|
Post by jayman153 on Nov 11, 2016 10:38:24 GMT -8
FRST.txt (119.83 KB)I have the virus on one of three machines. I have been using Nortons 360, but it will not remove this one. It is causing the machine to restart several times a day. Other than that the machine seems to be running fine. I will add frst.txt as soon as I have it. Thanks
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on Nov 11, 2016 22:19:44 GMT -8
I also need the Addition.txt file that FRST made on it's first scan. See below for the details on making (if you need to) the log and using wikisend.com to upload to and attach the url link to the file. Please follow the steps in this thread ( I think I am infected. What do I do? ). Notice that you will need to use wikisend.com to supply me with the Addition.txt log; steps to do this are explained here . Once you have provided the logs required, I will assist you as best we can. Thank you.
|
|
|
Post by jayman153 on Nov 12, 2016 7:42:29 GMT -8
I'm sorry for the extra steps for you. I will try to do a better job at following directions.
wikisend.com/download/678646/FRST.txt wikisend.com/download/212054/Addition.txt
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on Nov 12, 2016 11:05:07 GMT -8
FIRST >>>>Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed): Coupon Printer for Windows QuickTime 7 ShopAtHome.com Helper ShopAtHome.com Toolbar Yahoo Search SetTo do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window. Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software. SECOND >>>>Open notepad by pressing the Windows Key + R key, typing notepad in the Run box and pressing Enter. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy. Paste this into the open notepad. Save it to your desktop as fixlist.txtNOTE. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating systemStart FRST that is on the desktop by right clicking on file and selecting "Run as Administrator..." and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply. THIRD >>>>Please download Malwarebytes Anti-Rootkit from here- Unzip the contents to a folder in a convenient location.
- Open the folder where the contents were unzipped and run mbar.exe
- Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
- Click on the Cleanup button to remove any threats and reboot if prompted to do so.
- Wait while the system shuts down and the cleanup process is performed.
- Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
- When done, please post the two logs produced they will be in the MBAR folder... mbar-log.txt and system-log.txt .
[/ul] LAST >>>>INFO TO REPLY WITH:How is your system running now? How did the uninstall(s) go? Any problems? The Fixlog.txt text file (you should be able to attach this file; no need for wikisend.com usually). The logs from MBAR - mbar-log.txt and the system-log.txt files please. Any questions?
|
|
|
Post by jayman153 on Nov 12, 2016 12:27:21 GMT -8
I was unable to complete the first step. I could not find reference to "ShopAtHome.com" other than an SAH install.ini, FRST & addition.txt files. Can I proceed with the steps or must I do something else? Waiting for you. Thanks, Jay
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on Nov 12, 2016 19:01:58 GMT -8
In your Programs and Features list (in the Control Panel), what is listed in the S titles?
|
|
|
Post by jayman153 on Nov 12, 2016 19:11:47 GMT -8
I have Samsung USB Driver...; Smart Switch; Sound Blaster... and Symantec. I did find and delete a shortcut to ShopAtHome on my start menu.
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on Nov 12, 2016 19:48:09 GMT -8
Ok; continue on with the directions and we will deal with ShopAtHome later. Thanks.
|
|
|
Post by jayman153 on Nov 12, 2016 22:44:36 GMT -8
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on Nov 13, 2016 1:28:38 GMT -8
Understood; will check with you tomorrow. For now, it looks like wikisend.com is down (I can not ping the site nor download your files) but I will check in the morning.
Thanks for the assistance on your end.
|
|