[email protected] 0 Posted June 18, 2016 Report Share Posted June 18, 2016 My Emsisoft application is displaying a red "My Computer is Not Protected". Occasionally I receive a pop-up stating that there is no resource available for Emsisoft (not sure of exact message). I have uninstalled and re-installed Emsisoft per instructions. Now running trial version (I need to find my license number) Still not working. I have downloaded the applications and run the scans as directed and attached the files. Thank you for your help! FRST.txt Addition.txt scan_160618-063240.txt Link to post Share on other sites
Kevin Zoll 309 Posted June 20, 2016 Report Share Posted June 20, 2016 (edited) Do the following: Copy the below code to Notepad; Save As fixlist.txt to your Desktop. HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-1539214893-3760120510-3683430050-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-1539214893-3760120510-3683430050-1000\...\Policies\system: [DisableChangePassword] 0 ShellExecuteHooks-x32: - UPB:{B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No File [ ] ShortcutTarget: fixtclient.exe.lnk -> C:\Program Files (x86)\fixt\fixtclient.exe (No File) GroupPolicyScripts: Restriction <======= ATTENTION GroupPolicyScripts\User: Restriction <======= ATTENTION FF NetworkProxy: "type", 0 FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [No File] FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\new_plugin\npjp2.dll [No File] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] C:\Users\Mike Zinni\AppData\Local\Temp\1Password-1.0.9.341.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-1.0.9.342.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.1.0.530.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.1.0.538.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.2.0.548.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.3.0.556.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.3.1.560.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.5.0.572.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.5.0.574.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.5.0.575.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.6.0.582.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.6.0.583.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.6.0.584.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.6.0.585.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.6.0.586.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.6.0.592.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.6.0.598.exe C:\Users\Mike Zinni\AppData\Local\Temp\1Password-4.6.0.604.exe C:\Users\Mike Zinni\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsv6zdq.dll C:\Users\Mike Zinni\AppData\Local\Temp\G2MInstallerExtractor.exe C:\Users\Mike Zinni\AppData\Local\Temp\gzfumpce.dll C:\Users\Mike Zinni\AppData\Local\Temp\icqxyju3.dll C:\Users\Mike Zinni\AppData\Local\Temp\jre-8u31-windows-au.exe C:\Users\Mike Zinni\AppData\Local\Temp\jre-8u40-windows-au.exe C:\Users\Mike Zinni\AppData\Local\Temp\SkypeSetup.exe C:\Users\Mike Zinni\AppData\Local\Temp\SyncedTool-1.7.5.441.exe CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1539214893-3760120510-3683430050-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Mike Zinni\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File Close Notepad. NOTE: It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST64 and press the Fix button just once and wait. If the tool needed a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop (Fixlog.txt). Attach it to your reply. Note: If the tool warns you about an outdated version please download and run the updated version. Uninstall Emsisoft Anit-Malware. Restart the system twice. Download EmsiClean to your Desktop: https://dl.emsisoft.com/Emsiclean.zip After you downloaded the tool, just run it. Read the disclaimer carefully and press "Yes" if you accept it. The tool will then show a list of all Emsisoft objects it found installed on your system. Simply enable the check boxes of all objects you want to remove. Be careful with objects of type "Folder" though and check their contents before selecting them for removal, as they may still contain data that you may want to save first. Then press the "Remove selected objects" button and reboot when asked. Download and install Emsisoft Anti-Malware: http://dl.emsisoft.com/EmsisoftAntiMalwareSetup.exe Enter license information when prompted. Edited July 10, 2018 by GT500 Updated link for Emsiclean. There are now two versions (32-bit and 64-bit) bundled in a ZIP archive. Run EmsiClean64, and if you see an error message then run EmsiClean32. Link to post Share on other sites
Kevin Zoll 309 Posted June 23, 2016 Report Share Posted June 23, 2016 Thread ClosedReason: Lack of ResponsePM either Kevin, Elise, or Arthur to have this thread reopened.All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE if you don't we are just going to send you back to this thread. Link to post Share on other sites
Recommended Posts