Alright, I won't interfere, then.
Thank you
Posted 18 September 2023 - 08:13 AM
Alright, I won't interfere, then.
Thank you
Posted 18 September 2023 - 11:47 AM
Posted 18 September 2023 - 12:38 PM
Ok that's good.
ESET did some cleanup for us on the Data drive and I'm pleased to see that nothing was detected on the C drive.
The SFC error in the fix related to WindowsDefenderApplicationGuard.wim, but as you use Kaspersky and McAfee, we probably don't need to dwell on that. In any case it may get resolved in a future update.
I should mention that running two antivirus programs at the same time may cause conflicts.
This Kaspersky article offers some guidance.
------------------------------------------------------------------------------------------------------------------------------------------------
There are some unusual files that I suggest we try to remove next.
Start:: CreateRestorePoint: CloseProcesses: 2023-09-06 00:33 - 2023-09-12 08:08 - 003675072 _____ C:\WINDOWS\SysWOW64\AppRulesStorage-wal 2023-09-06 00:33 - 2023-09-06 15:05 - 000032768 _____ C:\WINDOWS\SysWOW64\DnsStorage-shm 2023-09-06 00:33 - 2023-09-06 15:05 - 000032768 _____ C:\WINDOWS\SysWOW64\AppRulesStorage-shm 2023-09-06 00:33 - 2023-09-06 00:33 - 000012288 _____ C:\WINDOWS\SysWOW64\DnsStorage 2023-09-06 00:33 - 2023-09-06 00:33 - 000012288 _____ C:\WINDOWS\SysWOW64\AppRulesStorage 2023-09-06 00:33 - 2023-09-06 00:33 - 000000000 _____ C:\WINDOWS\SysWOW64\DnsStorage-wal End::
Please copy the contents from this text file and paste into your next reply.
--------------------------------------------------------------------------------------------------------------------------------
As a final check I'd now like you to run a scan with AdwCleaner.
Please download AdwCleaner.
Once your computer has restarted ...
Also please provide an update on computer performance and advise if any issues remain.
Posted 18 September 2023 - 01:17 PM
Actually, I was pretty sure that I had uninstalled McAfee. It doesn't show up in the start menu anymore, and not even in the list of programs (control panel).
Did I do something wrong?
Posted 18 September 2023 - 01:21 PM
Posted 18 September 2023 - 01:30 PM
The scan with AdwCleaner didn't detect anything except 5 preinstalled programs, so it didn't prompt me to reboot.
Log file:
# -------------------------------
Posted 18 September 2023 - 01:41 PM
Ok good.
I suspected those files would be rather stubborn to remove.
Please boot into Safe Mode and try the FRST fix from post #18 again.
Windows 10/11 Safe mode.
------------------------------------------------------------------------------------
McAfee is showing enabled in the Security Center and there are some other entries showing, although it's not a running process.
It tends not to uninstall very cleanly, so we will do a manual cleanup of the remnants.
SearchAll: McAfee
.Is the computer running ok now?
Posted 18 September 2023 - 01:54 PM
Posted 18 September 2023 - 02:05 PM
Here is the Search.txt file:
Posted 18 September 2023 - 02:16 PM
Thanks -got it.
I'll prepare a script to remove McAfee tomorrow morning.
Posted 19 September 2023 - 04:28 AM
Here's the script to remove McAfee.
Start:: CreateRestorePoint: CloseProcesses: AV: McAfee VirusScan (Enabled - Up to date) {F682A51C-4EAD-6A3A-F460-B9C1D4A2DB09} FW: McAfee Firewall (Enabled) {CEB92439-04C2-6B62-DF3F-10F42A719C72} C:\Windows\System32\Tasks_Migrated\McAfee Remediation (Prepare) C:\Windows\System32\Tasks_Migrated\McAfeeLogon C:\Windows\System32\Tasks_Migrated\McAfee\McAfee Auto Maintenance Task Agent C:\Windows\System32\Tasks_Migrated\McAfee\McAfee Idle Detection Task C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee HIPS Driver.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~0BBD9DDB-F12A-43EF-9213-ED84DB2253E9~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~10271CA5-FDE6-4562-BD08-8DA931CA6E50~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~2BEB5910-DA0A-4916-8025-065EBE7924F7~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~61F857BA-7D4E-4BEE-B5AF-2EF2DF4980DC~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~74FCDCDB-56F3-4513-B852-3987D5CEE927~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~85D20F9C-E4B0-46D7-9296-2F14CBFB1AA1~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~88DC92DA-FD5E-4E99-9873-DE8678FB96FC~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~9BE5553B-A06D-48C2-8F3E-888C71CD9140~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~B44D0791-E05A-46C5-BE1F-B2EA1E2F7A89~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~B59B6C80-314B-4C3E-ADF6-E13EBA34A25A~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~C85BAC20-6C94-49C0-AB6E-B0AB3A86575F~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~CC41DFB8-BBF8-4699-AE6A-2728FA6732AB~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~DC9BD563-1785-45B0-BD90-A65F8FC57EE4~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~DF218D18-04D9-4627-B77C-5F168616FF54~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~E4EA0528-515E-49B3-B1A9-732E37FC9E65~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~E9409534-1655-4247-B1BC-9347A6FEF499~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~F0889FAE-AF57-4D01-816E-8D9CDC119020~amd64~~22.12.0.211.5.cat C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\McAfee-VSCore~FA3E1285-499D-4C1E-8513-F686EC156850~amd64~~22.12.0.211.5.cat C:\Users\Nathan\myCloud\mcafee_trial_setup_433.0207.3919_key.exe C:\Users\Nathan\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fdhgeoginicibhagdmblfikbgbkahibd C:\ProgramData\Lenovo\Vantage\Addins\LenovoSecurityAddin\1.0.0.97\McAfeeSdkApi.dll C:\ProgramData\Lenovo\Vantage\Addins\LenovoSecurityAddin\1.0.0.97\McAfeeSdkApi.dll.config C:\ProgramData\Lenovo\Vantage\AddinData\LenovoSystemUpdateAddin\session\Repository\mcafeehotfix714 C:\ProgramData\Lenovo\ImController\SystemPluginData\LenovoSystemUpdatePlugin\session\Repository\mcafeehotfix714 2021-02-10 11:27 - 2023-08-30 11:25 _____ C:\Windows\System32\Tasks_Migrated\McAfee 2021-09-24 14:29 - 2022-02-16 21:42 ___RS C:\Users\Nathan\Documents\McAfee Vaults 2023-09-05 00:55 - 2023-09-05 00:55 _____ C:\Users\Nathan\AppData\Roaming\McAfee 2021-02-10 11:26 - 2023-09-06 00:20 _____ C:\ProgramData\McAfee 2023-08-30 15:48 - 2023-08-30 15:48 _____ C:\ProgramData\Lenovo\Vantage\AddinData\LenovoSystemUpdateAddin\session\Repository\mcafeehotfix714 2023-08-30 14:23 - 2023-08-30 14:23 _____ C:\ProgramData\Lenovo\ImController\SystemPluginData\LenovoSystemUpdatePlugin\session\Repository\mcafeehotfix714 DeleteValue: HKEY_USERS\S-1-5-21-739449780-1690936981-217154247-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|McAfee.McAgent DeleteValue: HKEY_USERS\S-1-5-21-739449780-1690936981-217154247-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\ShowJumpView|McAfee.McAgent DeleteValue: HKEY_USERS\S-1-5-21-739449780-1690936981-217154247-1001\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData|McAfee.McAgent DeleteValue: HKEY_USERS\S-1-5-21-739449780-1690936981-217154247-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\McAfee\MSC\mcuihost.exe DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\McAfeeExtn DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee DeleteKey: HKEY_USERS\S-1-5-21-739449780-1690936981-217154247-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{190671ea-a1b7-4b0d-a12b-7219f90f7240}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~mcafee.mcagent DeleteKey: HKEY_USERS\S-1-5-21-739449780-1690936981-217154247-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{190671ea-a1b7-4b0d-a12b-7219f90f7240}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~mcafee.mcagent DeleteKey: HKEY_USERS\S-1-5-21-739449780-1690936981-217154247-1001\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\McAfee.McAgent End::
Please copy the contents from this text file and paste into your next reply.
Posted 22 September 2023 - 03:46 AM
Did you manage to run the fix?
If I don't hear back from you in the next 2 days, I will assume that you no longer need help and this topic will be closed.
Posted Today, 02:38 AM
I'm assuming that everything is ok now, as I haven't heard back from you.
This tool will remove the software we used.
KpRm by Kernel-panik
These articles offer good advice and information for the future.
Keep your computer secure at home
How your system gets infected.
Ransomware advice.
Choosing Secure Passwords.
Thank you for contacting us at Bleeping Computer.
Dennis
0 members, 3 guests, 0 anonymous users