Jump to content

Islandgirl62

Members
  • Posts

    14
  • Joined

  • Last visited

Everything posted by Islandgirl62

  1. i am happy to report there are no more issues Thanks again for your help
  2. Malwarebytes successfully reinstalled, and i ran a quick scan - everything looks good. I have a license for Premium which I will activate later as i don't have it with me now. I turned on Windows Defender Tamper Protection as it seemed like the correct thing to do. Please tell me if this is wrong. Thank you so much for all your help (and patience) Kirsty
  3. the Trojan detection is no longer showing up Windows defender for 2/4/20. Says remediation is incomplete on 2/3/20 and tamper protection is turned off - should i turn it back on? The computer seems good, though still not sure if malwarebyes is installed or working
  4. I hope I did that Windows Defender event file correctly, and is the new FRST file FRST.txt Addition.txt
  5. Log Name: Microsoft-Windows-Windows Defender/Operational Source: Microsoft-Windows-Windows Defender Date: 2/4/2020 4:49:07 PM Event ID: 2011 Task Category: None Level: Information Keywords: User: SYSTEM Computer: PDServer Description: Windows Defender Antivirus used Dynamic security intelligence Service to discard obsolete security intelligence updates. Current security intelligence Version: 1.309.332.0 Security intelligence Type: AntiSpyware Current Engine Version: 1.1.16700.3 Dynamic security intelligence Type: Security intelligence update Persistence Path: C:\ProgramData\Microsoft\Windows Defender\Scans\RtSigs\data\ca3a9b88a1a15ea4f143e985e9d0c5af6c82c11e Dynamic security intelligence Version: 0.0.0.0 Dynamic security intelligence Compilation Timestamp: 2/3/2020 4:25:14 PM Removal Reason: Automatic Persistence Limit Type: Duration Persistence Limit: 864000000 Event Xml: <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> <System> <Provider Name="Microsoft-Windows-Windows Defender" Guid="{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}" /> <EventID>2011</EventID> <Version>0</Version> <Level>4</Level> <Task>0</Task> <Opcode>0</Opcode> <Keywords>0x8000000000000000</Keywords> <TimeCreated SystemTime="2020-02-04T20:49:07.301122300Z" /> <EventRecordID>113</EventRecordID> <Correlation /> <Execution ProcessID="3604" ThreadID="8608" /> <Channel>Microsoft-Windows-Windows Defender/Operational</Channel> <Computer>PDServer</Computer> <Security UserID="S-1-5-18" /> </System> <EventData> <Data Name="Product Name">%%827</Data> <Data Name="Product Version">4.18.2001.7</Data> <Data Name="Current security intelligence Version">1.309.332.0</Data> <Data Name="Unused"> </Data> <Data Name="Unused2"> </Data> <Data Name="Unused3"> </Data> <Data Name="Unused4"> </Data> <Data Name="Domain"> </Data> <Data Name="User"> </Data> <Data Name="SID"> </Data> <Data Name="Security intelligence Type Index">2</Data> <Data Name="Security intelligence Type">%%801</Data> <Data Name="Unused5"> </Data> <Data Name="Unused6"> </Data> <Data Name="Current Engine Version">1.1.16700.3</Data> <Data Name="Unused7"> </Data> <Data Name="Unused8"> </Data> <Data Name="Unused9"> </Data> <Data Name="Unused10"> </Data> <Data Name="Unused11"> </Data> <Data Name="Unused12"> </Data> <Data Name="Dynamic security intelligence Type Index">1</Data> <Data Name="Dynamic security intelligence Type">%%863</Data> <Data Name="Persistence Path">C:\ProgramData\Microsoft\Windows Defender\Scans\RtSigs\data\ca3a9b88a1a15ea4f143e985e9d0c5af6c82c11e</Data> <Data Name="Dynamic security intelligence Version">0.0.0.0</Data> <Data Name="Dynamic security intelligence Compilation Timestamp">2/3/2020 4:25:14 PM</Data> <Data Name="Persistence Limit Type Index">2</Data> <Data Name="Persistence Limit Type">%%870</Data> <Data Name="Persistence Limit Value">864000000</Data> <Data Name="Removal Reason Index">2</Data> <Data Name="Removal Reason Value">%%869</Data> </EventData> </Event>
  6. I turned the computer off after an hour and gave up for the day. I tried again this morning and it tells me Malwarebytes uninstall failed. On the program files menu it shows Malwarebytes 4.04.49 does not have a file size. I ran the Windows Defender offline scan again this morning, I don't know how to print the report, so here is a screen shot I am at work today and won't be able to to anything else till this evening thanks
  7. How long does it take to uninstall? It has been at least 20 minutes and it seems stuck at about 25% complete
  8. I should add Windows installed 3 updates during 1 of the many restarts. Don't know if that makes any difference
  9. I'm sorry for the delay I ran the Windows Defender Offline Scan, but I do not seem to be able to find the threat history report. When I click on "Scan options", my next choice is "protection history" which says it has no recent action in it I have run the Offline Scan twice
  10. Malwarebytes would not open after I downloaded the update, and caused computer to freeze up. I forced a shut down and went straight to adwcleaner and got the notice of 4 Dell preinstalled software issues which it wants to quarantine. Here are the files. Now when computer restarted Windows defender shows trojan:win32/casdet!rfn which I quarantined. Malwarebytes did not do a scan FRST.txt Addition.txt AdwCleaner[C00].txt AdwCleaner[S00].txt
  11. Malwarebytes would not open after I downloaded the update, and caused computer to freeze up. I forced a shut down and went straight to adwcleaner and got the notice of 4 Dell preinstalled software issues which it wants to quarantine.
  12. the adwcleaner is telling me I have 4 preinstalled software it wants to quarantine and disable, all Dell. should i do this?
  13. Malwarebytes keeps telling me that it has quarantined a trojan.agent, but it keeps showing up every time I reboot the computer. I have read other blogs with the same problem, so I have done what you told others to do and downloaded the Farbar Recovery scan tool and attached the 2 files here. Thank you for any help FRST.txt Addition.txt
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.