if you click it it takes you to some page that makes you think it is norton or mcaffee.
screen shot attached it shows as a notification in chrome.
Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
Hello, medic.
Download Farbar Recovery Scan Tool and save it to your desktop. --> IMPORTANT
If your antivirus software detects the tool as malicious, it’s safe to allow FRST to run. It is a false-positive detection.
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
Was hoping someone knew what it was off the bat. here are the files.
thanks
Hi, medic.
It seems to me that the pop up is a spam alert.
I have some comments and instructions for you, regarding your logs, but please first adhere to the guidelines below, and then carefully follow, with the same order, all the instructions after:
1. Always ask before acting. Do not continue if you are not sure, or if something unexpected happens!
2. Do not run any tools unless instructed to do so. Also, do not uninstall or install any software during the procedure, unless I ask you to do so.
3. If your computer seems to start working normally, don't abandon the topic. Even if your system is behaving normally, there may still be some malware remnants left over. Additionally, malware can re-infect the computer if some remnants are left. Therefore, please complete all requested steps to make sure any malware is successfully eradicated from your PC.
4. You have to reply to my posts within 3 days. If you need some additional time, just let me know. Otherwise, I will leave the topic due to lack of feedback. If you are able, I would request you to check this thread at least once per day so that we can resolve your issues effectively and efficiently.
5. Logs from malware diagnostic or removal programs can take some time to get analyzed. Also, have in mind that all the experts here are volunteers and may not be available to assist when you post. Please, be patient, while I analyze your logs.
============================================
My first comments and instructions:
1. RAM
These lines are from your logs:
Percentage of memory in use: 94% Total physical RAM: 32714.05 MB Available physical RAM: 1653.83 MB
A percentage of 94% of the 4GB RAM you have, is in use. This makes the computer difficult to run. If you keep all those programs running, you definitely need additional RAM. This is something you have to consider after we finish with the cleaning procedure.
2. Many unnecessary (??) programs
You have so many programs installed (some of them probably are preinstalled from when you bought the computer) and I wonder if you really need or use them. Many of them are system optimizers or graphics utilities. I see that you play games and perhaps you need them, but have in mind that registry cleaners, system optimizers, driver boosters and the like may cause more problems than they claim to fix. It is your computer and certainly your choice. My recommendation is to uninstall programs like the following:
EasyTune EasyTuneEngineService Fast Boot Gigabyte Speed RivaTuner Statistics Server MSI Afterburner MSI Kombustor
Also, do you need Team Viewer?
If you decide to uninstall any of the above, as well as other programs you may not use/need, please do the following:
3. Many Chrome extensions
You have so many Chrome extension in every Chrome profile you have! Do you use all of them? Since the pop-up is from Chrome, it's not strange one of these extensions to be the cause. No need to do something for this now, but have in mind that it is possible the tools we are going to use to detect some of them as adware.
4. Google Drive Sync at start-up:
Are you aware that Google Drive sync is enable at start up? If Google Drive is set up to sync at startup, specific files in the TEMP folder are created every time you start your computer. We are going to delete them in a next fix, but they will continue to be created at every startup. In case you want to stop this:
5. AdwCleaner (Scan mode)
Download AdwCleaner and save it to your desktop.
6. Run Malwarebytes
Under the title Scan Options, all the options are checked. Under the title Windows Security Center (Premium only) the option is unchecked. Under the title Potentially unwanted items all options are set to Always.
If threats are not found, click View Report and proceed to the two last steps below.
If threats are found, make sure that all threats are not selected, close the program and proceed to the next steps below.
In your next reply, please post:
Nothing removed.
Hi, medic.
You mean you didn't uninstall any program?
Malwarebytes found nothing, but AdwCleaner detected some stuff.
1. AdwCleaner (Clean mode)
The findings in Folders and Chromium parts of the log, are adware and PUPs which stands for Potentially Unwanted Programs. In the instructions below, I will list them all to be removed. Among them is the Amazon Assistant for Chrome and remnants from IObit Advanced System Care. Since you have a product by IObit, I have to ask you if you intentionally installed IObit Software Updater. If not, please go on and uninstall it.
The section at the bottom under Preinstalled Software is software that was apparently installed when the device was new, which you may or may not use. It is an EPSON product, named EPSONCUSTOMERRESEARCHPARTICIPATION and I will also ask you to remove it.
To proceed, please do the following:
2. Fresh FRST logs
In your next reply, please post:
Latest.
I wanted to keep my amazon toolbar but the pop up continued even when I took the other stuff out so I removed it also.
Hi, medic.
It seems that some RAM is released now. This is good.
However, with so many Chrome extensions, optimizers/tuners and the Google Drive sync on, it's difficult to say right now what is the source of the problem.
Let's do this fix for now and please give me your feedback after that.
1. FRST fix
NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
Start:: CreateRestorePoint: CloseProcesses: BHO: No Name -> {4622318C-A9BB-4D2C-898C-10A9656A2B11}' -> No File FirewallRules: [UDP Query User{8C2CD61D-E24F-47DD-88E7-305E5C220BB7}C:\fahclient\fahclient.exe] => (Allow) C:\fahclient\fahclient.exe => No File FirewallRules: [TCP Query User{8FFB5AAF-2671-405E-92D5-1C9DBC70D8BD}C:\fahclient\fahclient.exe] => (Allow) C:\fahclient\fahclient.exe => No File HKLM-x32\...\Run: [EasySettingBox] => [X] GroupPolicy\User: Restriction ? <==== ATTENTION HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION C:\WINDOWS\system32\Tasks\AVAST Software C:\Users\aemtp\AppData\Roaming\AVG C:\WINDOWS\system32\Drivers\staport.sys C:\WINDOWS\system32\Drivers\asw4b0c4acbc4f029df.tmp C:\WINDOWS\system32\Drivers\aswb9a08bc49eb1dd0d.tmp C:\WINDOWS\system32\Drivers\asw283d75214625d12e.tmp C:\WINDOWS\system32\Drivers\aswd35ee59496dd0c8a.tmp C:\WINDOWS\system32\avgBoot.exe C:\WINDOWS\system32\Drivers\aswed71c87c035442df.tmp C:\WINDOWS\system32\Drivers\asw8ad8069a9c016236.tmp C:\WINDOWS\system32\Drivers\asw99b3cb18f36afa93.tmp C:\WINDOWS\system32\Drivers\asw67fc997623db1cca.tmp C:\WINDOWS\system32\Drivers\asw4477054a23f32c17.tmp C:\WINDOWS\system32\Drivers\asw1cd0838a14a0562a.tmp C:\WINDOWS\system32\Drivers\aswa2a73b537aa7038e.tmp C:\WINDOWS\system32\Drivers\aswa999eea98712beef.tmp C:\WINDOWS\system32\Drivers\aswdd4f6c06fcd545f0.tmp C:\WINDOWS\system32\Drivers\aswa1581da92070e9a3.tmp C:\WINDOWS\system32\Drivers\aswab10d82ed2e7dee5.tmp C:\Program Files\Common Files\AVG C:\ProgramData\AVG C:\Users\aemtp\Downloads\avg_antivirus_free_setup.exe virustotal: C:\Users\aemtp\AppData\Local\ars.cache;C:\Users\aemtp\AppData\Local\census.cache;C:\Users\aemtp\AppData\Local\housecall.guid.cache;C:\Users\aemtp\AppData\Local\keyfile3.drm;C:\Program Files (x86)\IObit\Software Updater\SUInit.exe;C:\Program Files (x86)\IObit\Software Updater\SoftwareUpdater.exe;C:\Program Files\thinkorswim\jxbrowser\v18\bin\chromium.exe EmptyTemp: End::
In your next reply please post:
1. The fixlog.txt
2. Your feedback about how is the computer running now
If it helps to know this just started a day or two ago when I downloaded something from an "unsafe" website. It was some lawyer's website of course. not sure if giving you the site will help but I can try to find it.
what will that script do? There are multiple programs in there I need.
I have deleted AVG btw - it was constantly popping up and bothering me.
Hi, medic.
No need to search again for the malicious site.
The script will not remove any installed program. Please proceed to the fix and provide feedback.
So far no more pop ups thanks!
Hi, medic.
Good news!
The log above indicates that some functions of IObit Software Updater you have installed in the computer are detected by some antivirus programs as malicious.
https://www.virustot...ea9b-1616365477
https://www.virustot...2ef5-1616354961
If you do not really need it, please uninstall it.
1. Uninstall IObit Software Updater
IObit Software Updater
2. Eset online scan
Download ESET Online Scanner and save it to your desktop.
3. FRST logs
In your next reply please post:
Hi, medic.
It seems that Eset completed the job for us.
Just a last fix:
NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
Start:: CreateRestorePoint: CloseProcesses: C:\Users\aemtp\AppData\Roaming\IObit C:\Program Files (x86)\IObit EmptyTemp: End::
How is the computer running now? Any remaining questions/concerns?
Running good, I have to run the last script but the problem is gone.
Thanks for the help, as soon as I run the last script I will post it.
Thanks
0 members, 1 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.