Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

PC riddled with malware plus SpyHunter [Solved]


  • This topic is locked This topic is locked

#16
peter plus

peter plus

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 278 posts

All seems to be running fine again.

Thank you


  • 0

Advertisements


#17
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts

All seems to be running fine again.

Thank you


Hello :)

That's great! One file still to be removed and then we'll have some cleanup procedures to go through.
  • Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy.
  • Right-click in the open notepad and select Paste).
  • Save it on the desktop as fixlist.txt

Start
C:\Users\All Users\InstallMate\{9A57F033-F89B-497A-AB91-B0B941B4D2C5}\Custom.dll
End


NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.


Run FRST and press the Fix button just once and wait. The tool will make a log on the desktop (Fixlog.txt) please post it in your next reply.


Things I need to see in your next post:

Fixlog.txt Log

  • 0

#18
peter plus

peter plus

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 278 posts

 Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 27-12-2014

Ran by Nigel at 2014-12-28 15:02:13 Run:2
Running from C:\Users\Nigel\Desktop
Loaded Profile: Nigel (Available profiles: Nigel)
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
Start
C:\Users\All Users\InstallMate\{9A57F033-F89B-497A-AB91-B0B941B4D2C5}\Custom.dll
End
*****************
 
"C:\Users\All Users\InstallMate\{9A57F033-F89B-497A-AB91-B0B941B4D2C5}\Custom.dll" => File/Directory not found.
 
==== End of Fixlog 15:02:13 ====
 
All running fine

  • 0

#19
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Hello :)

Great news, your logs are CLEAN! :thumbsup: :) but we still have a few things we need to address namely:
  • I need to remove the tools we installed on your machine.
  • We also have some programs on your machine that need updating to help protect you in the future.
Step 1: Tool Removal with Delfix and Creation of a clean restore point
  • Download Delfix from here
  • Ensure Remove disinfection tools is ticked
    Also tick:
    • Create registry backup
    • Purge system restore
    delfix.jpg
  • Click Run
The program will run for a few moments and then notepad will open with a log. Please paste the log in your next reply.

You can uninstall ESET Online Scanner at this time.

I recommend keeping Malwarebytes Anti-Malware installed. Make sure to update it and run it at least once a week. If it finds things such as PUP's (Potentially Unwanted Programs) you can delete those with no worries. However, if it finds something like a trojan, come see us.


Step 2: Java Warning and Update

A word about Java

Java has become the #1 program exploited by thieves and hackers as of today. It's gotten so bad, the Department of Homeland Security recently recommended that users disable Java on their machines.

For more information regarding this, see the two articles below:

Forbes: US Department of Homeland Security Calls on user do disable Java

US warns on Java software

Unless you have software on your machine that absolutely requires Java, I highly recommend you completely remove it from your system.

If you do have software that requires it, then disable it until such time as it's needed by those programs.

Please click the link below for instructions to disable Java.

How to Disable Java in your Web Browser


If you wish to continue to use Java on your machine, please be sure to keep it updated by following the instructions below.
  • Click on this link Java Website and click Do I Have Java?
  • Then click the Verify Java Version button. It will scan your current version and show you if you have the most current version.
You can find instructions for manually removing older versions for Windows XP, Vista, and 7 by clicking the link below:

Instructions for manually removing old versions of Java


Step 3: Tips, Information, and Optional Installation of Unchecky
  • Do not use P2P programs. This is a guaranteed way to get infected.
  • Watch what you open in your emails. If you get an email from an unknown source with any attached files, do not open it.
  • Install and keep only one anti-virus on your machine. Update it and scan your machine with it at least once a week.
  • Be careful of the websites you visit.
  • When installing new programs, don't be "click happy" and click through the screens. Many programs come with adware in them and are set to install them by default. Several programs require that you uncheck or select no to prevent the installation. Take you time and read each screen as you go. :)
To help protect yourself while on the web, I recommend you read How did I get infected in the first place?

Installation of Unchecky

This is a very good little program that will automatically uncheck any boxes during a software installation. This helps prevent the software from installing any malware that is by default checked while the program is being installed.

Click here to be taken to Unchecky.com

Click the very large Download button.

Click Save

Once downloaded, double click the program (Vista, Win 7, and 8, right click and Run as Administrator)

Once open, click the Install button.


unchecky1_zps667e512d.jpg


Then click Finish

unchecky2_zpsca4e7d0d.jpg


Unchecky is now installed and will help you keep unwanted check boxes unchecked. :thumbsup:

Things I need to see in your next post:

Delfix Log

  • 0

#20
peter plus

peter plus

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 278 posts
# DelFix v10.8 - Logfile created 28/12/2014 at 15:23:45
# Updated 29/07/2014 by Xplode
# Username : Nigel - NIGEL-PC
# Operating System : Windows 8.1  (64 bits)
 
~ Removing disinfection tools ...
 
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\TDSSKiller.3.0.0.42_27.12.2014_22.48.54_log.txt
Deleted : C:\Users\Nigel\Desktop\Fixlog.txt
Deleted : C:\Users\Nigel\Desktop\FRST64 (2).exe
Deleted : C:\Users\Nigel\Desktop\JRT.txt
Deleted : C:\Users\Nigel\Downloads\Addition.txt
Deleted : C:\Users\Nigel\Downloads\AdwCleaner.exe
Deleted : C:\Users\Nigel\Downloads\Extras.Txt
Deleted : C:\Users\Nigel\Downloads\FRST.exe
Deleted : C:\Users\Nigel\Downloads\FRST.txt
Deleted : C:\Users\Nigel\Downloads\FRST64 (1).exe
Deleted : C:\Users\Nigel\Downloads\FRST64.exe
Deleted : C:\Users\Nigel\Downloads\JRT.exe
Deleted : C:\Users\Nigel\Downloads\MiniToolBox.exe
Deleted : C:\Users\Nigel\Downloads\OTL.Txt
Deleted : C:\Users\Nigel\Downloads\OTL (1).exe
Deleted : C:\Users\Nigel\Downloads\OTL (2).exe
Deleted : C:\Users\Nigel\Downloads\OTL (3).exe
Deleted : C:\Users\Nigel\Downloads\OTL (4).exe
Deleted : C:\Users\Nigel\Downloads\OTL.exe
Deleted : C:\Users\Nigel\Downloads\SecurityCheck (1).exe
Deleted : C:\Users\Nigel\Downloads\SecurityCheck.exe
Deleted : C:\Users\Nigel\Downloads\tdsskiller.exe
Deleted : C:\Users\Nigel\Downloads\TFC (1).exe
Deleted : C:\Users\Nigel\Downloads\TFC.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
 
~ Creating registry backup ... OK
 
~ Cleaning system restore ...
 
Deleted : RP #55 [Windows Update | 12/10/2014 12:12:49]
Deleted : RP #56 [Windows Update | 12/14/2014 17:38:42]
Deleted : RP #57 [Windows Update | 12/18/2014 13:34:18]
Deleted : RP #58 [Scheduled Checkpoint | 12/26/2014 22:01:30]
Deleted : RP #60 [Restore Point Created by FRST | 12/27/2014 22:19:19]
 
New restore point created !
 
########## - EOF - ##########

  • 0

#21
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Looks good! :thumbsup: If we can be of further service in the future, please don't hesitate to come see us.

Safe surfing!

Pystryker :wave:
  • 0

#22
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP