1.

Solve : Help get all of "security tool" from computer.?

Answer»

Yesterday I saw the yellow shield in the bottom corner telling me updates for Windows were available. So, before bed I clicked install updates and shut down. After it became apparent something was wrong I searched for solutions and finally USED Malwarebytes' AntiMalware-which seemed to fix everything. But, I'm on here because there's still a red shield in the corner of my screen that I don't think should be there. When I move my mouse over the shield it reads "Windows security alerts." Other then that being there everything seems to be WORKING great. These are my logs:


Comments, help.

An update-the yellow shield with an exclamation mark has appeared again asking me to click here to install updates.

[Saving space, attachment deleted by admin]Just double click on the shield, open Security Center, disable the alerts.Please go to VirSCAN.org FREE on-line scan service
(If more than one file needs scanned they must be done separately and logs posted for each one)

1. Copy and paste the following file path into the Suspicious files to scan box on the top of the page.
Code: [Select]C:\Documents and Settings\sharyn\Application Data\MSA\msctrlp.exe2. At the upload site, click once inside the window next to Browse.
3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
4. Click on the Upload button.
This will perform a scan across multiple different virus scanning engines.
Your file will possibly be entered into a queue which normally takes less than a minute to clear.
Important: Wait for all of the scanning engines to complete.
5. Once the Scan is completed scroll down and click on the Copy to Clipboard button. This will copy the link of the report into the Clipboard.
6. Paste the contents of the Clipboard in your next reply.

----------

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to BLOCK DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.
Copy and paste will not work! And, I cannot type the line in the box either. So, I tried using the browse feature to find the path(?) or line to the file to scan. I could not find the exact path. Using browse I get to C:\Documents and Settings\sharyn\Application Data\MSA ( I was able to copy and paste this), but after MSA there are only download.list and update.list. I could not find msctrlp.exe(again copy and pasted here). I also had to change folder options to show hidden files to see the Application Data folder. I don't understand why I cannot type or paste into this box but I can use the browse feature.

I just tried using seach entering msctrlp.exe(again I could copy and paste) and no results.OK just continue on with DSS please. I'm 99.9% certain that msctrlp.exe is a malicious file so we will take care of it shortly.OK. Info posted.

[Saving space, attachment deleted by admin]Go to Add or Remove Programs and uninstall:

  • Java 2 Runtime Environment, SE v1.4.2_03
  • Java(TM) SE Runtime Environment 6 Update 1
  • Viewpoint Media Player
.
----------

Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

DDS::
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
uRun: [msctrlp.exe] c:\documents and settings\sharyn\application data\msa\msctrlp.exe

Folder::
c:\documents and settings\sharyn\application data\msa


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in CASE it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeI could not remove •Java 2 Runtime Environment, SE v1.4.2_03. I get messages saying SOMETHINGS not available. I tried to attached a screen shot of the dialogue boxes but the files were too big. The other two removed no problem. I did the messenger thing and have downloaded Combofix with running.Delete An Uninstall Entry

  • Start HijackThis
  • Click on the Open the Misc Tools section
  • Click on the Open Uninstall Manager button.
  • Highlight the entry you want to remove.
  • Click Delete this entry
Done. HJT is still open.Waiting for the ComboFix log...I hadn't run combofix before my last post. I opened HJT and clicked to removed the one file and then X closed it. Then ran combofix.

[Saving space, attachment deleted by admin]Is there a reason you aren't running an antivirus?I had McAfee when I got the computer but let it expire. Actually, when this started it was the biggest problem I've ever had. Couldn't use control panel and stuff like that. To answer your question-I don't have a specific reason. If you would like to recommend one I'll take your advice.

Download the McAfee Consumer Product Removal Tool to your Desktop.

Using McAfee Consumer Product Removal tool:

* Double click the MCPR.exe
* A Command Line window will be displayed, and then close automatically.
* Wait for a second Command Line window to be displayed.

Note: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear.

* After the second window appears, the program will begin the cleanup.
* Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: The machine must reboot to complete the un-installation. Reboot now? [y.n]
* Press Y on the keyboard.
* Wait for the computer to restart.
* All McAfee products are now removed from your computer.

----------

All of these are free for life and both very reliable.

Remember to only install one antivirus!

1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal

If you want a good free firewall.

1) Comodo (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any Ask.com options if you choose this one)
2) Online Armor
3) Sunbelt/Kerio


----------

Let me know when you get that done.

.


Discussion

No Comment Found