|
Post by nickmcmillan on Oct 10, 2016 11:15:39 GMT -8
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on Oct 10, 2016 12:58:59 GMT -8
FIRST >>>>Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed): ShopAtHome.com ToolbarTo do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window. Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software. SECOND >>>>Open notepad by pressing the Windows Key + R key, typing notepad in the Run box and pressing Enter. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy. Paste this into the open notepad. Save it to your desktop as fixlist.txtNOTE. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating systemStart FRST that is on the desktop by right clicking on file and selecting "Run as Administrator..." and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply. LAST >>>>Please tell me how the system is running now? Does the warning come back after the reboot?
|
|
|
Post by nickmcmillan on Oct 11, 2016 4:25:47 GMT -8
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on Oct 11, 2016 7:33:22 GMT -8
It would be easier to use separate threads as it makes keeping the logs / fixes / follow ups less confusing on my end. We need to run a search on this machine as there was a registry key that I want to make sure is removed. [/b] to disclaimer. Type software\gpfcxvufgp into the Search Box. Press the Search Registry button. It will produce a log called search.txt or SearchReg.txt in the same directory the tool is run from. Please copy and paste log back here. [/ul]
|
|
|
Post by nickmcmillan on Oct 11, 2016 8:25:07 GMT -8
Farbar Recovery Scan Tool (x64) Version: 10-10-2016 Ran by RWRPGL2 (11-10-2016 12:14:28) Running from C:\Users\RWRPGL2\Desktop Boot Mode: Normal
================== Search Registry: "software\gpfcxvufgp" ===========
====== End of Search ======
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on Oct 11, 2016 8:43:43 GMT -8
Cool; let's close this one out please. We need to remove the tools we've used during the cleaning of your machine. [/a] Ensure the following is ticked: - Remove disinfection tools
- Create registry backup
- Purge system restore
[/ul] Then click Run. The program will run for a few moments and then notepad will open with a log. Please paste the log in your next reply. Once you have the log file saved, please reboot your system to complete the clean up process.
|
|
|
Post by nickmcmillan on Oct 11, 2016 11:15:38 GMT -8
# DelFix v1.010 - Logfile created 11/10/2016 at 15:03:50
# Updated 26/04/2015 by Xplode
# Username : RWRPGL2 - PF00S9PP
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
~ Removing disinfection tools ...
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\RWRPGL2\Desktop\FRST-OlderVersion
Deleted : C:\Users\RWRPGL2\Desktop\Addition.txt
Deleted : C:\Users\RWRPGL2\Desktop\Fixlog.txt
Deleted : C:\Users\RWRPGL2\Desktop\FRST.txt
Deleted : C:\Users\RWRPGL2\Desktop\FRST64.exe
Deleted : C:\Users\RWRPGL2\Downloads\AdwCleaner.exe
~ Creating registry backup ... OK
~ Cleaning system restore ...
Deleted : RP #110 [Windows Update | 09/16/2016 07:00:47]
Deleted : RP #111 [Windows Update | 09/18/2016 07:00:44]
Deleted : RP #112 [Windows Update | 09/22/2016 11:52:26]
Deleted : RP #114 [Restore Point Created by FRST | 10/11/2016 11:43:52]
New restore point created !
########## - EOF - ##########
|
|