Jump to content

Ran Farbar Re Im Infected Instructions


Recommended Posts

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:21-08-2014
Ran by Carol at 2014-08-21 14:35:53 Run:4
Running from C:\Users\Carol\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
2014-07-28 19:18 - 2014-02-14 12:16 - 00000084 _____ () C:\Windows\system32\wcls.aou
2014-07-16 12:38 - 2014-07-16 12:38 - 00033280 _____ () C:\Windows\system32\psbgpti.eaz
2014-07-16 12:38 - 2014-02-13 17:48 - 00000296 _____ () C:\Windows\system32\zwrqa.dpi
HKLM\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start http://www.avg.com/w...gyMDEwKzItRkwxM (the data entry has 290 more characters).
AlternateDataStreams: C:\Windows:AstInfo
AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4
AlternateDataStreams: C:\ProgramData\TEMP:430C6D84
AlternateDataStreams: C:\ProgramData\TEMP:A8ADE5D8
AlternateDataStreams: C:\ProgramData\TEMP:AC9C6AC1
AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2

 

*****************

C:\Windows\system32\wcls.aou => Moved successfully.
C:\Windows\system32\psbgpti.eaz => Moved successfully.
C:\Windows\system32\zwrqa.dpi => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AvgUninstallURL => value deleted successfully.
"C:\Windows" => ":AstInfo" ADS not found.
C:\ProgramData\TEMP => ":0B4227B4" ADS removed successfully.
C:\ProgramData\TEMP => ":430C6D84" ADS removed successfully.
C:\ProgramData\TEMP => ":A8ADE5D8" ADS removed successfully.
C:\ProgramData\TEMP => ":AC9C6AC1" ADS removed successfully.
C:\ProgramData\TEMP => ":D1B5B4F1" ADS removed successfully.
C:\ProgramData\TEMP => ":DFC5A2B2" ADS removed successfully.

==== End of Fixlog ====

Link to post
Share on other sites

  • Replies 89
  • Created
  • Last Reply

Top Posters In This Topic

Hi,

 

 

You can uninstall programs that you had to install (e.g. MBAM or ESET Onlinescanner) in the control panel if you so wish.

 

I recommend you to scan your pc from time to time with MBAM & ESET. So, there is no need to uninstall.

 

You can't "uninstall" FRST because, it was never installed. If you run DelFix, FRST will be deleted automatically. Otherwise you can delete it manually. :)

Link to post
Share on other sites

Okay. I ran it in the meantime. Here is the log file, DelFix.txt:

 

# DelFix v10.8 - Logfile created 22/08/2014 at 20:58:53
# Updated 29/07/2014 by Xplode
# Username : Carol - BILL
# Operating System : Windows Vista Home Basic Service Pack 2 (32 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\Carol\Desktop\FRST-OlderVersion
Deleted : C:\Users\Carol\Desktop\Addition.txt
Deleted : C:\Users\Carol\Desktop\AdwCleaner.exe
Deleted : C:\Users\Carol\Desktop\esetsmartinstaller_enu.exe
Deleted : C:\Users\Carol\Desktop\Fixlog.txt
Deleted : C:\Users\Carol\Desktop\FRST.exe
Deleted : C:\Users\Carol\Desktop\FRST.txt
Deleted : C:\Users\Carol\Desktop\Search.txt
Deleted : C:\Users\Carol\Desktop\TFC.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware

~ Creating registry backup ... OK

~ Cleaning system restore ...

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########

Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.