C:\FRST\Quarantine\C\Windows\system32\drivers\aswH dsKe.sys.xBAD
                    C:\FRST\Quarantine\C\Windows\system32\GroupPolicy\ GPT.ini.xBAD
                    C:\FRST\Quarantine\C\Windows\SysWOW64\GroupPolicy\ GPT.ini.xBAD
                    C:\FRST\Quarantine\C\Windows\system32\drivers\etc\ hosts.xBAD
                    C:\FRST\Quarantine\C\Windows\system32\Tasks\Avast Software\Overseer.xBAD

                    Comment

                    • bbdra
                      PCHF Member
                      • May 2019
                      • 89

                      #40
                      C:\QuickDiag\Quarantine\C\ProgramData\AVAST Software.QuickScript
                      C:\QuickDiag\Quarantine\C\Windows\System32\Tasks\A vast Software.QuickScript
                      C:\QuickDiag\Quarantine\C\Windows\Tasks\ImCleanDis abled.QuickScript
                      C:\QuickDiag\Quarantine\C\ProgramData\Microsoft\Wi ndows\Start Menu\Programs\IObit Uninstaller.QuickScript
                      C:\QuickDiag\Quarantine\C\Program Files (x86)\IObit.QuickScript
                      C:\QuickDiag\Quarantine\C\Program Files (x86)\Common Files\IObit.QuickScript
                      C:\QuickDiag\Quarantine\C\ProgramData\IObit.QuickS cript
                      C:\QuickDiag\Quarantine\C\Users\Administrátor\AppD ata\LocalLow\IObit.QuickScript
                      C:\QuickDiag\Quarantine\C\Users\Administrátor\AppD ata\Roaming\IObit.QuickScript
                      C:\QuickDiag\Quarantine\C\Windows\IObit.QuickScrip t
                      C:\QuickDiag\Quarantine\C\Program Files\McAfee.QuickScript
                      C:\QuickDiag\Quarantine\C\ProgramData\McAfee.Quick Script
                      C:\QuickDiag\Quarantine\C\ProgramData{FA7D5C51-6ACA-0558-7668-96BA089C68BD}.QuickScript
                      C:\QuickDiag\Quarantine\C\Windows\System32\drivers \aswbidsdrivera.sys.QuickScript
                      C:\QuickDiag\Quarantine\C\Windows\System32\drivers \aswbidsha.sys.QuickScript
                      C:\QuickDiag\Quarantine\C\Windows\System32\drivers \aswbloga.sys.QuickScript
                      C:\QuickDiag\Quarantine\C\Windows\System\CMSPDIF2. ini .QuickScript
                      C:\QuickDiag\Quarantine\C\ProgramData\Microsoft\Wi ndows\Start Menu\Programs\IObit Uninstaller.lnk.QuickScript
                      C:\QuickDiag\Quarantine\C\Windows\iun6002.exe.Quic kScript
                      C:\QuickDiag\Quarantine\C\Windows\System32\Tasks\U ninstaller_SkipUac_Administrátor .QuickScript
                      C:\QuickDiag\Quarantine\C\Windows\Tasks\Uninstalle r_SkipUac_Administrátor.job.QuickScript

                      Comment

                      • Malnutrition
                        PCHF Moderator
                        • Jul 2016
                        • 7041

                        #41
                        There is nothing in here that would cause these issues, I suggest you run the all in one repair tool with all default items checked. I’d also suggest you run the checkdisk with the instructions I gave to you.

                        Comment

                        • Malnutrition
                          PCHF Moderator
                          • Jul 2016
                          • 7041

                          #42
                          I’ll tell you how to put the files back, because I am certain you believe I caused this issue.

                          Use these instructions at your own risk, because placing anything back that I removed and you will be reinfecting your machine.

                          Comment

                          • bbdra
                            PCHF Member
                            • May 2019
                            • 89

                            #43
                            Ok, gpo.ini are in C:\Windows\System32\GroupPolicy and C:\Windows\SysWOW64\GroupPolicy now.

                            Comment

                            • Malnutrition
                              PCHF Moderator
                              • Jul 2016
                              • 7041

                              #44
                              For FRST…

                              Open Everything search.
                              Copy and paste.
                              C:\FRST\Quarantine\C\Windows\system32\GroupPolicy\ GPT.ini.xBAD
                              Right click on the file and rename.
                              Then just delete the .xbad
                              Then copy and paste C:\FRST\Quarantine\C\Windows\system32\GroupPolicy\ GPT.ini
                              into the everything search window.
                              Drag this file to your desktop.
                              Then copy C:\Windows\system32\GroupPolicy
                              Double click that folder then drag the file from your desktop to that folder.

                              Repeat the same for this file as well.

                              C:\FRST\Quarantine\C\Windows\SysWOW64\GroupPolicy\ GPT.ini.xBAD

                              For Quick Diag…

                              Copy and paste C:\QuickDiag\Quarantine\C\Windows\System\CMSPDIF2. ini .QuickScript
                              Into the everything search.
                              Right click rename delete the .QuickScript
                              Then copy C:\QuickDiag\Quarantine\C\Windows\System\CMSPDIF2 into everything search drag that file to desktop.
                              Then open C:\Windows\System
                              Drag that file from desktop to this folder.

                              Repeat for any file that you like still will not change the issue.

                              If however you run the check disk as suggested and then run the all in one tool with all default items checked the issue will be resolved. But maybe not if you add these files back to your computer.

                              Comment

                              • Malnutrition
                                PCHF Moderator
                                • Jul 2016
                                • 7041

                                #45
                                You can go through and add back every file that I removed then reboot your machine, but once you see that it is nothing that I removed, I’d suggest that you re-run the fixes to put those files back into quarantine, then run the check disk with the instructions I provided, then run the all in one tool with all the boxes checked as suggested.

                                Comment

                                Working...