After removing the TeslaKrypt Virus when i boot my computer i get this error.
#1
Posted 30 January 2016 - 01:10 PM
#2
Posted 30 January 2016 - 01:37 PM
Please download Farbar Recovery Scan Tool and save it to your Desktop.
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
- Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
- Select additions at the bottom
- Press Scan button.
- It will produce a log called FRST.txt in the same directory the tool is run from.
- Please attach both logs generated.
#3
Posted 30 January 2016 - 01:54 PM
Here you go
Attached Files
#4
Posted 30 January 2016 - 02:23 PM
#5
Posted 30 January 2016 - 02:28 PM
Sorry about that lol got it confused here you go.
Attached Files
#6
Posted 30 January 2016 - 02:52 PM
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
HKU\S-1-5-21-2954068360-2895956722-819088778-1000\...\Run: [Idpwsoft] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\NorthP\AppData\Local\Ixsmsoft\mzrfocnl.dll
2016-01-29 16:32 - 2016-01-29 20:08 - 00000000 ___HD C:\Id3Lfn01uMHjikvC
2016-01-29 16:32 - 2016-01-29 20:05 - 00086304 _____ C:\spyhunter.fix
2016-01-29 04:44 - 2016-01-30 03:34 - 00000000 ____D C:\Users\NorthP\AppData\Local\Ixsmsoft
2016-01-03 04:54 - 2016-01-30 01:32 - 00000000 __HDC C:\ProgramData\{CF8DBD9D-2EFD-44F7-8D23-93B5C27D06D7}
2016-01-30 03:33 - 2015-06-04 09:44 - 00000000 ___HD C:\Users\NorthP\AppData\Local\0haexzEvrlru
2016-01-30 03:33 - 2014-08-12 10:37 - 00000000 ___HD C:\Users\NorthP\AppData\Local\02gMIi2NGGFFA
2016-01-30 03:33 - 2013-09-03 10:05 - 00000000 ___HD C:\Users\NorthP\AppData\Local\3gfNVtPRgkCSz
2016-01-30 01:32 - 2015-12-16 17:45 - 00000000 __HDC C:\ProgramData\{61A19DCC-35CF-45F2-9B6E-078047DDC28D}
2016-01-30 01:32 - 2015-02-18 10:13 - 00000000 __HDC C:\ProgramData\{2149AC3A-6876-48A5-8ACC-4DDA07B383D2}
2016-01-30 01:32 - 2015-02-18 10:08 - 00000000 __HDC C:\ProgramData\{BD761B7D-CF85-4D9F-8742-F8457E267565}
2016-01-30 01:32 - 2015-02-18 10:08 - 00000000 __HDC C:\ProgramData\{4F1011FE-3478-4D2B-8F9F-7EA7C144DFC2}
2016-01-30 01:32 - 2015-01-22 21:40 - 00000000 __HDC C:\ProgramData\{D9FE1BCD-7CBB-4429-93E8-07869EFFE08A}
2016-01-30 01:32 - 2015-01-21 22:44 - 00000000 __HDC C:\ProgramData\{B895D3F6-931C-4B01-A8AC-DCDBBE28F2F9}
2016-01-30 01:32 - 2015-01-20 14:38 - 00000000 __HDC C:\ProgramData\{3342DAE4-E9C8-491C-8DD2-FA5D6CB18DA6}
2016-01-30 01:32 - 2015-01-10 16:57 - 00000000 __HDC C:\ProgramData\{B7072B15-6E80-42FF-A9AE-4E62AF2B2418}
2016-01-30 01:32 - 2015-01-10 16:57 - 00000000 __HDC C:\ProgramData\{30FA7941-4170-4C83-A9A8-FDF01C431704}
2016-01-30 01:32 - 2014-12-30 08:07 - 00000000 __HDC C:\ProgramData\{3006A797-CDFA-44FC-98EF-155579E2CDBF}
2016-01-30 01:32 - 2014-08-30 19:24 - 00000000 __HDC C:\ProgramData\{087E1953-389C-4129-84BB-41E86CBEDF56}
2016-01-30 01:32 - 2014-08-28 15:39 - 00000000 __HDC C:\ProgramData\{7FFC8429-59AA-4310-831D-BDA0FDF42089}
2016-01-30 01:32 - 2014-08-28 15:38 - 00000000 __HDC C:\ProgramData\{B219DF15-4D19-412B-8C2C-CA83D4B20892}
2016-01-30 01:32 - 2014-08-27 23:11 - 00000000 __HDC C:\ProgramData\{39752E59-CE7D-4919-9B7F-020F8C66116C}
2016-01-30 01:32 - 2014-08-01 16:09 - 00000000 __HDC C:\ProgramData\{0EB7C0FC-5BF4-474E-B5F9-A6E991727B3E}
2016-01-30 01:31 - 2015-01-24 01:53 - 00000000 ____D C:\ProgramData\Globalscape
2016-01-30 01:31 - 2015-01-22 04:11 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-01-29 21:04 - 2014-10-03 19:23 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
CustomCLSID: HKU\S-1-5-21-2954068360-2895956722-819088778-1000_Classes\CLSID\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}\InprocServer32 -> C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\tsmf.dll => No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData:482EE99B1E21CE8C
AlternateDataStreams: C:\Users\All Users:482EE99B1E21CE8C
AlternateDataStreams: C:\ProgramData\Application Data:482EE99B1E21CE8C
AlternateDataStreams: C:\ProgramData\Microsoft:7xcZvmHdFBJnUZimSwk0gtDC96
AlternateDataStreams: C:\ProgramData\Microsoft:gVfN0FPTVfOjPSFjHqANlWH
AlternateDataStreams: C:\ProgramData\Microsoft:i2NGGFFAlczLYogETx7Q
AlternateDataStreams: C:\ProgramData\Microsoft:ne5y7L4fHVZEgKaOGugDRO
AlternateDataStreams: C:\ProgramData\Microsoft:PiFxbFf1UQbLYibTm
AlternateDataStreams: C:\ProgramData\Microsoft:SBI6rIn2edCogjBSEO
AlternateDataStreams: C:\ProgramData\Microsoft:sJhe70Itpv4JE0DaLZC90
AlternateDataStreams: C:\ProgramData\Microsoft:ZI8ZgrBvyMv5gGpVZ
AlternateDataStreams: C:\Users\NorthP\Local Settings:4UNsWCrCgjU6aVv5jyIBgAvdS9ciU1
AlternateDataStreams: C:\Users\NorthP\AppData\Local:4UNsWCrCgjU6aVv5jyIBgAvdS9ciU1
AlternateDataStreams: C:\Users\NorthP\AppData\Local\0haexzEvrlru:loYhfQkyhruyVgOS6jOoJV87Hft4
AlternateDataStreams: C:\Users\NorthP\AppData\Local\Application Data:4UNsWCrCgjU6aVv5jyIBgAvdS9ciU1
AlternateDataStreams: C:\Users\NorthP\AppData\Local\Temp:APgmbFsNHUkqmmBCKq8U
AlternateDataStreams: C:\Users\NorthP\AppData\Local\Temp:IkYXe9RayQEnEQVi6m
AlternateDataStreams: C:\Users\NorthP\AppData\Local\Temporary Internet Files:ojPTaTF40NGo5ITIFS75BWvL12
C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
- Close all open programs and internet browsers.
- Double click on AdwCleaner.exe to run the tool.
- Click on Scan.
- After the scan is complete click on "Clean"
- Confirm each time with Ok.
- Your computer will be rebooted automatically. A text file will open after the restart.
- Please post the content of that logfile with your next answer.
- You can find the logfile at C:\AdwCleaner[S0].txt as well.
#7
Posted 30 January 2016 - 03:08 PM
The error went away now thanks will run the adw cleaner
Attached Files
#8
Posted 31 January 2016 - 10:57 AM
#9
Posted 04 February 2016 - 12:28 PM
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Similar Topics
Also tagged with one or more of these keywords: RegSvr32
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users