Jump to content

Search the Community

Showing results for tags 'Closed'.

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


  • Malware Research Center
    • Help, my files are encrypted!
    • Help, my PC is infected!
    • Malware and Computer Security
    • Malware submissions
  • Company & Products
    • Customer Support
    • Beta Community
    • False positives
    • Emsisoft News
  • Other Languages
    • German Support - Deutscher Support
  • Private Zone

Find results in...

Find results that contain...

Date Created

  • Start


Last Updated

  • Start


Filter by number of...


  • Start





Website URL







  1. Hi there guys, I recently helped a firend to clear his laptop (Dell, Windows Home 10, 64-bit) What happened was he got some pretty bad PUPs and other dirt. I was able to clean it up meticulously with Emsisoft Emergency Kit, I checked Firefox extensions according to Emsisoft article here, I ran many scans and it is clean now. No redirection, no PUPs, nothing, zilch, looks like it's clean and it is clean. Everything is working as it should be working. The only thing that is left is the list of greyed out exclusions that these viruses and malware programs forced Windows d
  2. Hi guys, I need some help to remove a malware "Gen:Variant.Graftor.494726 (B)" which EMSISOFT found today. The software couldn't delete this. Error "Couldn't delete, cause of high risk to damge system." occured. Thnks for help. Gretings, Claas
  3. Hi I typed the name of a trusted website into the Google search box, clicked on that site and got redirected to an ‘advertisement’ saying ”Dear Chrome user, you are today’s lucky visitor…”. Something about a 2018 Annual Visitor Survey. The address bar displayed: play1549.i-our-prize60.loan. I didn’t click on anything and closed the window with the red x button top right. I haven’t downloaded anything for a while but checked in Programs and Features for anything unusual. There wasn’t. I ran EAM which found nothing. The Google redirect hasn’t happened again. I attach followi
  4. I am checking for any possible malware on my system, emsisoft antimalware, roguekiller and malwarebytes dont detect anything suspicious. But is there anything in these farbar logs? Btw, my emsisoft software said FRST.exe was suspicious and asked for my permission to allow it since it was trying to modify firewall somehow, i didnt manually approve it so the emsisoft then put the software in quarantee and shutdown the program, but the farbar was still able to make these logs, did that emsisoft interference make these logs less reliable in detecting malware? I decided to not approve the modificat
  5. Here's everything you need. Addition.txt FRST.txt scan_180617-172558.txt
  6. I have this impossible-to-delete-without-damage-your-cmp Rootkit problem and I don't know if it's this Cloudnet malware. I cannot access to windows defender, too, I tried many manually things. Ah, when I run an EEK scan after the results an 'Activate EEK protection' download pop up but then its says that's something wrong scan_180605-154342.txt Addition_05-06-2018 15.51.50.txt FRST_05-06-2018 15.51.50.txt
  7. Every time Chrome is opened it redirects to Yahoo search. Chrome is set as default. EAM scans haven't shown any issues but I wanted to make sure there wasn't a PUP or malware. Thank you! scan_180614-105720.txt Addition.txt FRST.txt
  8. Hello I was unable to remove file/program that keeps popping up on the desktop. The pop up is a small blue rectangle box with the words "please wait" Task manager has this app named "Windows Static Word (32bit)" File location is in C:/user/AppData/Roaming/StaticCheck/Audiod.exe The Audiod.exe file is associated with AnyCom I have used task manager to end the process as I was unable to simply remove the program from the task bar, and continued to delete the StaticCheck folder with the Audiod.exe file once the process has been cancelled. The file and folder ke
  9. hi guys i've just had this same issue just appear in theaudiod.exe last few days - any word on how to resolve - i've tried windows repair/restore, virus scanners - nothing.
  10. I ran a scan with emnisoft and it found several threaths. Tried to remove them. "The following objects C:\Windows\System32\Drivers\Winmon.sys C:\Windows\System32\Drivers\WinmonFS.sys were not removed for your safety ...Removing these items bears an unusually high risk of crashing your OS.." I followed the instructions on the "START HERE.." page and it asked to post remaining items here. Thanks for your help. (Sorry for my bad english, i'm not a native speaker) Edit: I can't start Windows Defender Addition.txt FRST.txt scan_180607-170710.txt scan_18
  11. Was online chatting with an emsisoft rep but they stopped responding over 4+ hours ago. The malware I have is consistently being identified and quarantined, repeatedly. I ran the FRST program and have added the files here in hope I can get some further assistance. Thank you. Addition.txt FRST.txt
  12. After updating to the latest version, the computer hangs on reboot. I had to go to Safe Mode to uninstall. OS: Win 7 Ultimate, 64-bit Other AV: Comodo Firewall (not AV), VodooShield free Autoruns: Eraser, SoftPerfect RAM disk, Samsung RAPID mode, Dimension 4, Virtual Clone Drive, ID Manager, Pure VPN, Rainlendar2, TextAloud 3, USB safely remove, KeyScrambler, Snagit and Hard disk sentinel. It is during the loading of the autoruns that the system hangs, and does not recover. Emsisoft Anti-Malware 2018.3.0.8555 Updating to this version required a reboot, and that is w
  13. System updated a short time ago, but I see no release details here. What is in Emsisoft Anti-Malware Full 2018.5.0.8686 beta [en-us] OS: Windows 8.1 (Version 6.3, Build 9600, 64-bit Edition)
  14. Before install emsi i click on a fb profile of one of my friends and he said it is virus . I click on "Special video" . What sould i do? Now i am installing EAM and runing that I put the url whith xxx to not compromise people https://xxx.facebook.com/Miklistli/activity/957761784401554?comment_id=957762854401447&notif_id=1527812882874767&notif_t=mentions_comment https://www.virustotal.com/es/url/6e1e012cb44db6112c38171df7f9a8829b386948ce5cb2588a5623aaef41d019/analysis/1527812941/ https://www.virustotal.com/es/url/81657085141be23c497e0c09
  15. I have the smartservice rootkit on my machine, and I can't remove it. I have been unable to start malwarebytes, windows defender, or avast. Emsisoft Emergency Kit has been able to detect this rootkit at C:\WINDOWS\System32\Drivers\mouvqrty.sys. However, it has been unable to delete this file. EEK says that this file cannot be removed for your own safety, and it says a computer restart is required. However, after restarting the virus is still there. I tried multiple EEK scans to no avail. I also used Zemana anti malware to detect it, but it cannot remove smartservice either. Help wo
  16. Win 10 using 8668 after autoupdate to new build. After having build on machine for half an hour or so, I decided to do a manual malware scan via GUI menu. The scan ended almost immediately. I asked to view logs for scan via scan window, and got a popup saying I couldn't look at the log as it wasn't available. So I opened general logs and it just says the scan is still in progress (and is still stuck saying this) Included are debug logs , db3 logs, and 2 screenshots. a2service_20180526043820(1728).zip
  17. Win 8.1, 64bit... Running 8631 with Beta feed... but there's been several updates since beta 8668 was announced and my machine hasn't selected it. Should it have done so? Emsisoft Anti-Malware Full 2018.4.0.8631 beta [en-us] OS: Windows 8.1 (Version 6.3, Build 9600, 64-bit Edition)
  18. Since updating to 8555 a short while ago I see this entry in BB list. Right-click options on it show nothing at all. Win 10
  19. 5/20/2018 11:31:29 AM A notification message "The following Windows kernel files have been detected as infected:C:\Windows\SysWOW64\schtasks.exeAs these files are essential for Windows to work, you can't delete or quarantine them now.The removal experts on the Emsisoft Forum will help you to safely remove this detection for free: http://support.emsisoft.com" has been shown
  20. Just wondering why a2contextmenu64.dll and a2contextmenu.dll in EAM Program folder do have up to date digital signatures.
  21. Win 10 1803 with EAM 8631 Turned on machine this morning but it wouldn't reach desktop.. just a grey screen with cursor. Did a hard reset and everything loaded okay after booting again, Debug logs and screenshot of event viewer entry (4.40.11 am) a2service_20180517044653(1624).zip
  22. I am having harrowing time with these malwares which no AV or Anti-malware softwares seem to remove, slowing down my already slow system. It keeps on coming back and have to rescan restart with no end in sight. Until I came across emsisoft and after scaning and trying to quarntine it says removing them will pose high risk of crashing the system during automatic cleaning, as the threat is deeply embedded and it refered to the online support for quidance for removal. Following the instruction at "START HERE' I managed to attach the requisite files. Plz kindly help which will be highly valued. Th
  23. I have misgivings if there's going to be no offline help at all. What happens if someone's not got an internet connection? The beta release notes say "Enhanced documentation which is available in our online Helpdesk that describes all aspects of the software." I sincerely hope you're planning to populate the online help because at the moment it seems a bit sparse. The first topic I looked at, in the FAQ section "Installing & Uninstalling" is described as "Best practice advise for installing and removing Emsisoft products properly."... and does not contain ANY relevant information
  • Create New...