Fiery said:When you are in FRST, are you pressing Scan or Fix?
start
HKU\Chris\...\Winlogon: [Shell] explorer.exe,C:\Users\Chris\AppData\Roaming\skype.dat [62976 2011-11-18] ()
2013-02-07 18:38 - 2013-02-08 07:57 - 00000004 ____A C:\Users\Chris\AppData\Roaming\skype.ini
end
Fiery said:Ok. Delete all the FRST logs, including FRST itself from the USB. Download a new copy of FRST and place it onto the USB. As well, make a new fixlist.txt.
Open notepad and copy & paste the following:
start
HKU\Chris\...\Winlogon: [Shell] explorer.exe,C:\Users\Chris\AppData\Roaming\skype.dat [62976 2011-11-18] ()
2013-02-07 18:38 - 2013-02-08 07:57 - 00000004 ____A C:\Users\Chris\AppData\Roaming\skype.ini
end
and save it as fixlist.txt onto your flash drive.
Then, boot to system recovery, plug in your flash drive, open FRST and click fix. Post the generated log and attempt to boot to normal mode again
Fiery said:Here you go:
<a title="External link" href="http://download.bleepingcomputer.com/farbar/FRST.exe" rel="nofollow external"><>Farbar Recovery Scan Tool</></a>
Fiery said:I just want to clarify, you can boot to normal mode now? Is that correct?
Fryern said:Thanks again,
You are looking at tomorrow or worst case Sunday for the analysis. I will also send the fixlist final log
Fiery said:You can try to connect to the internet via wired connection and see if you can download those tools.
If you are unable to connect, then you'll have to use your Mac to download the files and transfer them to the infected PC
Fryern said:Thanks again,
You are looking at tomorrow or worst case Sunday for the analysis. I will also send the fixlist final log
How do you suggest I connect my PC to the internet to do the download? If I use this mac I go for a walk and just hope something turns up. It is very old with lots of version conflicks.If I plug it in via ethernet will it see the connection. I can play with wireless in my own time.
Fiery said:Good!
Try getting roguekiller and OTL on to the machine
Fiery said:Did you click delete in roguekiller? if not, that first. Also in roguekiller, click fix host
Yes, I then did another log and it was empty. I'll doit again to be sure
Then let's try this.
Download OTH from here to your PC.
- Start OTH and click Kill All Processes
- Click Start OTL
- Click the Scan All Users checkbox.
*]Check the boxes beside LOP Check and Purity Check- Click on Run Scan at the top left hand corner.
- Please post the contents of the logs in your next reply.