Search the Community

Showing results for tags 'Closed'.

More search options

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


  • Malware Research Center
    • Help, my PC is infected!
    • Ransomware First Aid
    • Malware and Computer Security
    • Malware submissions
  • Company & Products
    • Customer Support
    • Public Betas
    • Feedback, Comments and Suggestions
    • False positives
    • Emsisoft News
  • Other Languages
    • German Support - Deutscher Support
    • French Support - Assistance Française
    • Russian Support - Русская поддержка
    • Dutch Support - Nederlandse Support
    • Italian Support - Supporto Italiano
    • Polish Support - Polskie wsparcie
  • Private Zone

Find results in...

Find results that contain...

Date Created

  • Start


Last Updated

  • Start


Filter by number of...


  • Start





Website URL







Found 678 results

  1. I GOT INFECTED BY i dont know how to remove this on my Chrome Browser... anyone can help me ASAP?
  2. I got this Virus Named and ovche.bit and finally cmd.exe keeps popping up my screen that runs my explorer.exe secretly But Melwarebytes Blocks it every min please help me stop this i don't know how to Delete this Even me i Cant afford the Premium Anti Malware i'm Just a 13 Boy Normal PC user Got Infected By Accident/ Unknown Reason
  3. Win 10 using 8668 after autoupdate to new build. After having build on machine for half an hour or so, I decided to do a manual malware scan via GUI menu. The scan ended almost immediately. I asked to view logs for scan via scan window, and got a popup saying I couldn't look at the log as it wasn't available. So I opened general logs and it just says the scan is still in progress (and is still stuck saying this) Included are debug logs , db3 logs, and 2 screenshots. a2service_20180526043820(1728).zip
  4. should I be concerned at all ? FRST.txt Addition.txt
  5. Win 8.1, 64bit... Running 8631 with Beta feed... but there's been several updates since beta 8668 was announced and my machine hasn't selected it. Should it have done so? Emsisoft Anti-Malware Full 2018.4.0.8631 beta [en-us] OS: Windows 8.1 (Version 6.3, Build 9600, 64-bit Edition)
  6. Since updating to 8555 a short while ago I see this entry in BB list. Right-click options on it show nothing at all. Win 10
  7. 5/20/2018 11:31:29 AM A notification message "The following Windows kernel files have been detected as infected:C:\Windows\SysWOW64\schtasks.exeAs these files are essential for Windows to work, you can't delete or quarantine them now.The removal experts on the Emsisoft Forum will help you to safely remove this detection for free:" has been shown
  8. Just wondering why a2contextmenu64.dll and a2contextmenu.dll in EAM Program folder do have up to date digital signatures.
  9. Win 10 1803 with EAM 8631 Turned on machine this morning but it wouldn't reach desktop.. just a grey screen with cursor. Did a hard reset and everything loaded okay after booting again, Debug logs and screenshot of event viewer entry (4.40.11 am) a2service_20180517044653(1624).zip
  10. I am having harrowing time with these malwares which no AV or Anti-malware softwares seem to remove, slowing down my already slow system. It keeps on coming back and have to rescan restart with no end in sight. Until I came across emsisoft and after scaning and trying to quarntine it says removing them will pose high risk of crashing the system during automatic cleaning, as the threat is deeply embedded and it refered to the online support for quidance for removal. Following the instruction at "START HERE' I managed to attach the requisite files. Plz kindly help which will be highly valued. Thanking you. FRST_10-05-2018 14.14.12.txt Addition_10-05-2018 14.14.12.txt scan_180510-131930.txt
  11. I have misgivings if there's going to be no offline help at all. What happens if someone's not got an internet connection? The beta release notes say "Enhanced documentation which is available in our online Helpdesk that describes all aspects of the software." I sincerely hope you're planning to populate the online help because at the moment it seems a bit sparse. The first topic I looked at, in the FAQ section "Installing & Uninstalling" is described as "Best practice advise for installing and removing Emsisoft products properly."... and does not contain ANY relevant information for current releases. Instead it just mentions XP and Vista. It's a backward step if all you're going to do is assemble a set of blog posts. I think the existing offline help document is already a bit sparse, but at least one could start at the top and read the whole thing. A set of miscellaneous Q&A isn't as good.
  12. EAM 7424 on Win 10 Creators Build. The Flash Player Settings Manager in Control Panel will not open unless EAM service is turned off. Debug logs attached. I turned EAM service off and on twice Frank just to make sure that EAM was responsible. a2guard_20170426152920(5700).zip
  13. Not sure what to do. Basically, i ran a scan with emsisoft and it found 4 threats, all within the same main folder. It was a game i downloaded(Universe Sandbox 2), in the folder downloads/games/Universe-sandbox-2. So, Emsisoft successfully removed 2 of the viruses but could not remove the other 2 displaying the error message: "The following objects were not removed for your safety ...Removing these items bears an unusually high risk of crashing your OS.." So i followed the instructions on the "START HERE.." page and now i'm posting. I'm not exceptionally good with computers so try to dull it down and make it simple for me, please. Thank you, and let me know if any other information is needed. Addition_06-05-2018 17.02.54.txt FRST_06-05-2018 17.02.54.txt scan_180506-164815.txt
  14. DanmarksTJensen

    CLOSED Could not be removed

    I get the message shown in attachment. Result from Emergency Kit Scanner attached. I cannot open FRST64. scan_180504-100342.txtscan_180504-100342.txtscan_180504-100342.txt Help, please! Yrs Torben Jensen
  15. Just noticed that the Core...Notification is missing in my Forensics log for this morning's 5.40 am auto update. (Thank goodness the logs were set to show default or I may have missed it )
  16. Hi, I just done a scanner with emisoft Emergency kit scanner and when i pressed on quarantine selected objects appears a message to me that says that these ones can't be removed, what can i do? C:\Program Files (x86)\Common Files\Over-Find\uninstall.exe C:\Program Files (x86)\Rabat\1317.exe C:\Program Files (x86)\Rabat\8461.exe C:\Program Files\0CQJLD2DYU\uninstaller.exe C:\Program Files\0PIEFBC8QC\uninstaller.exe C:\Program Files\1IUXO22K7E\uninstaller.exe C:\Program Files\3NNRG6D7TO\uninstaller.exe C:\Program Files\65NC92JAA6\uninstaller.exe C:\Program Files\8AT4HIRP9O\uninstaller.exe C:\Program Files\8VCJCQ067X\uninstaller.exe C:\Program Files\9S85KQF7J7\uninstaller.exe C:\Program Files\B1PA2QQFT7\uninstaller.exe C:\Program Files\IBDLPKDX40\uninstaller.exe C:\Program Files\KP1EGX8873\uninstaller.exe C:\Program Files\LJOIOEKYKV\uninstaller.exe C:\Program Files\O6JZ6XPU5P\uninstaller.exe C:\Program Files\S976WYX1K6\uninstaller.exe C:\Program Files\ULIQ84WGTX\uninstaller.exe C:\ProgramData\647aa69a-af5e-4df8-9558-e2c4b4c57398\OneSystemCare.exe C:\ProgramData\dcbdb831-95af-4d21-874a-b8159552646c\OneSystemCare.exe C:\Users\ricos\Downloads\Studio_12_5.exe C:\WINDOWS\bb6d490448c4a0c6997d6d4a32046007.exe C:\WINDOWS\ C:\WINDOWS\System32\Drivers\43278e20a3f4eb1b2c80abd764a24597.sys C:\WINDOWS\TEMP\g62B1.tmp.exe Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\03D22C9C66915D58C88912B64C1F984B8344EF09 Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\0F684EC1163281085C6AF20528878103ACEFCAAB Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\1667908C9E22EFBD0590E088715CC74BE4C60884 Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\18DEA4EFA93B06AE997D234411F3FD72A677EECE Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\249BDA38A611CD746A132FA2AF995A2D3C941264 Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\31AC96A6C17C425222C46D55C3CCA6BA12E54DAF Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\331E2046A1CCA7BFEF766724394BE6112B4CA3F7 Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\3353EA609334A9F23A701B9159E30CB6C22D4C59 Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\373C33726722D3A5D1EDD1F1585D5D25B39BEA1A Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATE
  17. I now have 2 n/a entries in BB list. Are they both the famous MEM compression? EDIT in Process Explorer... Pid 2348 is Mem compression Pid 96 is listed as Registry..NT Kernel & System
  18. Win 10 build 8555 Noticed last night that I have produced no debug logs from the 3rd April onwards. The last thing that all the logs say on the 3rd is that I disabled logging at boot (you know I wouldn't do that EAM did it !!) Looking at Forensics it was during boot and a restart of EAM was requested. No mention of debug logging being turned off in Forensics. Find attached debug logs for that short time which show logging being turned off. a2guard_20180403043818(7332).zip
  19. Some weeks ago i noticed that my CheatEngine now closes itself about 10 secs after i try to use it, no matter what. According to message at the top of' main page and to this topic there is supposed to be some malware targeting CheatEngine. Also, every time i try to find solution for that problem by typing requests like "CheatEngine crash" or CheatEngine malware", my browsers tend to close immediately. That affects absolutely all browsers, installed and portable, even ones running in Comodo Sandbox. Both CheatEngine and browsers worked perfectly well in the Safe Mode last time i checked. There is some tool called windowsrepair.exe that suggests to use to fix problems with malware, but it never worked for me. While said CheatEngine can be considered Riskware, it helped me to avoid hours of grinding in many games for many years without such problems as now. Also, it may be relevant or not, but few days ago i already tried to fix that problem, and while i did a full system scan with EEK, it found and quarantined plenty of copies of Gen:Variant.Symmi.45452 (B) [krnl.xmd] in four directories on my Disk E. I added report concerning them in addition to three mandatory logs, below all of them. Please help. I don't want to reinstall Windows just because of that problem i have.
  20. Hi again, Kevin, hope all is well with you. My system has become noticeably slower, and Windows Explorer (not MIE but the local system file browser) crashes with "Windows Explorer has stopped." I have run the System File Checker with "sfc /scannow" and all system files appear to be fine. EIS reports no issues, nonetheless, something is infesting my PC and causing the problems described as well as numerous other annoying anomalies.. Logs attached. Thanks in advance for waving your magic wand over my system. Again. FRST.txt Addition.txt scan_180419-205206.txt
  21. hi , i just ran quick scan with emsisoft antimalware and it detected DKOM.DoublePulsar(A) in OS Kernel and is unable to remove that. since i just ran out of trial period so as per forum rules the stable version of emsisoft anti malware will act as portable version of emsisoft emergency kit. Also I am using realtime eset protection and eset did not detected any thing. attached are the logs and image of detection. windows 8.1 Addition.txt FRST.txt Forensics_180419-031813.txt
  22. Just got this through updates (any info?)
  23. LiebherrGB

    CLOSED Behavior.Worm

    Hello I keep getting variations on this detection: Location: SHA1: 4EE29875C8322D363CDDC9492AC8C50FB8B61257 Detection: Behavior.Worm Detected by: Behavior Blocker Is this a concern and if so how can this be resolved?
  24. I have been troubleshooting a browser issue and as part of that troubleshooting on Win 10 machine I turned off protection via the EAM right-click taskbar option. When I turned it back on I waited the few seconds it sometimes takes for it to turn green again. It didn't. I couldn't turn on protection for the items via the GUI tickboxes. It said I needed to do a restart of machine. Happened around 7am in debug logs. After restarting machine all is well. a2guard_20180329070237(5520).zip
  25. Build 8555 updated smoothly (on my W8.1 64bit system), but since then I've noticed that a) the systray icon was hidden; it was possible to turn its display back on via the systray Customisation thing, but this is not normally needed b) I'd downloaded a copy of FRST64.exe; I right-clicked it and chose EAM scan... and nothing seemed to happen - I expected the GUI to be displayed and be told the scan result. I've repeated this and once the GUI has popped up. But I also get instances of the mouse pointer just becoming a revolving blue circle. Moving it towards the taskbar doesn't make the taskbar unhide as usual. Last time I tried to follow an Admin Tools shortcut (on my desktop, heading towards the Eventlog Viewer) and there was a sort of hiccup, a brief (sub-second) dispay of an all blue screen, then the Explorer desktop display was redrawn and the revolving blue circle had gone. Would that imply an issue with the code what runs from the file explorer context menu? - that weirdness starts with a right-click action.