R rosetta Well-known member Joined Oct 25, 2015 Posts 217 Feb 1, 2016 #21 this one trick me again for about 30 minutes i couldn't paste it my desktop where the frst folder is .Fix result of Farbar Recovery Scan Tool (x86) Version:27-01-2016Ran by Acer (2016-02-01 19:17:45) Run:1 Running from C:\Users\Acer\Desktop Loaded Profiles: Acer (Available Profiles: Acer) Boot Mode: Normal ============================================== fixlist content: ***************** start CreateRestorePoint: CloseProcesses: HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION S4 IObitUnlocker; C:\Program Files\IObit\IObit Unlocker\IObitUnlocker.sys [29912 2013-09-30] (IObit) S4 IObitUnlocker; C:\Program Files\IObit\IObit Unlocker\IObitUnlocker.sys [29912 2013-09-30] (IObit) 2016-01-23 23:44 - 2016-01-23 23:44 - 00013264 _____ (wisecleaner.com) C:\Windows\WiseHDInfo32.dll 2016-01-23 23:42 - 2016-01-23 23:42 - 06378664 _____ (WiseCleaner.com ) C:\Users\Acer\Downloads\WiseCare365.exe 2016-01-23 19:07 - 2016-01-23 19:10 - 00000000 ____D C:\Program Files\GUM96B3.tmp 2016-02-01 11:44 - 2015-08-23 17:24 - 00000000 ____D C:\Program Files\IObit 2016-02-01 11:44 - 2015-05-14 10:53 - 00000000 ____D C:\ProgramData\IObit 2016-02-01 11:18 - 2015-05-14 10:53 - 00000000 ____D C:\Users\Acer\AppData\Roaming\IObit 2016-02-01 11:05 - 2015-05-05 17:58 - 00000000 ____D C:\ProgramData\GlarySoft 2016-02-01 11:05 - 2015-05-05 17:44 - 00000000 ____D C:\Users\Acer\AppData\Roaming\GlarySoft 2016-01-29 10:47 - 2015-05-14 11:04 - 00200704 _____ C:\Windows\system32\config\default.iobit 2016-01-29 10:47 - 2015-05-14 11:04 - 00061440 _____ C:\Windows\system32\config\sam.iobit 2016-01-29 10:47 - 2015-05-14 11:04 - 00024576 _____ C:\Windows\system32\config\security.iobit 2016-01-29 10:47 - 2015-05-14 11:03 - 56688640 _____ C:\Windows\system32\config\software.iobit 2016-01-27 11:31 - 2015-05-14 11:04 - 21278720 _____ C:\Windows\system32\config\components.iobit HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ioloSystemService => ""="Service" EmptyTemp: end ***************** Restore point was successfully created. Processes closed successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully. IObitUnlocker => service removed successfully. IObitUnlocker => service not found. "C:\Windows\WiseHDInfo32.dll" => not found. "C:\Users\Acer\Downloads\WiseCare365.exe" => not found. C:\Program Files\GUM96B3.tmp => moved successfully C:\Program Files\IObit => moved successfully C:\ProgramData\IObit => moved successfully C:\Users\Acer\AppData\Roaming\IObit => moved successfully "C:\ProgramData\GlarySoft" => not found. "C:\Users\Acer\AppData\Roaming\GlarySoft" => not found. C:\Windows\system32\config\default.iobit => moved successfully C:\Windows\system32\config\sam.iobit => moved successfully C:\Windows\system32\config\security.iobit => moved successfully C:\Windows\system32\config\software.iobit => moved successfully C:\Windows\system32\config\components.iobit => moved successfully "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService" => key removed successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\ioloSystemService" => key removed successfully. EmptyTemp: => 65 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 19:18:31 ====
this one trick me again for about 30 minutes i couldn't paste it my desktop where the frst folder is .Fix result of Farbar Recovery Scan Tool (x86) Version:27-01-2016Ran by Acer (2016-02-01 19:17:45) Run:1 Running from C:\Users\Acer\Desktop Loaded Profiles: Acer (Available Profiles: Acer) Boot Mode: Normal ============================================== fixlist content: ***************** start CreateRestorePoint: CloseProcesses: HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION S4 IObitUnlocker; C:\Program Files\IObit\IObit Unlocker\IObitUnlocker.sys [29912 2013-09-30] (IObit) S4 IObitUnlocker; C:\Program Files\IObit\IObit Unlocker\IObitUnlocker.sys [29912 2013-09-30] (IObit) 2016-01-23 23:44 - 2016-01-23 23:44 - 00013264 _____ (wisecleaner.com) C:\Windows\WiseHDInfo32.dll 2016-01-23 23:42 - 2016-01-23 23:42 - 06378664 _____ (WiseCleaner.com ) C:\Users\Acer\Downloads\WiseCare365.exe 2016-01-23 19:07 - 2016-01-23 19:10 - 00000000 ____D C:\Program Files\GUM96B3.tmp 2016-02-01 11:44 - 2015-08-23 17:24 - 00000000 ____D C:\Program Files\IObit 2016-02-01 11:44 - 2015-05-14 10:53 - 00000000 ____D C:\ProgramData\IObit 2016-02-01 11:18 - 2015-05-14 10:53 - 00000000 ____D C:\Users\Acer\AppData\Roaming\IObit 2016-02-01 11:05 - 2015-05-05 17:58 - 00000000 ____D C:\ProgramData\GlarySoft 2016-02-01 11:05 - 2015-05-05 17:44 - 00000000 ____D C:\Users\Acer\AppData\Roaming\GlarySoft 2016-01-29 10:47 - 2015-05-14 11:04 - 00200704 _____ C:\Windows\system32\config\default.iobit 2016-01-29 10:47 - 2015-05-14 11:04 - 00061440 _____ C:\Windows\system32\config\sam.iobit 2016-01-29 10:47 - 2015-05-14 11:04 - 00024576 _____ C:\Windows\system32\config\security.iobit 2016-01-29 10:47 - 2015-05-14 11:03 - 56688640 _____ C:\Windows\system32\config\software.iobit 2016-01-27 11:31 - 2015-05-14 11:04 - 21278720 _____ C:\Windows\system32\config\components.iobit HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ioloSystemService => ""="Service" EmptyTemp: end ***************** Restore point was successfully created. Processes closed successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully. IObitUnlocker => service removed successfully. IObitUnlocker => service not found. "C:\Windows\WiseHDInfo32.dll" => not found. "C:\Users\Acer\Downloads\WiseCare365.exe" => not found. C:\Program Files\GUM96B3.tmp => moved successfully C:\Program Files\IObit => moved successfully C:\ProgramData\IObit => moved successfully C:\Users\Acer\AppData\Roaming\IObit => moved successfully "C:\ProgramData\GlarySoft" => not found. "C:\Users\Acer\AppData\Roaming\GlarySoft" => not found. C:\Windows\system32\config\default.iobit => moved successfully C:\Windows\system32\config\sam.iobit => moved successfully C:\Windows\system32\config\security.iobit => moved successfully C:\Windows\system32\config\software.iobit => moved successfully C:\Windows\system32\config\components.iobit => moved successfully "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService" => key removed successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\ioloSystemService" => key removed successfully. EmptyTemp: => 65 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 19:18:31 ====
R rosetta Well-known member Joined Oct 25, 2015 Posts 217 Feb 1, 2016 #22 Fix result of Farbar Recovery Scan Tool (x86) Version:27-01-2016 Ran by Acer (2016-02-01 19:17:45) Run:1 Running from C:\Users\Acer\Desktop Loaded Profiles: Acer (Available Profiles: Acer) Boot Mode: Normal ============================================== fixlist content: ***************** start CreateRestorePoint: CloseProcesses: HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION S4 IObitUnlocker; C:\Program Files\IObit\IObit Unlocker\IObitUnlocker.sys [29912 2013-09-30] (IObit) S4 IObitUnlocker; C:\Program Files\IObit\IObit Unlocker\IObitUnlocker.sys [29912 2013-09-30] (IObit) 2016-01-23 23:44 - 2016-01-23 23:44 - 00013264 _____ (wisecleaner.com) C:\Windows\WiseHDInfo32.dll 2016-01-23 23:42 - 2016-01-23 23:42 - 06378664 _____ (WiseCleaner.com ) C:\Users\Acer\Downloads\WiseCare365.exe 2016-01-23 19:07 - 2016-01-23 19:10 - 00000000 ____D C:\Program Files\GUM96B3.tmp 2016-02-01 11:44 - 2015-08-23 17:24 - 00000000 ____D C:\Program Files\IObit 2016-02-01 11:44 - 2015-05-14 10:53 - 00000000 ____D C:\ProgramData\IObit 2016-02-01 11:18 - 2015-05-14 10:53 - 00000000 ____D C:\Users\Acer\AppData\Roaming\IObit 2016-02-01 11:05 - 2015-05-05 17:58 - 00000000 ____D C:\ProgramData\GlarySoft 2016-02-01 11:05 - 2015-05-05 17:44 - 00000000 ____D C:\Users\Acer\AppData\Roaming\GlarySoft 2016-01-29 10:47 - 2015-05-14 11:04 - 00200704 _____ C:\Windows\system32\config\default.iobit 2016-01-29 10:47 - 2015-05-14 11:04 - 00061440 _____ C:\Windows\system32\config\sam.iobit 2016-01-29 10:47 - 2015-05-14 11:04 - 00024576 _____ C:\Windows\system32\config\security.iobit 2016-01-29 10:47 - 2015-05-14 11:03 - 56688640 _____ C:\Windows\system32\config\software.iobit 2016-01-27 11:31 - 2015-05-14 11:04 - 21278720 _____ C:\Windows\system32\config\components.iobit HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ioloSystemService => ""="Service" EmptyTemp: end ***************** Restore point was successfully created. Processes closed successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully. IObitUnlocker => service removed successfully. IObitUnlocker => service not found. "C:\Windows\WiseHDInfo32.dll" => not found. "C:\Users\Acer\Downloads\WiseCare365.exe" => not found. C:\Program Files\GUM96B3.tmp => moved successfully C:\Program Files\IObit => moved successfully C:\ProgramData\IObit => moved successfully C:\Users\Acer\AppData\Roaming\IObit => moved successfully "C:\ProgramData\GlarySoft" => not found. "C:\Users\Acer\AppData\Roaming\GlarySoft" => not found. C:\Windows\system32\config\default.iobit => moved successfully C:\Windows\system32\config\sam.iobit => moved successfully C:\Windows\system32\config\security.iobit => moved successfully C:\Windows\system32\config\software.iobit => moved successfully C:\Windows\system32\config\components.iobit => moved successfully "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService" => key removed successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\ioloSystemService" => key removed successfully. EmptyTemp: => 65 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 19:18:31 ====
Fix result of Farbar Recovery Scan Tool (x86) Version:27-01-2016 Ran by Acer (2016-02-01 19:17:45) Run:1 Running from C:\Users\Acer\Desktop Loaded Profiles: Acer (Available Profiles: Acer) Boot Mode: Normal ============================================== fixlist content: ***************** start CreateRestorePoint: CloseProcesses: HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION S4 IObitUnlocker; C:\Program Files\IObit\IObit Unlocker\IObitUnlocker.sys [29912 2013-09-30] (IObit) S4 IObitUnlocker; C:\Program Files\IObit\IObit Unlocker\IObitUnlocker.sys [29912 2013-09-30] (IObit) 2016-01-23 23:44 - 2016-01-23 23:44 - 00013264 _____ (wisecleaner.com) C:\Windows\WiseHDInfo32.dll 2016-01-23 23:42 - 2016-01-23 23:42 - 06378664 _____ (WiseCleaner.com ) C:\Users\Acer\Downloads\WiseCare365.exe 2016-01-23 19:07 - 2016-01-23 19:10 - 00000000 ____D C:\Program Files\GUM96B3.tmp 2016-02-01 11:44 - 2015-08-23 17:24 - 00000000 ____D C:\Program Files\IObit 2016-02-01 11:44 - 2015-05-14 10:53 - 00000000 ____D C:\ProgramData\IObit 2016-02-01 11:18 - 2015-05-14 10:53 - 00000000 ____D C:\Users\Acer\AppData\Roaming\IObit 2016-02-01 11:05 - 2015-05-05 17:58 - 00000000 ____D C:\ProgramData\GlarySoft 2016-02-01 11:05 - 2015-05-05 17:44 - 00000000 ____D C:\Users\Acer\AppData\Roaming\GlarySoft 2016-01-29 10:47 - 2015-05-14 11:04 - 00200704 _____ C:\Windows\system32\config\default.iobit 2016-01-29 10:47 - 2015-05-14 11:04 - 00061440 _____ C:\Windows\system32\config\sam.iobit 2016-01-29 10:47 - 2015-05-14 11:04 - 00024576 _____ C:\Windows\system32\config\security.iobit 2016-01-29 10:47 - 2015-05-14 11:03 - 56688640 _____ C:\Windows\system32\config\software.iobit 2016-01-27 11:31 - 2015-05-14 11:04 - 21278720 _____ C:\Windows\system32\config\components.iobit HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ioloSystemService => ""="Service" EmptyTemp: end ***************** Restore point was successfully created. Processes closed successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully. IObitUnlocker => service removed successfully. IObitUnlocker => service not found. "C:\Windows\WiseHDInfo32.dll" => not found. "C:\Users\Acer\Downloads\WiseCare365.exe" => not found. C:\Program Files\GUM96B3.tmp => moved successfully C:\Program Files\IObit => moved successfully C:\ProgramData\IObit => moved successfully C:\Users\Acer\AppData\Roaming\IObit => moved successfully "C:\ProgramData\GlarySoft" => not found. "C:\Users\Acer\AppData\Roaming\GlarySoft" => not found. C:\Windows\system32\config\default.iobit => moved successfully C:\Windows\system32\config\sam.iobit => moved successfully C:\Windows\system32\config\security.iobit => moved successfully C:\Windows\system32\config\software.iobit => moved successfully C:\Windows\system32\config\components.iobit => moved successfully "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService" => key removed successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\ioloSystemService" => key removed successfully. EmptyTemp: => 65 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 19:18:31 ====
Corrine Administrator, Microsoft MVP, Security Analyst Staff member Joined Feb 22, 2012 Posts 12,071 Location Upstate, NY Feb 1, 2016 #23 Don't know why it tricked you but glad you got it squared away. Now it is your choice as to whether you wish to run Delfix, information provided here.
Don't know why it tricked you but glad you got it squared away. Now it is your choice as to whether you wish to run Delfix, information provided here.
R rosetta Well-known member Joined Oct 25, 2015 Posts 217 Feb 1, 2016 #24 # DelFix v1.011 - Logfile created 01/02/2016 at 21:41:31 # Updated 18/08/2015 by Xplode # Username : Acer - ACER-PC # Operating System : Windows 7 Starter Service Pack 1 (32 bits) ~ Removing disinfection tools ... Deleted : C:\FRST Deleted : C:\AdwCleaner Deleted : C:\RegBackup Deleted : C:\Users\Acer\Desktop\Addition.txt Deleted : C:\Users\Acer\Desktop\Fixlog.txt Deleted : C:\Users\Acer\Desktop\FRST.exe Deleted : C:\Users\Acer\Desktop\FRST.txt Deleted : C:\Users\Acer\Desktop\JRT.exe Deleted : C:\Users\Acer\Desktop\SecurityCheck.exe Deleted : C:\Users\Acer\Downloads\adwcleaner_5.031.exe Deleted : C:\Users\Acer\Downloads\esetsmartinstaller_enu.exe Deleted : C:\Users\Acer\Downloads\JRT.exe Deleted : C:\Users\Acer\Downloads\MiniToolBox.exe Deleted : C:\Users\Acer\Downloads\rkill.exe Deleted : C:\Users\Acer\Downloads\RogueKiller(1).exe Deleted : HKLM\SOFTWARE\AdwCleaner ########## - EOF - ##########
# DelFix v1.011 - Logfile created 01/02/2016 at 21:41:31 # Updated 18/08/2015 by Xplode # Username : Acer - ACER-PC # Operating System : Windows 7 Starter Service Pack 1 (32 bits) ~ Removing disinfection tools ... Deleted : C:\FRST Deleted : C:\AdwCleaner Deleted : C:\RegBackup Deleted : C:\Users\Acer\Desktop\Addition.txt Deleted : C:\Users\Acer\Desktop\Fixlog.txt Deleted : C:\Users\Acer\Desktop\FRST.exe Deleted : C:\Users\Acer\Desktop\FRST.txt Deleted : C:\Users\Acer\Desktop\JRT.exe Deleted : C:\Users\Acer\Desktop\SecurityCheck.exe Deleted : C:\Users\Acer\Downloads\adwcleaner_5.031.exe Deleted : C:\Users\Acer\Downloads\esetsmartinstaller_enu.exe Deleted : C:\Users\Acer\Downloads\JRT.exe Deleted : C:\Users\Acer\Downloads\MiniToolBox.exe Deleted : C:\Users\Acer\Downloads\rkill.exe Deleted : C:\Users\Acer\Downloads\RogueKiller(1).exe Deleted : HKLM\SOFTWARE\AdwCleaner ########## - EOF - ##########
R rosetta Well-known member Joined Oct 25, 2015 Posts 217 Feb 1, 2016 #25 a powerful tool but i cannot remove the icons of the deleted tools off my computer.
R rosetta Well-known member Joined Oct 25, 2015 Posts 217 Feb 1, 2016 #26 Corrine you can disregard the previous log, i found a way too get the icons tools removed. going into safe mode did the trick. you can now call this case solved you did a tremendous job Corrine. Kudos,kudos ,kudos with thanks.
Corrine you can disregard the previous log, i found a way too get the icons tools removed. going into safe mode did the trick. you can now call this case solved you did a tremendous job Corrine. Kudos,kudos ,kudos with thanks.
Corrine Administrator, Microsoft MVP, Security Analyst Staff member Joined Feb 22, 2012 Posts 12,071 Location Upstate, NY Feb 2, 2016 #27 You are welcome. I'm very happy I was able to assist!