This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Experiencing erractic responses when navigating pages.

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi and welcome,.  sorry for the delay.
 
There is no active (seen) malware in the logs but we can run a couple of scans to see if anything is hidden.
 
I do want to mention you may have a bit much as in security apps on here…..can be a resources hog.

~~~~~~~~~~~~~~~~~~~~~~~~~~`

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan Now
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean and Repair
  • if it asks to reboot, allow the reboot
  • on reboot, click on View Log File; please attach the content of the log to your next reply.

============================================

You may have Malwarebytes Anti-Malware installed but if not, you can download it from here:

  • run the program
  • click on the β€˜Dashboard’ to make sure everything is up to date, (it is not necessary to upgrade to the premium version of MBAM)
  • click on the β€˜Scan’ tab, (directly below the Dashboard tab)
  • select the Threat Scan option
  • slick the Scan Now button
  • Threat Scan will begin
  • when the scan has completed and if malware was found, click the Quarantine Selected button to allow MBAM to quarantine what was found
  • if prompted to restart the computer, close all other programs and click Yes to restart your computer
  • once you are back at your desktop, open MBAM once more
  • click on the β€˜Reports’ tab
  • double-click on the most recent Scan Report
  • click on Export, then Copy to Clipboard

Logs to include with the next post:

AdwCleaner log
Mbam.txt

 

Currently Kapersky is the only security suite I'm running, could you elaborate on the other apps you're referring to.  Thanks.
 
 
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 8/25/20
Scan Time: 8:07 PM
Log File: 80b3914c-e738-11ea-ad3b-14b31f02ea20.json
 
-Software Information-
Version: 4.2.0.82
Components Version: 1.0.1025
Update Package Version: 1.0.29061
License: Trial
 
-System Information-
OS: Windows 10 (Build 19041.450)
CPU: x64
File System: NTFS
User: DESKTOP-UT3JJO6\ISM
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 295273
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 1 min, 21 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end)
————–
 
# β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”-
# Malwarebytes AdwCleaner 8.0.7.0
# β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”-
# Build:    07-22-2020
# Database: 2020-07-20.1 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”-
# Mode: Scan
# β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”-
# Start:    08-25-2020
# Duration: 00:00:14
# OS:       Windows 10 Pro
# Scanned:  31837
# Detected: 23
 
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
No malicious folders found.
 
***** [ Files ] *****
 
No malicious files found.
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries found.
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs found.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries found.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs found.
 
***** [ Hosts File Entries ] *****
 
No malicious hosts file entries found.
 
***** [ Preinstalled Software ] *****
 
Preinstalled.CyberLinkService   Folder   C:\Program Files (x86)\CYBERLINK\SHARED FILES\PLUGIN\NEWBLUE 
Preinstalled.CyberLinkShellExtension   Registry   HKLM\Software\Classes\CLSID\{3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} 
Preinstalled.DellCustomerConnect   Folder   C:\Program Files (x86)\DELL CUSTOMER CONNECT 
Preinstalled.DellCustomerConnect   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{04A41EBC-AB30-4574-A14D-E0CDFE31AB70} 
Preinstalled.DellDigitalDelivery   Folder   C:\Program Files (x86)\DELL DIGITAL DELIVERY 
Preinstalled.DellFoundationServices   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{BDB50421-E961-42F3-B803-6DAC6F173834} 
Preinstalled.DellSupportAssistAgent   Folder   C:\Program Files\DELL\SUPPORTASSISTAGENT 
Preinstalled.DellSupportAssistAgent   Folder   C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ALIENWARE\SUPPORTASSIST 
Preinstalled.DellSupportAssistAgent   Folder   C:\ProgramData\SUPPORTASSIST\CLIENT\TECHNICIANTOOLKIT 
Preinstalled.DellSupportAssistAgent   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{095AFF6A-36AE-4F8E-A618-086A44945B5D}  
Preinstalled.DellSupportAssistAgent   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{095AFF6A-36AE-4F8E-A618-086A44945B5D}  
Preinstalled.DellSupportAssistAgent   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dell SupportAssistAgent AutoUpdate 
Preinstalled.DellSupportAssistAgent   Task   C:\Windows\System32\Tasks\DELL SUPPORTASSISTAGENT AUTOUPDATE 
Preinstalled.DellUpdateforWindows10   Folder   C:\Program Files (x86)\ALIENWARE UPDATE 
Preinstalled.DellUpdateforWindows10   Folder   C:\Program Files (x86)\DELL\UPDATESERVICE 
Preinstalled.DellUpdateforWindows10   Folder   C:\ProgramData\DELL\UPDATE 
Preinstalled.DellUpdateforWindows10   Folder   C:\ProgramData\DELL\UPDATESERVICE 
Preinstalled.DellUpdateforWindows10   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{5EBBC1DA-975F-44A0-B438-F325BCD45577} 
Preinstalled.LenovoPower2Go   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F80B70F1-70CA-4CB9-A548-091255A778D6}  
Preinstalled.LenovoPower2Go   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CLVDLauncher 
Preinstalled.LenovoPower2Go   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2} 
Preinstalled.LenovoPower2Go   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2} 
Preinstalled.LenovoPower2Go   Task   C:\Windows\System32\Tasks\CLVDLAUNCHER 
 
 
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
 

Currently Kaspersky is the only security suite I'm running, could you elaborate on the other apps you're referring to.  Thanks.

AV: Trend Micro Maximum Security (Disabled - Up to date) {AFEE279F-FAE7-BAEE-3A88-4BF7277B8551}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Kaspersky Total Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: Kaspersky Total Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}


The above listed as enabled means they can both be running at the same time.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

What the scan found was preinstalled by the manufacturer, not a big issue.

Do you know if recently something you have on the computer as in security or app had an update?,  is it possible you have URL protection on and enabled through a security app?

 

Let's see if we can run an online scanner to check for remnants.

 

Download ESET Online Scanner and save it to your desktop.

 

 

  • Right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET.
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply.

β€”β€”β€”β€”-

 

The only recent major event was my Kaspersky suite expired and renewed.

 

I ran ESET and nothing came up on the scan. I also disabled the McAfee remnants. 

 

 

Date: 2020-08-24 18:00:40.5080000Z
Description:
Code Integrity determined that a process (\Device\HarddiskVolume9\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume9\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 20.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

There were several of the above listed in your event logs.  I tried to research for this but I really had no luck.

Only thing I could think of was maybe registering at Kaspersky forum, https://community.kaspersky.com/ and asking what this might lead to?

I think it might have something to do with renewing your subscription but thats just a guess.


I don't really think there is any infection on the computer but rather your security app. It's doing what it's designed to do really in scanning urls first before allowing you entry.
What you might experiment on is rebooting and using the computer in between reboots to see if it might can straighten itself out a bit.

Use the computer for a couple of days and report back if something odd or out of the ordinary occurs.

 

Let me know if you would like to remove tools and quarantine folders.

It's funny you said that because when it was time for my Security Suite to renew it did so without any action from me. I usually buy a new renewal every year but when 

when it was time for the reup it was already active. I'm not setup for auto renewal and my bank account did not reflect a charge. Seeing how I don't believe in

coincidences I was already leaning that way for an answer. It sounds like very likely. 

 

I also will be removing all the previously installed tools we used.

when it was time for my Security Suite to renew it did so without any action from me

Thats kinda odd, keep an eye on your credit card…..are you sure no notice was sent?


 

P.S. Not to sound paranoid but should I be concerned with Karpersky, being a Russian owned company and all?

I think your safe because Kaspersky has been around for years and I've known people in the security field who have used it personally. IF, something was going on in the background we would had heard about it and it would had stormed across the internet with the results.
 
I want to throw this out there, if you ever wanted to remove Kaspersky and download something different, free antivirus  or use what was built into the windows system,  Use the Kaspersky uninstall tool
https://community.kaspersky.com/kaspersky-virus-removal-tool-76
https://support.kaspersky.com/us/common/uninstall/12783

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~``

Use this tool to remove tools and quarantined items:

Please download KpRm by Kernel-panik and save to your Desktop.

  • Click on KpRm.exe to run the tool.

Vista/Windows 7/8/10 users right-click and select Run As Administrator.

  • Put a check mark next to these items:

- Delete tools
- Delete now

  • Click the "Run" button.

[external image: automatic.png]

  • When the tool has finished, it will create and open a log report and delete itself.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI