Windows 10: Unsure if we have a virus or not, shutdown failures etc

Discus and support Unsure if we have a virus or not, shutdown failures etc in AntiVirus, Firewalls and System Security to solve the problem; So yesterday something popped up on my fiance's computer which said that universal driver updater was unable to run. Then Avira popped up and said it... Discussion in 'AntiVirus, Firewalls and System Security' started by yuk75, Sep 28, 2016.

  1. yuk75 Win User

    Unsure if we have a virus or not, shutdown failures etc


    So yesterday something popped up on my fiance's computer which said that universal driver updater was unable to run. Then Avira popped up and said it had moved it to quarantine. He ran a whole scan, the program was not in the program list, nothing else seemed out of place.

    Until we tried to shut down. It looked like it was shutting down and then went to the welcome screen where you log in. It did this 4 times, we tried shutting down from the welcome screen, after logging in...and then finally we had to disconnect the power.

    He said to me he clicked a Facebook quiz link for fun and a new tab opened and then closed so I think he might have been hit by a driveby.....but I don't know what it was or how to find out and fix it. Any help is appreciated.

    Is this the workings of a virus? How do we troubleshoot it and also how do we uninstall that driver thing (we deleted its folder in program files but it pops up saying it's trying to install)? His specs are the same as my profile except he uses windows 10 and has a different screen *Smile.

    :)
     
    yuk75, Sep 28, 2016
    #1
  2. Lagcat Win User

    Windows 10 Not Shutting Down ! ?

    we removed our anti-virus (trend micro) this fixed our shutdown issue
     
    Lagcat, Sep 28, 2016
    #2
  3. grschinon Win User
    If we have any self respect, we should boycott Nokia in India. At least till the company closes down.

    Exactly. As far as I can see, chowdhury hasn't actually taken the issue up with Nokia themselves yet.

    One defective device does not a scam make.
     
    grschinon, Sep 28, 2016
    #3
  4. simrick Win User

    Unsure if we have a virus or not, shutdown failures etc

    Hi.
    Give this a try. Post the logs if you'd like me to evaluate.

    Run these scans, in this order; if you post logs, use CODE tags (# button).

    Create a restore point
    RKILL
    TDSSKiller (select all options - it will reboot to scan properly)
    RKILL (again, because everything RKILL does is undone by a reboot)
    ADWCleaner (it will reboot to clean)
    RKILL (again)
    Malwarebytes Antimalware (run a custom scan, select the box to scan for rootkits, and check the box to scan your entire system drive)
    JRT
    TempFile Cleaner
    Ccleaner - run on browsers and clean out temp + cache, then run on registry
     
    simrick, Sep 28, 2016
    #4
  5. yuk75 Win User
    We're up to TDSSKiller. Universal Driver Updater is back (including error popups because it's unable to excecute its file, createprocess failed with error code 2 because we deleted the file). I am attaching the Avira notice cause it may help, also attaching the scan...what should we do? The last two are legit things installed but not sure on the first one.


    Unsure if we have a virus or not, shutdown failures etc [​IMG]



    Unsure if we have a virus or not, shutdown failures etc [​IMG]
     
    yuk75, Sep 28, 2016
    #5
  6. Mikeymoo Win User
    On fiance's computer, just easier this way....

    Code: # AdwCleaner v6.020 - Logfile created 29/09/2016 at 11:16:13# Updated on 14/09/2016 by ToolsLib # Database : 2016-09-28.1 [Server] # Operating System : Windows 10 Pro (X64) # Username : Michael - DESKTOP-BH8K9VQ # Running from : D:\Library on D\Downloads on D\adwcleaner_6.020 (1).exe # Mode: Clean # Support : ToolsLib ***** [ Services ] ***** [-] Service deleted: AppVerifier ***** [ Folders ] ***** [-] Folder deleted: C:\Users\Mikey\AppData\Roaming\Advancedpccare.com [-] Folder deleted: C:\Users\Mikey\AppData\Roaming\EasyFileOpener [-] Folder deleted: C:\Program Files\Advanced PC Care [-] Folder deleted: C:\ProgramData\Advancedpccare.com [-] Folder deleted: C:\ProgramData\AppVerifier [#] Folder deleted on reboot: C:\ProgramData\Appverifier [#] Folder deleted on reboot: C:\ProgramData\Application Data\Advancedpccare.com [#] Folder deleted on reboot: C:\ProgramData\Application Data\AppVerifier [#] Folder deleted on reboot: C:\ProgramData\Application Data\Appverifier [-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced PC Care ***** [ Files ] ***** [-] File deleted: C:\appverifier.txt ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled Tasks ] ***** ***** [ Registry ] ***** [-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\AppVerifier [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\AppVerifier [-] Key deleted: HKU\S-1-5-21-1397434896-1249509146-2682902517-1001\Software\Advancedpccare.com [-] Key deleted: HKU\S-1-5-21-1397434896-1249509146-2682902517-1001\Software\ICSW1.17 [-] Key deleted: HKU\S-1-5-21-1397434896-1249509146-2682902517-1001\Software\ICSW1.19 [-] Key deleted: HKU\S-1-5-21-1397434896-1249509146-2682902517-1001\Software\csastats [#] Key deleted on reboot: HKCU\Software\Advancedpccare.com [#] Key deleted on reboot: HKCU\Software\ICSW1.17 [#] Key deleted on reboot: HKCU\Software\ICSW1.19 [#] Key deleted on reboot: HKCU\Software\csastats [#] Key deleted on reboot: [x64] HKCU\Software\Advancedpccare.com [#] Key deleted on reboot: [x64] HKCU\Software\ICSW1.17 [#] Key deleted on reboot: [x64] HKCU\Software\ICSW1.19 [#] Key deleted on reboot: [x64] HKCU\Software\csastats [-] Key deleted: [x64] HKLM\SOFTWARE\Advancedpccare.com [-] Key deleted: [x64] HKLM\SOFTWARE\AppVerifierService [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com ***** [ Web browsers ] ***** [-] [C:\Users\Mikey\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Deleted: hxxp://www.oursurfing.com/?type=hp&ts=1435465737&z=facc5ed2533890d3d835c61gbz0c2w4z6qbw6m5c7m&from=dig2&uid=ST9500325AS_6VEJ7EY5XXXX6VEJ7EY5 ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [3222 Bytes] - [29/09/2016 11:16:13] C:\AdwCleaner\AdwCleaner[S0].txt - [3165 Bytes] - [29/09/2016 11:14:55] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3368 Bytes] ##########[/quote] I think it's clear it picked something up, just wanted to keep you posted. I guess that appverifier has been taken care of.
     
    Mikeymoo, Sep 28, 2016
    #6
  7. yuk75 Win User
    Okay all of those are done now and it's shutting down right and we haven't had a universal driver popup again yet! *Biggrin

    I think you fixed it!! *Biggrin
     
    yuk75, Sep 28, 2016
    #7
  8. eLPuSHeR Win User

    Unsure if we have a virus or not, shutdown failures etc

    It seems you had quite a load of PUPs there.
     
    eLPuSHeR, Sep 28, 2016
    #8
  9. yuk75 Win User
    Yeah the only thing recently installed was the Hi-REZ thing, which was required to play their game Paladins, which was installed from Steam. We're not sure if it was a drive by (because of the tab popping up then vanishing) or if it was somehow attached to something or what.
     
    yuk75, Sep 28, 2016
    #9
  10. simrick Win User
    Glad things are getting under control. If you have any PC Care utilities, like SlimWare, or any other health programs or driver updaters, please uninstall them.
    Then run Ccleaner on the registry to get rid of leftovers.

    Then continue with the rest of my first post (if you haven't completed already):

    RKILL (again, because everything RKILL does is undone by a reboot)
    ADWCleaner (it will reboot to clean)
    RKILL (again)
    Malwarebytes Antimalware (run a custom scan, select the box to scan for rootkits, and check the box to scan your entire system drive)
    JRT
    TempFile Cleaner
    Ccleaner - run on browsers and clean out temp + cache, then run on registry

    You may find you need to RESET Internet Explorer (even if you don't use it), and all other browsers on the system.
     
    simrick, Sep 28, 2016
    #10
  11. yuk75 Win User
    What do you mean Reset? We did complete the list *Biggrin.
     
    yuk75, Sep 29, 2016
    #11
  12. simrick Win User
    simrick, Sep 29, 2016
    #12
  13. simrick Win User

    Unsure if we have a virus or not, shutdown failures etc

    p.s. Create a new restore point, and call it CLEAN. Then, open Ccleaner, go to Tools>System Restore, and delete all other restore points, to be sure you don't reintroduce the infection in the future.
     
    simrick, Sep 29, 2016
    #13
  14. yuk75 Win User
    Thank you so much!! We really appreciate the help *Biggrin.
     
    yuk75, Sep 29, 2016
    #14
  15. simrick Win User
    You're quite welcome. If all is well, please mark the thread as solved.
     
    simrick, Sep 29, 2016
    #15
Thema:

Unsure if we have a virus or not, shutdown failures etc

Loading...
  1. Unsure if we have a virus or not, shutdown failures etc - Similar Threads - Unsure virus shutdown

  2. My wifes pc keeps crashing and we are unsure why

    in Windows 10 Gaming
    My wifes pc keeps crashing and we are unsure why: We have changed the power supply, and updated the RAM. Each of these "fixes" stabilized the pc for about a week, then the crashing starts happening again. Here is the log from the latest crashes. I do not know much about pcs so any steps/help would be greatly appreciated....
  3. My wifes pc keeps crashing and we are unsure why

    in Windows 10 Software and Apps
    My wifes pc keeps crashing and we are unsure why: We have changed the power supply, and updated the RAM. Each of these "fixes" stabilized the pc for about a week, then the crashing starts happening again. Here is the log from the latest crashes. I do not know much about pcs so any steps/help would be greatly appreciated....
  4. Installation guide a virus, malware,etc

    in Windows 10 Software and Apps
    Installation guide a virus, malware,etc: I installed drivers for a USB hub on my windows 10 laptop. The installtion prompt guide for drivers was in Chinese text. Should i be concerned for virus,malware,etc?...
  5. Installation guide a virus, malware,etc

    in Windows 10 Drivers and Hardware
    Installation guide a virus, malware,etc: I installed drivers for a USB hub on my windows 10 laptop. The installtion prompt guide for drivers was in Chinese text. Should i be concerned for virus,malware,etc?...
  6. virus protection failure

    in AntiVirus, Firewalls and System Security
    virus protection failure: Have virus protect from bt through mcafee - cannot open or remove and reinstall...any ideas? https://answers.microsoft.com/en-us/protect/forum/all/virus-protection-failure/11b8c675-526b-4579-ba46-ec6a80517350
  7. Virus or hardware failure

    in Windows 10 Installation and Upgrade
    Virus or hardware failure: Running windows 10 old Dell optilex Turned on my Tpm so the other windows defender options would be available. GPU usage went to 90% browser crashed ..Error log shows a hardware failure but not what failed. Turned off TPM..Everything is normal. This is a second hand...
  8. Unsure if my PC is at risk of a virus/malware

    in AntiVirus, Firewalls and System Security
    Unsure if my PC is at risk of a virus/malware: My anti-virus and malware programme (Bitdefender) keeps flagging "C:\Windows\System32\wscript.exe" as a "Potentially malicious application". Also whenever I try to open windows security it says the page is not available and I have limited access to certain areas despite me...
  9. Virus, Bot, Malware, Etc?

    in AntiVirus, Firewalls and System Security
    Virus, Bot, Malware, Etc?: Good morning! I work in an office with 4 people. We are all connected to the Internet via Ethernet cables but also have WiFi. We have one particular computer/login that has been giving us issues and pulling down our connectivity speed. Basically, going from 24-26mbps to...
  10. How Many Firewalls etc. Do We have in Win10?

    in Windows 10 Network and Sharing
    How Many Firewalls etc. Do We have in Win10?: I have my win10 firewall enabled. I get hassles, can't see my IP cameras, want to check it's not the firewall, I disable it. Is that it? Or may there be other firewalls or similar that I need to look at? For instance I run Avira. Today I can find nothing about...