Someone's FISHING on my computer

Page 3 of 4 FirstFirst 1234 LastLast

  1. Posts : 78
    Windows 10 Pro
    Thread Starter
       #21

    All of what you said "MUST GO" were cleaned up after running AdwCleaner as I hit clean after the scan.

    I am currently at: the DNS Flush section. When I flush the DSN will the system still function or do I need the change the DNS at that point.

    I'm currently heading out to give my dogs their walks so I'll me away for some time.

    Thanks for your help thus far...

    Brian

      My Computer


  2. Posts : 16,325
    W10Prox64
       #22

    Flushing DNS will just get rid of the DNS memory. System will still function fine.
      My Computer


  3. Posts : 78
    Windows 10 Pro
    Thread Starter
       #23

    simrick said:
    Flushing DNS will just get rid of the DNS memory. System will still function fine.
    OK, cool.
    One dog walked, One to go.

    Responses to some of your comments:
    I will guess that most of this junk is a result of IOBit software. I would not trust anything from them. They were caught stealing proprietary virus-detection databases from Malwarebytes.
    Never installed any IOBit software while doing this install.......that I am aware of!

    Auslogics is now considered a PUP, as they try to install all kinds of other stuff when you install their program, plus they open your web browser and take you to a Giveaway page - very annoying. Until they clean up their act, I would not use them. Defraggler (free) by Piriform is a good replacement.
    Never installed any Auslogics software while doing this install.......that I am aware of!
    Her OS Drive is now an SSD and I do not defrag this drive. I have used Piriform Defragler in the past...maybe I used it to defrag the HDD(data drive)

    Do not ever, under any circumstances, install SpyHunter on a system!
    Been there, done that! What a mess.
    Will have to tell my brother about this as I think one of his computers has it. Think he bought it too.


    Scheduled Task - WiseCleaner
    Never installed it, though I think I did install Wise JetSearch

    Lavasoft needs to go
    I Know of them but have not used any of their software in years.

    As I said earlier, AdwCleaner should have taken care of these issues...

    Dog 2 out Now! 3:20P




      My Computer


  4. Posts : 16,325
    W10Prox64
       #24

    WinTenUser said:
    OK, cool.
    One dog walked, One to go.

    Responses to some of your comments:
    I will guess that most of this junk is a result of IOBit software. I would not trust anything from them. They were caught stealing proprietary virus-detection databases from Malwarebytes.
    Never installed any IOBit software while doing this install.......that I am aware of!

    Auslogics is now considered a PUP, as they try to install all kinds of other stuff when you install their program, plus they open your web browser and take you to a Giveaway page - very annoying. Until they clean up their act, I would not use them. Defraggler (free) by Piriform is a good replacement.
    Never installed any Auslogics software while doing this install.......that I am aware of!
    Her OS Drive is now an SSD and I do not defrag this drive. I have used Piriform Defragler in the past...maybe I used it to defrag the HDD(data drive)

    Do not ever, under any circumstances, install SpyHunter on a system!
    Been there, done that! What a mess.
    Will have to tell my brother about this as I think one of his computers has it. Think he bought it too.


    Scheduled Task - WiseCleaner
    Never installed it, though I think I did install Wise JetSearch

    Lavasoft needs to go
    I Know of them but have not used any of their software in years.

    As I said earlier, AdwCleaner should have taken care of these issues...

    Dog 2 out Now! 3:20P
    Maybe these are some leftovers from previous installs or other bundled software. No matter, as you say, ADWCleaner has taken care of them.
      My Computer


  5. Posts : 16,325
    W10Prox64
       #25

    WinTenUser said:
    Attachment 131404

    Took this capture before your suggestion. Didn't realize I could save a list via the prog!!

    Brian

    Getting ready to connect with my mother's computer.

    CCleaner - Installed Programs

    Weather Microsoft Corporation 4/22/2017 4.20.1102.0 All users
    Mozilla Maintenance Service Mozilla 4/20/2017 256 KB 53.0.0.6312 All users
    Mozilla Firefox 53.0 (x86 en-US) Mozilla 4/20/2017 88.8 MB 53.0 All users
    Malwarebytes version 3.0.6.1469 Malwarebytes 4/20/2017 154 MB 3.0.6.1469 All users
    Microsoft Solitaire Collection Microsoft Studios 4/13/2017 3.16.3302.0 All users
    Groove Music Microsoft Corporation 4/13/2017 10.17022.10301.0 All users
    Facebook Facebook Inc 4/13/2017 81.832.151.0 All users
    Microsoft Sticky Notes Microsoft Corporation 4/13/2017 1.8.0.0 All users
    Store Microsoft Corporation 4/13/2017 11701.1001.99.0 All users
    Adobe Flash Player 25 NPAPI Adobe Systems Incorporated 4/12/2017 5.94 MB 25.0.0.148 All users
    Stardock IconPackager Stardock Software, Inc. 4/11/2017 18.6 MB 10.02 All users
    Canon MG3000 series User Registration *Canon Inc. 4/11/2017 All users
    Canon MG3000 series On-screen Manual Canon Inc. 4/11/2017 8.81 MB 1.0.0 All users
    Canon MG3000 series MP Drivers Canon Inc. 4/11/2017 1.00 All users
    Canon Inkjet Printer/Scanner/Fax Extended Survey Program Canon Inc. 4/11/2017 5.2.0 All users
    Canon IJ Scan Utility Canon Inc. 4/11/2017 75.6 MB 1.3.0.19 All users
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 4/9/2017 940 KB 10.0.40219 All users
    TeamViewer 12 TeamViewer 3/25/2017 61.8 MB 12.0.75813 All users
    IncrediMail 2.5 IncrediMail Ltd. 3/25/2017 6.6.0.5302 All users
    Second Copy 9 Centered Systems 3/24/2017 43.9 MB 9.0.0.1 All users
    Pandora Pandora Media Inc 3/23/2017 11.3.1.0 All users
    gpedt.msc 1.0 Richard 3/22/2017 5.24 MB All users
    Backgammon Classic 7.2 Microsys Com Ltd. 3/22/2017 28.9 MB All users
    True Launch Bar Tordex 3/21/2017 17.1 MB 7.3.0.0 All users
    SUPERAntiSpyware SUPERAntiSpyware.com 3/21/2017 10.4 MB 6.0.1236 All users
    Second Nature - Light on the Water Second Nature Software, Inc. 3/21/2017 4.4 All users
    Microsoft SQL Server Compact 3.5 SP2 x64 ENU Microsoft Corporation 3/21/2017 15.2 MB 3.5.8080.0 All users
    Microsoft SQL Server Compact 3.5 SP2 ENU Microsoft Corporation 3/21/2017 12.2 MB 3.5.8080.0 All users
    Heartwild Solitaire Classic 3/21/2017 All users
    Heartwild Solitaire (Author's Edition) 3/21/2017 All users
    Hallmark Card Studio 2017 Deluxe Creative Home 3/21/2017 145 MB 18.0.0.14 All users
    Corel Paint Shop Pro Photo XI Corel Corporation 3/21/2017 197 MB 11.20.0000 All users
    Bonus Pack 2017 Creative Home 3/21/2017 30.1 MB 1.0.0.7 Sheila
    ACDSee 20 ACD Systems International Inc. 3/21/2017 618 MB 20.3.0.611 All users
    Stardock Start10 Stardock Software, Inc. 3/20/2017 41.3 MB 1.53 All users
    Shadow Defender ShadowDefender.com 3/20/2017 1.4.0.650 All users
    Alarms & Clock Microsoft Corporation 3/19/2017 10.1703.602.0 All users
    Calculator Microsoft Corporation 3/19/2017 10.1703.601.0 All users
    Voice Recorder Microsoft Corporation 3/19/2017 10.1703.601.0 All users
    App Installer Microsoft Corporation 3/19/2017 1.0.10332.0 All users
    Store Purchase App Microsoft Corporation 3/19/2017 11608.1000.2431.0 All users
    Xbox Identity Provider Microsoft Corporation 3/19/2017 11.19.19003.0 All users
    NVIDIA Graphics Driver 342.01 NVIDIA Corporation 3/19/2017 476 MB 342.01 All users


    CCleaner - Startup Items

    Yes HKCU:Run IncrediMail IncrediMail, Ltd. Sheila C:\Program Files (x86)\IncrediMail\bin\IncMail.exe /c
    Yes HKCU:Run SUPERAntiSpyware SUPERAntiSpyware Sheila C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Yes HKLM:Run Malwarebytes TrayApp Malwarebytes All users C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
    Yes HKLM:Run MouseDriver Pixart Imaging Inc All users TiltWheelMouse.exe
    Yes HKLM:Run WindowsDefender All users "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
    Yes Startup Common Snsicon.lnk Second Nature Software, Inc. All users C:\Program Files (x86)\Second Nature\Snsicon.exe
    Yes Startup User USBNavFix.lnk Microsoft Corporation Sheila C:\Windows\regedit.exe

    Note:
    1. Malwarebytes was installed as a trial just for troubleshooting
    2. Second Nature Software - been using this screen saver for years
    3. USBNAVFix - created a batch file to update the registry to remove the 2x removable drive icons from File Managers Navigation Pane
    Seems every time Windows updates that the default is restored.


    I just noticed you edited this post. Sorry. I don't get notifications for edits, only new posts.

    Not seeing Java in here, so that's good. Everything looks fine. MBAM (Malwarebytes) will revert to the free version after the trial expires. You can leave it on there, just have to manually run scans with it and there will be no active protection.

    So Defender is the AV on here. Please make sure it's updating virus defs.

    Yeah MS like to reset everything all the time - drives me nuts.
      My Computer


  6. Posts : 78
    Windows 10 Pro
    Thread Starter
       #26

    simrick said:
    Okay. No one really uses HJT anymore, so I'm not even going to try and parse that log.

    Change the DNS servers on her NICs to Open DNS
    See post #23 here:
    Protect Your Privacy - Page 3 - Solved - Windows 10 Forums

    For a final all-clear, run ESET Online Scanner.
    Free Virus Scan | Online Virus Scan from ESET ESET

    Create another restore point - call it "clean"

    Back into Ccleaner>Tools>System Restore
    Delete all restore points except the last two you just made.

    If all is well, after a couple days, remove the first restore point you created before the cleaning process.


    Will not be able to use OpenDNS straight off, I would have to attach their old Router to the new Modem/Router.

    They have the same router I do...

    Technicolor TC8305C

    The combination modem/router is one of the devices supplied by Comcast's Internet service. Due to the custom firmware, the device does not permit any changes to the DNS server settings. This is based from the support article for this particular model:

    http://docs.technicolor.com/data/fil...30228-0000.pdf

    So all I have left:
    01. flush the DNS
    02. run the ESET Online Scanner
    03. create "clean" Restore Point
    04. See what happens...

    Brian
      My Computer


  7. Posts : 16,325
    W10Prox64
       #27

    For some reason I can't get to that link.
    I've pulled up the user guide at
    https://secure.xfinity.com/anon.comc...User_Guide.pdf
    and I don't see anything regarding DNS servers - can you tell me what page?

    I don't understand how Comcast could tell you what DNS servers to put on your computer's network interface adapters...
      My Computer


  8. Posts : 16,325
    W10Prox64
       #28

    People do certainly put OpenDNS server addresses in their routers, but that's not what I was suggesting(?)
      My Computer


  9. Posts : 78
    Windows 10 Pro
    Thread Starter
       #29

    simrick said:
    For some reason I can't get to that link.
    I've pulled up the user guide at
    https://secure.xfinity.com/anon.comc...User_Guide.pdf
    and I don't see anything regarding DNS servers - can you tell me what page?

    I don't understand how Comcast could tell you what DNS servers to put on your computer's network interface adapters...

    The link did not work for me either, it was from the OpenDNS site. Must have changed.

    https://support.opendns.com/hc/en-us/articles/228008127

    simrick said:
    People do certainly put OpenDNS server addresses in their routers, but that's not what I was suggesting(?)
    Perhaps I am not following the instructions:

    Change the DNS servers on her NICs to Open DNS
    See post #23 here:
    Protect Your Privacy - Page 3 - Solved - Windows 10 Forums

      My Computer


  10. Posts : 5,452
    Windows 11 Home
       #30

    WinTenUser said:
    Perhaps I am not following the instructions:
    Run CMD as admin and copy/paste (Windows overrides router's settings):
    Code:
    wmic nicconfig where DHCPEnabled=TRUE call SetDNSServerSearchOrder ("208.67.222.222","208.67.220.220")
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 11:02.
Find Us




Windows 10 Forums