EMERGENCY!!!

Started by Moses, July 29, 2017, 06:57:54 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Moses

Here is the 2nd screen shot immediately after "accepting the risk"

techie

I'm not a Comodo fan, I don't dislike there security programs. A security company that uses such hidden add on programs I have to question. You can disable them from being installed, but it isn't straightforward, and you have to look at the installer close, enter a second page to uncheck the additional software being installed.

You can try Revo uninstaller and see if it shows in there removal tool option. I would simply remove anything that says Comodo at this point, if it does.

https://www.revouninstaller.com/start_freeware_download.html

The only other solution I have seen is you have to reinstall comodo completely and uninstall it correctly.

As you can see it has avoided removal by every solution thrown at it so far.

Moses

This was a good idea, but unfortunately I got the same reply:
See the image attached.

Moses

I uninstalled Comodo Back up, but then when I ran this new removal program, I got the same message as I did when I tried to
uninistall from Windows uninstall.  See image attached.

Corrine

The Comodo uninstaller did indicate that the service is missing so it shouldn't be able to run.  To see what may be remaining, and a path to browse to with Revo, try this with FRST:


  • Right click on the FRST64 desktop icon and choose Run as administrator
  • Click on Yes in the UAC window.
  • Type GeekBuddy into the Search field.
  • Click on Search Files(s) button.
  • Please post the Search.txt log that will be created in your next reply.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Moses

Doesn't look like there is too much here...if anything:

Farbar Recovery Scan Tool (x64) Version: 12-08-2017
Ran by Me (14-08-2017 07:47:25)
Running from C:\Users\Me\Desktop\Repair
Boot Mode: Normal

================== Search Files: "GeekBuddy" =============

====== End of Search ======

Corrine

Let's try one last thing.

Please download the Junkware Removal Tool to your desktop.

  • Right-click JRT.exe to "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next reply.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Moses

Here it is fresh off the press:

Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Home Premium x64
Ran by Me (Administrator) on Mon 08/14/2017 at 20:12:05.09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 48

Successfully deleted: C:\Users\Me\AppData\Local\{06494044-CAD0-4C35-91A1-105C8B971905} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{06AB31D3-B383-45D8-B31F-AF62D7BC2F92} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{0FC6EE34-C6D7-4431-94FA-2FC4444C54D0} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{1D4C7D9B-BE63-467E-ABBC-72BA07291BDA} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{29F8AEEA-29FE-48A4-97E2-D0A1A79D86C7} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{2A6B6271-32E1-4E56-A8F4-B819B040A786} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{2F7EDFAF-0DEC-413D-A4A5-A3BC94B5A50E} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{31E1CD07-0466-4C16-B7E3-878A3A1B9525} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{3BE979C5-6B9E-437A-B93B-4A3EA2B415F7} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{46E21E10-16B7-4777-9060-36D1B697FDCB} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{54F2F144-CC5A-4E40-A84A-8A03CFD55893} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{624483A1-C444-495D-BED5-7611EB252330} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{680824F6-B6D3-4605-8A35-85CDF3250750} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{742454CF-D572-4C82-95F9-78BF5BA012DE} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{81E809C3-2064-49EC-8625-EF939BB5F0C0} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{89CA66AD-DE75-4886-80A5-0E1B5959FB8F} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{934FEF31-EBAD-4FCD-98B5-3AB8B1BD5A6E} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{9957C680-5D29-4566-A2B9-1CCD1061DDD6} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{A1937F5C-1B23-47C5-B0D3-B30BE0EA43B5} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{A1BC0E1C-AEB5-4C05-9ED0-EA2C3F33A7DC} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{AE54B46C-8B43-46D3-AE74-92D2EC1F83B1} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{C87D58B2-F566-42F4-8996-09F361E48B6F} (Empty Folder)
Successfully deleted: C:\Users\Me\AppData\Local\{D02F0D49-A324-4B1F-B575-0CEDB1DFB312} (Empty Folder)
Successfully deleted: C:\Windows\wininit.ini (File)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33N1KA5Y (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\63RMBP5Q (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6GZ1M2OD (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9O39BV7N (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9PN1B5RZ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CQYH3RWY (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DXLO06SL (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7VX3X0B (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HDYT3NJL (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SWAZVVNK (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T1SF2H55 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VYW3JD5G (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33N1KA5Y (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\63RMBP5Q (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6GZ1M2OD (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9O39BV7N (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9PN1B5RZ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CQYH3RWY (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DXLO06SL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7VX3X0B (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HDYT3NJL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SWAZVVNK (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T1SF2H55 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VYW3JD5G (Temporary Internet Files Folder)



Registry: 1

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C0C3A6C6-03BC-4195-8FCB-AEA091301353} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 08/14/2017 at 20:17:28.05
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Corrine

Hi, Moses.

Based on the large number of temporary and appdata files removed, rather than uninstalling AdwCleaner and Junkware Removal Tool, I suggest you scan with both programs minimally once per week.  Instead, please do the following to run and remove FRST:

  • Please select the entire contents of the code box below, from the "Start::" line to "End", including both lies.  Right-click and select "Copy ".


Start::
CreateRestorePoint:
CloseProcesses:
DeleteQuarantine:
EmptyTemp:
End::

  • Please right-click on FRST/FRST64 to run as administrator.  When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, delete the FRST folder located in C:\Users\Me\Desktop\Repair
Although you no longer need to worry about Java updates, be sure to keep both Adobe Acrobat Reader DC and Adobe Flash Player updated.  Unless there is an out-of-band update, Flash Player updates the second Tuesday of each month.

Considering the experience you just went through, should you have questions about a freeware (or other) program, feel free to create a new topic in the Computer Problems, Questions and Solutions! forum.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Moses

Corrine,

  Of course I am once again indebted to you for all of your time. I wish I could return the good will some time.

Other than that. I plan on uninstalling the adobe pdf reader in order to reinstall my licensed phantom whatever, unless you object.

Also, it just happened again, that when I click on an email link  on a website, something happens and then about 25 IE pages open up one after the other and there is one window saying how the Live Mail had a problem. It happens all of the time. But, if I do the same with Chrome, the email does open properly.  Any idea?

techie

Try this to see if resolves your mail and IE problem.

    Click Start, select Default Programs
    Click Set program access and computer defaults
    Click Custom, and select your mail client (for example, Windows Mail)
    Click OK

    Then, follow these steps:

    Click Set your default programs
    Select your mail client from the list
    Click Set this program as default
    Click OK

Corrine

Moses,

Since it is a licensed software, you should be fine.  However, as mentioned earlier in this discussion, pay attention when installing it or any other program to ensure there aren't any unwanted extras.  Create a System Restore point before installation.

It sounds as though you need to avoid that website!  You may also want to install Adblock Plus for IE:  https://adblockplus.org/en/internet-explorer

As to Live Mail, all of the Windows Essentials programs reached the end of support on January 10, 2017.  I wasn't thinking about that earlier but it could very well be why the problem with that particular website.  As indicated in the FAQ at Essentials 2012 Release Notes - Windows Help:

QuoteCan I still use Windows Live Mail?
Yes. Though, some email service providers have moved to newer email protocols for improved security and reliability not supported by Windows Live Mail. These email service providers may no longer work.

Personally, I never cared for Live Mail.  Although I have Microsoft Office installed, my preference is Outlook.com.  When I launch the browser, I have that as one of my start pages.  From there, I can not only check my mail but also my calendar, contacts, OneDrive, etc.  Additional email accounts can be added just as in Live Mail.  Although there are other ways of accessing the free Office Online apps, it is easy to get there from Outlook.com.  For information about the free Office Online apps, see Free Microsoft Office Online, Word, Excel, Powerpoint.  Information about Outlook.com is available at (Get help with Outlook.com - Outlook.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.