SBMongoos 1 Posted February 23, 2015 Share Posted February 23, 2015 Not getting any options to remove or clean. Screenshot attached. Whan clickk on the little arrow right of "After all scan computer takes no action" the options are to : Shut down Reboot Sleep Hibernate No action This is on a Windows 8.1 laptop (Lenova Yoga 2). Link to comment Share on other sites More sharing options...
Administrators Marcos 4,919 Posted February 23, 2015 Administrators Share Posted February 23, 2015 It seems the scan hasn't finished yet. Click "Open scan in a new window" to see scan details. Link to comment Share on other sites More sharing options...
SBMongoos 1 Posted February 23, 2015 Author Share Posted February 23, 2015 yeah, sorry about that. I'm helping a friend and they did not send me the latest screenshot which actually is a screenshot where the scan is finished. But we still don't have any option to remove anything found. Link to comment Share on other sites More sharing options...
rugk 397 Posted February 23, 2015 Share Posted February 23, 2015 Normally threats are automatically cleaned after they found (as long as you didn't modified the settings). If PUA is found then ESS should ask the user whether he wants to delete it. Link to comment Share on other sites More sharing options...
SweX 871 Posted February 23, 2015 Share Posted February 23, 2015 Is the quarantine empty or is there items in there? Link to comment Share on other sites More sharing options...
SBMongoos 1 Posted February 23, 2015 Author Share Posted February 23, 2015 (edited) 0 in quarantine. And when I move back to the Scan it's as everything has reset and you have to start over. She was on Facebook last night and went to click on an article post from a friend. Didn't respond so she clicked a second time. Three Inbound Threats (Warning...what have you) popped up. She did a Smart Scan and found 18 threats but no way to clean them. I've re-scanned with the same method and here's the screenshot. Also, if I set and watch the Eset scan screen, that shows the 18 threats, it switches back to the main Scan screen on it's own like I never initiated the scan (see second screen shot). And by the way the same thing happens with a Custom Scan and choosing the Run as Admin option (I checked all boxes for scan). The Custom showed 24 Threats but I did not catch it going back to the default Scan screen like the Smart Scan had done. Pasted log below from Custom Scan. Scan Log Version of virus signature database: 11221 (20150223) Date: 2/23/2015 Time: 3:53:15 PM Scanned disks, folders and files: Operating memory;Boot sector;C:\Boot sector;C:\;D:\Boot sector;D:\ C:\hiberfil.sys - error opening [4] C:\pagefile.sys - error opening [4] C:\swapfile.sys - error opening [4] C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\cltmng.exe - a variant of Win32/Conduit.SearchProtect.I potentially unwanted application C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPTool64.exe - a variant of Win32/ClientConnect.A potentially unwanted application C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32.dll - a variant of Win32/Conduit.SearchProtect.H potentially unwanted application C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32Loader.dll - a variant of Win32/ClientConnect.A potentially unwanted application C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC64.dll - a variant of Win32/ClientConnect.A potentially unwanted application C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC64Loader.dll - a variant of Win32/ClientConnect.A potentially unwanted application C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\CltMngSvc.exe - a variant of Win32/Conduit.SearchProtect.H potentially unwanted application C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\SPTool.dll - a variant of Win32/Conduit.SearchProtect.H potentially unwanted application C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\uninstall.exe - a variant of Win32/ClientConnect.A potentially unwanted application C:\Program Files (x86)\LenovoBrowserGuard\UI\bin\cltmngui.exe - a variant of Win32/Conduit.SearchProtect.Y potentially unwanted application C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.log - error opening [4] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbtmp.log - error opening [4] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb - error opening [4] C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edb.log - error opening [4] C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edbtmp.log - error opening [4] C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb - error opening [4] C:\Users\Sara\NTUSER.DAT - error opening [4] C:\Users\Sara\ntuser.dat.LOG1 - error opening [4] C:\Users\Sara\ntuser.dat.LOG2 - error opening [4] C:\Users\Sara\AppData\Local\Google\Chrome\User Data\Default\Current Session - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\InputPersonalization\TextHarvester\WaitList.dat - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\Windows\UsrClass.dat - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\Windows\WebCacheLock.dat - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\Windows\Notifications\WPNPRMRY.tmp - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\Windows\SkyDrive\settings\98a360915e3824f0.dat - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\Windows\SkyDrive\settings\98a360915e3824f0.log - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\Windows\WebCache\V01.log - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log - error opening [4] C:\Users\Sara\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat - error opening [4] C:\Users\Sara\AppData\Local\Packages\Microsoft.Reader_8wekyb3d8bbwe\Settings\settings.dat - error opening [4] C:\Users\Sara\AppData\Local\Packages\Microsoft.Reader_8wekyb3d8bbwe\Settings\settings.dat.LOG1 - error opening [4] C:\Users\Sara\AppData\Local\Packages\Microsoft.Reader_8wekyb3d8bbwe\Settings\settings.dat.LOG2 - error opening [4] C:\Users\Sara\AppData\Local\Packages\winstore_cw5n1h2txyewy\Settings\settings.dat - error opening [4] C:\Users\Sara\AppData\Local\Packages\winstore_cw5n1h2txyewy\Settings\settings.dat.LOG1 - error opening [4] C:\Users\Sara\AppData\Local\Packages\winstore_cw5n1h2txyewy\Settings\settings.dat.LOG2 - error opening [4] C:\Users\Sara\AppData\Local\Temp\JET3217.tmp - error opening [4] C:\Users\Sara\AppData\Local\Temp\SPSetup.exe - a variant of Win32/ClientConnect.A potentially unwanted application C:\Users\Sara\SkyDrive\Work Pic June 2012.jpg - error opening [4] C:\Users\Sara\SkyDrive\Mobile uploads\Chicago-20110803-00537.jpg - error opening [4] C:\Users\Sara\SkyDrive\Mobile uploads\WP_000009.jpg - error opening [4] C:\Users\Sara\SkyDrive\Mobile uploads\WP_000013 (1).jpg - error opening [4] C:\Users\Sara\SkyDrive\Mobile uploads\WP_000013.jpg - error opening [4] C:\Users\Sara\SkyDrive\Mobile uploads\WP_000014.jpg - error opening [4] C:\Users\Sara\SkyDrive\Mobile uploads\WP_000025.jpg - error opening [4] C:\Users\Sara\SkyDrive\Mobile uploads\WP_000030.jpg - error opening [4] C:\Users\Sara\SkyDrive\Mobile uploads\WP_000033.jpg - error opening [4] C:\Users\Sara\SkyDrive\Mobile uploads\WP_000035.jpg - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0571.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0572.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0573.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0574.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0575.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0576.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0577.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0578.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0579.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0580.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0581.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0582.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0583.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0584.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0585.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0586.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0587.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0588.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0589.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0590.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0591.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0592.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0593.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0594.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0595.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0596.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0597.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0598.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0599.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0600.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0601.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0602.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0603.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0604.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0605.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0606.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0607.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0608.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0609.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0610.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0611.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0612.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0613.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0614.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0615.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0616.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0617.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0618.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0619.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0620.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0621.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0622.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0623.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0624.JPG - error opening [4] C:\Users\Sara\SkyDrive\OneNote\DSCN0625.JPG - error opening [4] C:\Windows\AppCompat\Programs\Amcache.hve - error opening [4] C:\Windows\AppCompat\Programs\Amcache.hve.LOG1 - error opening [4] C:\Windows\AppCompat\Programs\Amcache.hve.LOG2 - error opening [4] C:\Windows\apppatch\apppatch64\SPVCLdr64.dll - a variant of Win32/ClientConnect.A potentially unwanted application C:\Windows\apppatch\spbin\cltmng.exe - a variant of Win32/Conduit.SearchProtect.I potentially unwanted application C:\Windows\apppatch\spbin\SPTool64.exe - a variant of Win32/ClientConnect.A potentially unwanted application C:\Windows\apppatch\spbin\SPVC32.dll - a variant of Win32/Conduit.SearchProtect.H potentially unwanted application C:\Windows\apppatch\spbin\SPVC32Loader.dll - a variant of Win32/ClientConnect.A potentially unwanted application C:\Windows\apppatch\spbin\SPVC64.dll - a variant of Win32/ClientConnect.A potentially unwanted application C:\Windows\apppatch\spbin\SPVC64Loader.dll - a variant of Win32/ClientConnect.A potentially unwanted application C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT - error opening [4] C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1 - error opening [4] C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2 - error opening [4] C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\2410cc0df6b54754b57aa5f71ba04f3c\51490ccbd49e9582678e11e871956d67\grouping\db.mdb - error opening [4] C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\2410cc0df6b54754b57aa5f71ba04f3c\51490ccbd49e9582678e11e871956d67\grouping\edb.log - error opening [4] C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT - error opening [4] C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1 - error opening [4] C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2 - error opening [4] C:\Windows\System32\catroot2\edb.log - error opening [4] C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - error opening [4] C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - error opening [4] C:\Windows\System32\config\BBI - error opening [4] C:\Windows\System32\config\BBI.LOG1 - error opening [4] C:\Windows\System32\config\BBI.LOG2 - error opening [4] C:\Windows\System32\config\DEFAULT - error opening [4] C:\Windows\System32\config\DEFAULT.LOG1 - error opening [4] C:\Windows\System32\config\DEFAULT.LOG2 - error opening [4] C:\Windows\System32\config\SAM - error opening [4] C:\Windows\System32\config\SAM.LOG1 - error opening [4] C:\Windows\System32\config\SAM.LOG2 - error opening [4] C:\Windows\System32\config\SECURITY - error opening [4] C:\Windows\System32\config\SECURITY.LOG1 - error opening [4] C:\Windows\System32\config\SECURITY.LOG2 - error opening [4] C:\Windows\System32\config\SOFTWARE - error opening [4] C:\Windows\System32\config\SOFTWARE.LOG1 - error opening [4] C:\Windows\System32\config\SOFTWARE.LOG2 - error opening [4] C:\Windows\System32\config\SYSTEM - error opening [4] C:\Windows\System32\config\SYSTEM.LOG1 - error opening [4] C:\Windows\System32\config\SYSTEM.LOG2 - error opening [4] C:\Windows\System32\config\RegBack\DEFAULT - error opening [4] C:\Windows\System32\config\RegBack\SAM - error opening [4] C:\Windows\System32\config\RegBack\SECURITY - error opening [4] C:\Windows\System32\config\RegBack\SOFTWARE - error opening [4] C:\Windows\System32\config\RegBack\SYSTEM - error opening [4] C:\Windows\Temp\nsb1A38.exe » NSIS » Script.nsi - Win32/Conduit.SearchProtect.R potentially unwanted application C:\Windows\Temp\nscB22.exe » NSIS » Script.nsi - Win32/Conduit.SearchProtect.V potentially unwanted application C:\Windows\Temp\nsm6355.exe » NSIS » Script.nsi - Win32/Conduit.SearchProtect.V potentially unwanted application C:\Windows\Temp\nss6C01.exe » NSIS » Script.nsi - Win32/Conduit.SearchProtect.R potentially unwanted application C:\Windows\Temp\nstBA83.exe » NSIS » Script.nsi - Win32/Conduit.SearchProtect.R potentially unwanted application C:\Windows\Temp\nsvB301.exe » NSIS » Script.nsi - Win32/Conduit.SearchProtect.R potentially unwanted application Number of scanned objects: 229797 Number of threats found: 24 Number of cleaned objects: 0 Time of completion: 3:54:25 PM Total scanning time: 70 sec (00:01:10) Notes: [4] Object cannot be opened. It may be in use by another application or operating system. Edited February 23, 2015 by SBMongoos Link to comment Share on other sites More sharing options...
rugk 397 Posted February 24, 2015 Share Posted February 24, 2015 (edited) About the scan: As far as I can see this on the first view this is mostly PUA. Like I said you should be asked at the end of the scan what should be done with the fount threats.If you want to clean them right now, you could also use ESET SysRescue or ESET SysRescue Live (hxxp://www.eset.com/support/sysrescue).As for the second screenshot this is surely a bug. You can reproduce this?I have reported a similar bug some time ago. Maybe these bugs are similar (or maybe not of course )...https://forum.eset.com/topic/3999-ess-v8-freezes-and-shows-the-wrong-tab-in-gui/#entry23308 Edited February 24, 2015 by rugk Link to comment Share on other sites More sharing options...
Administrators Marcos 4,919 Posted February 24, 2015 Administrators Share Posted February 24, 2015 According to the first screen shot, the scan was competed successfully. Nothing was cleaned as the scan was most likely run with cleaning disabled. Had there been errors while cleaning, the errors would have been logged. Link to comment Share on other sites More sharing options...
rugk 397 Posted February 24, 2015 Share Posted February 24, 2015 @SBMongoos So just recheck your settings. Make sure your threat sense settings are configured this way: (and you also use this ThreatSense profile for scanning) And do not forget that this box shouldn't be checked: Link to comment Share on other sites More sharing options...
Recommended Posts