Jump to content

New install - still having VIRUS Found prompts


Recommended Posts

new install of Kaspersky Internet Security, due to getting infected with a trojan virus.  Bottom right corner of screen - see VIRUS Found and McAfee prompt with Answer now or Delete message buttons.  This cycles through countless versions of that message.  Win 10 Home edition, all patched up.

Examples include:

 

any many MANY more.  Can’t get rid of it, even afte rrunning Quick scans, and a FULL scan that reported no issues.  Funny enough, I’ve never had Mcafee on this machine.  

Suggestions/Guidance?   My expectation was that this new product (picked up a 3 yr subscription) would have resolve it.  I must be doing something wrong.  

 

Thanks.

Link to comment
Share on other sites

Hello @Gina

Welcome!

  1. Are the VIRUS Found and McAfee prompt alerts coming after a browser is opened? 
  2. Are the VIRUS Found and McAfee prompt alerts showing in the Windows notification section of the desktop? 
  3. Before installing KIS, were the VIRUS Found and McAfee prompt alerts happening?
  4. Before installing KIS was a software compatibility check done? 
  5. Create a System restore point
  6. Export all Bookmarks for all browsers
  7. Read Kaspersky notification of detection, file or website detected topic written by @richbuff & follow each of the steps he’s documented (don’t worry that it says “Kaspersky notification”). 
  8. Run the KIS Clean & Optimize tools. 
  9. Run AdwCleaner as Admin and attach the TXT-Log in your reply → ⚠ please don’t clean any detections - run the report only⚠
  10. At the completion of steps 5 to 9, shutdown the PC using Shutdown, not Restart, power on, login, recheck VIRUS Found and McAfee prompt alerts?

Please post back?

Thank you🙏

Flood🐳 +🐋

Link to comment
Share on other sites

Thanks Flood!

  1. Are the VIRUS Found and McAfee prompt alerts coming after a browser is opened?  YES
  2. Are the VIRUS Found and McAfee prompt alerts showing in the Windows notification section of the desktop?  YES
  3. Before installing KIS, were the VIRUS Found and McAfee prompt alerts happening? No virus found, but that prompt kept appearing - leading me to buy the 3 yr subsciption of KIS
  4. Before installing KIS was a software compatibility check done?  YES - was fine
  5. Create a System restore point - Please elaborate - not sure how to do that...
  6. Export all Bookmarks for all browsers - issue is on Chrome - would need to export all bookmarks
  7. Read Kaspersky notification of detection, file or website detected topic written by @richbuff & follow each of the steps he’s documented (don’t worry that it says “Kaspersky notification”).  ok, will look at that.
  8. Run the KIS Clean & Optimize tools.  ok, will run after reading item in 7 above
  9. Run AdwCleaner as Admin and attach the TXT-Log in your reply → ⚠ please don’t clean any detections - run the report only⚠ - what is that product?  is it in this suite of apps?  how do i access AdwCleaner?
  10. At the completion of steps 5 to 9, shutdown the PC using Shutdown, not Restart, power on, login, recheck VIRUS Found and McAfee prompt alerts? - I’ll need guidance and time to work through all of these - but I do appreciate the tidbits here.
Link to comment
Share on other sites

update.  i already have a 9Gig restore point for C: in place.

all bookmarks in Chrome are exported.  only browser used is Chrome

all but 10 temp files were deleted.  i could not delete the 10 as Chrome was currently using them.  is that a problem to be dealt with?

and beyond that i could not follow the article by @richbuff.  it asked to uninstall any recently installed junk.  huh? i don’t have anything, it’s a clean system.  Is this a browser setting?  or junk as it any odd apps from SW manager?  SW is clean (not much on machine).  

remove junk search providers - huh?  only use Chrome, etc… 

I stopped going through that article at this point.  

 

 

Link to comment
Share on other sites

Hello @Gina

You’re most welcome☺ !

💥 The goal of all the steps is to get rid of the adware!💥

Do all of the following: 

  • Create a NEW system restore point → in Windows search🔎 bar, type restore, select the Create a Restore point app, in System Protection tab select CREATE, allow the app to complete, select OK. 
  • Export Chrome bookmarks.
  • IF you've installed ANY programs/software, check Windows, Control Panel\All Control Panel Items\Programs and Features, make sure NO unwanted programs/software has been installed without your knowledge. 
  • Sign into Safe Mode
  • Clear all files & folders in C:\Windows\Temp
  • Clear all files & folders in C:\Users\USER\AppData\Local\Temp
  • Return to normal mode
  • Reset Chrome to Default - chrome://settings/reset - then exit Chrome & do not restart atm. 
  • Go to Chrome SHORTCUT, select Properties:
  • the TARGET field should only have  "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" written in it → image below, number (1)
  • the START IN field should only have  "C:\Program Files (x86)\Google\Chrome\Application" written in it - → image below, number (2)
  • EXIT all applications except KIS: run KIS Clean & Optimize tools. 
  • If you are using a router, reset the router, change the router password to a strong password, enter the correct information according to your internet providers instructions, then AGAIN clear browser cache and cookies.
  • When ALL the above steps are complete, shutdown the machine using SHUTDOWN, not Restart, power on, login
  • Open KIS app, make sure Perform recommended actions automatically is checked and make sure Delete malicious tools, adware, auto-dialers and suspicious packers is checked → make sure Save is selected, to apply any change. 
  • Run Malwarebytes AdwCleaner →  https://support.malwarebytes.com/hc/en-us/articles/360038520054-Download-and-install-Malwarebytes-AdwCleaner - scan ONLY →  post the report in your reply please

Thank you🙏

Flood🐳 +🐋

 

 

Link to comment
Share on other sites

Hi Flood. 

No idea who you are, but THANK YOU!  Here is the log file - indicating no malware or adware.

pasted here, and attached as a .txt file:

# -------------------------------
# Malwarebytes AdwCleaner 8.2.0.0
# -------------------------------
# Build:    03-22-2021
# Database: 2021-05-17.1 (Cloud)
# Support:  https://www.malwarebytes.com/support />#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    06-23-2021
# Duration: 00:00:29
# OS:       Windows 10 Home
# Scanned:  31988
# Detected: 47


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

Preinstalled.CyberLinkLabelPrint   Folder   C:\Program Files (x86)\CYBERLINK\LABELPRINT 
Preinstalled.CyberLinkLabelPrint   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243} 
Preinstalled.CyberLinkLabelPrint   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{C59C179C-668D-49A9-B6EA-0121CCFC1243} 
Preinstalled.HPClientServices   Folder   C:\Program Files\HEWLETT-PACKARD\HP CLIENT SERVICES 
Preinstalled.HPClientServices   Folder   C:\ProgramData\HEWLETT-PACKARD\HP CLIENT SERVICES 
Preinstalled.HPClientServices   Folder   C:\ProgramData\HEWLETT-PACKARD\HP CLIENT SERVICES\CONFIG 
Preinstalled.HPClientServices   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2} 
Preinstalled.HPClientServices   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2} 
Preinstalled.HPHealthCheck   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP HEALTH CHECK 
Preinstalled.HPHealthCheck   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6F340107-F9AA-47C6-B54C-C3A19F11553F} 
Preinstalled.HPLinkUp   File   C:\Users\Paul\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\HP LinkUp Viewer.lnk 
Preinstalled.HPLinkUp   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP LINKUP 
Preinstalled.HPLinkUp   Folder   C:\Users\Gina\AppData\Roaming\HEWLETT-PACKARD\HP LINKUP 
Preinstalled.HPLinkUp   Folder   C:\Users\Paul\AppData\Roaming\HEWLETT-PACKARD\HP LINKUP 
Preinstalled.HPLinkUp   Registry   HKLM\Software\Classes\CLSID\{B793E5EA-5344-488E-B98D-A18E2E5938AB} 
Preinstalled.HPLinkUp   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{C1AD9241-3ADD-483F-914D-071F3E50855A} 
Preinstalled.HPOdometer   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP ODOMETER 
Preinstalled.HPOdometer   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|hpsysdrv 
Preinstalled.HPOdometer   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Run|hpsysdrv 
Preinstalled.HPOdometer   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{B8AC1A89-FFD1-4F97-8051-E505A160F562} 
Preinstalled.HPSupportAssistant   Folder   C:\HP\SUPPORT 
Preinstalled.HPSupportAssistant   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP CUSTOMER FEEDBACK 
Preinstalled.HPSupportAssistant   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT INFORMATION 
Preinstalled.HPSupportAssistant   Folder   C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Folder   C:\Users\Gina\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Folder   C:\Users\NULL\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Folder   C:\Users\Paul\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Folder   C:\Users\Paul\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Registry   HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} 
Preinstalled.HPSupportAssistant   Registry   HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{E92D47A1-D27D-430A-8368-0BAFD956507D} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{EE202411-2C26-49E8-9784-1BC1DBF7DE96} 
Preinstalled.HPSupportAssistant   Registry   HKU\S-1-5-21-1469610128-175261771-1071931264-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} 
Preinstalled.HPSupportAssistant   Registry   HKU\S-1-5-21-1469610128-175261771-1071931264-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} 
Preinstalled.LenovoPower2Go   File   C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Power2Go.lnk 
Preinstalled.LenovoPower2Go   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658} 
Preinstalled.LenovoPower2Go   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{40BF1E83-20EB-11D8-97C5-0009C5020658} 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDTANGENT GAMES 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDTANGENT GAMES\APP 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGameProvider-hp-genres 

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
 

Guest
This topic is now closed to further replies.


×
×
  • Create New...