S Sawcey New Member Thread author Jan 15, 2018 2 0 1 United States Jan 15, 2018 #1 Clicked on a sketchy link ended up with adware fortunately i got rid of it using Malawarebytes. Now i have fake window process manager running no idea what its causing on my pc. Hopefully, you can help me fix this issue. Attachments (S&D)180115-191227.xml.cleaning.log (S&D)180115-191227.xml.cleaning.log 3 KB · Views: 2 (S&D)Checks.180115-1935.txt (S&D)Checks.180115-1935.txt 8.9 KB · Views: 1 Addition.txt Addition.txt 59.5 KB · Views: 0 FRST.txt FRST.txt 38.3 KB · Views: 0 scan1malawarebytes.txt scan1malawarebytes.txt 17.6 KB · Views: 0 scan2malawarebytes.txt scan2malawarebytes.txt 1.3 KB · Views: 0
Clicked on a sketchy link ended up with adware fortunately i got rid of it using Malawarebytes. Now i have fake window process manager running no idea what its causing on my pc. Hopefully, you can help me fix this issue.
S Sawcey New Member Thread author Jan 15, 2018 2 0 1 United States Jan 15, 2018 #2 Forgot to mention the name of the Windows process manager's are conmdza.exe (not sure if this helps)
TwinHeadedEagle Level 41 Verified Mar 8, 2013 22,627 2,906 3,979 Jan 17, 2018 #3 Hello, Please download Farbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Boot to windows recovery by using one of the methods on this link: Boot to Advanced Startup Options in Windows 10 If you're unable to boot to recovery you will need to create a recovery drive. You can do it by following this guide: https://support.microsoft.com/en-us/help/4026852/windows-create-a-recovery-drive Make sure to uncheck Back up system files to the recovery drive box, so that process goes faster. Now you should get a window like this where you need to click Troubleshoot. In the next window, click Advanced options and select Command Prompt. Now you should log in into your account and after that Command Promptwindow. Access the notepad and identify your USB drive In the Command Prompt please type in: Code: notepad and press Enter. When the notepad opens, go to File menu. Select Open. Go to Computer and search there for your USB drive letter. Note down the letter and close the notepad. Scan with Farbar Recovery Scan Tool Once back in the command prompt window, please do the following: Type in e:\frst64.exe and press Enter. You need to replace e with the letter of your USB drive taken from notepad! FRST will start to run. Give him a minute or so to load itself. Click Yes to Disclaimer. In the main console, please click Scan and wait. When finished it will produce a logfile named FRST.txt in the root of your pendrive and display it. Close that logfile. Transfer it to your clean machine and include it in your next reply.
Hello, Please download Farbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Boot to windows recovery by using one of the methods on this link: Boot to Advanced Startup Options in Windows 10 If you're unable to boot to recovery you will need to create a recovery drive. You can do it by following this guide: https://support.microsoft.com/en-us/help/4026852/windows-create-a-recovery-drive Make sure to uncheck Back up system files to the recovery drive box, so that process goes faster. Now you should get a window like this where you need to click Troubleshoot. In the next window, click Advanced options and select Command Prompt. Now you should log in into your account and after that Command Promptwindow. Access the notepad and identify your USB drive In the Command Prompt please type in: Code: notepad and press Enter. When the notepad opens, go to File menu. Select Open. Go to Computer and search there for your USB drive letter. Note down the letter and close the notepad. Scan with Farbar Recovery Scan Tool Once back in the command prompt window, please do the following: Type in e:\frst64.exe and press Enter. You need to replace e with the letter of your USB drive taken from notepad! FRST will start to run. Give him a minute or so to load itself. Click Yes to Disclaimer. In the main console, please click Scan and wait. When finished it will produce a logfile named FRST.txt in the root of your pendrive and display it. Close that logfile. Transfer it to your clean machine and include it in your next reply.