Greetings redbchtrblr and
My nickname is Ruggie and I will be assisting you in cleaning your computer.
Please be aware I am currently in the final stages of training right now and all my work will be checked by an instructor so there may be a slight delay between posts. The added benefit to this is that you will have 2 sets of eyes looking at your problem so you can be assured you will get the best possible help.
- Malware removal can be a long process and will at times get complicated with multiple steps to perform to ensure that your system is no longer infected.
- When we start the process, the list of instructions must be followed closely, it may seem difficult at times but it is important that you stay with me until your computer is declared clean.
- If you are receiving help elsewhere, please let me know so we can close this thread and help someone else.
Before going any further, I recommend that you print out (or save to a file) these guidelines and also the instructions when I post them, as part of the repair process may involve going into safe mode and therefore you will not have internet access.
The following guidelines are important but the ones highlighted in RED are of the highest importance and must not be skipped.
Please be aware, the fixes we perform are specific to this machine, at this moment in time. They must not be used on another computer or unsupervised at another time. This can render your computer unbootable.
If at all possible, Make backups of all your important files, whilst we will do our best to ensure that no files are lost or damaged, sometimes things can go wrong.
I will do everything in my power to ensure that this clean is successful, but occasionally failure hits us all. In this event, please have your original installation disks to hand and be prepared to have to format and reinstall your computer.
Refrain from using any tool that hasn't been instructed as it could alter the process that we are working through and cause further problems. Also only use the tools I instruct in the manner provided as they are very powerful and if not used properly can cause even more problems. It is best if you can avoid using the computer at all, apart from to perform the cleaning steps to ensure that any infections aren't spread.
Please stick with me until the end. malware removal is difficult and time consuming. We have to analyse hundreds of lines in log files. This takes time which we give freely so I ask that you do us the courtesy of seeing it through.
Only paste the contents of log files into your reply, DO NOT attach any log files unless requested to do so.
If you have any questions or get stuck, stop and ask....I am here to help you make this go as smoothly as possible.
If you do not reply within 3 days, your topic will be closed. It can be reopened if you ask. But if you plan on being gone for a longer period, just let me know and I will hold it open for you.
Ready? Now lets get to work
I would like to see fresh logs with updated software so please follow the steps below.
Initial FRST Scan
Please download Farbar Recovery Scan Tool and save it to your Desktop. There will be 2 versions offered, if you know which version is the one you need, download that one, if not, download both, only one will work on your computer, that is the one you need.
- Right click to run as administrator. When the tool opens click Yes to the disclaimer.
- Ensure that the following are ticked as in the image below
- Press Scan button.
- It will produce a log called FRST.txt in the same directory the tool is run from.
- Please copy and paste log back here.
- This will also generate another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
Download aswMBR.exe ( 511KB ) to your desktop. If you already have this application, this is a new version I need you to download.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
If your computer supports Virtualization Technology, select Yes to use it for rootkit detection. When it offers to download the virus database allow that as well
On completion of the scan click Save Log, save it to your desktop and post in your next reply
The tool will also produce a copy of the mbrdump labeled MBR.dat. Please do not delete this file, it will be removed in our cleanup at the end.
Items I need to see in your next post:
- FRST and Addition Log
- ASWmbr Log