Solved Back again!

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
I need help! Same issues as three weeks ago, don't know how it got fixed then?? But have tried to fix with doing everything, scans etc.. but still not working properly!
 

Attachments

  • Addition - FRST 2 4-07-15.txt
    29.5 KB · Views: 23
  • FRST 2 4-07-15.txt
    586.4 KB · Views: 24
  • Addition FARBAR 4-07-15.txt
    29.3 KB · Views: 22
  • AdwCleaner[R1].txt 4-06-15.txt
    1 KB · Views: 23
  • mbar-log-2003-12-31 (22-33-15).txt
    2.2 KB · Views: 22

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
Helllo,

My name is Argus and and I will be helping you with your computer problems.

Before we begin, please note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The logs can take some time to research, so please be patient with me.
  • Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • Please do not run any tools until requested ! The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.
  • Please perform all steps in the order received. If you can't understand something don't hesitate to ask.
  • Again I would like to remind you to make no further changes to your computer unless I direct you to do so. I will not help you if you do not follow my instructions.




warning.gif
Rules and policies

We won't support any piracy.
That being told, if any evidence of illegal OS, software, cracks/keygens or any other will be revealed, any further assistance will be suspended. If you are aware that there is this kind of stuff on your machine, remove it before proceeding!
The same applies to any use of P2P software: uTorrent, BitTorrent, Vuze, Kazaa, Ares... We don't provide any help for P2P, except for their removal. All P2P software has to be uninstalled or at least fully disabled before proceeding!

Failure to follow these guidelines will result with closing your topic and withdrawning any assistance.




51a5bf3d99e8a-ComboFixlogo16.png
Scan with ComboFix

This is a very powerful tool that should be used only if advised by Malware Analyst.
Do not run ComboFix on your own!


Referring to this instruction, please download ComboFix by sUBs and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a5bf3d99e8a-ComboFixlogo16.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Accept the disclaimer and agree if prompted to install Recovery Console.
  • Do not take any actions while ComboFix goes through your System - it may cause it to stall!
  • This scan may take some time!
  • When finished - it will display a logfile (located also on your main drive, usually C:\ComboFix.txt).

Include that log in your next reply.
icon_idea.gif
If you'll encounter any issues with internet connection after running ComboFix, please visit this link.
icon_idea.gif
If an error about operation on the key marked for deletion will appear after running the tool, please reboot your machine.
 

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
Hi Argus, appreciate your help! I have completed the combofix and have attached the log! Thank you!!
 

Attachments

  • log.txt combo fix 4-08-15.txt
    26.2 KB · Views: 22

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
Uninstall McAfee
http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe


1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:

Code:
Folder::
c:\program files\Lavasoft

Driver::
gzflt

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif


Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at C:\ComboFix.txt which I will require in your next reply.
 

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
Sorry Argus, but I don't know how to save the CFScript.txt in the same location as ComboFix.exe??
 

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
Thanks Argus! Done and attached!
 

Attachments

  • combo fix 2 4-8-15 log.txt
    24.1 KB · Views: 20

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
So far so good! It has restarted itself and I have opened a web browser, just one, and it seems ok! Thanks!! So do you know what the name of the thing that was in my computer that was causing the issues?? Is it fixed? Thanks again!
 

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\User\WINDOWS
c:\windows\system32\config\systemprofile\WINDOWS

I think this is a problem. Legitimate location is C:\Windows


Download DelFix by Xplode and save it to your desktop.
  • Run the tool by right click on the
    51a5ce45263de-delfix.png
    icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run and wait until the tool completes his work.
  • All tools we used should be gone. Tool will create an report for you (C:\DelFix.txt)
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
 

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
Sorry for the delay Argus, I have been trying to figure this out... Is there something I should do with the following info?? >>
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\User\WINDOWS
c:\windows\system32\config\systemprofile\WINDOWS

Are there changes I should make??

Do I need to set up an administrator with password on my computer to do the DelFix? I am it, so not sure if it is a required set up?? Or is there away around it??

Thanks Argus!
 

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
Thanks again Argus, done! Is there something I should do with this info you posted?? Should I be changing something??
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\User\WINDOWS
c:\windows\system32\config\systemprofile\WINDOWS
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top