Windows 10: Remove PUP application from DVD Drive (F:) CDROM

Discus and support Remove PUP application from DVD Drive (F:) CDROM in AntiVirus, Firewalls and System Security to solve the problem; I think Slartybart noticed the Hitman log was incomplete? Discussion in 'AntiVirus, Firewalls and System Security' started by myrnsterMash, Aug 3, 2016.

  1. simrick Win User

    Remove PUP application from DVD Drive (F:) CDROM


    I think Slartybart noticed the Hitman log was incomplete?
     
    simrick, Aug 19, 2016
    #91

  2. "Son of a Poweliks mother jammer!" The recap is beyond appreciated, because trying to do things in order tends to get muddled amongst the posts written and received at different points in time. With that said, I would appreciate it if you would start using the motto:
    "Do NOT be a !"
    Rule#
    • Wait until you recieve a response before doing anything else
    • Do not be a Doofus and Pay Attention to every detail
    • Do NOT make the same mistake, AGAIN!

    So, here is the recap, of which I began with the first item:
    Outstanding tasks:

    HitmanPro - were the threats cleaned?
    ESET online scan: running with auto set
    Clean Boot
    Reg key query
    Bitdefender Rescue
    TDSSKiller
    Dism
    SFC
    Tra la la, decides to go to downloads in C: Drive (no need to download the same programs, again, right), and this is what I see:

    Remove PUP application from DVD Drive (F:) CDROM [​IMG]


    Granted, I did download the some of the same programs twice thinking it best to start "clean," but realized that was stupid, afterwards, sigh. There is not one reason, whatsoever for the .zip files, none! I have it set to ask how I want to open files, and .zip files are not supposed to open, much less run, ever. Seriously? The .zip files shown for ESET were not .zip files until I rebooted, now what?

    Please, note my email in permissions...is that typical?
    "Jeepers, am I being watched? I think my toaster is infected, too it keeps making crumbs, why do telemarketers know my name".....really, ugh........*Homer Drooling

    What the heck.....opened the supposed log from the .zip files:
    [2016.08.18 15:37:57.326] - Begin
    [2016.08.18 15:37:57.328] -
    [2016.08.18 15:37:57.344] - ....................................
    [2016.08.18 15:37:57.346] - ..::::::::::::::::::....................
    [2016.08.18 15:37:57.349] - .::EEEEEE:::SSSSSS::..EEEEEE..TTTTTTTT.. Win32/Poweliks
    [2016.08.18 15:37:57.354] - .::EE::::EE:SS:::::::.EE....EE....TT...... Version: 1.0.0.5
    [2016.08.18 15:37:57.357] - .::EEEEEEEE::SSSSSS::.EEEEEEEE....TT...... Built: Jun 30 2015
    [2016.08.18 15:37:57.359] - .::EE:::::::::::::SS:.EE..........TT......
    [2016.08.18 15:37:57.361] - .::EEEEEE:::SSSSSS::..EEEEEE.....TT..... Copyright (c) ESET, spol. s r.o.
    [2016.08.18 15:37:57.368] - ..::::::::::::::::::.................... 1992-2015. All rights reserved.
    [2016.08.18 15:37:57.369] - ....................................
    [2016.08.18 15:37:57.369] -
    [2016.08.18 15:37:57.370] - --------------------------------------------------------------------------------
    [2016.08.18 15:37:57.370] -
    [2016.08.18 15:37:57.372] - INFO: OS: 6.2.9200 SP0
    [2016.08.18 15:37:57.372] - INFO: Product Type: Workstation
    [2016.08.18 15:37:57.373] - INFO: WoW64: False
    [2016.08.18 15:37:57.373] - INFO: Machine guid: DFA3F11D-1180-47E0-B36D-654F2CAE83E7
    [2016.08.18 15:37:57.374] -
    [2016.08.18 15:38:03.172] - INFO: Scanning for system infection...
    [2016.08.18 15:38:03.174] - --------------------------------------------------------------------------------
    [2016.08.18 15:38:03.174] -
    [2016.08.18 15:38:03.174] - INFO: Processing [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]...
    [2016.08.18 15:38:03.177] - INFO: Processing [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]...
    [2016.08.18 15:38:03.179] - INFO: Processing [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]...
    [2016.08.18 15:38:03.180] - INFO: Processing [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce]...
    [2016.08.18 15:38:03.181] - INFO: Processing [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]...
    [2016.08.18 15:38:03.181] - INFO: Processing [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]...
    [2016.08.18 15:38:03.181] - INFO: Processing classes...
    [2016.08.18 15:38:03.182] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}]
    [2016.08.18 15:38:03.182] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}]
    [2016.08.18 15:38:03.182] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}]
    [2016.08.18 15:38:03.182] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{5999E1EE-711E-48D2-9884-851A709F543D}]
    [2016.08.18 15:38:03.182] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
    [2016.08.18 15:38:03.182] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{6bb93b4e-44d8-40e2-bd97-42dbcf18a40f}]
    [2016.08.18 15:38:03.182] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}]
    [2016.08.18 15:38:03.183] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}]
    [2016.08.18 15:38:03.183] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}]
    [2016.08.18 15:38:03.183] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{7D4733C0-C43B-4A81-AF43-F9B20D1F8348}]
    [2016.08.18 15:38:03.183] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}]
    [2016.08.18 15:38:03.184] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
    [2016.08.18 15:38:03.184] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{A3CA1CF4-5F3E-4AC0-91B9-0D3716E1EAC3}]
    [2016.08.18 15:38:03.184] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
    [2016.08.18 15:38:03.185] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{A9DC7008-F751-405D-9DD2-BAA4CD84A705}]
    [2016.08.18 15:38:03.185] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}]
    [2016.08.18 15:38:03.185] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
    [2016.08.18 15:38:03.185] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}]
    [2016.08.18 15:38:03.185] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}]
    [2016.08.18 15:38:03.185] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
    [2016.08.18 15:38:03.186] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}]
    [2016.08.18 15:38:03.186] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}]
    [2016.08.18 15:38:03.186] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}]
    [2016.08.18 15:38:03.186] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}]
    [2016.08.18 15:38:03.187] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{5999E1EE-711E-48D2-9884-851A709F543D}]
    [2016.08.18 15:38:03.187] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
    [2016.08.18 15:38:03.187] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{6bb93b4e-44d8-40e2-bd97-42dbcf18a40f}]
    [2016.08.18 15:38:03.187] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}]
    [2016.08.18 15:38:03.187] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}]
    [2016.08.18 15:38:03.187] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}]
    [2016.08.18 15:38:03.187] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{7D4733C0-C43B-4A81-AF43-F9B20D1F8348}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{A3CA1CF4-5F3E-4AC0-91B9-0D3716E1EAC3}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{A9DC7008-F751-405D-9DD2-BAA4CD84A705}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
    [2016.08.18 15:38:03.188] - INFO: Processing clsid [\Registry\User\S-1-5-21-2048041476-2006749296-819459500-1005\SOFTWARE\Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}]
    [2016.08.18 15:38:03.189] - INFO: Processing [HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32]...
    [2016.08.18 15:38:03.193] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
    [2016.08.18 15:38:03.193] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
    [2016.08.18 15:38:03.193] - INFO: Processing invalid values in [HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32]...
    [2016.08.18 15:38:03.193] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
    [2016.08.18 15:38:03.194] - INFO: Processing value [ServerExecutable] = [%systemroot%\system32\wbem\wmiprvse.exe]
    [2016.08.18 15:38:03.194] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
    [2016.08.18 15:38:03.194] - INFO: Processing value [ServerExecutable] = [%systemroot%\system32\wbem\wmiprvse.exe]
    [2016.08.18 15:38:03.194] - INFO: Processing invalid subkeys in [HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32]...
    [2016.08.18 15:38:03.194] - INFO: Processing [HKLM\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]...
    [2016.08.18 15:38:03.205] - INFO: Processing subkey [\Registry\Machine\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32]
    [2016.08.18 15:38:03.205] - INFO: Processing subkey [\Registry\Machine\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32]
    [2016.08.18 15:38:03.206] - INFO: (XSW) Scanning for XSW variant...
    [2016.08.18 15:38:03.250] - INFO: (XSW) Processing users subkeys...
    [2016.08.18 15:38:03.258] - INFO: Win32/Poweliks not found
    [2016.08.18 15:38:13.606] - End
     
    myrnsterMash, Aug 19, 2016
    #92
  3. I'll read your re-recap again.


    Here' what I would do next.

    • Turn off hibernation
      Command Prompt (Admin)
      powercfg /h off
    • Clean Startup (boot)
      Clean Boot - Perform in Windows 10 to Troubleshoot Software Conflicts - Windows 10 Forums

    • Rkill
      I'd like to see the log. There was an object that was stopped before, I think it was ReImage and that was cleaned up. Let's see though.

    • Uninstall Avast
      Make sure Windows Defender is running

      This step is only because you've reported that Avast has opened dialogs for operations that I don't quite understand. Is it an older version known to have issues with Win10? Is something not correctly configured? Is there something overly configured? Basically, it's easier to remove Avast from the equation than to play 20 questions.

      As long as you have Defender running, your machine is sufficiently protected for these exercises.
      You can, if you chose, install the current version of Avast after you're done the remaining tasks.

    • Run an offline threat scan with Bitdefender Rescue
      • Download the Bitdefender Rescue CD ISO

      • Insert a blank CD-R disc in your Optical drive

      • Navigate to your Downloads folder
        • Right click bitdefender-rescue-cd.iso
        • Select Burn disc image
        • Verify that the drive is correct
        • Press the Burn button
      • When the burn finishes, the disc should eject
        Label the Disc
        Bitdefender Rescue Disc
        MM/DD/YYYY
      • Perform an offline scan of your machine
        See: How to scan your computer with Bitdefender Rescue CD

    Depending on what Bitdefender finds, this might be the final scan.

    Then there's the cleanup.
    cCleaner (files & reg), Dism, SFC

    might as well do some other house cleaning chores
    chkdsk & defrag
     
    Slartybart, Aug 19, 2016
    #93
  4. Remove PUP application from DVD Drive (F:) CDROM

    Okay, thanks soooo much. Are the .zip files out of the ordinary, and my email address in permissions? I just want to know for future reference.
     
    myrnsterMash, Aug 19, 2016
    #94
  5. Rkill 2.8.4 by Lawrence Abrams (Grinler)
    BleepingComputer.com - News, Reviews, and Technical Support
    Copyright 2008-2016 BleepingComputer.com
    More Information about Rkill can be found at this link:
    RKill - What it does and What it Doesnt - A brief introduction to the program - Anti-Virus, Anti-Malware, and Privacy Software

    Program started at: 08/20/2016 12:03:54 PM in x86 mode.
    Windows Version: Windows 10 Home

    Checking for Windows services to stop:

    * No malware services found to stop.

    Checking for processes to terminate:

    * No malware processes found to kill.

    Checking Registry for malware related settings:

    * No issues found in the Registry.

    Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

    Performing miscellaneous checks:

    * Windows Defender Disabled

    [HKLM\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware" = dword:00000001

    Checking Windows Service Integrity:

    * b06bdrv [Missing Service]
    * ebdrv [Missing Service]
    * iaLPSSi_GPIO [Missing Service]
    * iaLPSSi_I2C [Missing Service]
    * ibbus [Missing Service]
    * ksthunk [Missing Service]
    * mlx4_bus [Missing Service]
    * ndfltr [Missing Service]
    * PerfHost [Missing Service]
    * vpci [Missing Service]
    * WinMad [Missing Service]
    * WinVerbs [Missing Service]

    * NetTcpPortSharing => %systemroot%\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [Incorrect ImagePath]

    * PrintNotify => C:\WINDOWS\system32\spool\drivers\W32X86\3\PrintConfig.dll [Incorrect ServiceDLL]

    Searching for Missing Digital Signatures:

    * No issues found.

    Checking HOSTS File:

    * No issues found.

    Program finished at: 08/20/2016 12:06:13 PM
    Execution time: 0 hours(s), 2 minute(s), and 19 seconds(s)
     
    myrnsterMash, Aug 19, 2016
    #95
  6. Looks as though the zip files are logs from the ESET poweliks removal tool. You can delete them if you like.

    The security permissions are showing your MS Account login ID - just as they show other login ID permissions.

    Good, Rkill doesn't see anything to stop - I'm fairly certain that was ReImage and now that it's gone, Rkill doesn't have to kill it.

    Please do me a favor and explicitly tell me what you ran so I don't have to guess.

    The list
    Turn off hibernation
    Clean Startup (boot)
    Rkill - This one I know you ran, you posted a log *Wink
    Next up
    Uninstall Avast
    Make sure Windows Defender is running
    <!> If Defender doesn't Start - post that information .... that's a signal that soemthing is a miss.Run an offline threat scan with Bitdefender Rescue

    I have to look where a log might be written (C:\RescueCD Logs I think), but a camera shot of threats found would work too.
    Then remove or quarantine the threats, if any.
     
    Slartybart, Aug 19, 2016
    #96
  7. Defender wants to run a scan, but is not included in your directions, so I skipped it and restarting to finish the Avast uninstall. Fingers crossed...I ran everything in order, hibernate, and clean reboot per the instructions your link directed me. Defender is on, like I mentioned....
     
    myrnsterMash, Aug 20, 2016
    #97
  8. Remove PUP application from DVD Drive (F:) CDROM

    I wouldn't worry about the toaster, not much you can do other than sweep the crumbs into the garbage pail.

    Progress sounds good.

    It would have been OK to run a scan with Defender - but you're following directions and that wasn't on the list *Wink

    So now you're running Bitdefender Rescue scan?
    See the bottom of post# 91 if you need a refresher
     
    Slartybart, Aug 20, 2016
    #98
  9. Ahhhh, yes, if things could only happen as they should....

    Remove PUP application from DVD Drive (F:) CDROM [​IMG]


    Should I try a flash drive? I do not know if USB was referring to an external drive, but if a CD/DVD is okay, why not a flash drive? Then, again what do I know, obviously. I tried to burn 2x on 2 different DVD + RW, and received the same message both times...I know I am a royal pain 3, 4 days, uhhh weeks ago, and I apologize, sincerely. I do not want to continue bothering any of you, so I completely understand if you want to wash your hands of this mess I created, at this point. It is what it is, and is not going to be my detriment. If this is the worst thing that happens to me, I am lucky and should take that short drive to Vegas! (but not to get married, nuh uh, no luck there *Tongue ).
     
    myrnsterMash, Aug 20, 2016
    #99
  10. Command Prompt (Admin)
    Copy the line below and paste it into the Command window (right click = paste)
    Put a tick mark in every box, then press OK

    Do NOT close the Command Prompt window until the cleanup finishes

    %SystemRoot%\System32\Cmd.exe /c Cleanmgr /sageset:65535 & Cleanmgr /sagerun:65535
    Download and run cCleaner FREE
    CCleaner - Standard

    Watch during the installation for extras, such as Google Chrome or any toolbars.
    Remove the ticks from those extra packages

    Cleaner option

    I clean just about everything, you might not want to clean some things such as passwords or cookies- that's up to you


    Remove PUP application from DVD Drive (F:) CDROM [​IMG]

    Analyse
    Run Cleaner

    Registry option

    Scan for issues
    Answer yes to backup
    Clean everything

    Scan registry again for any dependency entries from the 1st scan/clean
    Answer yes to backup
    Clean everything
    See if Burn disc works.
     
    Slartybart, Aug 20, 2016
  11. C'est la vie!

    I hate it when I make coasters - that hole n the middle doesn't protect my fine Ikea furniture very well.

    I prefer to use a CD - nasties can't write to them (but neither can you at the moment *Sad, but sure, you can put Bitdefender Rescue on a Flash drive. A CD-R is large enough - but try the flash dirve method

    See: How to create a Bitdefender Rescue CD
    Creating a Bitdefender Rescue CD on a USB flash drive

    When you cannot write a CD/DVD, you can use a USB flash drive. Bitdefender recommends Stickifier, a free open-source tool that creates a bootable Rescue CD on a USB flash.
    I've never used Stickifer
    The only things I see worth mentioning are
    Select an existing ISO image - the Bitdefender ISO you already have
    The USB must be FAT32 formatted
    <!> and all data will be erased.

    Let me know if you get stuck using Stickifier
    Please don't apologize. Everyone here volunteers because they enjoy helping people with technological issues.

    If I give up, and I rarely do, I'll raise a white flag and suggest a clean install. I didn't think the issue warranted a clean install when I started helping, and the issues still aren't bad. There will always be some residual cleanup after malware remediation. Bitdeferende was probably the last scan , but HW got in the way
    - Lions, Tigers, and Bears ... Oh My !!!
     
    Slartybart, Aug 20, 2016
  12. OMG! I am afraid, very, very afraid ticking every box, but I trust you....my old Windows 7 stuff, ("if you are sure no users personal files are missing after the upgrade" Yikes), Windows upgrade log files, etc.
     
    myrnsterMash, Apr 5, 2018
Thema:

Remove PUP application from DVD Drive (F:) CDROM

Loading...
  1. Remove PUP application from DVD Drive (F:) CDROM - Similar Threads - Remove PUP application

  2. cdrom dvd player not working since win10 and 11

    in Windows 10 Gaming
    cdrom dvd player not working since win10 and 11: My DVD player has stopped working although it says it's working properly.Device settings for SCSI\CdRom&Ven_hp&Prod_DVDRW_GUE1N\4&1c0866d&1&010000 were not migrated from previous OS installation due to partial or ambiguous device match. Last Device Instance Id:...
  3. cdrom dvd player not working since win10 and 11

    in Windows 10 Software and Apps
    cdrom dvd player not working since win10 and 11: My DVD player has stopped working although it says it's working properly.Device settings for SCSI\CdRom&Ven_hp&Prod_DVDRW_GUE1N\4&1c0866d&1&010000 were not migrated from previous OS installation due to partial or ambiguous device match. Last Device Instance Id:...
  4. Dvd drive;F

    in Windows 10 Drivers and Hardware
    Dvd drive;F: Hi i installed a app of adobe audition and today i uninstalled from the control panel and it uninstalled but when i was browsing my files i sa that there was a file named Dvd drive;f and it contained my audition app files so i tried to delete them but there was no option and...
  5. DVD/CDROM drive not working Toshiba Laptop Windows 10

    in Windows 10 Drivers and Hardware
    DVD/CDROM drive not working Toshiba Laptop Windows 10: since updating Toshiba Satellite L850 laptop to Win10 the DVD/CD will not work [ATTACH] https://answers.microsoft.com/en-us/windows/forum/all/dvdcdrom-drive-not-working-toshiba-laptop-windows/10946ee8-c151-4877-811c-84211bb4ce3b
  6. cdrom

    in Windows 10 Drivers and Hardware
    cdrom: Windows 10 will read a cd but will not recognize a dvd. Anyone have any ideas? I have checked the device manager which shows my cdrom as working normally and I have run SFC and DISM. no problem shown. Why will it read a cd but will not even recognize a dvd?...
  7. How to remove built-in DVD drive from 'Devices and Drives'?

    in Windows 10 Drivers and Hardware
    How to remove built-in DVD drive from 'Devices and Drives'?: My Dell 4650 has a built-in CD/DVD drive that works just fine, but the computer is on a shelf under a desk and facing the wrong way, so using the drive is awkward. So I bought a Toshiba 'external' drive that connects with a USB cable, and it works just as well and can be...
  8. How to remove built-in DVD drive from 'Devices and Drives'?

    in Windows 10 Support
    How to remove built-in DVD drive from 'Devices and Drives'?: My Dell 4650 has a built-in CD/DVD drive that works just fine, but the computer is on a shelf under a desk and facing the wrong way, so using the drive is awkward. So I bought a Toshiba 'external' drive that connects with a USB cable, and it works just as well and can be...
  9. Adwcleaner does can not remove PUP's

    in AntiVirus, Firewalls and System Security
    Adwcleaner does can not remove PUP's: Finding IE 11 somewhat sluggish, I ran the Adwcleaner. It found 6 pup's, but when I clicked on clean, it stalled and I had to use the task manager to stop the process. see attached [img] [img] AdwCleaner[S16].txtfiles. 94814
  10. Part 2: Remove PUP application from DVD Drive (F:) CDROM

    in AntiVirus, Firewalls and System Security
    Part 2: Remove PUP application from DVD Drive (F:) CDROM: Unfortunately, I am back again after a couple months (I think), since tormenting Slartybart and Simrick with my Trojan removal nightmare. Perhaps, I should post on that thread, (for something to reference), but it is a lot to gloss over. Here is the link associated with the...