Operating System
Windows 8
System logs
Yes, I've uploaded the FRST.txt logs
Yes, I've uploaded both FRST.txt and Addition.txt logs


New Member
Hi, and thanks in advance for your advice.
I couldn't run aswmbr, so no log of that attached. The computer was running Microsoft Security Essentials, but that has been disabled by the virus. There are multiple files being created under *username*/appdata/Local/ C:\Users\Owner\AppData\Local\ntuserlitelist This is the root to it all i cant get rid of it no matter what it regenerates even when i do get it to delete and it wont let me recover, run system restore or run windows security all anti virus programs including the one you have linked here do not work says resource in use. only thing i can get to run is frst.txt and lock hunter which temrinates the processes of the virus but i have to repetitively terminate the processes and reboot my pc when ram usage gets to high as it constantly builds everytime i reboot my pc. PLEASE HELP!!!!!!!!!!!!!!!!!!!!!!!!!


  • Like
Reactions: upnorth


Removal Expert
Staff member
Please download Farbar Recovery Scan Tool x64 and save it to a flash drive.
  • Now you should get a window like this where you need to click Troubleshoot.

  • In the next window, click Advanced options and select Command Prompt.
  • Now you should log in into your account and after that Command Promptwindow.
Access the notepad and identify your USB drive

In the Command Prompt please type in:
and press Enter.
  • When the notepad opens, go to File menu.
  • Select Open.
  • Go to Computer and search there for your USB drive letter.
  • Note down the letter and close the notepad.

Scan with Farbar Recovery Scan Tool

Once back in the command prompt window, please do the following:
  • Type in e:\frst64.exe and press Enter.
    You need to replace e with the letter of your USB drive taken from notepad!
  • FRST will start to run. Give him a minute or so to load itself.
  • Click Yes to Disclaimer.
  • In the main console, please click Scan and wait.
  • When finished it will produce a logfile named FRST.txt in the root of your pendrive and display it. Close that logfile.
Transfer it to your clean machine and include it in your next reply.