This thread's last reply is from January 2, 2016, 11:33 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Risky Rick
#1 FIXLOG
Fix result of Farbar Recovery Scan Tool (x64) Version:23-12-2015
Ran by [removed] (2015-12-30 14:00:57) Run:4
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
fixlist content:
*****************
C:\Users\Rick\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\stub_data\askrt_en.cab
EmptyTemp:
CreateRestorePoint:
*****************
C:\Users\Rick\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\stub_data\askrt_en.cab => moved successfully
Restore point was successfully created.
EmptyTemp: => 375.3 MB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 14:01:16 ====
#2 FSS Log
Farbar Service Scanner Version: 10-06-2014
Ran by [removed] (administrator) on 30-12-2015 at 14:53:49
Running from "C:\Users\Rick\Desktop"
Microsoft Windows 10 Home (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is unreachable
Google.com is accessible.
Yahoo.com is accessible.
Other Services:
==============
File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
**** End of log ****
#3 MTB LOG
MiniToolBox by Farbar Version: 02-11-2015
Ran by [removed] (administrator) on 30-12-2015 at 14:57:18
Running from "C:\Users\Rick\Desktop"
Microsoft Windows 10 Home (X64)
Model: DX4831 Manufacturer: Gateway
Boot Mode: Normal
***************************************************************************
========================= IP Configuration: ================================
Intel(R) 82578DC Gigabit Network Connection = Local Area Connection (Connected)
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
reset
set global
set interface interface="Local Area Connection" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 1" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
popd
# End of IPv4 configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : Rick-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : HiTech
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . : HiTech
Description . . . . . . . . . . . : Intel(R) 82578DC Gigabit Network Connection
Physical Address. . . . . . . . . : 90-FB-A6-2B-B1-C9
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::c9a3:d666:4f2a:db82%3(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.2.2(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Wednesday, December 30, 2015 2:02:51 PM
Lease Expires . . . . . . . . . . : Saturday, February 05, 2152 9:25:35 PM
Default Gateway . . . . . . . . . : 192.168.2.1
DHCP Server . . . . . . . . . . . : 192.168.2.1
DHCPv6 IAID . . . . . . . . . . . : 194050982
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-12-AE-CA-A5-90-FB-A6-2B-B1-C9
DNS Servers . . . . . . . . . . . : 192.168.2.1
NetBIOS over Tcpip. . . . . . . . : Enabled
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:5ef5:79fb:1422:baf:cd58:ef98(Preferred)
Link-local IPv6 Address . . . . . : fe80::1422:baf:cd58:ef98%2(Preferred)
Default Gateway . . . . . . . . . : ::
DHCPv6 IAID . . . . . . . . . . . : 117440512
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-12-AE-CA-A5-90-FB-A6-2B-B1-C9
NetBIOS over Tcpip. . . . . . . . : Disabled
Tunnel adapter isatap.HiTech:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : HiTech
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
DNS request timed out.
timeout was 2 seconds.
Server: UnKnown
Address: 192.168.2.1
Name: google.com
Addresses: 2607:f8b0:4002:c06::66
64.233.176.102
64.233.176.100
64.233.176.139
64.233.176.113
64.233.176.101
64.233.176.138
Pinging google.com [74.125.138.100] with 32 bytes of data:
Reply from 74.125.138.100: bytes=32 time=33ms TTL=41
Reply from 74.125.138.100: bytes=32 time=32ms TTL=41
Ping statistics for 74.125.138.100:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 32ms, Maximum = 33ms, Average = 32ms
Server: UnKnown
Address: 192.168.2.1
Name: yahoo.com
Addresses: 2001:4998:44:204::a7
2001:4998:58:c02::a9
2001:4998:c:a06::2:4008
206.190.36.45
98.139.183.24
98.138.253.109
Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=51ms TTL=46
Reply from 98.139.183.24: bytes=32 time=43ms TTL=46
Ping statistics for 98.139.183.24:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 43ms, Maximum = 51ms, Average = 47ms
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
3...90 fb a6 2b b1 c9 ......Intel(R) 82578DC Gigabit Network Connection
1...........................Software Loopback Interface 1
2...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
5...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.2.1 192.168.2.2 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.2.0 255.255.255.0 On-link 192.168.2.2 276
192.168.2.2 255.255.255.255 On-link 192.168.2.2 276
192.168.2.255 255.255.255.255 On-link 192.168.2.2 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.2.2 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.2.2 276
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
2 306 ::/0 On-link
1 306 ::1/128 On-link
2 306 2001::/32 On-link
2 306 2001:0:5ef5:79fb:1422:baf:cd58:ef98/128
On-link
3 276 fe80::/64 On-link
2 306 fe80::/64 On-link
2 306 fe80::1422:baf:cd58:ef98/128
On-link
3 276 fe80::c9a3:d666:4f2a:db82/128
On-link
1 306 ff00::/8 On-link
3 276 ff00::/8 On-link
2 306 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
**** End of log ****
COMPUTER .... My Incredimail will not start up now. Claims there is a problem. It went from not being able to send to not being able to start the program. Will reload it when we are done.
Risky Rick
Thanks for all your help nunped. You have a great 2016 as well!
# DelFix v1.011 - Logfile created 01/01/2016 at 11:13:40
# Updated 18/08/2015 by Xplode
# Username : Rick - RICK-PC
# Operating System : Windows 10 Home (64 bits)
~ Activating UAC ... OK
~ Removing disinfection tools ...
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\RegBackup
Deleted : C:\Users\Rick\Downloads\FRST-OlderVersion
Deleted : C:\Users\Rick\Desktop\Addition.txt
Deleted : C:\Users\Rick\Desktop\AdwCleaner.exe
Deleted : C:\Users\Rick\Desktop\AdwCleaner[S1].txt
Deleted : C:\Users\Rick\Desktop\CKScanner.exe
Deleted : C:\Users\Rick\Desktop\Fixlog.txt
Deleted : C:\Users\Rick\Desktop\FRST.txt
Deleted : C:\Users\Rick\Desktop\FSS.exe
Deleted : C:\Users\Rick\Desktop\FSS.txt
Deleted : C:\Users\Rick\Desktop\MiniToolBox.exe
Deleted : C:\Users\Rick\Desktop\Search.txt
Deleted : C:\Users\Rick\Downloads\esetsmartinstaller_enu.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
~ Creating registry backup ... OK
~ Cleaning system restore ...
Deleted : RP #3 [Windows Update | 12/09/2015 18:08:04]
Deleted : RP #4 [Windows Update | 12/18/2015 21:25:31]
Deleted : RP #5 [Installed SketchUp 2016 | 12/21/2015 19:17:09]
Deleted : RP #7 [Restore Point Created by FRST | 12/25/2015 15:53:38]
Deleted : RP #8 [Windows Update | 12/30/2015 13:21:20]
New restore point created !
~ Resetting system settings ... OK
########## - EOF - ##########
Cypher
As your problems do not appear to be malware related,