hii, nasdaq !!Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.
If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===
Please enable your Avas Antivirus if not already done.
AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Avast Antivirus (Disabled - Up to date) {5078598A-1FA2-C888-AA5F-A9C66537DB12}
<<<>>>
Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.
Run FRST and click Fix only once and wait.
The Computer will restart when the fix is completed.
It will create a log (Fixlog.txt) please post it to your reply.
===
Please post the Fixlog.txt and let me know what problem persists.
p.s.
If the problem persists please run a scan with the Farbar program and post fresh logs for my review.
i have cleaned my computer today and followed all the steps above it's now more fast than before but he still making alot of noise is it normal !!Hi,
No malware was found in your logs.
Let Reset these services and do some maintenance.
Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.
Run FRST and click Fix only once and wait.
The Computer will restart when the fix is completed.
It will create a log (Fixlog.txt) please post it to your reply.
===
Please post the Fixlog.txt and let me know what problem persists.
p.s.
Do this scan if the problem persists after the startup.
Sophos Virus Removal Tool
Please download Sophos Virus Removal Tool and save it to your computer's Desktop.
Note: Whenever necessary, the log will be in the following location:
- Right-click the icon and select Run as administrator.[/*]
- Click Yes to accept any security warnings that may appear.[/*]
- Click the Next button.[/*]
- Select 'I accept the terms in the license agreement', then click Next twice.[/*]
- Click the Install button and wait until the installation is complete.[/*]
- Click the Finish button. The tool created a shortcut icon on the Desktop of your computer.[/*]
- Now, double-click the Sophos Virus Removal Tool shortcut icon to run the tool.[/*]
- Click Yes to accept any security warnings that may appear.[/*]
- After it updatesand a "Start Scanning" button appears in the lower right:
[/*]
- Disconnect from the Internet or physically unplug your Internet cable connection.[/*]
- Close all open programs, scheduling/updating tasks and background processes that might activate during the scan including the screensaver.[/*]
- Temporarily disable your anti-virus and real-time anti-spyware protection.[/*]
- Click the "Start Scanning" button in the lower right to start the scan.[/*]
- After starting the scan, do not use the computer until the scan has completed.[/*]
- When finished, if it detected anything there will be a "Start Clean-up" button, click it and allow it to finish.[/*]
- When finished, re-enable your anti-virus/anti-malware (or reboot) and then you can reconnect to the Internet.[/*]
- If any threats are found click Details, then View Log file (bottom left-hand corner).[/*]
- Copy and paste its contents in your next reply and note any errors encountered.[/*]
- Close the Notepad document, close the Threat Details screen, then click Start cleanup.[/*]
- Click Exit to close the program.[/*]
- If no threats were found, please confirm that result.[/*]
Windows Vista and above:
C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs\SophosVirusRemovalTool.log
Please post the contents of the log in your next reply and note any errors encountered.
===
Sophos Scan & Clean
www.sophos.com
Computer name . . . . : OCTOPUS-PC
Windows . . . . . . . : 6.1.1.7601.X86/2
User name . . . . . . : octopus-PC\octopus
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2023-06-27 00:06:07
Scan mode . . . . . . : Normal
Scan duration . . . . : 16m 41s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 0
Traces . . . . . . . : 44
Objects scanned . . . : 1,090,632
Files scanned . . . . : 50,574
Remnants scanned . . : 300,290 files / 739,768 keys
Suspicious files ____________________________________________________________
C:\Program Files\MediatekWiFi\Common\ApUI.exe
Size . . . . . . . : 9,507,656 bytes
Age . . . . . . . : 1451.0 days (2019-07-07 01:14:42)
Entropy . . . . . : 5.0
SHA-256 . . . . . : 12C83DB5452ACD4B6343DC3D5BC5E0B0840B4E804DDBC76E8BDED8D6D4D1EA2D
Product . . . . . : ApUI Application
Publisher . . . . : Mediatek Inc.
Description . . . : Mediatek Wireless Access Point Utility
Version . . . . . : 5.0.6.5
Copyright . . . . : (c) Copyright 2014, Mediatek Inc. All rights reserved.
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Invalid
Fuzzy . . . . . . : 26.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
File belongs to an identified security risk.
C:\Program Files\MediatekWiFi\Common\RaUI.exe
Size . . . . . . . : 15,624,008 bytes
Age . . . . . . . : 1451.0 days (2019-07-07 01:14:46)
Entropy . . . . . : 5.4
SHA-256 . . . . . : 83B5454A7402353C3F2652A826B95AC7F23003985543010DB74F06F067B909CA
Product . . . . . : RaUI Application
Publisher . . . . : Mediatek Inc.
Description . . . : Mediatek Wireless LAN Card Utility
Version . . . . . : 5.0.9.19
Copyright . . . . : (c) Copyright 2014, Mediatek Inc. All rights reserved.
RSA Key Size . . . : 2048
Parent Name . . . : C:\Windows\Explorer.EXE
LanguageID . . . . : 1033
Authenticode . . . : Invalid
Running processes : 3408
Fuzzy . . . . . . : 32.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
Uses the Startup folder in the Start Menu to run each time the user logs on.
Program is running but currently exposes no human-computer interface (GUI).
Program starts automatically without user intervention.
The file is in use by one or more active processes.
Startup
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Mediatek Wireless Utility.lnk
References
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mediatek Wireless\Mediatek Wireless Utility.lnk
Cookies _____________________________________________________________________
C:\Users\octopus\AppData\Local\Microsoft\Edge\User Data\Default\Cookies:scorecardresearch.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:adfarm1.adition.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:adform.net
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:adnxs.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:ads.pubmatic.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:adsrvr.org
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:bidr.io
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:bidswitch.net
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:casalemedia.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:contextweb.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:crwdcntrl.net
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:demdex.net
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:dotomi.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:doubleclick.net
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:dpm.demdex.net
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:everesttech.net
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:ipredictive.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:lijit.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:mathtag.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:openx.net
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:pool.admedo.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:pubmatic.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:rlcdn.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:rubiconproject.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:scorecardresearch.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:simpli.fi
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:sitescout.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:smartadserver.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:taboola.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:tapad.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:tidaltv.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:tribalfusion.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:turn.com
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:w55c.net
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:weborama.fr
C:\Users\octopus\AppData\Local\Vivaldi\User Data\Default\Network\Cookies:xiti.com
C:\Users\octopus\AppData\Roaming\Microsoft\Windows\Cookies\Low\octopus@doubleclick[2].txt
C:\Users\octopus\AppData\Roaming\Microsoft\Windows\Cookies\Low\octopus@scorecardresearch[2].txt
C:\Users\octopus\AppData\Roaming\Microsoft\Windows\Cookies\Low\octopus@www.googleadservices[2].txt
hii,Hi,
When you say noise what kind of noise, beeps, etc...
Restart the computer and let me know how the computer is running.