This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Redirecting

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I read the instructions this time before posting. Yesterday I had tried MalwareBytes to no avail. The redirecting continues at every website. The ASW scan was scanning for a few minutes, then froze for 30 minutes, so I saved it at that point.

 

I appreciate your helping me on this.

Hi and welcome

Running from C:\Users\[removed]\Downloads

It's best we move Farbar's to desktop.

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
Or use this method Press the windows key [external image: Windows_Logo_key.gif]+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
U3 aswMBR; \??\C:\Users\Jim\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Jim\AppData\Local\Temp\aswVmm.sys [X]
2016-01-26 20:06 - 2008-09-10 02:17 - 0073728 ____R () C:\Users\Jim\AppData\Local\Temp\eject.exe
2012-03-16 06:51 - 2012-03-16 06:51 - 0864368 ____N (CANON INC.) C:\Users\Jim\AppData\Local\Temp\MSETUP4.EXE
2016-03-26 21:12 - 2016-03-26 21:14 - 24658468 _____ () C:\Users\Jim\AppData\Local\Temp\vlc-2.1.5-win64.exe
2016-07-15 10:59 - 2016-07-15 11:08 - 31717016 _____ () C:\Users\Jim\AppData\Local\Temp\vlc-2.2.4-win64.exe
2016-04-12 18:38 - 2016-04-12 18:38 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate1227821.exe
2016-03-06 14:29 - 2016-03-06 14:29 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate1297007.exe
2016-03-28 17:05 - 2016-03-28 17:05 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate1406723.exe
2016-02-27 01:47 - 2016-02-27 01:47 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate22026155.exe
2016-03-08 16:07 - 2016-03-08 16:07 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate3123342.exe
2016-03-15 23:23 - 2016-03-15 23:23 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate323811.exe
2016-03-17 12:27 - 2016-03-17 12:27 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate324029.exe
2016-03-18 18:42 - 2016-03-18 18:42 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate324232.exe
2016-03-14 19:18 - 2016-03-14 19:18 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate324279.exe
2016-03-09 00:30 - 2016-03-12 13:18 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate324419.exe
2016-03-16 11:24 - 2016-03-16 11:24 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate324528.exe
2016-03-19 19:49 - 2016-03-19 19:49 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate324591.exe
2016-03-16 20:26 - 2016-03-16 20:26 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate324825.exe
2016-03-01 13:45 - 2016-03-01 13:45 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate325168.exe
2016-03-14 13:19 - 2016-03-14 13:19 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate325542.exe
2016-03-08 15:20 - 2016-03-08 15:20 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate326026.exe
2016-03-05 14:55 - 2016-03-05 14:55 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate326104.exe
2016-03-26 11:11 - 2016-03-26 11:11 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate326385.exe
2016-03-18 12:17 - 2016-03-18 12:17 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate326525.exe
2016-02-27 14:18 - 2016-02-27 14:18 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate326681.exe
2016-03-15 11:10 - 2016-03-15 11:10 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate326728.exe
2016-02-26 14:04 - 2016-02-26 14:04 - 0880360 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate326744.exe
2016-03-13 12:35 - 2016-03-13 12:35 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate326853.exe
2016-04-06 20:57 - 2016-04-06 20:57 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate326946.exe
2016-03-07 13:14 - 2016-03-07 13:14 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate327758.exe
2016-03-19 22:39 - 2016-03-19 22:39 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate327867.exe
2016-03-17 20:47 - 2016-03-23 20:22 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate328163.exe
2016-03-10 19:38 - 2016-03-10 19:38 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate328241.exe
2016-03-11 11:57 - 2016-03-11 11:57 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate328787.exe
2016-03-03 15:31 - 2016-03-03 15:31 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate329817.exe
2016-03-19 14:02 - 2016-03-19 14:02 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate329910.exe
2016-04-04 21:47 - 2016-04-04 21:47 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate330800.exe
2016-03-13 15:46 - 2016-03-13 15:46 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate330924.exe
2016-04-08 13:20 - 2016-04-08 13:20 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate331190.exe
2016-03-21 12:33 - 2016-04-04 13:40 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate331299.exe
2016-03-20 18:42 - 2016-03-20 18:42 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate331548.exe
2016-03-24 14:08 - 2016-03-24 14:08 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate331782.exe
2016-03-31 00:15 - 2016-03-31 00:15 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate331814.exe
2016-03-25 01:06 - 2016-03-25 01:06 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate332094.exe
2016-03-27 12:17 - 2016-03-27 12:17 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate333296.exe
2016-03-18 18:49 - 2016-04-01 14:12 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate333561.exe
2016-04-05 20:38 - 2016-04-05 20:38 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate333670.exe
2016-02-29 13:58 - 2016-02-29 13:58 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate333748.exe
2016-04-03 13:24 - 2016-04-03 13:24 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate334902.exe
2016-04-06 14:14 - 2016-04-06 14:14 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate335090.exe
2016-03-01 22:01 - 2016-03-01 22:01 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate335246.exe
2016-04-04 17:20 - 2016-04-04 17:20 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate335526.exe
2016-02-28 13:20 - 2016-02-28 13:20 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate335589.exe
2016-04-05 16:04 - 2016-04-05 16:04 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate335667.exe
2016-03-10 12:49 - 2016-03-10 12:49 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate335792.exe
2016-04-02 14:50 - 2016-04-02 14:50 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate335838.exe
2016-03-31 14:18 - 2016-03-31 14:18 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate335854.exe
2016-04-16 11:40 - 2016-04-16 11:40 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate335916.exe
2016-03-23 14:02 - 2016-03-23 14:02 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate336400.exe
2016-04-07 13:14 - 2016-04-07 13:14 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate336494.exe
2016-04-18 13:59 - 2016-04-18 13:59 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate337679.exe
2016-04-12 12:43 - 2016-04-12 12:43 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate337991.exe
2016-04-02 20:19 - 2016-04-02 20:19 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate338225.exe
2016-03-16 13:29 - 2016-03-16 13:29 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate339364.exe
2016-03-02 14:30 - 2016-03-02 14:30 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate339660.exe
2016-03-25 11:59 - 2016-03-25 11:59 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate344247.exe
2016-03-22 14:43 - 2016-03-22 14:43 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate345542.exe
2016-04-15 20:53 - 2016-04-15 20:53 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate346306.exe
2016-04-15 11:38 - 2016-04-15 11:38 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate347975.exe
2016-04-14 09:06 - 2016-04-14 09:06 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate349317.exe
2016-03-29 12:48 - 2016-03-29 12:48 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate350830.exe
2016-04-17 14:14 - 2016-04-17 14:14 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate356743.exe
2016-04-10 11:30 - 2016-04-10 11:30 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate362483.exe
2016-03-04 10:13 - 2016-03-04 10:13 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate368255.exe
2016-03-07 08:07 - 2016-03-07 08:07 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate379035.exe
2016-04-13 12:47 - 2016-04-13 12:47 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate382717.exe
2016-03-28 10:03 - 2016-03-28 10:03 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate401546.exe
2016-06-30 11:14 - 2016-06-30 11:14 - 0896984 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate403652.exe
2016-03-09 12:05 - 2016-03-09 12:05 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate406835.exe
2016-02-28 19:57 - 2016-02-28 19:57 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate410391.exe
2016-03-09 00:22 - 2016-03-09 00:22 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate423636.exe
2016-04-19 12:22 - 2016-04-19 12:22 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate426101.exe
2016-04-20 00:05 - 2016-04-20 00:05 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate42615697.exe
2016-02-26 03:44 - 2016-02-26 03:44 - 0880360 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate54421026.exe
2016-04-11 15:19 - 2016-04-11 15:19 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate556720.exe
2016-04-07 21:44 - 2016-04-07 21:44 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate568998.exe
2016-04-09 13:50 - 2016-04-09 13:50 - 0880872 _____ (Webroot) C:\Users\Jim\AppData\Local\Temp\WRupdate911857.exe
CustomCLSID: HKU\S-1-5-21-1857361978-2762791575-2848178065-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Jim\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1857361978-2762791575-2848178065-1000_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Jim\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
EmptyTemp:
Hosts:
End


Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~``

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
    In order to use AdwCleaner, you have to agree the Eula:
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
– File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please download Junkware Removal Tool
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
~~~~
please post
Fixlog.txt
AdwCleaner[C1].txt
JRT.txt
Hi Juliet, 
The redirecting to ads continues whenever I click on anything. Here are those files you requested.
Thanks,
Jim
 
 
 
# AdwCleaner v6.043 - Logfile created 03/02/2017 at 21:26:51
# Updated on 27/01/2017 by Malwarebytes
# Database : 2017-02-03.2 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Jim - JIM-PC
# Running from : C:\Users\Jim\Desktop\adwcleaner_6.043.exe
# Mode: Scan
# Support : https://www.malwarebytes.com/support
 
 
 
***** [ Services ] *****
 
No malicious services found.
 
 
***** [ Folders ] *****
 
No malicious folders found.
 
 
***** [ Files ] *****
 
No malicious files found.
 
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
 
***** [ WMI ] *****
 
No malicious keys found.
 
 
***** [ Shortcuts ] *****
 
No infected shortcut found.
 
 
***** [ Scheduled Tasks ] *****
 
No malicious task found.
 
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
 
***** [ Web browsers ] *****
 
No malicious Firefox based browser items found.
No malicious Chromium based browser items found.
 
*************************
 
C:\AdwCleaner\AdwCleaner[S0].txt - [1005 Bytes] - [03/02/2017 21:26:51]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1078 Bytes] ##########
 
Please download the Malwarebytes Anti-Malware setup file to your Desktop.

OR from this location Here
  • After the installation IS complete let it update if it asks.
  • Under SETTINGS…..APPLICATIONS leave everything at default
  • Under SETTINGS…..PROTECTION make sure AUTOMATIC QUARANTINE is on.
  • Then go to the Dashboard and click on SCAN NOW
  • When the scan is finished click on EXPORT SUMMARY……COPY TO CLIPBOARD
  • Then come back to this thread and and under REPLY TO THIS TOPIC, right click in the reply and select Paste
  • Then click on POST
  • Exit Malwarebytes
The redirecting continues as steady as it has been. I look forward to each thing you suggest. Thanks.
 
 
 
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 2/4/17
Scan Time: 1:55 PM
Logfile: 
Administrator: Yes
 
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.50
Update Package Version: 1.0.1181
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Jim-PC\Jim
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 325960
Time Elapsed: 1 min, 59 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)
Is it mostly when using Google Chrome?
  • Download Emsisoft Emergency Kit and save it to your desktop.
  • Double-click icon then click Install
  • A Window should open highlighting Start Emergency Kit Scanner
  • Right click on the icon and select Run as administrator
  • Click 1. Update now!
  • Once the update is completed select Settings under Scan
  • Uncheck Join the Emsisoft Anti-Malware Network
  • Click Scan at the top
  • Click On scan completion
  • Click Quarantine detected objects, then click OK
  • Click Malware Scan
  • Once completed click View Report
  • Save the file to your Desktop using the default file name
  • Copy and paste the report in your reply
Juliet, I didn't download Emsisoft Emergency Kit because when I went online today, all the redirecting mysteriously did a no-show. No more redirecting. Guess what? Now I miss it. No, just kidding. But the popup ads kept coming up on my screen - blocking a lot of the screen - when I went to amazon. So I googled div.fo-deals-header.fo-header.fo-close-xyz.sgsefvhuedc  –  & one of the search results talked about clicking on 'Reset Settings' under 'Advanced Settings' in Chrome. That made me think of your question ("Is it mostly when using Google Chrome?"). After clicking on 'Reset Settings', there were no more popup ads. Gone. Vanished. And right then I actually thought I could maybe hear the flutter of your wings. 
 
Case closed. My entire problem solved.
 
Jim
LOL
When I asked the question, the next step depending on your reply, was to refresh or uninstall/reinstall Google Chrome.

Personally, I would run the Eset scan. It's very good at finding things other scanners might have missed.

If you think we're done here
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
I'm ready to download DelFix on your go-ahead nod of approval & ok. Thanks for recommending I also do the Emsisoft Emergency Kit scan. The results were: 
 
Emsisoft Emergency Kit - Version 12.0
Last update: 2/5/2017 11:00:57 PM
User account: Jim-PC\Jim
Computer name: JIM-PC
OS version: Windows 7x64 Service Pack 1
 
Scan settings:
 
Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files
 
Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Direct disk access: Off
 
Scan start: 2/5/2017 11:09:20 PM
 
Scanned 89142
Found 0
 
Scan end: 2/5/2017 11:50:40 PM
Scan time: 0:41:20
Yes
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
************************

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI