Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Win7 notebook hit by "Microsoft Support" scam, possible Rootki


  • Please log in to reply

#106
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,803 posts
Reboot the computer now and tell me everything is still ok.
  • 0

Advertisements


#107
HALlives

HALlives

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts

It seems to be okay, although it is taking noticably longer to boot. 

 

You get to the "Loading Windows" screen and the swirling dots, then there's a black screen for anywhere from 4-16 seconds before the Log-in screen opens. 


  • 0

#108
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,803 posts

Are you suggesting I hand her back the machine and tell her to go ahead and do all her online banking, taxes etc and not worry?

The machine is clean, there's no malware, more importantly there's nothing to worry about. Safe & sound. After a few more reboots it may boot faster.

Next

If you have any text files (.txt files) on the desktop, put them in a folder.

We need to remove all those tools we downloaded.

The following procedures will implement some cleanup procedures to remove these tools. It will also reset your System Restore by flushing out previous restore points and create a new restore point. It will also remove all the backups our tools may have made.
Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).

Why we need to remove some of our tools:
Some of the tools we have used to clean your computer were made by fellow malware fighters and are very powerful and if used incorrectly or at the wronge time can make the computer an expensive paper weight. They are updated all the time and some of them more than once a day so by the time you are ready to use them again they will already be outdated.

Download Dellfix https://www.bleeping...ownload/delfix/ by Xplode and save it to your desktop.
  • Run the tool by right click on the 51a5ce45263de-delfix.png icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run.
  • The program will run for a few seconds and display a notepad report.
    Paste it for my review.

  • 0

#109
HALlives

HALlives

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts
# DelFix v1.010 - Logfile created 17/02/2017 at 21:18:02
# Updated 26/04/2015 by Xplode
# Username : Barb - BARB-PC
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
 
~ Removing disinfection tools ...
 
Deleted : C:\Qoobox
Deleted : C:\32788R22FWJFW
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\Barb\Desktop\FRST-OlderVersion
Deleted : C:\TDSSKiller.3.1.0.12_15.02.2017_19.37.11_log.txt
Deleted : C:\Users\Barb\Desktop\adwcleaner_6.043.exe
Deleted : C:\Users\Barb\Desktop\aswMBR.exe
Deleted : C:\Users\Barb\Desktop\FRST64.exe
Deleted : C:\Users\Barb\Desktop\JRT.exe
Deleted : C:\Users\Barb\Desktop\MBR.dat
Deleted : C:\Users\Barb\Desktop\Silent Runners.vbs
Deleted : C:\Users\Barb\Downloads\Silent Runners.zip
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR
 
~ Cleaning system restore ...
 
Deleted : RP #45 [Scheduled Checkpoint | 02/08/2017 22:17:37]
Deleted : RP #47 [Restore Point Created by FRST | 02/13/2017 03:57:20]
Deleted : RP #49 [Restore Point Created by FRST | 02/14/2017 02:22:38]
Deleted : RP #50 [Windows Update | 02/15/2017 03:04:16]
Deleted : RP #51 [Restore Operation | 02/16/2017 02:27:20]
Deleted : RP #52 [JRT Pre-Junkware Removal | 02/18/2017 01:30:02]
Deleted : RP #54 [Restore Point Created by FRST | 02/18/2017 02:01:46]
 
New restore point created !
 
~ Resetting system settings ... OK
 
########## - EOF - ##########

  • 0

#110
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,803 posts
You're a good person to do all this work for Barb.

Please be assured that the computer is safe and nothing to worry about. I'll leave this topic open for a while In case you need something.

Thanks
Joe :)
  • 0

#111
HALlives

HALlives

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts

Thanks its been a long week and i need to crash! :)


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP